Solved

User cannot authenticate to ISA 2006 with firewall client

Posted on 2013-01-14
11
1,791 Views
Last Modified: 2013-01-19
I have a ISA 2006 server setup in single adapter mode, it's being used just as a proxy, it has web filtering software installed on it.

Many users have the firewall client installed. Starting a few days ago users have a red x in the firewall client. "Disabled: cannot authenticate to ISA server".

Any ideas? I'm not sure how to trouble shoot this or what logs to look at, thanks. I have rebooted the pc's and the server itself, no luck.

Thanks
0
Comment
Question by:cb_it
  • 6
  • 4
11 Comments
 

Author Comment

by:cb_it
ID: 38775841
OK, I've done a full days worth of trouble shooting. The problem still exists but I have narrowed it down some. I have 2 ISA servers here. Proxy1 and Proxy2.

All users MS firewall client point to proxy1. If I point the fw client to proxy2 everything works as normal. Moving back to proxy1 and the problem returns. The red x will popup on the tray icon.

I'm the only IT person here and I have not made changes to the ISA server or anything else in the past couple days, that I can remeber!

I enabled logging on both servers and I can see on proxy1 the client "initiated connection" and then right away "closed connection". This shows port 1745.

Logging on proxy2 shows the initiated connection port 443 going out to the external ip address, rule is Allow ALL. This is good.

So it seems to be an authentication issue on proxy1 - any ideas?

I checked the event viewer on the client and found the following when the fw client points to proxy1. I'm logged in as a domain admin.



Event Type:      Error
Event Source:      Microsoft Firewall Client 2004
Event Category:      None
Event ID:      2
Date:            1/14/2013
Time:            11:12:08 AM
User:            N/A
Computer:      BR05CSR1
Description:
Application [EZTellerENT.EXE]. Authentication failed.
Verify that the user account running this application has the required permissions.
If the application is running under a system account, you can apply different credentials for
this application via the client configuration and FwcCreds.exe.
0
 
LVL 23

Accepted Solution

by:
Suliman Abu Kharroub earned 500 total points
ID: 38776252
From networking node ( ISA managment console), open internal network properties and try to disable firewall client and re enable it again.
0
 

Author Comment

by:cb_it
ID: 38776313
Clients are also getting this kerberos error at the same time as the above error. I dont have any dup machine accounts, that I can find. I've researched this error and many people talk about duplicate SPN's. (I changed the server and domain name below)


Event Type:      Error
Event Source:      Kerberos
Event Category:      None
Event ID:      4
Date:            1/14/2013
Time:            3:34:13 PM
User:            N/A
Computer:      BR05CSR1
Description:
The kerberos client received a KRB_AP_ERR_MODIFIED error from the server host/proxy1.mydomain.com.  
This indicates that the password used to encrypt the kerberos service ticket is different than that on the target server.
Commonly, this is due to identically named  machine accounts in the target realm (MYDOMAIN.COM), and the client realm.
0
Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

 
LVL 23

Expert Comment

by:Suliman Abu Kharroub
ID: 38776327
0
 

Author Comment

by:cb_it
ID: 38776641
I ran "setspn -L proxy1" on the actual proxy1 server and got the following. Doesnt look like I have any dup SPN's??

C:\Documents and Settings\bstrain\Desktop>setspn -L proxy1
Registered ServicePrincipalNames for CN=PROXY1,OU=Other Servers 2,DC=DOMAIN,DC=com:
    MSSQLSvc/PROXY1.DOMAIN.COM
    HOST/PROXY1
    HOST/PROXY1.DOMAIN.COM

any other spn test or checks I can do?? Thanks.
0
 
LVL 23

Expert Comment

by:Suliman Abu Kharroub
ID: 38777078
did you check the internal netowrk properties ?
0
 
LVL 16

Expert Comment

by:PaciB
ID: 38777755
Hi,

I suppose your ISA servers are members of an AD domain !?
In this case, in the IP settings of these ISA servers, what DNS servers do interrogates ?

If you use internal and external DNS servers in your DNS servers list you will randomly encounter that sort of problems.

The ISA server must resolve internal AND external DNS names, but to do that IT MUST NOT interrogate external and internal DNS servers.
Why ? Because of that :

If you ISA server have to locate DCs of the AD domain to authenticate users, and if the ISA server interrogate external DNS servers for that, these DNS servers wil ALWAYS answer "domain does not exist", which is an authoritative negative answer.
With this type of answers the DNS client on the ISA server will stop to try to resolve the name by any other way and will suppose the domain does not exists and is unreachable. So the authentication will fail.


What MUST be done:
Your ISA servers must ONLY interrogate internal DNS servers. The internal DNS servers host the DNS zone for the internal AD domain and must be configured with DNS forwarders that point to external DNS servers.
Doing like this the internal DNS servers will retransmit DNS request for any external name to external DNS servers.


Have a good day.
0
 

Author Comment

by:cb_it
ID: 38778144
Sulimanw - what would I check the internal network properties for? Nothing has changed. I'm the only one with access to make any changes.

As for the last comment, our ISA servers are not used as firewalls, they are just in a single adapter mode, they dont have any external DNS settings, they just point to our internal DNS server.
0
 
LVL 23

Expert Comment

by:Suliman Abu Kharroub
ID: 38778550
Even if nothing changed, it worth's to check basices as a first troubleshooting step .
0
 

Author Comment

by:cb_it
ID: 38778802
I checked the internal network properties for both proxy1 and proxy2, they are the same and all settings seem OK.

I do have 'require all users to authenticate' turned on, this is needed for our web content filtering software on proxy1 to work properly. If I turn 'require all users to authenticate' off then all works well, so it seems more and more to point to some authentication problem on proxy1.

Any ideas??
0
 

Author Comment

by:cb_it
ID: 38787084
Anyone out there have ANY more ideas?? This error still keeps popping up on clients trying to authenticate to my ISA server.

I even tried removing the ISA server from the domain, deleting it's AD computer account, and rejoining to the domain. The problem persists!

Event Type:      Error
Event Source:      Kerberos
Event Category:      None
Event ID:      4
Date:            1/14/2013
Time:            3:34:13 PM
User:            N/A
Computer:      BR05CSR1
Description:
The kerberos client received a KRB_AP_ERR_MODIFIED error from the server host/proxy1.mydomain.com.  
This indicates that the password used to encrypt the kerberos service ticket is different than that on the target server.
Commonly, this is due to identically named  machine accounts in the target realm (MYDOMAIN.COM), and the client realm.
0

Featured Post

Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Publishing Lync 2013 using Firewall 9 492
Server 2012 Domain Controler 4 456
forefront TMG internet logs 1 101
Restrict External Access to OWA 12 98
Forefront is the brand name for Microsoft's major security product. Forefront covers a number of specific security areas and has 'swallowed' a number of applications under this umbrella including Antigen, ISA Server, the Integrated Access Gateway (t…
So the following errors occurs in 2 ways that I am aware of at this stage, and you receive one of the following error messages: ERROR 1. When trying to save a rule: No Web listener is specified for the Web publishing rule Autodiscovery Publishin…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

786 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question