Solved

User cannot authenticate to ISA 2006 with firewall client

Posted on 2013-01-14
11
1,876 Views
Last Modified: 2013-01-19
I have a ISA 2006 server setup in single adapter mode, it's being used just as a proxy, it has web filtering software installed on it.

Many users have the firewall client installed. Starting a few days ago users have a red x in the firewall client. "Disabled: cannot authenticate to ISA server".

Any ideas? I'm not sure how to trouble shoot this or what logs to look at, thanks. I have rebooted the pc's and the server itself, no luck.

Thanks
0
Comment
Question by:cb_it
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 4
11 Comments
 

Author Comment

by:cb_it
ID: 38775841
OK, I've done a full days worth of trouble shooting. The problem still exists but I have narrowed it down some. I have 2 ISA servers here. Proxy1 and Proxy2.

All users MS firewall client point to proxy1. If I point the fw client to proxy2 everything works as normal. Moving back to proxy1 and the problem returns. The red x will popup on the tray icon.

I'm the only IT person here and I have not made changes to the ISA server or anything else in the past couple days, that I can remeber!

I enabled logging on both servers and I can see on proxy1 the client "initiated connection" and then right away "closed connection". This shows port 1745.

Logging on proxy2 shows the initiated connection port 443 going out to the external ip address, rule is Allow ALL. This is good.

So it seems to be an authentication issue on proxy1 - any ideas?

I checked the event viewer on the client and found the following when the fw client points to proxy1. I'm logged in as a domain admin.



Event Type:      Error
Event Source:      Microsoft Firewall Client 2004
Event Category:      None
Event ID:      2
Date:            1/14/2013
Time:            11:12:08 AM
User:            N/A
Computer:      BR05CSR1
Description:
Application [EZTellerENT.EXE]. Authentication failed.
Verify that the user account running this application has the required permissions.
If the application is running under a system account, you can apply different credentials for
this application via the client configuration and FwcCreds.exe.
0
 
LVL 23

Accepted Solution

by:
Suliman Abu Kharroub earned 500 total points
ID: 38776252
From networking node ( ISA managment console), open internal network properties and try to disable firewall client and re enable it again.
0
 

Author Comment

by:cb_it
ID: 38776313
Clients are also getting this kerberos error at the same time as the above error. I dont have any dup machine accounts, that I can find. I've researched this error and many people talk about duplicate SPN's. (I changed the server and domain name below)


Event Type:      Error
Event Source:      Kerberos
Event Category:      None
Event ID:      4
Date:            1/14/2013
Time:            3:34:13 PM
User:            N/A
Computer:      BR05CSR1
Description:
The kerberos client received a KRB_AP_ERR_MODIFIED error from the server host/proxy1.mydomain.com.  
This indicates that the password used to encrypt the kerberos service ticket is different than that on the target server.
Commonly, this is due to identically named  machine accounts in the target realm (MYDOMAIN.COM), and the client realm.
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 23

Expert Comment

by:Suliman Abu Kharroub
ID: 38776327
0
 

Author Comment

by:cb_it
ID: 38776641
I ran "setspn -L proxy1" on the actual proxy1 server and got the following. Doesnt look like I have any dup SPN's??

C:\Documents and Settings\bstrain\Desktop>setspn -L proxy1
Registered ServicePrincipalNames for CN=PROXY1,OU=Other Servers 2,DC=DOMAIN,DC=com:
    MSSQLSvc/PROXY1.DOMAIN.COM
    HOST/PROXY1
    HOST/PROXY1.DOMAIN.COM

any other spn test or checks I can do?? Thanks.
0
 
LVL 23

Expert Comment

by:Suliman Abu Kharroub
ID: 38777078
did you check the internal netowrk properties ?
0
 
LVL 16

Expert Comment

by:Bruno PACI
ID: 38777755
Hi,

I suppose your ISA servers are members of an AD domain !?
In this case, in the IP settings of these ISA servers, what DNS servers do interrogates ?

If you use internal and external DNS servers in your DNS servers list you will randomly encounter that sort of problems.

The ISA server must resolve internal AND external DNS names, but to do that IT MUST NOT interrogate external and internal DNS servers.
Why ? Because of that :

If you ISA server have to locate DCs of the AD domain to authenticate users, and if the ISA server interrogate external DNS servers for that, these DNS servers wil ALWAYS answer "domain does not exist", which is an authoritative negative answer.
With this type of answers the DNS client on the ISA server will stop to try to resolve the name by any other way and will suppose the domain does not exists and is unreachable. So the authentication will fail.


What MUST be done:
Your ISA servers must ONLY interrogate internal DNS servers. The internal DNS servers host the DNS zone for the internal AD domain and must be configured with DNS forwarders that point to external DNS servers.
Doing like this the internal DNS servers will retransmit DNS request for any external name to external DNS servers.


Have a good day.
0
 

Author Comment

by:cb_it
ID: 38778144
Sulimanw - what would I check the internal network properties for? Nothing has changed. I'm the only one with access to make any changes.

As for the last comment, our ISA servers are not used as firewalls, they are just in a single adapter mode, they dont have any external DNS settings, they just point to our internal DNS server.
0
 
LVL 23

Expert Comment

by:Suliman Abu Kharroub
ID: 38778550
Even if nothing changed, it worth's to check basices as a first troubleshooting step .
0
 

Author Comment

by:cb_it
ID: 38778802
I checked the internal network properties for both proxy1 and proxy2, they are the same and all settings seem OK.

I do have 'require all users to authenticate' turned on, this is needed for our web content filtering software on proxy1 to work properly. If I turn 'require all users to authenticate' off then all works well, so it seems more and more to point to some authentication problem on proxy1.

Any ideas??
0
 

Author Comment

by:cb_it
ID: 38787084
Anyone out there have ANY more ideas?? This error still keeps popping up on clients trying to authenticate to my ISA server.

I even tried removing the ISA server from the domain, deleting it's AD computer account, and rejoining to the domain. The problem persists!

Event Type:      Error
Event Source:      Kerberos
Event Category:      None
Event ID:      4
Date:            1/14/2013
Time:            3:34:13 PM
User:            N/A
Computer:      BR05CSR1
Description:
The kerberos client received a KRB_AP_ERR_MODIFIED error from the server host/proxy1.mydomain.com.  
This indicates that the password used to encrypt the kerberos service ticket is different than that on the target server.
Commonly, this is due to identically named  machine accounts in the target realm (MYDOMAIN.COM), and the client realm.
0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
FOPE 1 day Quarantine Notifications 4 283
Lync 2013 External Authentication 1 657
Upgrade TMG 2010 to Latest roll up 5 2 237
IRM and Office 2016 5 492
Forefront Threat Management Gateway 2010 or FTMG comes with some very neat troubleshooting tools built-in when trying to identify what is actually happening behind the scenes within the product when traffic is passing through its interfaces. To the …
So the following errors occurs in 2 ways that I am aware of at this stage, and you receive one of the following error messages: ERROR 1. When trying to save a rule: No Web listener is specified for the Web publishing rule Autodiscovery Publishin…

710 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question