Cisco ASA and Microsoft TMG Back to Back Issue

Hello Experts,

I have weird issue.

I have a Cisco ASA 5540 with 4 interfaces Outside,Inside, DMZ, TMG ( back to Back).

I have Microsoft TMG with 2 NICs. Internal Interface connected to Inside Switch and External directly connected to ASA TMG interface (Gi0/3).

I have default gateway on external interface pointing to ASA.

We are using TMG only as Web Proxy. Very often I start receiving call from user that cannot browse internet and they receive TMG error page.

When we move to TMG to diagnose the issue, we came to know that TMG cannot ping IP of ASA interface ( Gi0/3- Default of gateway TMG. In order to resolve this issue I have to reboot to the ASA.

Please can someone help to resolve this issue.

Thanks
LVL 3
cciedreamerAsked:
Who is Participating?
 
Craig BeckConnect With a Mentor Commented:
I'm good thanks, Samir, hope you are well :-)

I'd just take some traffic logs at the time you stop being able to pass traffic through the ASA.  You might be able to see something being blocked.

Do you have any IDS or IPS running?
0
 
Craig BeckCommented:
Hi Samir,

Can you do some debugging on the ASA?  The logs should be able to give you some clues if you check at around the time the issue started to happen.
0
 
cciedreamerAuthor Commented:
Hi Sir,

How are you ? Hope all is well.

Any important debug command to start with ?

Thanks
0
The IT Degree for Career Advancement

Earn your B.S. in Network Operations and Security and become a network and IT security expert. This WGU degree program curriculum was designed with tech-savvy, self-motivated students in mind – allowing you to use your technical expertise, to address real-world business problems.

 
cciedreamerAuthor Commented:
Yes  We have IPS and module installed on ASA ?
0
 
cciedreamerAuthor Commented:
I am just waiting to let issue appear again.

Thanks
0
 
cciedreamerAuthor Commented:
Thanks Sir,

Issue Resolved. ASA was putting the TMG server into shunned mode

I entered no shun command on ASA

I have no idea why ASA putting TMG server into shun mode.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.