Cisco ASA and Microsoft TMG Back to Back Issue

cciedreamer
cciedreamer used Ask the Experts™
on
Hello Experts,

I have weird issue.

I have a Cisco ASA 5540 with 4 interfaces Outside,Inside, DMZ, TMG ( back to Back).

I have Microsoft TMG with 2 NICs. Internal Interface connected to Inside Switch and External directly connected to ASA TMG interface (Gi0/3).

I have default gateway on external interface pointing to ASA.

We are using TMG only as Web Proxy. Very often I start receiving call from user that cannot browse internet and they receive TMG error page.

When we move to TMG to diagnose the issue, we came to know that TMG cannot ping IP of ASA interface ( Gi0/3- Default of gateway TMG. In order to resolve this issue I have to reboot to the ASA.

Please can someone help to resolve this issue.

Thanks
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Top Expert 2014

Commented:
Hi Samir,

Can you do some debugging on the ASA?  The logs should be able to give you some clues if you check at around the time the issue started to happen.

Author

Commented:
Hi Sir,

How are you ? Hope all is well.

Any important debug command to start with ?

Thanks
Top Expert 2014
Commented:
I'm good thanks, Samir, hope you are well :-)

I'd just take some traffic logs at the time you stop being able to pass traffic through the ASA.  You might be able to see something being blocked.

Do you have any IDS or IPS running?
Should you be charging more for IT Services?

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Author

Commented:
Yes  We have IPS and module installed on ASA ?

Author

Commented:
I am just waiting to let issue appear again.

Thanks

Author

Commented:
Thanks Sir,

Issue Resolved. ASA was putting the TMG server into shunned mode

I entered no shun command on ASA

I have no idea why ASA putting TMG server into shun mode.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial