kevbaz Posted July 1, 2009 Author Posted July 1, 2009 If telnet didn't work then your ISA server is most likely blocking it or it's unreachable further down the line. ISA servers normally can't web browse unless you have specifcally set them up to do so. Try doing a tracert to BBC - Homepage and see where the trace stops. I would still try the ALLOW all rule - just make sure that it's at the top above and deny rules and that you have applied the changes. If that still doesn't work the issue is probably further down the line. tracert to bbc website is destination host unreachable? not sure how to go about the allow all rule?
mb2k01 Posted July 1, 2009 Posted July 1, 2009 I'd guess as your internal mail is working fine on exchange it's probably not a DC or GC connectivity issue.... Is internal mail working fine? Lol i should really read more thoroughly
kevbaz Posted July 1, 2009 Author Posted July 1, 2009 its just very odd that we have internet access yet external emails in or out dont work and neither does the college website.... cant get my head around that
mrmontymick Posted July 1, 2009 Posted July 1, 2009 its just very odd that we have internet access yet external emails in or out dont work and neither does the college website.... cant get my head around that That's normally either a publishing error with ISA server or an ACL (access control list) error on your router or down the line with your ISP. External publishing of services in ISA is fairly differently setup from web browsing. Is your ISA server acting as a web proxy or do you pass requests through to an external web proxy or does your ISA server chain to an external web proxy? Have you asked your ISP if they can make a connection to your exchange server or website from their internal network? And to trace to see where it's stopping? If it stops at your ISA server address (technically probably just before it) then it's the ISA server that's causing the issue. If it stops before that it's a chaining/routing/ACL issue between you and your ISP. Again bypassing ISA or an overriding allow rule would probably help you diagnose this.
kevbaz Posted July 1, 2009 Author Posted July 1, 2009 yes one of our isa's is our web proxy, swgfl said they could find no errors on their end when they tested earlier. how do i go about creating an allow rule?
elsiegee40 Posted July 1, 2009 Posted July 1, 2009 It is unlikely to be your problem as I'm sure you've actually checked, but I wasted an hour on Monday because a CAT5 cable wasn't plugged into the back of a PC... A(nother) visual check that everything is plugged into what's it's supposed to be plugged into may be worthwhile.
kevbaz Posted July 1, 2009 Author Posted July 1, 2009 checked checked and checked again everyhtign is as it should be
mrmontymick Posted July 1, 2009 Posted July 1, 2009 checked checked and checked again everyhtign is as it should be Can you just confirm your version of ISA.... I think you said 2003 earlier but from memory ISA comes in 2000, 2004, 2006 versions and then Forefront TMG is replacing it later this year.
mrmontymick Posted July 2, 2009 Posted July 2, 2009 yeah sorry its isa 2006 If you go into ISA Server Management Console and right click on "Firewall Policy" and then New -> Access rule you will bring up the appropriate wizard. Give it a name such as TEST ALLOW ALL and click next Select "Allow" and click next Under "This Rule Applies to...." select "All Protocols" and click next Select Access Rule source as "Internal" - click next Select Access Rule destination as "External" click next Click this rule applies to "Everyone" - or "All Users" - Can't remember which one of these it is. - Or you can specify your Exchange server and Web server by computer name. Then click finish. Now do the same again but have Access rule source as "external" and access rule destination as "internal" Make sure both rules are at the top of your firewall rules list and click apply changes at the top of the ISA page - wait a couple of minutes for it to update and then try your exchange and web access. * Sorry if the instructions are slightly vague I don't have an ISA server in the building I'm in at the moment. It is hopefully close enough to make sense! 1
kevbaz Posted July 2, 2009 Author Posted July 2, 2009 ok ive done the above, but as we have 2 isa's one in one out, ive applied them accordingly. how long do you normally have to wait for it to refresh?
kevbaz Posted July 2, 2009 Author Posted July 2, 2009 15mins gone and still no change. ive rang swgfl again and they are now also looking into it, im hoping its just something their end....
kevbaz Posted July 2, 2009 Author Posted July 2, 2009 is it possible one of the isa servers is in shutdown mode? my outbound isa has wspsrv.exe running but my inbound one doesnt, but according to services all firewall services are running?
mrmontymick Posted July 2, 2009 Posted July 2, 2009 is it possible one of the isa servers is in shutdown mode? my outbound isa has wspsrv.exe running but my inbound one doesnt, but according to services all firewall services are running? Yes, I would think that's an issue, from memory I think if it's not working then the ISA server drops to the default DENY ALL state. Does the Microsoft Firewall server definately show as running in services? What happens if you try and start it manually from a CMD box: net start fwsrv 1
kevbaz Posted July 2, 2009 Author Posted July 2, 2009 Issue is now resolved, turns out on one of the isa servers the default gateway had been changed to an incorrect address on one of its lan cards!..... who did it and why is what im trying to acertain now.... thank you all ever so much for your help
mrforgetful Posted July 2, 2009 Posted July 2, 2009 I would suggest not making too many changes and definately documenting changes you do make, don't want to make things worse. In my 6 years of using Exchange (2000/2003) whenever we've run into problems, every time, it has not been us. Always the ISP. Have you raised a support ticket with them? They may know of some issue.
mrmontymick Posted July 2, 2009 Posted July 2, 2009 Issue is now resolved, turns out on one of the isa servers the default gateway had been changed to an incorrect address on one of its lan cards!..... who did it and why is what im trying to acertain now.... thank you all ever so much for your help Don't forget to look back at this thread and undo any test changes we have made. Particularly the ALLOW ALL rule on the ISA server - that must be taken back off or you are leaving yourself wide open.
kevbaz Posted July 2, 2009 Author Posted July 2, 2009 yep thats all done, all the settings are back to as they were. who reconfigured the lan card noone knows...
mrmontymick Posted July 2, 2009 Posted July 2, 2009 yep thats all done, all the settings are back to as they were. who reconfigured the lan card noone knows... I'm glad it's all working If you ever find the lan card changer do feel free to take them out the back and beat them with a big stick - I might even pop over and help out...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now