Jump to content

Recommended Posts

Posted

Hi all,

 

Not sure if this is the right section of the forum but it looked the best place to put it for now

 

We've got an issue where flash content from websites such as vimeo is not loading for whatever reason.

 

Our (very) basic network outline for outbound traffic is - Client PC > ISA 2006 > suffolk CC cachebox with filtering > suffolk CC proxy server (@ suffolk CC). we operate a private 172.* network routed by ISA to our CC

 

The tests that i've done to rule out things such as the cachebox being at fault are;

Local admin user through ISA – Working, no authentication requested by ISA

Local user through ISA - Working, no authentication requested by ISA

Going through our DMZ out through our cachebox – Working

Test network accounts going via our county proxy (proxy.gfl.*, but will still be routed by isa) – Working

Test network user going through usual route (isa-01 > cachebox > proxy.gfl.*) – NOT WORKING

 

The previous solution to this was to put the URL into the internal networks web proxy direct access list. this has worked for some parts of youtube, google vids, etc but it's still very flakey.

Basically all content for the page loads and the flash box just sits loading.

 

Thanks

Posted
Have you tried setting up a monitoring filter in ISA to try and isolate the problem? I suggest you use the IP of a PC with the problem to see if ISA is blocking anything.
  • Thanks 1
Posted

No i hadn't, thanks.

 

The content appears to be allowed to load then it gives the message "10054 An existing connection was forcibly closed by the remote host"

The destination IP is our cache/filter box

Posted
Is the error also saying which rule its using? It could be a case of adding the IP address of the cache/filter box to the "Allow to" and "Allow from" in this rule.
Posted
It initiates the connection then allows the connection for about 2 seconds before closing the connection. about 50 allow logs in total but definately closing it fairly instantly
Posted

I was wondering which client type you have enrolled for your user : securenat, proxy or firewall client ?

 

bio..

Posted

Web proxy and firewall client support is enabled as well as NAT being used to forward clients out.

Not 100% sure if that's the information you mean though

Posted
Web proxy and firewall client support is enabled as well as NAT being used to forward clients out.

Not 100% sure if that's the information you mean though

 

Well what does you monitor log show ? is it a firewall client, webproxy client ? There is a huge difference on how the isa handles traffic by those types.

Another thing you might check since you forward traffic to another proxy/FW is connection rate limits. It could be that your isa is trying to open many connections to the upstream proxy and get denied by it. example : ISA Server Network Protection: Protecting Against Floods and Attacks

 

bio..

  • Thanks 1
Posted

Thanks, i'll take a look. would i be able to mail you a log if you PM me your address?

There are a few "too many connection" type warnings in the OS event viewer so it could well be somthing to do with it, although none of the IPs logged are my test PCs

  • 9 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...