Quantcast
Channel: Forefront TMG and ISA Server forum
Viewing all articles
Browse latest Browse all 3822

ISA 2004 IPSec VPN Routing Issue

$
0
0

Hi
I have an ISA2004 server (not able to be replaced yet) at a remote site in the Philippines connecting back to head office in Melbourne where there is a Juniper SRX210. The VPN is up and Melbourne has full access to the Philippines network. The Philippines network has access back to Melbourne but the Philippines server does not. The server is a DC as well as running ISA 2004. It has two NIC's, the internal with no gateway and the external with ISA controlling access. This is resulting in the server being unable to replicate Active Directory between sites. Debugging logs shows the issue to be with ISA, not a rule in Melbourne on the Juniper. The error is:

Denied Connection  10/20/2012 6:25:37 PM
Log type: Firewall service
Status: A packet generated on the local host was rejected because its source IP address is assigned to one network adapter and its destination IP address is reachable through another network adapter.
Rule: 
Source: Local Host ( 192.168.79.1:137)
Destination: Melbourne ( 192.168.75.6:137)
Protocol: NetBios Name Service
User: 
 Additional information
Number of bytes sent: 0 Number of bytes received: 0
Processing time: 0ms Original Client IP: 192.168.79.1
Client agent:
 
The Networks, Network Sets, Network Rules and routes all appear fine. How else is one supposed to setup ISA to send traffic from itself to the VPN tunnel? A static route to either its own internal IP or the external gateway kills the VPN. ISA should be intercepting the traffic and directing it over the tunnel. It is for the Philippines LAN just not for the server itself. It is the firewall service itself, there is no rule to tweak.

This is causing me no end of grief, any assistance appreciated. I have been through http://technet.microsoft.com/library/bb794765.aspx and it has not helped. Everything from Melbourne to the Philippines is fine, it is just the Philippines Server (the ISA one) that cannot see the Melbourne network. It also seems to be still trying to initiate an IP Sec VPN after the Juniper initiated SA is up and running and the VPN is up.

Thanks, Ben


Viewing all articles
Browse latest Browse all 3822

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>