Hi,
Please believe i do do my own research all the time but i really am
stuck and am getting depressed!!!
In a nut shell, We have and 1 SBS 2000 server using exchange and ISA
+ ADSL with static IP, this basically connects up to and ISP's POP box
(I know it's not the right way)and downloads the mail.
Now this setup has worked pretty well for the last few years but on
friday it went a bit wrong, we were trying to work out why a specific
SSL site would not work over our proxy thus were trying new rules and
playing with the SSL listeners etc. After all this it became evident
there was a small compat. issue between the site and ISA.
Anyhow we put everything back the way it was........and guess what is
don't work. Now exchange does send out all SMTP with no probs and the
POP connector brings down the mail also however we have no idea in
hell where they now go, have checked all the que etc. + the POP
inforward folders + all relevant services.
On top of that I can no longer access OWA even from the server - just
keep getting 403 forbidden. Now i cant help thinking that it must be
a rule or policy however i've set ISA to allow all traffic on all
ports (or so i think i have) but still nothing.
Please help I REALLY AM ON THE EDGE!!!
All the best
yus
Marina Roos - 29 Sep 2003 20:41 GMT
You can always rerun the ICW-wizard and make sure it will make changes to
your ISA-setup. That way all the defaults in ISA will come back. After that
you can decide which other rules you possible made have to be enabled.
Marina
> Hi,
>
[quoted text clipped - 26 lines]
> All the best
> yus
SuperGumby - 29 Sep 2003 23:20 GMT
as Marina suggests, re-run the ICW. It will disable but not delete any extra
rules you have implemented
BTW the small problem with ISA and SSL, did it have to do with SSL on a port
other than 443? if so there's a simple fix.
> Hi,
>
[quoted text clipped - 26 lines]
> All the best
> yus
Yus - 01 Oct 2003 00:28 GMT
Hi,
Many thanx for your quick responses, it really is much appreciated :-)
We were just about to re-run the wizard as you both suggeseted, but
then took a long shot which did kinda work as a temp solution.
We added another IP on the first NIC then in IIS hosted the default
website on that IP. will obviously need to fix it properly soon.
I hope you dont mind if i ask a few more questions:
1)Being that hosting the site on the original IP is now forbidden,
this would indicate a rule or permission in the ISA blocking web
traffic to that IP!! Is this Correct???
2)I know very little about ISA, now in a basic network that at present
only uses POP to get mail SMTP to send it and all internal clients use
outlook 2000 exchnage clients and port 8080 to access net through the
proxy, I feel there may be far to many rules and filters in the ISA.
Do you know of any good straight forward sources that could aid a
better config??? firewall is bit lax at mo (I know it sounds terribly
general,so sorry!)
Now being that you ask about the initial SSL problem i'll fill you in.
Now until now no network PC's have had any problem accessing any web
sites including SSL sites. recently the customer needs to use the
following site www.woolworths.co.uk/supplier/somi. This site is
accessible however the moment you try to log in the site just seems to
freez and the IE globe just keeps spinning. Once in a blue moon it
does get through and then just freezez on the very next part of the
site. When ISA is disabled it works fine.
Spoke to woolworths and because we can access the customer purchase
part of the site they can't understand why as it has supposedly used
all the same web components etc. eventhough they admit they have not
spent anywhere near as much time optimizing the supplier site.
Thinking about it now, it may not even really be an SSL problem but
could be.
If you do have any ideas or thoughts i really would be most greatful.
> as Marina suggests, re-run the ICW. It will disable but not delete any extra
> rules you have implemented
[quoted text clipped - 32 lines]
> > All the best
> > yus