[isalist] Re: 0xc004000d FWX_E_Policy_Rules_Denied - ISA drops HTTPS connection for OWA

  • From: Danny <nocmonkey@xxxxxxxxx>
  • To: isalist@xxxxxxxxxxxxx
  • Date: Wed, 6 Dec 2006 14:08:20 -0500

Appears to be resolved. Will post the resolution shortly.

Thanks.

On 12/6/06, Danny <nocmonkey@xxxxxxxxx> wrote:

SSL Certificate - Check
OWA works internally - Check
DNS resolves from Internet to External IP of ISA Server 2004 SP1 - Check
No firewalls logically in-front of the ISA Server - Check
Other published traffic such as SMTP works fine - Check
DNS resolves from Internal Hosts, Servers and ISA to Internal IP of
Exchange Server 2003 SP2 (only one Exchange server) - Check
Imported SSL Certificate from Exchange Server - Check
Created OWA Mail Server Publishing Rule - Check
Tested OWA Externally, DNS resolves, URL correct, but connection timesout;
there is no ISA error - Check

ISA Log:

Original Client IP    Client Agent    Authenticated Client    Service
 Server Name    Referring Server    Destination Host Name    Transport
 MIME Type    Object Source    Source Proxy    Destination Proxy
 Bidirectional    Client Host Name    Filter Information    Network
Interface    Raw IP Header    Raw Payload    Source Port    Processing
Time    Bytes Sent    Bytes Received    Result Code    HTTP Status Code
 Cache Information    Error Information    Log Record Type    Log Time
 Destination IP    Destination Port    Protocol    Action    Rule    Client
IP    Client Username    Source Network    Destination Network    HTTP
Method    URL
123.123.123.123                RTH-ISA    -        TCP    -
         -                1714    0    0    0    0xc004000d
FWX_E_POLICY_RULES_DENIED        0x0    0x0    Firewall    06/12/2006
12:34:17 PM     124.124.124.124    443    HTTPS    Denied Connection
 Default rule    123.123.123.123        External    Local Host    -    -
123.123.123.123                RTH-ISA    -        TCP    -
         -                1714    0    0    0    0xc004000d
FWX_E_POLICY_RULES_DENIED        0x0    0x0    Firewall    06/12/2006
12:34:19 PM     124.124.124.124    443    HTTPS    Denied Connection
 Default rule    123.123.123.123        External    Local Host    -    -
123.123.123.123                RTH-ISA    -        TCP    -
         -                1714    0    0    0    0xc004000d
FWX_E_POLICY_RULES_DENIED        0x0    0x0    Firewall    06/12/2006
12:34:25 PM     124.124.124.124    443    HTTPS    Denied Connection
 Default rule    123.123.123.123        External    Local Host    -    -

ISA Event Log:

Event Type:    Warning
Event Source:    Microsoft ISA Server Web Proxy
Event Category:    None
Event ID:    14148
Date:        06/12/2006
Time:        1:00:18 PM
User:        N/A
Computer:    ISA
Description:
The Web Proxy filter failed to bind its socket to 124.124.124.124 port
443. This may have been caused by another service that is already using the
same port or by a network adapter that is not functional. To resolve this
issue, restart the Microsoft Firewall service. The error code specified in
the data area of the event properties indicates the cause of the failure.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 40 27 07 80               @'.€




--
CPDE - Certified Petroleum Distribution Engineer
CCBC - Certified Canadian Beer Consumer

Other related posts: