I'm not - I'm saving that for the "engineer" and his tech lead. It's just pisses me off when folks give "tribal knowledge" troubleshooting advice. -----Original Message----- From: Greg Mulholland [mailto:greg@xxxxxxxxxxxxxx] Sent: Thursday, April 21, 2005 10:04 PM To: [ISAserver.org Discussion List] Subject: [isalist] RE: Host Server Unreachable http://www.ISAserver.org Dude, he was acting on advice from an ms engineer, I wouldn't jump all over his back... :) -----Original Message----- From: Jim Harrison [mailto:Jim@xxxxxxxxxxxx] Sent: Friday, April 22, 2005 2:55 PM To: [ISAserver.org Discussion List] Subject: [isalist] RE: Host Server Unreachable http://www.ISAserver.org Turning off ISA "solves many problems", too. That doesn't validate the mitigation technique. -----Original Message----- From: Wayne Berry [mailto:wayne@xxxxxxxxxx] Sent: Thursday, April 21, 2005 8:32 PM To: [ISAserver.org Discussion List] Subject: [isalist] RE: Host Server Unreachable http://www.ISAserver.org Jim, I didn't want to get anyone in trouble. After 3 hours I was sort of beat, however in retrospect there is something else that should corrected. Unchecking the box did solve the problem. -Wayne -----Original Message----- From: Jim Harrison [mailto:Jim@xxxxxxxxxxxx] Sent: Thursday, April 21, 2005 7:03 PM To: [ISAserver.org Discussion List] Subject: [isalist] RE: Host Server Unreachable http://www.ISAserver.org This is incorrect. I'll be speaking to the "engineer" tomorrow. ISA 2004 supports "transparent proxy" for VPN clients with and without the HTTP Filter. Disabling that is a mistakw. -----Original Message----- From: Wayne Berry [mailto:wayne@xxxxxxxxxx] Sent: Thursday, April 21, 2005 12:58 PM To: [ISAserver.org Discussion List] Subject: [isalist] RE: Host Server Unreachable http://www.ISAserver.org Jim, Unless the Internal resource is across a VPN like in my case. Ok, just got off the phone with Microsoft. Here is the problem: 1) I needed to uncheck Web Proxy Filter in the HTTP protocol rules. Basically, I didn't have my browser set to use ISA 2004 as a proxy, I was using it as a gateway for my client and I guess for some reason you don't need the web proxy filter. Which is really odd, since external worked, just not the VPN network. Support thought it might be related to not having the external IP of the destination gateway of the VPN in my IP for the VPN network on the ISA 2004 server however adding it didn't help. -Wayne -----Original Message----- From: Jim Harrison [mailto:Jim@xxxxxxxxxxxx] Sent: Thursday, April 21, 2005 12:49 PM To: [ISAserver.org Discussion List] Subject: [isalist] RE: Host Server Unreachable http://www.ISAserver.org Your definition is a waste. There is no reason to force internal clients through ISA to internal resources. ------------------------------------------------------- Jim Harrison MCP(NT4, W2K), A+, Network+, PCG http://isaserver.org/Jim_Harrison/ http://isatools.org Read the help / books / articles! ------------------------------------------------------- -----Original Message----- From: Wayne Berry [mailto:wayne@xxxxxxxxxx] Sent: Thursday, April 21, 2005 11:43 To: [ISAserver.org Discussion List] Subject: [isalist] RE: Host Server Unreachable http://www.ISAserver.org Dan, The guy at Microsoft support said that there are two sessions with a proxy connection like would happen with HTTP, however the connections are made on the networks that are involved and not from Local Host. So in my case it is the Internal and Remote networks. Which means that if I am connecting from the Internal network with the ISA proxy the local host doesn't need access to the Remote network. My definition of proxy in this case is two connection, client to ISA and ISA to web server, not a bridge. -Wayne -----Original Message----- From: Ball, Dan [mailto:DBall@xxxxxxxxxxx] Sent: Thursday, April 14, 2005 11:42 AM To: [ISAserver.org Discussion List] Subject: [isalist] RE: Host Server Unreachable http://www.ISAserver.org The ISA server itself is referred to as "Local Host" as far as policies is concerned. If you don't have a policy to allow you to connect from the ISA server to your webserver, you will need to add one. The computers on your internal network probably are contacting the server directly if they are on the same subnet. All mail to and from this domain is GFI-scanned. ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Other Internet Software Marketing Sites: World of Windows Networking: http://www.windowsnetworking.com Leading Network Software Directory: http://www.serverfiles.com No.1 Exchange Server Resource Site: http://www.msexchange.org Windows Security Resource Site: http://www.windowsecurity.com/ Network Security Library: http://www.secinf.net/ Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: wayne@xxxxxxxxxx To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist Report abuse to listadmin@xxxxxxxxxxxxx ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Other Internet Software Marketing Sites: World of Windows Networking: http://www.windowsnetworking.com Leading Network Software Directory: http://www.serverfiles.com No.1 Exchange Server Resource Site: http://www.msexchange.org Windows Security Resource Site: http://www.windowsecurity.com/ Network Security Library: http://www.secinf.net/ Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: jim@xxxxxxxxxxxx To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist Report abuse to listadmin@xxxxxxxxxxxxx All mail to and from this domain is GFI-scanned. ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Other Internet Software Marketing Sites: World of Windows Networking: http://www.windowsnetworking.com Leading Network Software Directory: http://www.serverfiles.com No.1 Exchange Server Resource Site: http://www.msexchange.org Windows Security Resource Site: http://www.windowsecurity.com/ Network Security Library: http://www.secinf.net/ Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: greg@xxxxxxxxxxxxxx To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist Report abuse to listadmin@xxxxxxxxxxxxx ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Other Internet Software Marketing Sites: World of Windows Networking: http://www.windowsnetworking.com Leading Network Software Directory: http://www.serverfiles.com No.1 Exchange Server Resource Site: http://www.msexchange.org Windows Security Resource Site: http://www.windowsecurity.com/ Network Security Library: http://www.secinf.net/ Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: jim@xxxxxxxxxxxx To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist Report abuse to listadmin@xxxxxxxxxxxxx All mail to and from this domain is GFI-scanned.