Hi Tiago, Nice tip. Thanks! What I would wonder is what created the initial problem. I'll bet a quarter that some hardware is going to meet its maker soon. Tom Thomas W Shinder, M.D. Site: www.isaserver.org Blog: http://spaces.msn.com/members/drisa/ Book: http://tinyurl.com/3xqb7 MVP -- ISA Firewalls **Who is John Galt?** > -----Original Message----- > From: Tiago de Aviz [mailto:Tiago@xxxxxxxxxxxxxxx] > Sent: Thursday, January 26, 2006 6:07 PM > To: [ISAserver.org Discussion List] > Subject: [isalist] RE: Server cant be pinged > > http://www.ISAserver.org > > Same Behavior that I saw on a customer of mine. > > The firewall service wouldn't go up and as Jim stated a long > time ago, ISA 2004 will enter a "Network Brick" mode, that > it'll be able to access anything, but anything won't be able > to access ISA. > > I had that issue back some time ago when an specific GPO > change made my customer's ISA stop starting... > > Together with Microsoft's folks, we diagnosed that there's a > policy locally on your ISA Box named "Generate Security > audits", and in that policy you must have two accounts listed: > > NETWORK SERVICE > LOCAL SERVICE > > It's just a tip of what may be happening. But by the symptoms > you described, either: > > -You have a rule configuration problem > -ISA isn't loading its own rules > -ISA installation gone FUBAR for whatever reason > -Conflict with another firewall installed (E.G.: Trend or > McAffee ones that go up together with the AV) > > > > Tiago de Aviz > SoftSell - Curitiba > (41) 3340-2363 > www.softsell.com.br > > Esta mensagem, incluindo seus anexos, tem caráter > confidencial e seu conteúdo é restrito ao destinatário da > mensagem. Caso você tenha recebido esta mensagem por engano, > queira por favor retorná-la ao destinatário e apagá-la de > seus arquivos. Qualquer uso não autorizado, replicação ou > disseminação desta mensagem ou parte dela é expressamente > proibido. A SoftSell não é responsável pelo conteúdo ou a > veracidade desta informação. > > >>> mross@xxxxxxxxxxx 26/01/06 21:14 >>> > http://www.ISAserver.org > > brain fog.. how do i reset the SC > > ________________________________ > > From: Mark Morgan [mailto:MMorgan@xxxxxxxxxxxxxxxxxxxxx] > Sent: Thursday, January 26, 2006 5:08 PM > To: [ISAserver.org Discussion List] > Subject: [isalist] RE: Server cant be pinged > > > http://www.ISAserver.org > > > > The Third event you send is stating RPC will not be > available. it looks > like you have no SC to the DC. > > > _______ > > ------------------------------------------------------ > List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist > ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp > ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ > ------------------------------------------------------ > Visit TechGenix.com for more information about our other sites: > http://www.techgenix.com > ------------------------------------------------------ > You are currently subscribed to this ISAserver.org Discussion > List as: tshinder@xxxxxxxxxxxxxxxxxx > To unsubscribe visit > http://www.webelists.com/cgi/lyris.pl?enter=isalist > Report abuse to listadmin@xxxxxxxxxxxxx > >