That would be a question to the experts. When I solved it, I was just too tired to go after the cause of the issue. The customer didn't care as well ;) His hardware was cr@p indeed. Old, but never failed for any reason. All I can tell is that I didn't apply W2k3 SP1 on the ISA Box (DC's don't have it applied yet and the customer has some SP1-imcompatible apps on them) and it has got Automatic Updates turned on. Jim, why would that happen? Tiago de Aviz SoftSell - Curitiba (41) 3340-2363 www.softsell.com.br Esta mensagem, incluindo seus anexos, tem caráter confidencial e seu conteúdo é restrito ao destinatário da mensagem. Caso você tenha recebido esta mensagem por engano, queira por favor retorná-la ao destinatário e apagá-la de seus arquivos. Qualquer uso não autorizado, replicação ou disseminação desta mensagem ou parte dela é expressamente proibido. A SoftSell não é responsável pelo conteúdo ou a veracidade desta informação. >>> tshinder@xxxxxxxxxxx 27/1/2006 00:01 >>> http://www.ISAserver.org Hi Tiago, Nice tip. Thanks! What I would wonder is what created the initial problem. I'll bet a quarter that some hardware is going to meet its maker soon. Tom Thomas W Shinder, M.D. Site: www.isaserver.org Blog: http://spaces.msn.com/members/drisa/ Book: http://tinyurl.com/3xqb7 MVP -- ISA Firewalls **Who is John Galt?** > -----Original Message----- > From: Tiago de Aviz [mailto:Tiago@xxxxxxxxxxxxxxx] > Sent: Thursday, January 26, 2006 6:07 PM > To: [ISAserver.org Discussion List] > Subject: [isalist] RE: Server cant be pinged > > http://www.ISAserver.org > > Same Behavior that I saw on a customer of mine. > > The firewall service wouldn't go up and as Jim stated a long > time ago, ISA 2004 will enter a "Network Brick" mode, that > it'll be able to access anything, but anything won't be able > to access ISA. > > I had that issue back some time ago when an specific GPO > change made my customer's ISA stop starting... > > Together with Microsoft's folks, we diagnosed that there's a > policy locally on your ISA Box named "Generate Security > audits", and in that policy you must have two accounts listed: > > NETWORK SERVICE > LOCAL SERVICE > > It's just a tip of what may be happening. But by the symptoms > you described, either: > > -You have a rule configuration problem > -ISA isn't loading its own rules > -ISA installation gone FUBAR for whatever reason > -Conflict with another firewall installed (E.G.: Trend or > McAffee ones that go up together with the AV) > > > > Tiago de Aviz > SoftSell - Curitiba > (41) 3340-2363 > www.softsell.com.br > > Esta mensagem, incluindo seus anexos, tem caráter > confidencial e seu conteúdo é restrito ao destinatário da > mensagem. Caso você tenha recebido esta mensagem por engano, > queira por favor retorná-la ao destinatário e apagá-la de > seus arquivos. Qualquer uso não autorizado, replicação ou > disseminação desta mensagem ou parte dela é expressamente > proibido. A SoftSell não é responsável pelo conteúdo ou a > veracidade desta informação. >