Can't access certain websites & all fail randomly under ISA 2004.

starriol

Member
Jan 3, 2006
187
0
0
Hi guys. Hope you can help with this cause I'm very lost at the moment.

The problem I'm experiencing is that I cannot enter this site:

http://www.mercadolibre.com.ar/jm/myML

It's an Ebay type of site... there, you login into your account.

The error I get is this:

"X
Network Access Message: The page cannot be displayed
Explanation: There is a problem with the page you are trying to reach and it cannot be displayed.

Try the following:

* Refresh page: Search for the page again by clicking the Refresh button. The timeout may have occurred due to Internet congestion.
* Check spelling: Check that you typed the Web page address correctly. The address may have been mistyped.
* Access from a link: If there is a link to the page you are looking for, try accessing the page from that link.

If you are still not able to view the requested page, try contacting your administrator or Helpdesk.

Technical Information (for support personnel)

* Error Code: 502 Proxy Error. Not implemented (-2147467263)
* IP Address: 64.58.88.115
* Date: 19/09/2007 11:08:30 p.m.
* Server: isa.SERVINBUE.LOCAL
* Source: web filter "

This happens everytime.
Please check ISA logs here: http://www.sendspace.com/file/9r8e91

Download the .xls file; the logs for the computer trying to enter are in yellow.
For those who don't wanna download it, the basic error is:

"No autenticated client, using ISA as a proxy, on the url http://www.mercadolibre.com.ar/jm/myML with TCP you get an HTTP status of 0x80004001 (whatevr that means), log record type is Web Proxy Filter, destination ip is 206.57.4.11 on port 80 with http protocol. The action is Failed Connection Attempt under the rule with the client user name asanonymous and the HTTP Method is GET"


Also, some pages don't load. Either they say "done" in the status bar but the page is all white or they take forever to load but they don't load at all.

Any info would be very welcomed.

Thanks.
 

RebateMonger

Elite Member
Dec 24, 2005
11,586
0
0

starriol

Member
Jan 3, 2006
187
0
0
Ok, I've been able to solve this problem by installing Isa's SP3

Now I have another problem, I can't connect from the internal network (neither from ISA) to any SMTP server to send my mail.

I also need to allow access from the internet to my ISA server for Mdaemon's webmail (on port 3000) & allow VNC on port 5900, I think.

How do you do this exactly? I haven't been able just creating the rules like they look like they should.

I also have a Pfsense firewall between the modem & ISA. I'm not asking how to configure it to be able to enter ISA on VNC & webmail ports, but could it be possible that the server is blocking all outbond SMTP traffic?

Sounds weird to me...
 

RebateMonger

Elite Member
Dec 24, 2005
11,586
0
0
By default, ISA pretty much blocks everything, both in and out.

If you want, do a "Telnet microsoft.com 25" and take a look at the ISA log and see if the traffic was denied by ISA.
 

starriol

Member
Jan 3, 2006
187
0
0
Yep, did just that, the log said port 25, protocol smtp, host, the ip of the host (in this case, the external NIC's ip of the ISA server) and it was blocked by the default block all rule.

The weird thing is that I did install the rule for it to get out, but I did it wrong obviously.
How do you allow SMTP traffic out & VNC & access to another mail server?
 

RebateMonger

Elite Member
Dec 24, 2005
11,586
0
0
Normally, you'd "Publish a Mail Server", but if all you want is to allow OUTBOUND SMTP traffic, it shouldn't be a big deal. Create a rule near the top of the Firewall Policy list:

From: Create a "Computer" object for your mailserver's internal IP address and use that.
To: External
Protocol: SMTP
Users: All Users