Registered users    
MembershipMembership:
Latest New UserLatest:jenisa villarin
New TodayNew Today:11
New YesterdayNew Yesterday:11
User CountOverall:23322

Private messaging    
You must be logged in to use this module.
Top 10 posters    
NamePosts
Mariette Knap12893
Marina Roos12507
Eriq Neale2114
Stan Guinn1913
Michael Patrick1912
Robert Pearman1771
Nick Pieters1425
Stewart Brown616
william warren598
Kevin D.579
Welcome unauthorized visitor    
If you want to join us in the discussions on this forum you need to register first. Registration is free! If you are already a registered user please login to join the forum.
Small Business Server Support Forum    
Subject: DHCP Requests Blocked by ISA
Prev Next
You are not authorized to post a reply.

Author Messages
MTBox Tech User is Offline
Notre Dame Indiana, USA
Member since
10/23/2006

Platinum Membership
Posts: 15

9/18/2007 02:07 AM  
I am having trouble with an ISA install at a client site.
 
A little background info.  This server had the motherboard get fried from a lightning strike that came in through the cable modem line, blew out router, blew out switch and blew out WAN connection on server which warranted the motherboard replacement in the server since it was onboard.  We replaced the Motherboard, rebooted clients and clients could not talk to server, server could not talk to internet or talk to workstations.  This occuring mid week and mid day and 25 users that could not work we uninstalled ISA.  Did some research and was then confident we could reinstall ISA and get everything back up and running off hours.
 
After the reinstall and reconifguring some extra rules to allow Managed Workplace to function we thought everything was working fine until we had a wireless laptop that could not connect.  We discoverd that the laptop could not DHCP.  We also learned we could break additional computers by doing a DHCP release and renew.  Result was limited or no connectivity.  If we gave the devices static ips, everything appears well except for the fact that the clients can no longer autodetect the ISA server in the firewall client.  on static clients I had to manually set the ISA server.
 
After more troubleshooting and watching the ISA log I am seeing that DHCP requests are getting denied.  I connected to another known working ISA box and verified all the firewall pollicies and everything looks good but i still can not find why clients can not DHCP or autodetect ISA server.  Below is the Denied message from ISA:
 
Denied Connection
Log Type: Firewall service
Status: The Policy rules do not all the user request.
Rule:
Source: Internal (0.0.0.0:68)
Destination: Local Host (255.255.255.255:67)
Protocol: DHCP (request)
User:
 
Any guidance would be appreciated.

Thank you,
Matthew Konkol
M/T Box Computers, Inc
South Bend IN 46660
574.277.2775
Eriq Neale User is Offline
Texas, USA
Member since
5/3/2005

Microsoft MVP
Posts: 2114

9/18/2007 03:43 AM  
Matthew -

Take a look at this post (http://simultaneouspancakes.com/Lessons/2007/01/15/isa-and-dhcp/) and see if i matches what you have set up. There are a couple of instances where ISA will block DHCP for no seemingly good reason. you might be able to set up a couple of DHCP rules as outlined in http://www.microsoft.com/technet/isa/2004/plan/isaondhcpserver.mspx to get around the issue. I've had to do that a couple of times.

My suspicion is that there is a deny access rule somewhere in the setup, and you may be able to get around this by specifically excluding the DHCP protocols in the Deny rule.

HTH...

-Eriq

Eriq Neale - Small Business Specialist, SBS MVP, Mac Guru
EON Consulting LLC www.eonconsulting.net
Lead Author of Windows Small Business Server 2008 Unleashed
In bookstores December 10, available for pre-order now
Listen to eOnCall at AIRtunZ or visit www.eoncall.com.
You are not authorized to post a reply.



ActiveForums 3.7
Forum policy    
These Discussion Forums are dedicated to the discussion of the Small Business Server and related server and client software. For the benefit of the community please observe the following posting guidelines:
  1. No Advertising. This includes promotion of commercial products and non-commercial products which are not directly related to Small Business Server and related server and client software.
  2. No Flaming or Trolling.
  3. No Profanity, Racism, or Prejudice.
  4. Site Moderators have the final word on approving/removing a thread or post or comment.