Registered users    
MembershipMembership:
Latest New UserLatest:Maurice Tutor
New TodayNew Today:5
New YesterdayNew Yesterday:7
User CountOverall:23064

Private messaging    
You must be logged in to use this module.
Top 10 posters    
NamePosts
Mariette Knap12622
Marina Roos12280
Eriq Neale2105
Michael Patrick1906
Stan Guinn1840
Robert Pearman1724
Nick Pieters1425
Stewart Brown609
Kevin D.563
william warren548
Welcome unauthorized visitor    
If you want to join us in the discussions on this forum you need to register first. Registration is free! If you are already a registered user please login to join the forum.
Small Business Server Support Forum    
Subject: ISA 2004 blocking access to my managed switch
Prev Next
You are not authorized to post a reply.

Author Messages
Chester Hull User is Offline
United States
Member since
4/28/2005

Registered Users
Posts: 30

6/04/2008 02:28 PM  
I'm using my SBS 2003 Dual Nic box to manage the D-Link 1228p web smart switch. I can ping the switch's IP, I can browse to the switch's GUI, but when I run the D-Link management software, it can't find the switch.
 
When I try to "Discover" the switch, I see in the ISA monitoring that ISA is blocking the SNMP requests, by blocking port 161 traffic to the switch's IP. 
 
The ISA rule that is blocking the traffic is the "SBS Internet Access Rule"
 
My SBS box is setup like this:

Internal NIC: 192.168.16.2
LAN switch (for client computers): 192.168.16.10
 
External NIC: 192.168.0.2
Internet Router: 192.168.0.1
 
D-Link Managed Switch (for our public WiFi system): 192.168.0.20

 I guess I need some help walking through how to allow the SNMP traffic to flow through ISA. 
 
Thank you very much!

Chester
robert pearman User is Offline
United Kingdom
Member since
2/23/2007

Platinum Membership
Posts: 1724

6/05/2008 01:15 PM  
right click firewall policy - new access rule, name the rule, set to allow, choose your protocol (snmp) allow from LocalHost, to destination which is your switch. this can either be the entire external network, or you can create a special object, a computer or address range (which is more secure), to allow snmp to. set it for all users, then click finish and apply.

to create a new object, under firewall policy on the right hand side go into toolbox, then click new, computer, enter a name and the IP address of the device (192.168.0.2) then when you create your rule as outlined above, use this object as the destination for snmp traffic.
Chester Hull User is Offline
United States
Member since
4/28/2005

Registered Users
Posts: 30

6/05/2008 02:16 PM  
Robert,
Thanks much! I'm learning!

I was trying to set the Source as the Internal Network, rather than the Local Host. That was my mistake!

Thanks for your help, it's working now!

Chester    

robert pearman User is Offline
United Kingdom
Member since
2/23/2007

Platinum Membership
Posts: 1724

6/05/2008 02:34 PM  
good stuff.

in ISA Server localhost refers to the machine isa is running on.
erd beer User is Offline
Phillipines
Member since
7/8/2006

Platinum Membership
Posts: 233

8/12/2008 07:44 AM  
hi,
 
i am also having a problem managing my dlink managed web smart switch, in my case , i cannot access the gui of my switch. and a check on my isa monitoring, i am having a failed connection attempt..
 
rule: allow/http/https requests from isa server to selected servers for connectivity verifiers
 
shoul i configure something ?
 
thanks
robert pearman User is Offline
United Kingdom
Member since
2/23/2007

Platinum Membership
Posts: 1724

8/15/2008 03:39 PM  
i had an issue with a netgear switch that i couldnt not access properly via isa sp3, i had to remove sp3 and go back to sp1 for isa 2004.
You are not authorized to post a reply.
Forums > Microsoft Smallbusiness Server > ISA Server 2004 > ISA 2004 blocking access to my managed switch



ActiveForums 3.7
Forum policy    
These Discussion Forums are dedicated to the discussion of the Small Business Server and related server and client software. For the benefit of the community please observe the following posting guidelines:
  1. No Advertising. This includes promotion of commercial products and non-commercial products which are not directly related to Small Business Server and related server and client software.
  2. No Flaming or Trolling.
  3. No Profanity, Racism, or Prejudice.
  4. Site Moderators have the final word on approving/removing a thread or post or comment.