Registered users    
MembershipMembership:
Latest New UserLatest:Mark Ellis
New TodayNew Today:9
New YesterdayNew Yesterday:7
User CountOverall:23403

Private messaging    
You must be logged in to use this module.
Top 10 posters    
NamePosts
Mariette Knap12957
Marina Roos12627
Eriq Neale2117
Stan Guinn1917
Michael Patrick1914
Robert Pearman1786
Nick Pieters1425
william warren640
Stewart Brown620
Kevin D.579
Welcome unauthorized visitor    
If you want to join us in the discussions on this forum you need to register first. Registration is free! If you are already a registered user please login to join the forum.
Small Business Server Support Forum    
Subject: ISA 2004 occasionally reports Event 14147
Prev Next
You are not authorized to post a reply.

Author Messages
Ze'ev Ionis User is Offline
Canada
Member since
6/13/2005

Platinum Membership
Posts: 56

11/04/2005 03:01 AM  
I am irregularly getting Event 14147 "ISA Server detected routes through adapter "adapter name" that do not correlation with the network element to which this adapter belongs.  the address ranges in conflict are: 192.0.0.192 - 192.0.0.192...  The adapter in question is my internal adapter.

I consulted the KB article 884496 "Client Computers cannot access external resources, and event ID 14147 appears in the Application log in ISA Server 2004.  This does not really apply to me as my clients can access external resources, and other then the event message I see no symptoms.  In addition, I never manually added IP address ranges to the adapter, as the article states might have been the problem. 

Could this be a spoof attack?  And if so, what steps should I take?  I see this address range in my routing table, but in the dynamic, not in the persistent, stack.  I tried to delete it but because it wasn't persistent I off course couldn't!
 
Ze'ev
Amy Babinchak User is Offline
Michigan, United States
Member since
5/23/2005

Microsoft MVP
Posts: 204

11/04/2005 05:09 PM  
Ze'ev,
 
I haven't seen this error before but it does seme to indicate that the routing table is messed up. Did you happen to change NIC's in thes server or change which one is the external adapter? I'm assuming here, that you have 2 nics.

Amy Babinchak
for ThirdTier.net

Need additional help?
http://www.thirditer.net
Ze'ev Ionis User is Offline
Canada
Member since
6/13/2005

Platinum Membership
Posts: 56

11/04/2005 05:28 PM  
I do have 2 NICS - one for the LAN, one for the WAN (I am connected via a Cable Modem directly out).  I did not change NICs recently - this is a new built server, not an upgrade or a swing server.
Marina Roos User is Offline
The Netherlands
Member since
3/24/2005

Forum Admins
Posts: 12627

11/04/2005 11:43 PM  
Hi Ze'ev,
 
Can you post the ipconfig/all from the server please? Was ISA upgraded from 2000?

Marina Roos Smallbizserver.Net AdministratorMission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local  network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain'
Ze'ev Ionis User is Offline
Canada
Member since
6/13/2005

Platinum Membership
Posts: 56

11/07/2005 02:24 AM  
I've reproduced the output from ipconfig /all below.  This was not an upgrade, but a fresh install on new hardware with SBS 2003 & ISA 2004.
 ============================
Windows IP Configuration
   Host Name . . . . . . . . . . . . : zi-server
   Primary Dns Suffix  . . . . . . . : MENDZ.LOCAL
   Node Type . . . . . . . . . . . . : Unknown
   IP Routing Enabled. . . . . . . . : Yes
   WINS Proxy Enabled. . . . . . . . : Yes
   DNS Suffix Search List. . . . . . : MENDZ.LOCAL
                                       oawh1.on.cogeco.ca
Ethernet adapter Server Local Area Connection:
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Linksys LNE100TX Fast Ethernet Adapter(LNE100TX v4)
   Physical Address. . . . . . . . . : 00-0C-41-1C-0A-F0
   DHCP Enabled. . . . . . . . . . . : No
   IP Address. . . . . . . . . . . . : 192.168.16.2
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . :
   DNS Servers . . . . . . . . . . . : 192.168.16.2
   Primary WINS Server . . . . . . . : 192.168.16.2
Ethernet adapter Network Connection:
   Connection-specific DNS Suffix  . : oawh1.on.cogeco.ca
   Description . . . . . . . . . . . : Intel(R) PRO/1000 CT Network Connection
   Physical Address. . . . . . . . . : 00-11-11-60-77-12
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : No
   IP Address. . . . . . . . . . . . : 24.141.37.132
   Subnet Mask . . . . . . . . . . . : 255.255.240.0
   Default Gateway . . . . . . . . . : 24.141.32.1
   DHCP Server . . . . . . . . . . . : 24.226.1.121
   DNS Servers . . . . . . . . . . . : 192.168.16.2
   NetBIOS over Tcpip. . . . . . . . : Disabled
   Lease Obtained. . . . . . . . . . : November 6, 2005 1:40:57 PM
   Lease Expires . . . . . . . . . . : November 13, 2005 1:40:57 PM
Marina Roos User is Offline
The Netherlands
Member since
3/24/2005

Forum Admins
Posts: 12627

11/07/2005 03:16 AM  
Hi Ze'ev,
 
You would do better to get yourself a router and put that between the external nic and the cable modem. You are now getting the foreign DNS in the suffix search list.

Marina Roos Smallbizserver.Net AdministratorMission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local  network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain'
Amy Babinchak User is Offline
Michigan, United States
Member since
5/23/2005

Microsoft MVP
Posts: 204

11/07/2005 08:27 PM  
I don't see anything wrong with your IP configuration on this server. It's coming from the inside. I'll go out on a limb and say that you've got a printer with a web interface (many do these day) that is in the 192.0.0 range. Let me know if I'm correct.

Amy Babinchak
for ThirdTier.net

Need additional help?
http://www.thirditer.net
Marina Roos User is Offline
The Netherlands
Member since
3/24/2005

Forum Admins
Posts: 12627

11/08/2005 03:03 AM  
Hi Amy,
 
Although it doesn't explain the error Ze'ev is getting, that ipconfig is not good with that foreign dns suffix.

Marina Roos Smallbizserver.Net AdministratorMission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local  network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain'
Ze'ev Ionis User is Offline
Canada
Member since
6/13/2005

Platinum Membership
Posts: 56

11/08/2005 03:19 AM  
I will get (already ordered) a router, but that doesn't explain why the errant message shows up on the internal adapter side of things.
 
AMY - I checked just to confirm, but as expected the only printer that has a web page is on my normal subnet of 192.168.16.0 ... 192.168.16.255.
 
Thanks to both of you!

Ze'ev
Marina Roos User is Offline
The Netherlands
Member since
3/24/2005

Forum Admins
Posts: 12627

11/08/2005 03:22 AM  
Hi Ze'ev,
 
Well, if I ping to 192.0.0.192 on my laptop, it is giving me the message that it is used for printservices discovery. So are you sure you haven't got a printserver hanging around?

Marina Roos Smallbizserver.Net AdministratorMission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local  network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain'
Ze'ev Ionis User is Offline
Canada
Member since
6/13/2005

Platinum Membership
Posts: 56

11/08/2005 03:28 AM  
Now that's interesting!!  I've pinged before, but did not try -a parameter.  Did that now, and got the same message back ("Pinging 192.0.0.0-is-used-for-printservices-discovery----illegally.iana.net 𖐸
.0.0.192] with 32 bytes of data:").  I have a printer (HP) attached to the network using a Jet Direct Card.  This is the one configured to a "regular" ip address.  But I've also installed the HP Jet Direct software that does a "discovery" to find printers.  I wonder if that's somehow generating this message?
Marina Roos User is Offline
The Netherlands
Member since
3/24/2005

Forum Admins
Posts: 12627

11/08/2005 03:34 AM  
Hi Ze'ev,
 
Remove that Jet Direct software from the server, you don't need it anyway, and see if that does the trick.

Marina Roos Smallbizserver.Net AdministratorMission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local  network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain'
Ze'ev Ionis User is Offline
Canada
Member since
6/13/2005

Platinum Membership
Posts: 56

11/08/2005 03:43 AM  
Checked the HP Jet Admin "readme file" (you mean you're actually supposed to read this stuff!! ) and found the following:
 21. Question: What is the Remote Discovery Agent (RDA) feature?
         
            Solution: RDA allows HP Web Jetadmin to discover unconfigured HP devices (IP addresses of 192.0.0.192) on remote TCP/IP subnets. HP Web Jetadmin has the ability to push a piece of software to a PC on the remote subnet. This software will then run as a service (under Windows) or as a process (under Unix/Linux), discovering unconfigured devices and passing this information back to HP Web Jetadmin.
           
            RDA is now configurable with HP Web Jetadmin. Different discovery mechanisms can be selected and scheduled.


Now to find out where this service has been installed, and if it's been pushed to any of the other desktops!  Fascinating, what you find when you actually RTFM.
 
Thanks very much!  Feel much better knowing that the dangerous hacker attacking my systems is me!
 
Ze'ev
Marina Roos User is Offline
The Netherlands
Member since
3/24/2005

Forum Admins
Posts: 12627

11/08/2005 11:11 AM  

Marina Roos Smallbizserver.Net AdministratorMission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local  network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain'
Graham Keen User is Offline
Australia
Member since
11/21/2005

Registered Users
Posts: 2

11/21/2005 12:47 AM  
I use ISDN dial-on-demand on my SBS 2003 server and I also get the Event 14147 error messages in the Application Log each time the server connects to the Internet (which is every 15 minutues to collect POP3 mail). However, unlike Ze'ev's problem, my error seems to be related to the External network and not the Internal network. The full error message is:

"Description: ISA Server detected routes through adapter Loopback that do not correlate with the network element to which this adapter belongs. For best practice, the address range of an ISA Server network should match the address ranges routable through the associated network adapter as defined in the routing table. Otherwise valid packets may be dropped as spoofed. (This alert may occur momentarily when you create a remote site network. You may safely ignore this message if it does not reoccur.) The address ranges in conflict are: 144.134.109.254-144.134.109.254;."

Could it be that ISA doesn't properly support dial-up connections with dynamically assigned IP addresses? Each time the server connects, I can a new IP address on the External network. Could it be that Windows correctly updates the LAT but ISA sees this as a conflict and reports it as an error? There is no adverse affects of the error but I would like to stop it because it fills up the Alert screen making it harder to see any other errors.

Here's the result of an ipcfonig/all:

Windows IP Configuration

Host Name . . . . . . . . . . . . : cadbase01
Primary Dns Suffix . . . . . . . : CADBASE.local
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : Yes
WINS Proxy Enabled. . . . . . . . : Yes
DNS Suffix Search List. . . . . . : CADBASE.local

Ethernet adapter Server Local Area Connection:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network Connection
Physical Address. . . . . . . . . : 00-11-43-ED-AC-F5
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 10.0.0.1
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . : 10.0.0.1
Primary WINS Server . . . . . . . : 10.0.0.1

PPP adapter Telstra ISDN:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : WAN (PPP/SLIP) Interface
Physical Address. . . . . . . . . : 00-53-45-00-00-00
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 144.134.109.208
Subnet Mask . . . . . . . . . . . : 255.255.255.255
Default Gateway . . . . . . . . . : 144.134.109.208
DNS Servers . . . . . . . . . . . : 203.49.70.20
139.134.2.190

Graham (cadbase)

PS I also see "spoofing" attack messages on 127.0.0.1 but I'm not sure if this is related directly to the 1417 problem.
Marina Roos User is Offline
The Netherlands
Member since
3/24/2005

Forum Admins
Posts: 12627

11/21/2005 01:20 AM  
Hi Graham,
 
If you only have 1 nic in the server, it doesn't make much sense to use ISA. Have you considered adding a second nic and let that connect to a router which can do the dial up for you?

Marina Roos Smallbizserver.Net AdministratorMission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local  network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain'
Graham Keen User is Offline
Australia
Member since
11/21/2005

Registered Users
Posts: 2

11/21/2005 02:42 AM  
Thanks for the quick reply.
 
We've had ISA 2000 for 3 years under this ISDN dial-on-demand arrangement - initially with SBS 2000 and later with SBS 2003 and it's never been a problem. In all other respects, SBS supports dial-on-demand very well and ISA does provide all the same benefits as using two NICs and a router. We applied SBS 2003 Service Pack 1 (which includes an upgrade from ISA 2000 to ISA 2004) on the weekend and noticed these 14147 messages only today.
 
We haven't looked into ISDN routers yet. At the moment we use a "Telstra NT1 Plus II" ISDN interface box that was supplied by the telco. This interfaces with SBS through a USB port. We only have one twisted pair into the building so this NT1 is quite good in that it provides shared telephone, fax and Internet access over the one phone line. The box has two analogue ports where one connects to a telephone and the other to a modem on the server for send/receive fax transmissions. When the server connects to the Internet, it uses both ISDN channels to achieve 128K speed. If a phone call comes in on one channel or an fax comes in on the other while the server is on-line, the NT1 box drops one channel to the USB port resulting in 64K connection to the Internet and the other channel is made active for voice or fax call. When the telephone call finishes, the NT 1 box re-establishes a connection on the second channel so the speed of the Internet connection is increased back to 128K - all without the active connection being interrupted. I'm not sure if an ISDN router will do all of this - although I'll do some research.
Unfortunately we can't get ADSL or cable at this location so ISDN is our only option. Since this is charged by the second, we have to limit the time on-line. We can't get an permanent IP address under our ISP contract.
I suspect the same problem would occur if our Internet access was dial-on-demand through an analogue modem. This would also get a different IP on each dial.

We had cable up until 3 years ago and connected to that using a second NIC. However we found with that the IP address rarely changed - maybe  once every 6 months or so when the Telco changed something. I suspect ISA would report the same 14147 message when this happens on cable customers  - but because its rare it probably doesn't get reported as a problem.

As mentioned before, ISA does everything it's supposed to do and does provide all the same benefits as a server with a permanent Internet connection through a second NIC or outer - so maybe we can simply ignore the config errors?

Graham Keen
Stephen Cashman User is Offline
United States
Member since
8/1/2008

Platinum Membership
Posts: 3

9/22/2008 05:31 PM  
We have a new SBS 2003 installation on a new server with two NICs. I occasionally get this event id, but I don't know if I should be concerned about it or not. Here is a typical error message:

Event Type: Error
Event Source: Microsoft Firewall
Event Category: None
Event ID: 14147
Date: 9/22/2008
Time: 9:40:09 AM
User: N/A
Computer: FILESERVER1
Description: ISA Server detected routes through the network adapter Network Connection WAN that do not correlate with the network to which this network adapter belongs. When networks are configured correctly, the IP address ranges included in each array-level network must include all IP addresses that are routable through its network adapters according to their routing tables. Otherwise valid packets may be dropped as spoofed. The following ranges are included in the network's IP address ranges but are not routable through any of the network's adapters: 10.0.1.0-10.255.255.254;. Note that this event may be generated once after you add a route, create a remote site network, or configure Network Load Balancing and may be safely ignored if it does not re-occur.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

I'm not an ISA expert so I don't want to mess anything up by making unnecessary changes to my configuration. All client computers are able to access all external web sites, FTP site, etc.

We do have a copy HP printers with Jet Direct cards on our network, but I don't have any HP software installed on the server. We do have a Dell Remote Access card that we have not used yet. It appears to have an IP address of 10.0.0.16.

Here are the results of IPCONFIG/ALL:

Windows IP Configuration
Host Name . . . . . . . . . . . . : fileserver1
Primary Dns Suffix . . . . . . . : cashmanstahler.local
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : Yes
WINS Proxy Enabled. . . . . . . . : Yes
DNS Suffix Search List. . . . . . : cashmanstahler.local

Ethernet adapter Server Local Area Connection LAN:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Broadcom BCM5708C NetXtreme II GigE (NDIS VBD Client)
Physical Address. . . . . . . . . : 00-1E-C9-D6-2A-AC
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 10.0.0.2
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . : 10.0.0.2
Primary WINS Server . . . . . . . : 10.0.0.2

Ethernet adapter Network Connection WAN:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Broadcom BCM5708C NetXtreme II GigE (NDIS VBD Client) #2
Physical Address. . . . . . . . . : 00-1E-C9-D6-2A-AE
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 66.9.251.50
Subnet Mask . . . . . . . . . . . : 255.255.255.240
Default Gateway . . . . . . . . . : 66.9.251.49
DNS Servers . . . . . . . . . . . : 10.0.0.2
Primary WINS Server . . . . . . . : 10.0.0.2
NetBIOS over Tcpip. . . . . . . . : Disabled

PPP adapter RAS Server (Dial In) Interface:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : WAN (PPP/SLIP) Interface
Physical Address. . . . . . . . . : 00-53-45-00-00-00
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 10.0.0.16
Subnet Mask . . . . . . . . . . . : 255.255.255.255
Default Gateway . . . . . . . . . :
NetBIOS over Tcpip. . . . . . . . : Disabled

Thanks for any help you can offer.
Marina Roos User is Offline
The Netherlands
Member since
3/24/2005

Forum Admins
Posts: 12627

11/25/2008 12:04 AM  
Hi Stephen,
 

Marina Roos Smallbizserver.Net AdministratorMission accomplished. We have joined the branch office to our SBS 2003 Headquarters and have the same user experience on the branch office as we have on our local  network at the Headquarters. Want to know how? Signup up for a subscription and get instant access to the article series 'How to add an additional Domain Controller from a remote office to the SBS domain'
You are not authorized to post a reply.
Forums > Microsoft Small Business Server 2003 & 2000 > ISA Server 2000 > ISA 2004 occasionally reports Event 14147



ActiveForums 3.7
Forum policy    
These Discussion Forums are dedicated to the discussion of the Small Business Server and related server and client software. For the benefit of the community please observe the following posting guidelines:
  1. No Advertising. This includes promotion of commercial products and non-commercial products which are not directly related to Small Business Server and related server and client software.
  2. No Flaming or Trolling.
  3. No Profanity, Racism, or Prejudice.
  4. Site Moderators have the final word on approving/removing a thread or post or comment.