ISA Server 2006

Hello,
How can I determine how our ISA Server 2006 boxes are being utilized within our organization? The original Exchange 2003 admin left the company years ago and now I am here trying to prepare for our upgrade to Exchange 2010.
Any help will be greatly appreciated.
Thank you,
Sandy

Look at the firewall logs (for ALL traffic) to see if there is any activity at all for a period of time.
This should be sufficient to determine if the box is still be used at all.
https://technet.microsoft.com/en-us/library/bb794817.aspx?f=255&MSPPError=-2147217396
Blog: http://theinfraguys.com
Follow me at Facebook
The Infra Guys Facebook Page
Join the Singapore System Center Admin Group
SG System Center Admin Group
Please remember to click Mark as Answer on the answer if it helps you in anyway

Similar Messages

  • ISA server 2006 OS Support Information (Product ID: 78984-270-4276405-04003)

    1.       We are using ISA server 2006 in Window server 2003RS SP2 OS and we are upgrading our OS form 2003 to 2012 standred Edt. 64bit.
    So ISA server Compatible with 2012 standred Edt. 64bit
    2.       If it is not compatible with it then share the upgradation process of ISA server which is compatible with server 2012 standred Edt. 64bit.

    HI
    ISA is not supported on 2012 Server, You need to switch to TMG or UAG.
    Also
    Windows 2012 has a new feature called  Remote Access role service in Windows Server® 2012 R2  which can be used to publish website.
    If you want full fuctions of ISA then upgrade to TMG or UAG

  • M4E and MS ISA server 2006 works well

    Just to let you know, M4E and MS ISA server 2006 works well together. A new feature is that you can actually publish all Exchange services on only 1 IP address: OWA, OMA, Outlook everywhere (RPC over https) and active sync. There is a little glitch with the OMA that is unresolved. Look at this thread:
    http://forums.isaserver.org/Cannot_publish_OMA%2c_EAS_and_OWA_with_only_one_listener/m_2002026314/tm.htm

    Just to let you know, M4E and MS ISA server 2006 works well together. A new feature is that you can actually publish all Exchange services on only 1 IP address: OWA, OMA, Outlook everywhere (RPC over https) and active sync. There is a little glitch with the OMA that is unresolved. Look at this thread:
    http://forums.isaserver.org/Cannot_publish_OMA%2c_EAS_and_OWA_with_only_one_listener/m_2002026314/tm.htm

  • ISA Server 2006 DNS error issue

    we are using ISA server 2006, and we are facing issue DNS Clients services, we need to restart its DNS client services in 10min or 15mins, 1st error event ID is 8003, Sources :-MRxSmb and 2nd event ID 11160, Source:- DNSApi.

    Hi,
    By default, ISA Server is configured to log requests that come through the Web Proxy Service. You can check by opening
    the ISA Management MMC and choosing Monitoring Configuration, and then clicking Logs. In addition,
    all log files are stored in the ISALogs folder found in the Microsoft ISA Server folder if you never specify the folder for storing the log file.
    You can check the IAS log files for troubleshooting since it is hard to say which would be the reason.
    Best regards,
    Susie

  • ISA server 2006 crashed after some times :(

    Hello.
    My ISA server is crashed. For
    example when my clients upload files to a remote server my upload speed is Reduced and
    server crashed :(. How can I troubleshoot it? It is
    ver vital for me and my clients are upset.
    Thank you and cheers.

    1. Some more information is needed. Your description of proble is incomplete and no one can guess what has happened.
    2. Find some material evidence - like Event logs and fw logs
    3. There is a special diskussion on ISA server in forum
    http://forums.isaserver.org/ and trobleshooting procedures in
    http://www.isaserver.org/
    4. For troubleshooting read
    http://support.microsoft.com/kb/943462
    http://technet.microsoft.com/en-us/library/bb794787.aspx
    http://technet.microsoft.com/en-us/library/bb794753.aspxhttp://blogs.technet.com/b/yuridiogenes/archive/2010/01/20/troubleshooting-isa-server-2006-performance-issues-webcast-for-ms-partners.aspx
    Regards
    Milos

  • ISA Server 2006 + Average response time for Non Cached requests = performance issues?!?!?!

    All,
    I am in a predicament with internet browsing speeds...We have a 3rd party look after our line and internet facing f/w  so I cant troubleshoot them, so at the moment Im looking at ISA as the potential bottleneck - we have a fairly standard environment:
    Internal > Local Host > Perimiter n/work > Firewall > Internet
    I have been running custom reports on the ISA server to see what data can be collected - I have noticed that "Average response time for non cached requests" (traffic by time of day) can be as high as 76 seconds!!!!!! Cached hits are between .5
    and 2 seconds.
    I have also coonfigured a connectivity verifier which is also flagging slow connectivity, massively over the >5000ms and also reporting "cant resolve server name on occassions- and this is configured for
    www.Microsoft.com --- DNS ???!?!, however I have looked through DNS (no obvious errors / config issues) which I can see 
    I have run the BPA on ISA server to ensure its Health - - connectivity verifier errors flagged timeouts to microsoft.com as expected...
    Can anyone advise any obvious areas to investigate as Im struggling! - as always the 3rd party have told us the internet pipe is fine :O

    Problem resolved.
    DNS forwarders have been changed on the ISA server / DNS and this has improved lookup speed considerably.
    thanks all :)

  • Cleanup of ISA rules in ISA server 2004 and 2006

    Hi Team
    how could i know, which rules are actively working and which rules are not being used in ISA server 2004 and 2006 . based on this we are going to disable the rule initially and delete the rules which is currently not being used in later stage. since we have
    lot rules in ISA , we need to segregate this 
    Could you please able to help me

    Hi,
    Please check the Creating Custom Reports parts in the following blog to see whether it can help you.
    Logging and Reporting in ISA Server 2006
    http://www.isaserver.org/articles-tutorials/configuration-general/Logging-Reporting-ISA-Server-2006.html
    Note:
    Microsoft provides third-party contact information to help you find technical support. This contact information may change without notice. Microsoft does not guarantee the accuracy of this third-party contact information.
    Best Regards,
    Joyce

  • SharePoint 2010 and ISA server proxy - Any step by step documentation to do this?

    Hi there,
    I know that ISA is deprecated - still for next few months we still need to use it. 
    I will appreciate if you could please share any document on how to have a SharePoint 2010 Intranet Web Application available on Internet using ISA server proxy.
    Thank you so much.

    Hi,
    here you are
    http://blogs.technet.com/b/paulpaa/archive/2009/09/23/steps-to-publish-sharepoint-sites-created-in-host-header-mode-hh-mode-with-isa-server-2006.aspx
    http://serverfault.com/questions/174061/how-to-configure-aams-in-sp-2010-to-work-with-isa-2006-and-kerberos-authenticati
    http://www.benjaminathawes.com/2010/08/22/publishing-sharepoint-2010-with-isa-server-2006-sp1/
    http://www.isaserver.org/articles-tutorials/publishing/How-to-Publish-Microsoft-Sharepoint-Service-ISA-Server-2006.html
    http://technet.microsoft.com/library/bb794854.aspx#SecureWebPublishing
    Kind Regards,
    John Naguib
    Technical Consultant/Architect
    MCITP, MCPD, MCTS, MCT, TOGAF 9 Foundation
    Please remember to mark your question as answered if this solves your problem

  • ISA server Compatible with 2012 standred Edt. 64bit

    We are using ISA server 2006 in Window server 2003RS SP2 OS and we are upgrading our OS form 2003 to 2012 standred Edt. 64bit.
    So ISA server Compatible with 2012 standred Edt. 64bit?

    Hello,
    Please read this links:
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/1d2d9a08-8656-4cae-bf30-10ce6e874c67/isa-for-window-server-2012
    http://social.technet.microsoft.com/Forums/forefront/en-US/0e6af2cf-2c18-408e-8da6-2f751181026a/future-of-forefron-tmg-support-and-service-packs-?forum=Forefrontedgegeneral
    Regards

  • ISA server

    Hi
    In ISA server 2006, everyday end users reports that they are being prompted for authentication. Its ISA 2006 installed in windows server 2003 and active directory environment
    After restarting the affected server it will start working again. What could be possible reasaons
    Please advise if anyone dealt with the same situation. Thanks!!

    Hello,
    ISA server related questions please ask in
    https://social.technet.microsoft.com/Forums/forefront/en-US/home?forum=Forefrontedgegeneral
    Best regards
    Meinolf Weber
    MVP, MCP, MCTS
    Microsoft MVP - Directory Services
    My Blog: http://blogs.msmvps.com/MWeber
    Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
    Twitter:  

  • Testing an ISA Server Rule, the recursive query to other DNS Servers test fails

    Hello,
    I am trying to configure the following infrastructure with ISA Server 2006 and two W2003 servers (called "Server1" and "Server2") . "Server1" is a domain controller, and in
    "Server2" is the ISA Server installed, which also has
    attached two network Ethernet cards, one called "Internal Ethernet Card", and the other one called
    "External Ethernet Card".
    The infrastructure would be:  "Internal Ethernet Card"---- ISA Server ----"External Ethernet Card"---"Router"----"Internet"
    "Internal Ethernet Card" manages the internal package traffic of the infrastructure, the network segment which belongs is isolated from what we could called the Outbound traffic, which is linked to a router. "Internal Ethernet Card" it`s
    a virtual network.
    "Internal Ethernet Card" feature configuration is the following:
    - IP address: 192.168.3.3
    - Subnet Mask: 255.255.255.0
    - DHCP Enabled: No
    - DNS Server: 192.168.3.1 (Must point to the DC "Server1" which has the DNS Service installed)
    - Default Gateway:  None  (because doesnt point to outside)
    - Primary WINS Server: 192.168.3.1  
    The "External Ethernet Card" provides, the outbound connection, and this card is connected to the physical router.
    It`s feature configuration is the following:
    - IP address: 192.168.1.50
    - Subnet Mask: 255.255.255.0
    - DHCP Enabled: No
    - Default Gateway: 192.168.1.1
    - DNS Servers: 192.168.3.1 (Must point to the DC "Server1" which has the DNS Service installed)
    After configuring the network cards, I create the following rule in the ISA Server to allow the traffic towards outside from the server and the clients which have joined to the domain:
    Action: Allow.  Protocol: DNS.  From:"Server2".  To : External.  Condition: All Users
    After applying the changes to update the configuration, I enter in the Dns Server of "Server1" and in the "Monitoring" tab, I run a "recursive query to other DNS Servers" but fails.
    Only works the "simple query against this DNS Server".
    I don`t know why fails, but I`m stucked on this issue, because in the "Server1" DNS Server, in the "domain forward IP address list", I have added two DNS addresses which work OK.
    I would appreciate some help to solve this issue.
    Thanks
    Regards 

    Hello Ms. Long, 
    Yes, you are right. In the Server1 is configured the DNS server, to use forwarders whose are set in the field "Selected domain`s forwarder IP address list", two DNS address numbers obtained from "Open DNS", which work well.
    There is no DNS Server linked to the External NIC.
    The Server1 belongs to a private network configured as "VMnet3", which it is set as follows:
    IP address: 192.168.3.1
    Subnet Mask: 255.255.255.0
    Default Gateway: 192.168.3.3
    DNS Server: 192.168.3.1
    I have tried to test your suggested idea:
    > set d2
    > google.com
    Server:  srv-dcfs-01.dominio.local
    Address:  192.168.3.1
    SendRequest(), len 42
        HEADER:
            opcode = QUERY, id = 2, rcode = NOERROR
            header flags:  query, want recursion
            questions = 1,  answers = 0,  authority records = 0,  additional = 0
        QUESTIONS:
            google.com.dominio.local, type = A, class = IN
    Got answer (113 bytes):
        HEADER:
            opcode = QUERY, id = 2, rcode = NXDOMAIN
            header flags:  response, auth. answer, want recursion, recursion avail.
            questions = 1,  answers = 0,  authority records = 1,  additional = 0
        QUESTIONS:
            google.com.dominio.local, type = A, class = IN
        AUTHORITY RECORDS:
        ->  dominio.local
            type = SOA, class = IN, dlen = 46
            ttl = 3600 (1 hour)
            primary name server = srv-dcfs-01.dominio.local
            responsible mail addr = hostmaster
            serial  = 41
            refresh = 900 (15 mins)
            retry   = 600 (10 mins)
            expire  = 86400 (1 day)
            default TTL = 3600 (1 hour)
    SendRequest(), len 28
        HEADER:
            opcode = QUERY, id = 3, rcode = NOERROR
            header flags:  query, want recursion
            questions = 1,  answers = 0,  authority records = 0,  additional = 0
        QUESTIONS:
            google.com, type = A, class = IN
    DNS request timed out.
        timeout was 2 seconds.
    timeout (2 secs)
    SendRequest failed
    *** Request to srv-dcfs-01.dominio.local timed-out
    As you can see highlighted in bold, the problem remains in the "recursive query to other DNS Servers" check.
    Maybe is better to put the issue on the "Windows Server General Forum" , because the issue has not nothing in common with the ISA Server, dont you?
    Thanks
    Best regards

  • I can't connect to ISA Server proxy

    Hello,
    I have Nokia E70 and I can't connect to the Internet at my work place since they run the ISA Server 2006 as a proxy. The thing is, I can't find where should I supply my Domain username and password.
    After the phone connects to the Wireless, it doesn't complete to open the page and give me an error message "Unable to complete operation"
    So could you please tell me what should I do?

    m8s,
    An IT dept. that does not provide support! What ever the reason most likely they don't want to slow downs the whole network. An ISA admin knows(should)  this.Heres a sample of one IT dept in a university suggest to one with E51.
    E51  a sample settings for ISA server connection (it could different according what security being implemented) * WLAN security mode: 802.1X
    * WLAN Security settings:
    * WPA/WPA2: EAP
    * EAP plug-in settings:
    * EAP-PEAP (Only this one is selected).
    * Personal ceritificate: Not Defined
    * Authority certificate: Certificate of your ISA Server
    * User name in use: User defined
    * User name: Your User Name (Can be eventualy: Your Domain\Your User Name
    * Realm in use: User defined
    * Realm: Empty
    * Allow PEAPv0: Yes
    * Allow PEAPv0: No
    * Allow PEAPv0: No
    * EAP-MSCHAPV2 (Only this one is selected).
    * User name: Your User Name
    * Prompt password: No
    * Password: Your Password
    Note that you *have to* install the certificate of your Radius Server on your phone (ie: it is not trusted if you leave it blank).
    Knowledge not shared is knowledge wasted!
    If you find it helpfull, it's not hard to click the STAR..

  • Reporting Services through ISA server for All Authenticated Users

    Hello colleagues.
    I have MS SQL 2012 server with Reporting Services and it work via link:
    https://reports2.domain.com/reports
    In LAN all work fine, but I want publish this resource via ISA for All Authenticated Users.
    When in publish rule I configure (in Condition) "All users" - all work fine, but when I configure "All Authenticated Users" - I have trouble on web form on
    https://reports2.domain.com/reports/Pages/Report.aspx?ItemPat...  - scripts not work, because it run how "anonymous" (I see on ISA logging) and ISA block scripts.
    I can't use "All Users", because it's not secure.
    Maybe somebody publish Reporting Services through ISA server for All Authenticated Users?
    OR maybe - how on Reporting Services configure Negotiate authenticated for scripts?

    Hi Alexander,
    All users or applications who request access to report server content or operations must be authenticated using the authentication type configured on the report server before access is allowed. The AuthenticationType named RSWindowsNegotiate is supported
    by Reporting Services. To configure Windows Authentication on the Report Server, please see:
    http://msdn.microsoft.com/en-us/library/cc281253(v=sql.110).aspx
    Besides, we can publish report server via ISA server. Please note that you should use a new web port number with a new listener which shouldn’t be used by other web site for report server. Reference:
    http://social.technet.microsoft.com/Forums/forefront/en-US/1cc68996-1ce6-4d88-a30d-2bfd13fba06e/how-to-publish-ssrs-2008-through-isa-2006?forum=Forefrontedgegeneral
    Hope this helps.
    Thanks,
    Katherine Xiong
    Katherine Xiong
    TechNet Community Support
    Katherine thanks for answer.
    Report Server service started as Domain account.
    I have in RSReportServer.config this:
    <Authentication>
    <AuthenticationTypes>
    <RSWindowsNegotiate />
    </AuthenticationTypes>
    <RSWindowsExtendedProtectionLevel>Allow</RSWindowsExtendedProtectionLevel>
    <RSWindowsExtendedProtectionScenario>Proxy</RSWindowsExtendedProtectionScenario>
    <EnableAuthPersistence>true</EnableAuthPersistence>
    </Authentication>
    In web.config I have this:
    <authentication mode="Windows" />
        <identity impersonate="true" />
    I can go (from Internet through ISA) to
    https://reports2.domain.com/reports  and LogOn Authentication is work, but scripts not work, because it run how "anonymous" (I see this on ISA logging) and ISA block scripts.
    Do you know where in Reporting Services configure run scripts with Negotiate authentication?

  • Applet fails to connect behind isa server 2004

    hi, for security I have to activate authentication on Isa server 2004 and under this configuration the applet can't connect here is the log:
    NETg Learning Studio (Web) 3.1.8.8
    Copyright � 1997-2005 Thomson NETg, a division of Thomson Learning, Inc. All rights reserved.
    java.vendor = Sun Microsystems Inc., version = 1.5.0_06
    os.name = Windows XP
    Friday, September 15, 2006
    Memory: Total 4767744, Free 998864
    SMD was found.
    AICC_HACP_Connection: IOException processHACPPost().
    java.net.SocketException: Connection reset
         at java.net.SocketInputStream.read(Unknown Source)
         at java.io.BufferedInputStream.fill(Unknown Source)
         at java.io.BufferedInputStream.read1(Unknown Source)
         at java.io.BufferedInputStream.read(Unknown Source)
         at sun.net.www.http.HttpClient.parseHTTPHeader(Unknown Source)
         at sun.net.www.http.HttpClient.parseHTTP(Unknown Source)
         at sun.net.www.protocol.http.HttpURLConnection.doTunneling(Unknown Source)
         at sun.net.www.http.HttpClient.parseHTTP(Unknown Source)
         at sun.net.www.protocol.http.HttpURLConnection.doTunneling(Unknown Source)
         at sun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.connect(Unknown Source)
         at sun.net.www.protocol.http.HttpURLConnection.getOutputStream(Unknown Source)
         at sun.net.www.protocol.https.HttpsURLConnectionImpl.getOutputStream(Unknown Source)
         at netg.AICC.HACP.nls_jk.i(DashoA8374)
         at netg.AICC.HACP.nls_jk.a(DashoA8374)
         at netg.AICC.HACP.nls_nj.allSecure(DashoA8374)
         at netg.signpost.nls_kq.run(DashoA8374)
         at java.security.AccessController.doPrivileged(Native Method)
         at netg.signpost.SunSecurity.g(DashoA8374)
         at netg.signpost.SunSecurity.f(DashoA8374)
         at netg.AICC.HACP.nls_jk.a(DashoA8374)
         at netg.InterNETgBase.run(DashoA8374)
         at netg.util.nls_l.run(DashoA8374)
    Could not communicate with HACP host!
    and when (for testing purposes) I deactivate authentication on my ISA the applet works fine (here is the log)
    NETg Learning Studio (Web) 3.1.8.8
    Copyright � 1997-2005 Thomson NETg, a division of Thomson Learning, Inc. All rights reserved.
    java.vendor = Sun Microsystems Inc., version = 1.5.0_06
    os.name = Windows XP
    Friday, September 15, 2006
    Memory: Total 9728000, Free 1392944
    SMD was found.
    Sending HACP host the following:
    command=GetParam&version=2.0&session_id=CRS3684_SCR2304_STU9782_SOL59084_&AICC_Data=
    HACP host returned the following:
    Error=0
    error_text=successful
    version=2.0
    aicc_data=
    [Core]
    Student_ID=josky.jara
    Student_Name=Jara, Josky
    Lesson_location=
    path=
    Credit=credit
    Lesson_status=I,A
    Score=
    Time=73:09:13
    Lesson_Mode=Normal
    [Core_Lesson]
    TSF=0_2_0_1lsi_42_42_cuc2_0_0_0_0_0_0_0_; MVA=00000000000000; UPF=12_2_0_1_0_1_1; sSkew=0; ATS1=fvvv; LastTopic=en_US_20811_Assmt1.nlo; MP=80; PC=48; DOWNLOAD=0; LastPage=-1;
    [Core_Vendor]
    [Student_Data]
    Mastery_Score=80
    Error: java.lang.ThreadDeath: null
    java.lang.ThreadDeath
         at java.lang.Thread.stop(Unknown Source)
         at java.lang.ThreadGroup.stopOrSuspend(Unknown Source)
         at java.lang.ThreadGroup.stop(Unknown Source)
         at sun.awt.AppContext.dispose(Unknown Source)
         at sun.applet.AppletClassLoader.release(Unknown Source)
         at sun.plugin.security.PluginClassLoader.release(Unknown Source)
         at sun.applet.AppletPanel.release(Unknown Source)
         at sun.applet.AppletPanel.sendEvent(Unknown Source)
         at sun.plugin.AppletViewer.onPrivateClose(Unknown Source)
         at sun.plugin.AppletViewer$1.run(Unknown Source)
         at java.lang.Thread.run(Unknown Source)
    loading copyright notices
    loading copyright notices
    loading copyright notices
    Copyrights for NLO /skillb/en_US_20811/en_US_20811.nlo:
    Copyright � 2004 Thomson NETg, a division of Thomson Learning, Inc.
    All rights reserved. No part of the material protected by this copyright may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying, recording, broadcasting, or by any information storage and retrieval system, without permission in writing from Thomson NETg.
    Skill Builder is a registered trademark of Thomson NETg. All other trademarks referenced are the trademark, service mark, or registered trademark of their respective holders. Thomson NETg is not affiliated with any company or any other product or vendor mentioned in this course and its accompanying materials.
    Cisco Systems is a registered trademark of Cisco Systems, Inc. Cisco IOS is a trademark of Cisco Systems, Inc. Novell and Netware are registered trademarks of Novell, Inc.
    The software and technology used to implement this course contain trade secrets that Thomson NETg considers to be confidential and proprietary information, and your right to use this material is subject to the restrictions in the license agreement under which you obtained it.
    Companies, names, products, and data used in the examples in this course are fictitious. Any resemblance to existing companies, persons, or products is coincidental and unintentional.
    Versions for NLO /skillb/en_US_20811/en_US_20811.nlo:
    BuilderVersion=Builder Version: GenNLO 3.6.2.32
    BuildDate=Build Date: 05-Jul-2004
    TemplateVersion=Template Version: 20030630
    ContentVersion=Content Version: 20811-0406-10
    SrcOrigRelease=Original Release: <200407051839>
    SrcCurRelease=Current Release: <200407051839>
    SrcPrevRelease=Previous Release: <>
    SrcNlo=Source Nlo: <>
    LocalOrigRelease=Local Original Release: <>
    LocalCurRelease=Local Current Release: <>
    LocalPrevRelease=Local Previous Release: <>
    PandoraVersion=Pandora Version: 1.2.0.0
    PandoraBuildDate=Build Date: 09-Jul-2004
    RSObjective not found.
    bUseUserDir = false
    vars.netgIniFile set to "C:\Documents and Settings\All Users\Application Data\NETg/netg.ini"
    In DisplayViewSettings...
    curMode = -1
    In preferences, audioinstalled = 1
    no UserLinkBox
    Setting default font size to 12
    could someone give me a hand?

    Try a security/authentication forum. This isn't a VM issue.
    Sorry.

  • Customers not able to log in with Microsoft ISA server firewall.

    I have a few external customers that are having issues logging in.  In all cases it is with the customer having Microsoft ISA firewalls.
    They can get to the site.  They put in their username and password.  The screen flashes back to the logon screen, no errors, just back to the screen.
    On the logs I seen the logon page request and the 200 OK but, the username and password never come across.
    I can not tell if the username and password are being blocked by the ISA server or when the logon screen is presented that the username and password fields are just not active.
    Has anyone else see or hear about this one?

    We are seeing a slightly different problem but certainly related. We are using a SAP cFolder server for PLM collaboration. Companies using a Microsoft ISA server are not seeing problems logging in but are seeing problems with the mass download feature. They are seeing the connection hang. Looking at the ISA log file on the server they are receiving an authentication problem and a broken connection. If you try a single file download everything works OK. Also vendors without ISA are working fine.
    What is it about ISA that would be causing issues like these?

Maybe you are looking for