TMG Traffic For a Specific IP isn't leaving the server despite valid routes and no firewall

Hi,
 I'm struggling to troubleshoot a TMG networking issue:
I have a TMG server setup in my DMZ. Inbound traffic hits the a 3rd party firewall router, goes to the TMG server and is then routed back through the 3rd party firewall router to my internal network. I've setup web publishing rules and listeners for IIS
sites and SMTP traffic using a different IP to listen for 2 different websites and another IP for SMTP.
The issue I have is that my TMG server can't ping a server on the internal network on a specific IP:
TMG can ping 192.168.11.190
TMG cannot ping 192.168.11.191
Firewall rules are configured to permit traffic (no deny connections are shown in the monitor).
tracert and pings to 192.168.11.190 hit the internal IP of the 3rd party router
tracert to 192.168.11.191 simply responds with * * * * before timing out
Monitoring from within TMG shows the correct IP is being used in both cases (internal NIC 192.168.10.10).
A route print from TMG has a valid route to the internal network:
(network)192.168.11.128 (mask) 255.255.255.128 (gateway) 192.168.10.126
In summary:
 - TMG can ping 192.168.11.190, but not 192.168.11.191
 - Valid routes exists 
 - No firewall rules are blocking communication
 - Traffic to 192.168.11.191 doesn't seem to be leaving the TMG server 
Any advice on solving this would be appreciated.
Cheers

It can have many reasons, but it appears to me you are having a routing issue. I can't say for sure, because I don't have the entire IP Addressing sheme. I assume you have used separate subnets for the External DMZ and Internal DMZ.
Have you configured the 192.168.11.128/25 subnet as a correct 'Address' range 192.168.11.128 - 192.168.11.255 on the 'Internal' interface within TMG?
Boudewijn Plomp | BPMi Infrastructure & Security
This posting is provided "AS IS" with no warranties, and confers no rights. Please remember, if you see a post that helped you please click "Vote as Helpful", and if it answered your question, please click "Mark as Answer".

Similar Messages

  • HT204266 how to search for a specific app eg tetris in the app store?

    Hi is there anyone that can please help me on how to search for a specific app eg tetris in the app store? Thanks

    Hi Friend,
    You just write down the name of the app or for what the app is used for (eg, write down Notes and then will appear a lot of options), then download what you wish.
    Hope it will be helpful

  • HT4864 I am getting a triangle with an exclamation point next to my inbox...it says: There may be a problem with the mail server or network. Verify the settings for account "MobileMe" or try again.  The server returned the error: Mail was unable to log in

    I can send but cannot recieve email
    This is the messege I am gewtting:
    There may be a problem with the mail server or network. Verify the settings for account “MobileMe” or try again.
    The server returned the error: Mail was unable to log in to the IMAP server “p02-imap.mail.me.com” using “Password” authentication. Verify that your account settings are correct.
    The server returned the error: Service temporarily unavailable

    Also if I go to system preferences accounts and re-enter the password it fixes the glitch sometimes.

  • Yosemite 10.10.2 server app. FTP help. I have a program running in my local server enviroment that wants to FTP to my mac folder. It asks for the server , name, password, port and path. what are they?

    So I have set up a localhost area in my Mac. I have the new server.app and I am running yosemite 10.10.2 .
    I have a program running in my local server enviroment that wants to FTP to my mac .
    It asks for the server , name, password, port and path. what are they?
    I am pretty certain that the Serveris "localhost",
    Name is my macs name (like my-mac-min)
    password is "my login password"
    and they suggest port 21.
    But what is the file path, lets just say my site is set up http://localhost/siteftp and is actually at my Users/Sites/siteftp folder.
    Why cant this program connect to the mac.
    Is it because they are both operating in the same localhost enviroment,
    could it be my folder permissions are not correct on siteftp folder?
    Help please !

    I tried turning the computer off and then back on. The alerts don't show the notice to update as resolved. Hopefully this is not a problem or an indicator or another problem. Should I ignore or reload 10.10.1 from the app store to trigger a resolved check in a green circle?
    Interesting that I had to buy server software after my free Yosemite download. I would have hoped that the two pieces of software would have gone together without any complication. It is not positive to end up buying a problem. Ah well, time to move on.

  • I can't update my ipod. When I check for updates it says "can't connect to server"(despite internet connection being fine). Also, when I try and update software it starts then stops after 2 seconds

    I can't update my Ipod. When I check for updates it says "can't connect to server" despite internet connection being fine. When I receive a software update message;I say install and it starts updating then stops after 2 seconds. Help! (It is a 3rd gen IPod touch(I think)). Presumably as a result of this, I have tried to put my library onto my gf's new iPod touch and it just charges it..doesn't download my library onto the touch).

    Update Server
    Try:
    - Powering off and then back on your router.
    - iTunes for Windows: iTunes cannot contact the iPhone, iPad, or iPod software update server
    - Change the DNS to either Google's or Open DNS servers
    Public DNS — Google Developers
    OpenDNS IP Addresses
    - For one user uninstalling/reinstalling iTunes resolved the problem
    - Try on another computer/network
    - Wait if it is an Apple problem

  • Name of the table where can get the two fields Valid-From and Valid-to for

    Hi gurus
    I want name of the table where I can get the two fields Valid-From and Valid-To and their relation ship with the header table in BOM
    Regards
    Kaisar

    You can only get the Valid from date from the table STKO.
    To get the valid to date, you have to take one day less than the valid-from date of the next record for the same BOM.
    Alternatively use the Function module:
    CSAP_MAT_BOM_READ
    It will give both valid from and valid to dates in the tables parameter: T_STKO
    Regards,
    Ravi
    Edited by: Ravi Kanth Talagana on Jul 2, 2008 4:37 PM

  • I am trying now for more than a week to download the free trial of photoshop and still was not succe

    I am trying now for more than a week to download the free trial of photoshop and still was not successful

    Well, since youi did not provide any system info or other details, you might as well try for another week. We know nothing about your operating system, what browsers you use, what network connection and so on. Start here:
    Direct Download Links for Adobe Software
    Troubleshoot Adobe Download Assistant
    Mylenium

  • The file required for contribute compatibility does not exist on the server

    Hi, when connecting to a server in Dreamweaver that is set up
    for Contribute I keep getting this message when putting files:
    quote:
    The file required for contribute compatibility does not exist
    on the server. Would you like to turn off Contribute compatibility?
    I see the post from jonbradley below, but the solution
    suggested doesn't help me:
    Does anyone have any idea what this means and how to stop it
    from displaying?
    Thanks in anticipation...
    Simon

    Did you search the forum on compatibility?
    http://www.adobe.com/cfusion/webforums/forum/searchresults.cfm?requesttimeout=500&cate gory=290&forumid=55&FTVAR_KEYWORD1FRM=compatibility&FTVAR_SEARCHWHATFRM=c& FTVAR_RESULTTYPE=topics&FTVAR_AUTHORFRM=&FTVAR_TABLECHOICEFRM=current&FTVAR_CA TEGORYIDFRM=290&Selection=false&FTVAR_DATESELFRM=Select&FTVAR_STARTDATEFRM=&am p;FTVAR_ENDDATEFRM=&cal_d1=0&cal_d2=0

  • Thanks for nothing. I tryed to install the 8.1 Update. And it deleted all my fotos and data. thanks...

    Thanks for nothing. I tryed to install the 8.1 Update. And it deleted all my fotos and data. thanks...

    Nope....I know. i need to blame myself. it just asked me when i pluged the phone to my pc for the first time since looong...
    so. its okay. i had a back up with some pictures and some contacts and all that.
    the install process just got an issue so it stoped half way through and i could only completely start over.
    i was mad. now its okay

  • Does anyone experience not being able to search SMS for a specific contact? You know the info is in the old texts, but it won't search that only contact. Weird...

    When I use the search engine in the messages, I can search any text message belonging to any contact with the exception of one. For example, I'll type in "apple" because I need to know some info that was sent via text (AND  I KNOW IT'S THERE), but it will not come up for that specific contact. I can search anyone else and it will go to the exact date and all, but for this one contact, it will not do it. Is there something I'm missing or may have changed? This contact is a primary contact who I communicate with on the daily.

    When I use the search engine in the messages, I can search any text message belonging to any contact with the exception of one. For example, I'll type in "apple" because I need to know some info that was sent via text (AND  I KNOW IT'S THERE), but it will not come up for that specific contact. I can search anyone else and it will go to the exact date and all, but for this one contact, it will not do it. Is there something I'm missing or may have changed? This contact is a primary contact who I communicate with on the daily.

  • Whats in the full feature driver & software download for officejet pro8600 which isn't in the basic?

    Does anyone know what is in the full feature driver & software download V28.8  or for any version really other version for the matter for Officejet pro8600 ......which isn't in the basic download?
    I'm running vista on an old computer and it doesn't have service pack 2 on it, which is needed for the full download feature download.
    Just wondering if its worth installing service pack 2 to get better features.
    Cheers 
    This question was solved.
    View Solution.

    Hi,
    For Windows Vsita any service pack is supported and you are not required to install a service pack to install the Full Feature Software, Only Windows XP require atleast Service Pack 2..
    You may find the system requirements listed below:
    http://h10025.www1.hp.com/ewfrf/wc/document?docname=c02858465&cc=us&dlc=en&lang=en&lc=en&product=432...
    The most important feature of the Full Feature Software is the Read Iris OCR which allow scanning to editable text or searchable PDF..
    Say thanks by clicking the Kudos thumb up in the post.
    If my post resolve your problem please mark it as an Accepted Solution

  • Is there a fix for Mountain Lion audio output settings after the laptop goes to sleep and wakes back up?

    Mac Book Pro running Mountain Lion OS X 10.8.5 after the notebook sleeps audio and video does work (for example on YouTube).  I have been able to temporarily work around this by toggling the settings on Built-in Output in Audio Midi Setup, Audio window between 2ch-20bit Integer and 2ch-24bit Integer.  But this is a temporary fix until the laptop sleeps again.
    When it's not working, all system sounds (emails "dings", delete file "swish", etc.) are silenced, and video playbacks on YouTube and elsewhere freeze and have no audio until the Audio Output settings are toggled then they all immediately start working.
    Has anyone encountered the same?  Have a long term fix for this annoyance?
    I cannot upgrade the OS to 10.9 Mavericks yet because of a corporate policy - there is some conflict with 10.9 and our corporate VPN connection.

    Apple support article:
    Startup Grey Screen
    You can try to check your hard drive.
    Apple Hardware Test doesn't catch everything, so even if it doesn't find a problem, you could have one.
    Apple Hardware Test

  • I have Verizon FiOS service for phone, internet and TV but I only have one TV hooked up for it for just basic cable service with no DVR and no need for widgets.  Can I use an Airport Extreme as my router and not use the FiOs router?

    I want to use an Airport Extreme as my router.  I currently have a Verizon FiOS router.  I have Verizon for phone, internet and TV.  However, TV-wise, I just have a basic service for one TV with just a regular box.  No HD, no DVR.  Don't need access to a menu, widgets, on-demand.  Can I eliminate the FiOS Router and just use the Airport Extreme and still have phone and internet?

    I know that it will increase my wireless coverage in my house but will it increase the speeds?
    Not sure what you are asking here.  The AirPort Extreme is only going to be as fast as the Internet connection that it receives.....which is 75/75. It cannot take a 75/75 connection and make it go any faster.
    If you locate the AirPort Extreme in an area where you need more wireless signal coverage, the AirPort Extreme would deliver 75/75 in that area.  But, keep in mind that the AirPort Extreme must connect to the FIOS router using a permanent, wired Ethernet cable connection.
    If you are asking if the AirPort Extreme can wirelessly connect to the FIOS modem router, and extend the FIOS wireless network, the AirPort Extreme would not be compatible with a FIOS product for that purpose.

  • Power Bi for o365 - Odata connection test worked but "The server encountered an error processing the request. See server logs for more details". Port 8051? Authority\System

    We set up the Data Management Gateway and created a new data source (odata to SQL via sqL user)
    Did a connection test and it was successful!
    Tried the URL (maybe it needs more):
    https://ourdomain.hybridproxy.powerbi.com/ODataService/v1.0/odatatest
    That resolves to some :8051 port address and then spits out this message:
    The server encountered an error processing the request. See server logs for more details.
    I checked and the data management gateway is running.
    Does that 8051 port need to be opened on our firewall for this server? How can I confirm that is the issue.. I see no event on the server indicating this is the issue?
    I am seeing this event:
    Login failed for user 'NT AUTHORITY\SYSTEM'. Reason: Failed to open the explicitly specified database 'PowerBiTest'. [CLIENT: IP of the Server]

    O365,
    Is this still an issue?
    Thanks!
    Ed Price, Azure & Power BI Customer Program Manager (Blog,
    Small Basic,
    Wiki Ninjas,
    Wiki)
    Answer an interesting question?
    Create a wiki article about it!

  • Linked Server error: Login Failed for user 'NT AUTHORITY\ANONYMOUS LOGON' between sql server 2005 32 bit and sql server 2012 64 bit

    Hi All,
    Here the linked server is created between sql server 2012 64 bit and sql server 2005 32 bit. I am getting the below error  when i try to access linked server from third server. I have created linked from Instance 1 to Instance 2. When i access it from
    instance 3 i am getting the below error. SPN setting has been done between these 2 servers. Also the option 'Trust the delegate' is enabled for the both the service account. 
    'Login Failed for user 'NT AUTHORITY\ANONYMOUS LOGON' 
    Appreciate your quick response. 
    Vikas.M.S

    Hello,
    Please read the following resources:
    http://www.databasejournal.com/features/mssql/article.php/3696506/Setting-Up-Delegation-for-Linked-Servers.htm
    http://social.msdn.microsoft.com/Forums/sqlserver/en-US/ea26de43-4c6b-4991-86d7-e1578f107c92/linked-server-login-failed-for-user-nt-authorityanonymous-logon?forum=sqldataaccess
    Hope this helps.
    Regards,
    Alberto Morillo
    SQLCoffee.com

Maybe you are looking for

  • Find and Replace HS5.5

    How do I include a line feed in the replace section of the find and replace feature of Homesite 5.5? Converting many lengthy files from <pre> and <tt> formats into CSS. Presently the target pages have paragraphs broken into short lines of text with C

  • Edit Original... but not in Paint!

    I'm running InDesign CS2 on Win XP. When I click on the Links Pallet and chose "Edit Original" and the image is an RGB .jpg, it opens by default in Microsoft Paint.  How can I set it up so that these images open up in Photoshop? Every time Paint open

  • White spots on macbook pro retina

    Theres some weird white spots that have appeared on my macbook pro retina and it's really annoying, can someone tell what they are and how they got there as there is no external damage to the macbook or screen, everything else works perfectly, I do h

  • Oracle DB Enterprise for non-commercial use

    Hi. I've unusual question about using an Enterprise edition od Oracle Database (11g). I need to show some extended options of this daabase in my thesis, but I don't know how long can I use it after the installation. If I remember correctly, when I us

  • Undo delete message command in Mail Exchange account doesn't work post Yosemite

    Before I installed Yosemite on my MacBook Air, I was able to undo a message deleted in Mail Exchange 2010 account with menu command (Undo Delete Message) or Command-Z.  Even with recent updates to 10.10.1 which were supposed to address Mail-Exchange