Help and Support
 

powered byLive Search

ISA Server 2004 and ISA Server 2006 do not support traffic redirection

Article ID:888042
Last Review:December 4, 2007
Revision:4.1

SUMMARY

This article discusses how to troubleshoot an issue that occurs when a client computer on a remote subnet sends TCP traffic to another internal computer.

MORE INFORMATION

When a client computer that is behind Microsoft Internet Security and Acceleration (ISA) Server 2004 or Microsoft ISA Server 2006 sends traffic to another internal computer, the ISA Server computer may drop the traffic.

This behavior occurs when TCP packets in one direction follow a route that does not involve ISA Server, and TCP packets in the other direction follow a route that does involve ISA Server.

For example, consider a client computer on a remote subnet that is behind an internal network. In this case, the remote subnet is separated from the ISA Server computer by a router. When the client computer sends a packet to another client computer that is located on the internal network, the traffic is forwarded directly to the computer on the internal network.

When the client computer on the internal network responds, the packet is routed through ISA Server because this computer has the IP address of the internal network defined as its default gateway. ISA Server has no route back to the remote subnet. Therefore, the source IP address is identified as spoofed.

This issue occurs even when the server has valid routes to both source and destination subnets. In this situation, the TCP connection request (SYN) from the client to the server bypasses ISA Server. However, the SYN-ACK packet is routed to the server and dropped with a TCP_NOT_SYN_PACKET error. In short, both sides of a TCP session must go through the ISA Server computer.

This behavior may not occur with User Datagram Protocol (UDP) traffic, or Internet Control Message Protocol (ICMP) traffic.

For more information about how to troubleshoot this issue and other network configuration issues, visit the following Microsoft Web site:
http://go.microsoft.com/fwlink/?LinkID=60491 (http://go.microsoft.com/fwlink/?LinkID=60491)
For more information about how to configure ISA Server 2004 networks, visit the following Microsoft Web site:
http://go.microsoft.com/fwlink/?LinkID=56780 (http://go.microsoft.com/fwlink/?LinkID=56780)

APPLIES TO
Microsoft Internet Security and Acceleration Server 2006 Standard Edition
Microsoft Internet Security and Acceleration Server 2006 Enterprise Edition
Microsoft Internet Security and Acceleration Server 2004 Standard Edition
Microsoft Internet Security and Acceleration Server 2004 Enterprise Edition

Back to the top

Keywords: 
kbtshoot kbfirewall kbprb KB888042

Article Translations

 

Other Support Options

  • Need More Help?
    Contact a Support professional by Email, Online or Phone.
  • Customer Service
    For non-technical assistance with product purchases, subscriptions, online services, events, training courses, corporate sales, piracy issues, and more.
  • Newsgroups
    Pose a question to other users. Discussion groups and Forums about specific Microsoft products, technologies, and services.