Article ID: 934022 - Last Review: October 24, 2008 - Revision: 2.0 An ISA Server 2004 or ISA Server 2006 downstream server does not reuse the TCP connections to a third-party upstream serverSYMPTOMSConsider the following scenario. A downstream server is running Microsoft Internet Security and Acceleration (ISA) Server 2004 or Microsoft Internet Security and Acceleration (ISA) Server 2006. This downstream server is chained to a third-party upstream server through Web-chaining configuration. In this scenario, ISA Server does not reuse the TCP connections that have been created to the upstream server. Instead, ISA Server closes each TCP connection after an HTTP response is received.
When the network is under a heavy load, this behavior may cause ISA Server to exhaust all available TCP ports. CAUSESome third-party proxy servers send an HTTP response that includes both of the following headers:
RESOLUTIONRESOLUTIONTo resolve this problem, obtain the latest ISA Server service pack.
For more information, click the following article numbers to view the articles in the Microsoft Knowledge Base:
Important These steps may increase your security risk. These steps may also make the computer or the network more vulnerable to attack by malicious users or by malicious software such as viruses. We recommend the process that this article describes to enable programs to operate as they are designed to or to implement specific program capabilities. Before you make these changes, we recommend that you evaluate the risks that are associated with implementing this process in your particular environment. If you decide to implement this process, take any appropriate additional steps to help protect the system. We recommend that you use this process only if you really require this process.954258
(http://support.microsoft.com/kb/954258/
)
How to obtain the latest Internet Security and Acceleration (ISA) Server 2006 service pack
891024
(http://support.microsoft.com/kb/891024/
)
How to obtain the latest ISA Server 2004 service pack
Warning After you follow the steps in this section, ISA Server 2004 will not close the TCP connections, even if both the Content-Length header and the "Transfer-Encoding: Chunked" header are present in the HTTP response. This resolution reduces the protection that is provided by ISA Server. Therefore, we do not recommend that you apply this change unless the upstream server provides protection against HTTP smuggling attacks. To change the default ISA behavior, follow these steps:
STATUSMicrosoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section. MORE INFORMATIONFor more information about how to install ISA Server hotfixes and updates, click the following article number to view the article in the Microsoft Knowledge Base:
885957
(http://support.microsoft.com/kb/885957/
)
How to install ISA Server hotfixes and updates
APPLIES TO
| Article Translations
|
Back to the top
