Exchange 2010 Deployment Notes - ISA 2004 Server Issue

Posted by BWCA on Geeks with Blogs See other posts from Geeks with Blogs or by BWCA
Published on Mon, 14 Feb 2011 20:45:54 GMT Indexed on 2011/02/14 23:26 UTC
Read the original article Hit count: 297

Filed under:


An interesting ISA 2004 tidbit …

While we were setting up our Exchange 2010 ActiveSync environment, we encountered a problem where we could not successfully telnet over port 443 from one of our ISA 2004 Servers to our Exchange 2010 Client Access Server Array.

When we tried to telnet over port 443 from the ISA Server to the Client Access Server Array name, we would get a “Could not open connection to the host on port 443: Connect failed” error message.

Also, when we used portqry over port 443 from the ISA Server to the Client Access Server Array name, we would get a “Error opening socket: 10065” and “No route to host” error messages.

It was odd because we did not have any problems with using ping or tracert from the ISA Server to the Client Access Server Array and our firewall firewall policy was allowing 443 traffic to pass through.

After some troubleshooting, we were able to telnet and use portqry over port 443 successfully if we stopped the Microsoft Firewall service on the ISA 2004 Server.  So, it was strictly a problem with ISA.  Eventually, we were able to isolate the problem to a ISA 2004 Server System Policy setting as shown below (to modify the System Policy, right-click Firewall Policy and click Edit System Policy).

ISA-1

Under the Diagnostics ServicesHTTP Connectivity verifiers Configuration Group, you need to enable the configuration group under the General tab to resolve the problem.  After we enabled the setting, we no longer had a problem.

© Geeks with Blogs or respective owner