Understanding ISA Firewall, H.323 and packet filter Performance counter.
The main types of performance counters categories are listed below the others are pretty general. In this tutorial I will cover the counters in bold.
Firewall Service (FWSRV.EXE)
To see how the Firewall service interacts with other ISA services checkout my Understanding ISA services tutorial. Click on the link below. http://www.isaserver.org/authors/magalhaes/tutorials/Understanding ISA services.htm
You can also look at an article by Curt Simmons Click on the link below. http://www.isaserver.org/pages/tutorials/isa_server_performance.htm
How to tell if your firewall service is not running properly?
It is always a good idea to check that all of your ISA services are running after a server restart or when the peak hours are in progress. Make sure that you can access local sites and web based applications quickly using the Firewall client without any errors. If this is so then you will not need to go any further because everything is working. If you have complaints from users check that the settings are correct then close all applications including Internet explorer and the try again. Then ask if the application has worked before. If not then maybe the application will not work. Try the application from another machine to isolate if the problem is general. If you still can't connect check the settings within the application and make sure that those settings are correct. Check that the appropriate ISA filters are created or active. Look at your event logs to see what types or errors you are receiving when you are not able to connect.
Here is a summary of the Firewall service, H.323 and packet filter performance counters for easy reading and quick perusal. This table is a summarized version of the counters descriptions found in the ISA help files, I have gone through them and taken out only the relevant information.
Firewall service performance counters
The H.323 protocol filter allows multimedia enriched applications like net meeting to place calls through the H.323Gatekeeper filter. Net meeting allows you to video conference use an electronic white board, exchange files, text chat and have voice conversations with two or more parties. If the firewall is H.323 compliant then you will be able to place these calls through it. Most new video conference systems comply with this standard and have had huge success over Microsoft networks. H.323 protocol filter does not directly allow clients to communicate directly with their peers and acts as a true proxy. This method protects the integrity of your network making it more secure and avoiding personal attacks on unsuspecting users.
H.323 filter performance counters
If packet filtering is enabled (disabled by default) ISA server lets administrators control IP traffic to and from ISA Server. All packets on the external Network interface card are dropped unless rules allow them to be transmitted, either statically by IP packet filters or dynamically by access policy or publishing rules.
Packet filter performance counters
Summary: This tutorial will help you isolate issues that are related to the Firewall service performance counter, H.323 filter performance counters and Packet filter performance counters. I have outlined these counters. The remaining counters will appear in the next tutorial. To understand how to access the built in ISA performance monitor and how to add counters please refer to my previous tutorial on the web proxy service counters as it is briefly detailed in that tutorial.