Yuri Diogenes recently presented an interesting case of failed authentication attempts by VPN clients because of connectivity issues with a domain controller. What was interesting was that the ISA firewall had basic connectivity to the domain controller. Yet, authentication attempts failed.
What was the problem? The problem was that the interface order was incorrect. In Yuri’s scenario, the external interface was on the top of the connections list.
Multihomed computers have a number of issues with name resolution and authentication, so you have to be aware of the importance of putting the internal interface on the top of the network connection list. We’ve made that point many times on this site, in our books, and in any talks or lectures me, Jim Harrison, Yuri Diogenes, Mohit Saxena, Jason Jones and Richard Hicks and any other ISA or TMG firewall pro have given.
For more information, check out Yuri’s blog post over at:
HTH,
Tom
Thomas W Shinder, M.D., MCSE
Sr. Consultant / Technical Writer
Prowess Consulting www.prowessconsulting.com
PROWESS CONSULTING | Microsoft Forefront Security Specialist
Email: [email protected]
MVP — Forefront Edge Security (ISA/TMG/IAG)