<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Ryan Wetmore&#039;s Adventures in Life and IT</title>
	<atom:link href="http://ryanwetmore.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://ryanwetmore.wordpress.com</link>
	<description>My Personal and Work Experiences</description>
	<lastBuildDate>Mon, 22 Jun 2009 19:51:37 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='ryanwetmore.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Ryan Wetmore&#039;s Adventures in Life and IT</title>
		<link>http://ryanwetmore.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://ryanwetmore.wordpress.com/osd.xml" title="Ryan Wetmore&#039;s Adventures in Life and IT" />
	<atom:link rel='hub' href='http://ryanwetmore.wordpress.com/?pushpress=hub'/>
		<item>
		<title>ISA 2004 Lockdown Mode Issue (Cont&#8217;d)</title>
		<link>http://ryanwetmore.wordpress.com/2009/06/22/isa-2004-lockdown-mode-issue-contd/</link>
		<comments>http://ryanwetmore.wordpress.com/2009/06/22/isa-2004-lockdown-mode-issue-contd/#comments</comments>
		<pubDate>Mon, 22 Jun 2009 19:51:37 +0000</pubDate>
		<dc:creator>ryanwetmore</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[ISA]]></category>
		<category><![CDATA[ISA2004]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[support]]></category>

		<guid isPermaLink="false">http://ryanwetmore.wordpress.com/?p=14</guid>
		<description><![CDATA[I finally got a callback from Microsoft today for our ISA 2004 Lockdown issue.  The support engineer told me that the logs that he collected pointed to the Web Proxy component of ISA on one of our firewalls was causing it not to start the firewall services.  We rummaged around  the ISA settings looking for the &#8220;HTTP Filter&#8221; in [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ryanwetmore.wordpress.com&amp;blog=6733987&amp;post=14&amp;subd=ryanwetmore&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I finally got a callback from Microsoft today for our ISA 2004 Lockdown issue.  The support engineer told me that the logs that he collected pointed to the Web Proxy component of ISA on one of our firewalls was causing it not to start the firewall services.  We rummaged around  the ISA settings looking for the &#8220;HTTP Filter&#8221; in the Enterprise Add-Ins section of the ISA console.  We noticed that this was disabled so we enabled it.  Went to the Sevices MMC and tried to restart the firewall services.  No go&#8230;.  Same error message.</p>
<p>Next we looked through the NTFS permissions in the &#8220;Microsoft ISA Server&#8221; directory on the C: drive.  All permissions seemed to be correct and not modified.</p>
<p>I downloaded the latest ISA 2004 patch from KB article 954264 (<a href="http://support.microsoft.com/kb/954264">http://support.microsoft.com/kb/954264</a>)  as per the MS engineer and applied it to the box and rebooted.  Checked the firewall services and they did not start.</p>
<p>The support engineer suggested doing a repair of ISA 2004 using the original installation media.  Needless to say I wasn&#8217;t to keen on doing this given the awful track record of doing a repair on Windows installation from the installation media.  But, I reluctantly went along for the ride.  I downloaded the ISA installation files from one of our file shares to the local drive of the firewall.  Then we proceeded to run the installer and selected the &#8220;Repair&#8221; option.  After about 10 minutes of holding my breath, the repair process completed and we rebooted the ISA server.</p>
<p>To my total astonishment, the firewall services restarted as if nothing ever happened.  Now I can breath again.  I really wasn&#8217;t looking forward to a ISA server re-build.  Needless to say, I will monitor the server for the next couple days for any issues.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ryanwetmore.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ryanwetmore.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ryanwetmore.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ryanwetmore.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ryanwetmore.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ryanwetmore.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ryanwetmore.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ryanwetmore.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ryanwetmore.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ryanwetmore.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ryanwetmore.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ryanwetmore.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ryanwetmore.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ryanwetmore.wordpress.com/14/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ryanwetmore.wordpress.com&amp;blog=6733987&amp;post=14&amp;subd=ryanwetmore&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ryanwetmore.wordpress.com/2009/06/22/isa-2004-lockdown-mode-issue-contd/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/483fbc2975c89e9a134828c4fac2d75b?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">ryanwetmore</media:title>
		</media:content>
	</item>
		<item>
		<title>ISA 2004 Lockdown Mode Issue</title>
		<link>http://ryanwetmore.wordpress.com/2009/06/20/isa-2004-lockdown-mode-issue/</link>
		<comments>http://ryanwetmore.wordpress.com/2009/06/20/isa-2004-lockdown-mode-issue/#comments</comments>
		<pubDate>Sun, 21 Jun 2009 00:35:16 +0000</pubDate>
		<dc:creator>ryanwetmore</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[ISA]]></category>
		<category><![CDATA[ISA2004]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://ryanwetmore.wordpress.com/?p=4</guid>
		<description><![CDATA[Came in to work Thursday morning to notice that one of our three ISA 2004 nodes in a NLB cluster had stopped passing traffic.  The reason I noticed was because I couldn&#8217;t connect to the HP Management Log console to check the logs on that particular ISA server. Pretty weird considering I could RDP to the server to check [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ryanwetmore.wordpress.com&amp;blog=6733987&amp;post=4&amp;subd=ryanwetmore&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Came in to work Thursday morning to notice that one of our three ISA 2004 nodes in a NLB cluster had stopped passing traffic.  The reason I noticed was because I couldn&#8217;t connect to the HP Management Log console to check the logs on that particular ISA server. Pretty weird considering I could RDP to the server to check the event logs.    Here is what I found in the event logs:</p>
<p>Event Type: Information<br />
Event Source: Microsoft ISA Server Control<br />
Event Category: None<br />
Event ID: 21263<br />
Date:  6/18/2009<br />
Time:  3:26:37 AM<br />
User:  N/A<br />
Computer: *********<br />
Description:<br />
ISA Server switched back to the primary Configuration Storage server *********** after using the alternate Configuration Storage server.</p>
<p>Event Type: Error<br />
Event Source: Microsoft Firewall<br />
Event Category: None<br />
Event ID: 14019<br />
Date:  6/18/2009<br />
Time:  3:26:59 AM<br />
User:  N/A<br />
Computer: **********<br />
Description:<br />
ISA Server failed to load the firewall policy configuration. The failure occurred while loading the policy rule &#8220;Corporate FTP Server&#8221;.</p>
<p>Event Type: Error<br />
Event Source: Microsoft ISA Server Web Proxy<br />
Event Category: None<br />
Event ID: 21177<br />
Date:  6/18/2009<br />
Time:  3:27:00 AM<br />
User:  N/A<br />
Computer: ***********<br />
Description:<br />
The Web filter [OWA Forms-Based Authentication Filter] failed to reload the configuration. If you recently applied changes to the configuration, verify that these changes are configured properly.</p>
<p>Event Type: Error<br />
Event Source: Microsoft ISA Server Web Proxy<br />
Event Category: None<br />
Event ID: 21177<br />
Date:  6/18/2009<br />
Time:  3:27:00 AM<br />
User:  N/A<br />
Computer: ************<br />
Description:<br />
The Web filter [Link Translation Filter] failed to reload the configuration. If you recently applied changes to the configuration, verify that these changes are configured properly.</p>
<p>Event Type: Error<br />
Event Source: Microsoft ISA Server Web Proxy<br />
Event Category: None<br />
Event ID: 21177<br />
Date:  6/18/2009<br />
Time:  3:27:00 AM<br />
User:  N/A<br />
Computer: ************<br />
Description:<br />
The Web filter [HTTP Filter] failed to reload the configuration. If you recently applied changes to the configuration, verify that these changes are configured properly.</p>
<p>Event Type: Error<br />
Event Source: Microsoft ISA Server Control<br />
Event Category: None<br />
Event ID: 21209<br />
Date:  6/18/2009<br />
Time:  3:27:00 AM<br />
User:  N/A<br />
Computer:************<br />
Description:<br />
The ISA Server configuration agent was unable to upload the configuration to the ISA Server services. This could be due to a corrupt configuration. The ISA Server configuration agent is reverting the configuration back to the last known configuration. The service that failed to load the configuration is: fwsrv.</p>
<p>Event Type: Error<br />
Event Source: Microsoft ISA Server Control<br />
Event Category: None<br />
Event ID: 21210<br />
Date:  6/18/2009<br />
Time:  3:27:06 AM<br />
User:  N/A<br />
Computer: ************</p>
<p>Description:<br />
The new configuration cannot be set, and configuration settings cannot be reverted to last known good values. As a result ISA Server is now in lockdown mode. For more information, see the topic Lockdown Mode in ISA Server online help. The error description is: Some configuration changes were not applied. See the Windows event viewer for more details.</p>
<p>____________________________________________________________________</p>
<p>OH, CRAP!!!!!  That was a more polite way of expressing my feelings at the time.</p>
<p>Needless to say my first stop for troubleshooting this issue was Google.  Didn&#8217;t find a whole heck of a lot about this issue, but did find out that this &#8220;lockdown&#8221; mode was a way for ISA server to help protect the internal network if something went wrong with ISA server or if it was being DDOS&#8217;d, etc, etc.</p>
<p>Being that we host some critical applications for our customers, I decided that I should call Microsoft Support.  After a callback, I was on the phone for a couple of hours w/ an MS ISA support engineer. Looking through the ISA console, we found that two firewall rules that used the same HTTP listener would throw an error when we right-clicked and selected &#8220;Properties&#8221;.  We deleted and recreated the HTTP listener (after we backed them up <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> ) for these rules and tried to re-start the firewall services.  No go&#8230;</p>
<p>Then we decided to recreate the two firewall rules (after backing them up <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> ).  Tried to restart the firewall services again.  Another no go&#8230;</p>
<p>This time the MS ISA engineer decided it was time to escalate this issue to his colleagues.  He initiated an ISA log collection with something called the &#8220;ISA Data Packager&#8221;.  See more about this tool from another blog here:  <a href="http://tinyurl.com/cjd4uh">http://tinyurl.com/cjd4uh</a> . </p>
<p>Needless to say the issue has not been resolved yet.  I&#8217;m beginning to think that the ISA configuration file (mostly XML) might be corrupted.</p>
<p>Stay Tuned&#8230;&#8230;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ryanwetmore.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ryanwetmore.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ryanwetmore.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ryanwetmore.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ryanwetmore.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ryanwetmore.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ryanwetmore.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ryanwetmore.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ryanwetmore.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ryanwetmore.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ryanwetmore.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ryanwetmore.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ryanwetmore.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ryanwetmore.wordpress.com/4/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ryanwetmore.wordpress.com&amp;blog=6733987&amp;post=4&amp;subd=ryanwetmore&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ryanwetmore.wordpress.com/2009/06/20/isa-2004-lockdown-mode-issue/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/483fbc2975c89e9a134828c4fac2d75b?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">ryanwetmore</media:title>
		</media:content>
	</item>
	</channel>
</rss>
