Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

A Proxy Chain Error Message "12206" Is Displayed


View products that this article applies to.

Symptoms

When your Web browser attempts to locate a Web site that has been published by Internet Security and Acceleration (ISA) Server or Microsoft Forefront Threat Management Gateway, Medium Business Edition, you may receive a "12206" proxy chain error message.

↑ Back to the top


Cause

This behavior can occur because the external network adapter references an Internet service provider (ISP) Domain Name System (DNS) server and the binding order on ISA Server or Microsoft Forefront Threat Management Gateway, Medium Business Edition lists the external network adapter first. When the publishing server is redirected by a Fully Qualified Name and the zone of the server matches the zone located on the external DNS server, the external DNS server is used to resolve the name. The external DNS server redirects the traffic back to the external network adapter on ISA Server or Microsoft Forefront Threat Management Gateway, Medium Business Edition. Each time the traffic arrives at ISA Server or Microsoft Forefront Threat Management Gateway, Medium Business Edition, an "HTTP Via" record is added to the packet. When two of these records exist, ISA Server or Microsoft Forefront Threat Management Gateway, Medium Business Edition returns the 12206 error message.

NOTE: This behavior can occur even when there is only one ISA Server or Microsoft Forefront Threat Management Gateway, Medium Business Edition that publishes the Web site.

↑ Back to the top


Resolution

To resolve this behavior, remove the external DNS server address from the external network adapter, and then change the binding order on ISA Server or Microsoft Forefront Threat Management Gateway, Medium Business Edition so that the internal network adapter is listed first:
  1. Click Network and Dial-Up connections.
  2. On the Advanced menu, click Advanced Settings to display the binding order.
  3. Click the internal network adapter, and then move it to the top. The internal DNS is used to resolve the server name so that redirection works properly.
Note For ISA Server 2006 and Microsoft Forefront Threat Management Gateway, Medium Business Edition, the IP address of the published server can be specified in the Web publishing rule properties on the TO tab. By specifying this IP address, ISA Server or Microsoft Forefront Threat Management Gateway, Medium Business Edition will establish a connection to the published server without having to make a name resolution. This will avoid hitting the Proxy Chain Error.

↑ Back to the top


Keywords: KB296202, kbprb, kbdns, kbisa2004yes

↑ Back to the top

Article Info
Article ID : 296202
Revision : 4
Created on : 1/15/2006
Published on : 1/15/2006
Exists online : False
Views : 569