Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

Packets from the branch office may not reach the destination servers in the central office in ISA Server 2006


View products that this article applies to.

Symptoms

Consider the following scenario:
  • You use Microsoft Internet Security and Acceleration (ISA) Server 2006 to create a site-to-site VPN connection between a central office and a branch office.
  • The ISA Server 2006 computer is located in the central office.
  • Clients in the branch office use ISA Server to access servers in the central office.
In this scenario, packets from the branch office may not reach the destination servers in the central office. For example, DNS requests from a client in the branch office may not reach the DNS servers in the central office.

↑ Back to the top


Cause

This problem occurs because the Microsoft Firewall service incorrectly handles IP address bindings. A site-to-site VPN connection may be lost and then re-created. However, ISA Server still uses the old IP address of the previous virtual network interface for the site-to-site VPN connection.

↑ Back to the top


Resolution

To resolve this problem, install hotfix 955151.

For more information about how to do this, click the following article number to view the article in the Microsoft Knowledge Base:
955151 Description of the ISA Server 2006 hotfix package: July 6, 2008

↑ Back to the top


Workaround

To work around this problem, restart the Microsoft Firewall service on the computer that is running ISA Server 2006.

↑ Back to the top


Status

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.

↑ Back to the top


More information

For more information about a hotfix for a similar issue, click the following article numbers to view the articles in the Microsoft Knowledge Base:
947255 Packets from the branch office may not reach the destination servers in the central office over a site-to-site VPN connection that you create through ISA Server 2006
955150 Packets from a branch office may not reach the destination servers in the central office after you use ISA Server 2006 to create a site-to-site VPN connection between a central office and a branch office

↑ Back to the top


Keywords: KB955118, kbqfe, kbexpertiseadvanced

↑ Back to the top

Article Info
Article ID : 955118
Revision : 1
Created on : 9/11/2008
Published on : 9/11/2008
Exists online : False
Views : 348