Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

Packets from a branch office may not reach the destination servers in the central office after you use ISA Server 2006 to create a site-to-site VPN connection between a central office and a branch office


View products that this article applies to.

Symptoms

Consider the following scenario:
  • You use Microsoft Internet Security and Acceleration (ISA) Server 2006 to create a site-to-site VPN connection between a central office and a branch office.
  • The ISA Server 2006 computer is located in the central office.
  • Clients in the branch office use ISA Server to access servers in the central office.
In this scenario, packets from the branch office may not reach the destination servers in the central office. For example, HTTP requests from a client in the branch office may not reach Web servers in the central office.

↑ Back to the top


Cause

This problem occurs because the Microsoft Firewall service incorrectly handles IP address bindings. A site-to-site VPN connection may be lost and then re-created. However, ISA Server still uses the old IP address of the previous virtual network interface for the site-to-site VPN connection.

↑ Back to the top


Resolution

To resolve this problem, apply the hotfix rollup package that is described in the following Microsoft Knowledge Base article:
955151 Description of the ISA Server 2006 hotfix package: July 06, 2008

↑ Back to the top


Workaround

To work around this problem, restart the Microsoft Firewall service on the ISA Server 2006 computer.

↑ Back to the top


Status

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.

↑ Back to the top


More information

The hotfix that is described in this article resolves an issue for a scenario that resembles the hotfix in the following Microsoft Knowledge Base articles:
947255 Packets from the branch office may not reach the destination servers in the central office over a site-to-site VPN connection that you create through ISA Server 2006.
955118 Packets from the branch office may not reach the destination servers in the central office in ISA Server 2006

↑ Back to the top


Keywords: KB955150, kbqfe, kbexpertiseadvanced

↑ Back to the top

Article Info
Article ID : 955150
Revision : 1
Created on : 9/11/2008
Published on : 9/11/2008
Exists online : False
Views : 324