Just one more comment... I think this has something to do with MTU/packet size. Pings being very small, always went through without issue. Non-ping packets, have extreme difficulty. The link between Network A and B is a VPN, and I'm wondering if this has something to do with MTU path or whatnot being different on ISA versus what is seen on the VPN connection itself.
Which might explain why changing ServerXYZ to have a static route for 192.168.111.0/24 via the 10.0.0.254 gateway, and bypassing ISA (10.0.0.1), fixed the issue? I'm still a bit fuzzy, but that's what I'm sorta thinking.... ?? J Original Message: ----------------- From: [email protected] [email protected] Date: Tue, 3 Nov 2009 13:05:02 -0500 To: [email protected], [email protected] Subject: Network Q I know there's a reason for this, I'm just not sure and was hoping someone here would. I have two networks. Network A - 10.0.0.0/24 Network B - 192.168.111.0/24 There is a gateway at 10.0.0.254 that is used for a specific connection to the gateway at 192.168.111.1 and the 192.168.111.0/24 network in general. Network A also has another gateway that is used for EVERYTHING else (main internet), that gateway is 10.0.0.1. Here's what had me confused... >From a PC-A (192.168.111.200) in Network B, I could ping Server XYZ (10.0.0.8)in Network A successfully. However, trying to do anything other thing pinging led to very intermittent results (what triggered this was trying to access the Exchange 2007 mail server on ServerXYZ from PC-A, the Outlook profile wouldn't resolve the username). For example... * I could only intermittently (1 try out of 8 or so) telnet over port 25 into Server XYZ. * Opening up SMB shares (\\ServerXYZ) would take a really long time * Trace routing to ServerXYZ from PC-A mostly resulted in 3 hops. And about 20% of the time resulted in 4 hops (the extra hop ended up being the 10.0.0.1 gateway). The strange/different traceroutes had me confused. I did a tracert from ServerXYZ to PC-A and the first hop was 10.0.0.1. The 10.0.0.1 router (Forefront server) HAS a route to 192.168.111.0/24 via 10.0.0.254. I fixed all these issues by adding a static and persistent route on ServerXYZ to 192.168.111.0/24 via 10.0.0.254. Since doing so... From PC-A, I no longer have issues with Outlook client, or telnetting over port 25, or accessing SMB shares on ServerXYZ. Yet, the entire time before making the routing change, I *WAS* able to PING ServerXYZ (by IP and DNS) from PC-A. I am looking for input as to what was really going on here, heh. (I think it has something to do with pinging being different in the way it can be resolved versus other network protocols?) Thanks! -------------------------------------------------------------------- mail2web.com – Enhanced email for the mobile individual based on Microsoft® Exchange - http://link.mail2web.com/Personal/EnhancedEmail ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~ -------------------------------------------------------------------- mail2web - Check your email from the web at http://link.mail2web.com/mail2web ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~
