09-09-2008 02:56 PM
This is mostly a heads-up and a request for anybody that can replicate this problem. We've opened a support request with IronPort and they are looking into it. I'm hoping this might help a few people that have been banging their heads trying to figure out what's going on. :?
We've identified a problem where our C350 is unable to communicate with any Windows 2008 server if specific firewalls are in the middle. This includes some very common firewalls such as Cisco PIX. I don't believe it matters where the incompatible firewall lies -- on your network or a remote network. You need "W2K8<->Incompatible Firewall<->IronPort appliance" in this scenario. Any other configuration seems to work, including Windows 2008 on the same LAN as the IronPort appliance.
It seems to be directly related to TCP Window Scaling that Microsoft has enabled by default in Windows 2008/Vista. When a connection is attempted the TCP handshake completes but all following packets sent by the IronPort appliance are silently dropped by the firewall. If you disable Window Scaling on the Windows 2008 server, the connection works as expected.
Microsoft has a list of incompatible firewalls and steps to disable Windows Scaling here. Cisco also makes note of this problem in a troubleshooting document.
09-15-2008 10:16 PM
Hi bpoyner,
What protocols are you talking about?
just "plain" SMTP trafic, LDAP traffic, management traffic? of maybe a combination of those?
I'm interested in some more details.
Steven
09-16-2008 01:52 AM
What protocols are you talking about?
just "plain" SMTP trafic, LDAP traffic, management traffic? of maybe a combination of those?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide