FTP Client May Not Work When You Enable IP Routing on a Downstream ISA Server (313356)



The information in this article applies to:

  • Microsoft Internet Security and Acceleration Server 2000

This article was previously published under Q313356

SYMPTOMS

When you use a secure Network Address Translation service (NAT) client computer, you may not be able to send or receive data over secondary connections for protocols that allow secondary connections if the support for the connections is provided through a program filter that supports Kernel mode data pump when:
  • The client's ISA server is a downstream server that uses an upstream ISA to chain to

    -and-
  • IP routing is enabled on the downstream server

RESOLUTION

To resolve this problem, obtain latest service pack for ISA Server 2000. For additional information about the latest service pack, click the article number below to view the article in the Microsoft Knowledge Base:

313139 How to Obtain the Latest Internet Security and Acceleration Server 2000 Service Pack

STATUS

Microsoft has confirmed that this is a problem in the Microsoft products that are listed at the beginning of this article.

This problem was corrected in ISA Server 2000 SP1.

MORE INFORMATION

When you enable Internet protocol (IP) routing on an ISA server, the Kernel mode data pump feature is also enabled. This feature provides a significant performance advantage for the data-rich secondary connections by handling the traffic in Kernel mode.

Steps to Reproduce the Problem

To reproduce the problem that is described in the Symptoms section:
  1. Configure the downstream ISA server with FW chaining to the upstream ISA server.
  2. Enable FTP filter on both servers.
  3. Enable IP routing on the downstream server.
  4. Make the client a NAT client of the downstream ISA server.
  5. On the client, run the FTP client and connect to an FTP server that is running on an external network that is upstream of the ISA server.
  6. Log onto the FTP server and try to list the folder contents (with the dir command) or try to transfer a file.
The FTP client stops responding (hangs) when you try to receive a list of the folder contents.

Note that this problem does not occur if you disable IP routing on the downstream ISA server.

Modification Type:MajorLast Reviewed:10/16/2002
Keywords:kbISAServ2000sp1fix kbprb kbQFE KB313356