Forefront Edge Security - Internet Access ForumA forum for the discussion of issues and ideas regarding Internet access through Forefront Edge Security (ISA Server).© 2009 Microsoft Corporation. All rights reserved.Sun, 29 Nov 2009 12:33:08 Z10e5e945-b117-4f86-807b-a7bee944e4b3http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/a736afde-6bad-4ad9-914f-2670086e87efhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/a736afde-6bad-4ad9-914f-2670086e87efNathan Vileynhttp://social.technet.microsoft.com/Profile/en-US/?user=Nathan%20Vileyn[ISA 2006] Authentication required to upload some filesBest, <br/> in our school we use an ISA server in a domain to specify who can access the Internet, etc. <br/> We also use the service 'Smart School' which allows us to do a part of the school administrationonline. <br/> <br/> The ISA server is configured so that we always have access to smartschool, with the http and https protocols. <br/> Other Internet sites and protocols are not allowed. <br/> <br/> <br/> But we have a problem with uploading some files. If we want to upload files to smart school the AD users are being asked for their username and password for the domain, but if we fill them in running Internet Explorer, the browser crashed. And if we click the cancel button we get error 407. <br/> I had discovered that somewhere you should check the release of &quot;Require all users to authenticate&quot; but that was already out. what could be wrong here, and what should we set so that we are not more asked to authorize us? <br/> <br/> regards <br/> <br/> P.S.: sorry for my bad english <br/> <br/> A screenshot with the authorisation window:<br/> <br/> <a href="http://www.familievileyn.be/upload/tweakers/foutmelding_ISA2.JPG-for-web-LARGE.jpg">http://www.familievileyn.be/upload/tweakers/foutmelding_ISA2.JPG-for-web-LARGE.jpg</a> <br/> <br/> A screenshot when i click on cancel: <br/> <br/> http://www.familievileyn.be/upload/tweakers/fout22.JPG-for-web-LARGE.jpgMon, 23 Nov 2009 20:37:12 Z2009-11-28T11:55:59Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/1825a825-0abe-4553-b321-22ac8d6a5ac0http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/1825a825-0abe-4553-b321-22ac8d6a5ac0Bruno Martinez Ribeirohttp://social.technet.microsoft.com/Profile/en-US/?user=Bruno%20Martinez%20RibeiroURL RequestSomebody configured a ISA 2006 server.<br/> There are Internal network and VPN Client.<br/> The ISA itself is working fine, but yesterday I put a Squid to filter th web content, but the Squid is is only filtering the Internel Network, the VPN client pass through the Squid. Looking in ISA Logging I noticed that the traffic from VPN clients the ISA is forwarding to squid, but changing the URL to the IP destiny. Thats why the Squid is not filtering. Looking the traffic from Internal Network is working normally, the URL is the DNS name of the site.<br/> I need to know why the ISA is changing the URL request to the IP, and how I can fix this problem?<br/> thanksWed, 25 Nov 2009 15:48:16 Z2009-11-25T17:40:36Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/e772b988-3a5e-44b9-83cb-4ad317a1434bhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/e772b988-3a5e-44b9-83cb-4ad317a1434b-MK2-http://social.technet.microsoft.com/Profile/en-US/?user=-MK2-404 errors and pages won't load correctly using upstream server using ISA 2006<span style="font-family:'Times New Roman';font-size:medium"> <div style="color:#000000;font-family:Verdana, Arial, Helvetica, sans-serif;font-size:67%;background-image:initial;background-repeat:initial;background-attachment:initial;background-color:#ffffff;margin:8px"> <div>Hi,</div> <div><br/></div> <div>We've got a single network adapter scenario.</div> <div><br/></div> <div>I configured ISA 2006 to work as the default router/firewall for the network. </div> <div>It works good, with no problems, but when I create a webchaining rule which redirects to an upstream server (a proxy server), it won't work properly. Many pages comes with error, like 404 error, some pages won't load. But the weird thing is that many pages will work right too. </div> <div>The problem isn't on the external proxy server, because I can use it normally on proxy settings on IE, for example. </div> <div>Both SSL and HTTP ports are 8080.</div> <div>I tried a hotfix for ISA http://support.microsoft.com/?kbid=941297, but it didn't work.</div> <div><br/></div> <div>When I run best practices analyzer, it comes with some issues:</div> <div><br/></div> <div><span style="font-style:italic">The secure channel to the domain controller cannot be verified. </span>&gt;<strong> I don't believe it's relevant, but says its critical.</strong></div> <div><br/></div> <div><em>Strict RPC compliance is enforced in the access rule web, which allows traffic to or from the Local Host network. This message can be safely ignored if this is your intention. To allow non-strict RPC traffic, expand the Firewall Policy node, right-click the rule web, click Configure RPC protocol, and clear the Enforce strict RPC compliance check box. &gt; </em><strong>Not sure about this one.</strong></div> <div><strong><br/></strong></div> <div><em>This computer has only one connected network adapter. Note that several ISA Server features, for example, application filters, cannot be used with only one network adapter. Traffic requiring an application filter (for example, FTP traffic) will not pass through an ISA Server computer operating in a single network adapter scenario. </em><strong>Not sure about this one, but shouldn't be a problem, it works ok when web chaining upstream is disabled.</strong></div> <div><strong><br/></strong></div> <div>Another thing is that I'm using NAT instead Route relationship. Could it be relevant?</div> <div><br/></div> <div>Well, thanks fro any help</div> <div><br/></div> <div>MK2</div> <div><em><br/></em></div> <div><em><br/></em></div> <div><br/></div> </div> </span>Wed, 18 Nov 2009 00:12:52 Z2009-11-18T21:49:43Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/f0d42363-b238-411c-a83d-17a605627b54http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/f0d42363-b238-411c-a83d-17a605627b54DougB12345http://social.technet.microsoft.com/Profile/en-US/?user=DougB12345TMG RC1 - Multiple External Networks - spoofed packet errorI have TMG RC1 running.  I have 3 NICS.  1 Internal, 1 the default external, 1 an additional External (second ISP).  I am set up with ISP redundancy and this is working.<br/><br/>I want to take advantage of the second ISP additional inbound IP access to web sites and MX data.<br/><br/>If I ping an IP address on the second external NIC I see the packet on TMG and get the following error: <span>A packet was dropped because Forefront TMG determined that the source IP address is spoofed.  I allow PING inbound on that network.<br/><br/>I also have a Policy rule to allow an address on the second external NIC for OWA access.  If I telnet port 443 I get the same spoofing error.<br/><br/>What am I missing?  Maybe I am assuming the concept will work and it won't?<br/><br/>Any help is appreciated.  Is this the correct Forum?<br/><br/>Thanks.<br/><br/>Doug</span>Mon, 02 Nov 2009 01:05:39 Z2009-11-17T19:27:47Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/c60594d8-8abd-41e6-88e2-5762c2cf8726http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/c60594d8-8abd-41e6-88e2-5762c2cf8726TBorelyhttp://social.technet.microsoft.com/Profile/en-US/?user=TBorelyfailure to parse response headerWe have recently configured an ISA caching server behind a SPAM appliance.  Browsing to most sites are fine, but we have noticed that when accessing microsoft related sites (such as hotmail and technet, to name a few), the users are getting &quot;Forbidden 403 - Failure to parse response header&quot;.  To bypass this, we have to disable the ISA caching.<br/><br/>Any thoughts on this?Tue, 10 Nov 2009 13:03:56 Z2009-11-16T03:58:11Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/63ef37f5-fddd-4ba5-aff9-89ce432fe862http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/63ef37f5-fddd-4ba5-aff9-89ce432fe862Emem2http://social.technet.microsoft.com/Profile/en-US/?user=Emem2ISA Server 2006 configuration<p>Hi,</p> <p>I am testing the installation of ISA server 2006 and I'm having a few issues.</p> <p>1. Local urls that do not have FQDN does not get resolved. e.g. from the browser typing &quot;servername:2301&quot; will be completely blocked but &quot;servername.n.e.local:2301&quot; works.</p> <p>2. using the eg above i.e. &quot;servername.n.e.local:2301&quot;, it redirects to https and fails. when I attempt to configure the firewall to redirect ssl requests, it requests for certificate and I am unable to find nor create any certificate.</p> <p>Can you please assist.</p> <p>Thanks a lot,</p> <p>Emem</p>Tue, 10 Nov 2009 07:51:10 Z2009-11-16T03:09:51Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/c0e2b6ca-6183-4d89-a5ef-21d1488c9a5ehttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/c0e2b6ca-6183-4d89-a5ef-21d1488c9a5ewwITmanhttp://social.technet.microsoft.com/Profile/en-US/?user=wwITmanInternet access through a Forefront TMG server virtual machineAnyone running a Windows 2008 Forefront TMG Security Server as a virtual machine?<br/>I have a ESXi 4 host running Windows Essential Business Server 2008 - Management, Security, and Messaging Servers.  The host is a new Dell T105, 2.3GHz dual core, 8GB, Dual NICS, with SATA 7.2K drives - very modest but the performance metrics of ESXi doesn't reveal any real bottlenecks in this very light duty evaluation environment.  Internet access is very fast and responsive when connecting directly to the Internet with physical or virtual machies with my router as the gateway but when using this Forefront Security Server as the gateway I am experiencing very slow webpage loading.  If I run a Internet bandwidth test, the results are very similar to using my router or Forefront server as the gateway.<br/>I have very little experience with this software firewall on a physical or virtualized server and don't know if I am asking too much running in a virtual environment.<br/><br/>With this kind browsing responsiveness, I will be forced to avoid Forefront as my firewall/gateway. Anyone have suggestions/comments?<br/><br/> Fri, 30 Oct 2009 16:00:04 Z2009-11-14T16:54:40Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/cc97133b-361e-407d-9cd4-02203c754cb7http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/cc97133b-361e-407d-9cd4-02203c754cb7TDS_Samhttp://social.technet.microsoft.com/Profile/en-US/?user=TDS_SamEBS security server not allowing any acces to the internetNew setup of EBS 2008 everything seems to be ok but the security server which is set as the edge firewall will not allow any internet access.<br/> <br/> We are running it on a virtual environment with ESXI4 as the host OS the nics connect to a virtual switch which has the physical nic attached to as well<br/> <br/> The forefront threat managment seems to be blocking the traffic out<br/> <br/> Any help would be appreciated.<br/> ThanksTue, 18 Aug 2009 15:46:13 Z2009-11-11T10:24:51Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/f5ab7159-6b11-4b37-887e-2e812a85b67chttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/f5ab7159-6b11-4b37-887e-2e812a85b67cJamesHickmotthttp://social.technet.microsoft.com/Profile/en-US/?user=JamesHickmottISA 2004 - js error on webpageHi,<br/>I am currently running ISA 2004 SP3 on our network however i have noticed recently that on a couple of sites certain .js files are not downloaded correctly.<br/><br/>for example:<br/><a href="http://media.Theage.com.au">http://media.Theage.com.au</a> - does not download the europa.packed.js therefore causing the media player not to load (<span style="color:#0000ff"><a href="http://resources.theage.com.au/core/2007-11/js/europa.packed.js">http://resources.theage.com.au/core/2007-11/js/europa.packed.js</a>)<br/><br/><a href="https://na.blackberry.com/eng/services">https://na.blackberry.com/eng/services</a> - does not correctly download mootools.js therefore making the site unuseable. (<a href="http://na.blackberry.com/eng/mootools.js">http://na.blackberry.com/eng/mootools.js</a>) <br/><br/>both instance only download half or less of the actual js file.<br/><br/>when i am not behind the ISA it works fine so it is not firewall related.<br/><br/>Hoping someone can help<br/><br/>James</span>Tue, 10 Nov 2009 22:54:39 Z2009-11-18T02:23:08Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/2d0a5b14-1542-45c9-bb90-793f67dd071bhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/2d0a5b14-1542-45c9-bb90-793f67dd071btslaikjerhttp://social.technet.microsoft.com/Profile/en-US/?user=tslaikjerHowto tunnel Zyxel ZyWall client through ISA 2006?Hi,<br/>I have a challenge in tunnelling a ZyWall clint throuig the ISA server!<br/>I have done this before with a Cisco VPN client, which was &quot;piece of cake&quot;, but this is driving me crazy.<br/><br/>On the inside network we have a computer installed with ZyWall IPSec VPN client version 2.4, that should connect to a customer site - they have a Zyxel &quot;something&quot; router. <br/>Connecting from home is OK, the client connects as supposed, so config should be fine.<br/><br/>I have created a rule on the ISA Server which allows &quot;IKE Client&quot; and &quot;IPSec NAT-T Client&quot;.<br/>When initiating a connection from inside network, I see the connection is initated on port 500 UDP and the &quot;IKE Client&quot; rule is used to allow traffic.<br/>A little later the remote site resonds to a high number port like 30158 but the response is rejected as &quot;Unidentified IP traffic&quot;, which end the session. <br/><br/>Hope some of you clever people have a suggestion, I am stuck on this.<br/><br/>SW: Isa 2006 SP1 on Windows 2003 - all updates applied <br/>BR TorbenMon, 14 Sep 2009 07:52:09 Z2009-11-05T09:40:00Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/d95d03c1-38b8-4441-8bf5-e9c0f55859d1http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/d95d03c1-38b8-4441-8bf5-e9c0f55859d1lorfohttp://social.technet.microsoft.com/Profile/en-US/?user=lorfoDirect users to a "do you agree to company policy" page before surfingMy HR dept wants all allowed users when they first open a web browser to be directed to a page that the staff member needs to click that they accept all company policies on internet access before allowing them to the wild.<br/><br/>I had a SonicWall PRO100 firewall ages ago that this was a built in feature of the device, but can this be done on a ISA box.<br/><br/>I have ISA 2004 but can upgrade to 2006 as its in SA at the moment.<br/><br/>Thanks in advance<br/><br/>LiamMon, 26 Oct 2009 23:11:28 Z2009-11-02T20:23:05Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/899d53bb-c585-42c4-a40f-cbaa7b4de681http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/899d53bb-c585-42c4-a40f-cbaa7b4de681imprisehttp://social.technet.microsoft.com/Profile/en-US/?user=impriseDifferent proxy settings for different web sites...Hi all;<br/> <br/> I have two ISA Server 2006 that are connected to two different ISPs. Can I configured proxy settings in clients that connect to Internet via the first ISA server and connect to a different site through the second ISA Server?<br/> <br/> ThanksThu, 22 Oct 2009 11:00:45 Z2009-10-26T21:19:58Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/6aa3cb2b-3241-4d78-8a10-2ba9d924d6aehttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/6aa3cb2b-3241-4d78-8a10-2ba9d924d6aeSteve Killanhttp://social.technet.microsoft.com/Profile/en-US/?user=Steve%20KillanAccessing Facebook through TMG RCWe have sporadic issues accessing facebook through TMG, the error in the logs shows Status 13 The data is invalid<br /><br />Sometime I get get people to log on, but any messages in the inbox do not show up and the TMG server logs the above failure.<br /><br />Any ideas on a fix?<br /><br />Thx!Wed, 14 Oct 2009 20:03:18 Z2009-10-20T10:00:05Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/5bdc0cdf-ef04-4f52-80bc-e7975c1c46d5http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/5bdc0cdf-ef04-4f52-80bc-e7975c1c46d5rickyjohnhttp://social.technet.microsoft.com/Profile/en-US/?user=rickyjohnHostname replacement for outgoing requests<p>We send messages from an internal app&nbsp;to an external&nbsp;app/webserver&nbsp;(via ISA 2006)&nbsp;where the internal&nbsp;app uses a specific&nbsp;hostname in its http request (we use a&nbsp;Webchaining rule to bridge the http to SSL and we also have an access rule to allow the trafic through to the destination server).&nbsp;This works happilly&nbsp;but we now&nbsp;require the hostname on the request to be changed to a different value (for various reasons I won't go into we can't have&nbsp;our app&nbsp;do this).<br /><br />I.e. we send a request to URL <a href="http://testserver.bob.job.co.uk/blah">http://testserver.bob.job.co.uk/blah</a> and the destination requires the request to be <a href="https://newserver.bob.job.co.uk/blah">https://newserver.bob.job.co.uk/blah</a>.&nbsp;What I suppose I'm looking for&nbsp;is a similar thing to the web publishing rule which&nbsp;allows you to&nbsp;modify the host value sent onto&nbsp;requests for incoming web server requests?<br /><br />Any help greatly appreciated.&nbsp;</p>Thu, 08 Oct 2009 16:08:29 Z2009-10-14T01:55:05Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/629fde91-5bd5-4706-89fa-5cab8c62d29ehttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/629fde91-5bd5-4706-89fa-5cab8c62d29ecpgthttp://social.technet.microsoft.com/Profile/en-US/?user=cpgtISA 2006 Error Code: 403 Forbidden. The server denied the specified Uniform Resource Locator (URL). Contact the server administr<p align=left><font face=Arial size=2></font> </p> <p class=MsoNormal style="margin:0in 0in 0pt"><font size=3><font face="Times New Roman">I installed and configured ISA 2006 to allow HTTP traffic.  I am unable to access any website other than Microsoft.com.<span style="">  </span>The following error occurs whenever I try to access a non-Microsoft website. (I can ping any website from the command prompt on the ISA server.)</font></font></p> <p class=MsoNormal style="margin:0in 0in 0pt"><font face="Times New Roman" size=3> </font></p> <p class=MsoNormal style="margin:0in 0in 0pt"><b style=""><i style=""><font size=3><font face="Times New Roman">The page cannot be displayed</font></font></i></b></p> <p class=MsoNormal style="margin:0in 0in 0pt"><b style=""><i style=""><font size=3><font face="Times New Roman">Error Code: 403 Forbidden. The server denied the specified Uniform Resource Locator (URL). Contact the server administrator. (12202) </font></font></i></b></p> <p class=MsoNormal style="margin:0in 0in 0pt"><font face="Times New Roman" size=3> </font></p> <p class=MsoNormal style="margin:0in 0in 0pt"><font size=3><font face="Times New Roman">I am not seeing any relevant documentation on Microsoft website. I saw a hot fix that Microsoft sent.<span style="">  </span>I tried it but it did not work.</font></font></p> <p class=MsoNormal style="margin:0in 0in 0pt"><font face="Times New Roman" size=3> </font></p> <p class=MsoNormal style="margin:0in 0in 0pt"><font size=3><font face="Times New Roman">I am allowing HTTP traffic, and I am not blocking the websites we want to access. What do I have to do differently on ISA 2006 from what I did on our ISA 2004?<span style="">   </span>I configured ISA 2006 the same way I did for our working copy of ISA 2004.</font></font></p> <p class=MsoNormal style="margin:0in 0in 0pt"><font face="Times New Roman" size=3> </font></p>Thu, 13 Dec 2007 21:57:08 Z2009-10-09T13:50:40Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/47444574-2a14-43af-94bf-448139adbb58http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/47444574-2a14-43af-94bf-448139adbb58John Gwinnerhttp://social.technet.microsoft.com/Profile/en-US/?user=John%20GwinnerISA 2006, 500 Internal Server Error. The request is not supported. (50) staples.com not available!We recently upgraded to ISA 2006 from ISA 2004.  Now, many web sites give an error (see below).  Help!<br/><br/>ISA 2006, on Win2k3, all current on patches and SP's.  Single edge Firewall / router configuration.<br/><br/>Steps to reproduce:<br/>1) Go to www.staples.com<br/>2) Add any product to the cart<br/><br/>The following web page comes up immediatly:<br/><br/> <table border=0 width=400> <tbody> <tr> <td width=25> </td> <td width=400><strong>Technical Information (for support personnel)</strong> <ul class=adminList> <li>Error Code: 500 Internal Server Error. The request is not supported. (50) </li> <li>IP Address: 72.246.110.125 </li> <li>Date: 8/13/2009 8:33:21 PM [GMT] </li> <li>Server: Server-FWall-2.example.local </li> <li>Source: proxy </li> </ul> </td> </tr> </tbody> </table> I've already disabled the compresesion filter (fixed the problem in ISA 2004), DiffServe filter, HTTP Filter, and Caching Compressed Content Filter.  Caching is turned off.  In General prefferences, HTTP Compression is enabled, but no sites are configured.  (all web filters had been turned on initially, except for Authentication Delegation Filter, which I disabled to allow some web sites to be published).<br/><br/>Under Firewall Policy, the outbound rule has max headers at 32k, any payload length, and max URL at 16k, no verify normalization and block high bit off.  No blocking of responses containing Windows executables, all methods, all extensions, send original header, and send default header.<br/><br/>As near as I can tell it's 'wide open' but still not working.<br/><br/>I checked the logging tab and there are no firewall rules that are denying the request, I get pretty much the same info as above.<br/><br/>I find it very hard to believe that pretty much 'out of the box' ISA 2006 doesn't allow you to book hotel rooms at Marriot or order products from Staples.  This was a problem in 2004, and it's obviously still a problem in 2006 :(<br/><br/>I've checked ISA Server.org but no answers there either.<br/><br/>Any ideas?<br/><br/>== John ==<br/><br/>P.S.  Response from the Firewall logs:<br/><br/>Original Client IP Client Agent Authenticated Client Service Referring Server Destination Host Name Transport HTTP Method MIME Type Object Source Source Proxy Destination Proxy Bidirectional Client Host Name Filter Information Network Interface Raw IP Header Raw Payload GMT Log Time Source Port Processing Time Bytes Sent Bytes Received Cache Information Error Information Authentication Server Log Time Client IP Destination IP Destination Port Protocol Action Rule Result Code HTTP Status Code Client Username Source Network Destination Network URL Server Name Log Record Type<br/>0.0.0.0 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Yes Proxy  72.246.110.125 TCP GET  Internet - -  - Req ID: 0cdeeb8f  - - - 8/13/2009 8:59:04 PM 0 5359 4258 1957 0x3040000 0xd00  8/13/2009 1:59:04 PM 192.168.253.8 72.246.110.125 80 http Failed Connection Attempt Outbound <br/><br/>Access  50 The request is not supported.  anonymous Internal External <a href="http://72.246.110.125/office/supplies/StaplesAddToCart?ST_viewFrom=sku&amp;langId=-1&amp;storeId=10001&amp;productId=221478&amp;errorUrl=sku&amp;URL=yourorder&amp;catalogId=10051&amp;quantity_1=1&amp;partNumber_1=733726&amp;cmArea_1=FEATURED:SC3:CG75&amp;ST_minLeadTime_1=1&amp;ST_maxLeadTime_1=1">http://72.246.110.125/office/supplies/StaplesAddToCart?ST_viewFrom=sku&amp;langId=-1&amp;storeId=10001&amp;productId=221478&amp;errorUrl=sku&amp;URL=yourorder&amp;catalogId=10051&amp;quantity_1=1&amp;partNumber_1=733726&amp;cmArea_1=FEATURED:SC3:CG75&amp;ST_minLeadTime_1=1&amp;ST_maxLeadTime_1=1</a> SERVER-FWALL-2 Web Proxy Filter<br/><br/> <table border=0 width=400> <tbody> <tr> <td width=25> </td> <td width=400> <p> </p> </td> </tr> </tbody> </table><hr class="sig">== John ==Thu, 13 Aug 2009 21:12:35 Z2009-10-07T18:46:52Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/0e00445c-2db1-46f4-aa53-53a205d5a02chttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/0e00445c-2db1-46f4-aa53-53a205d5a02cIsaac2k2http://social.technet.microsoft.com/Profile/en-US/?user=Isaac2k2OWA issueHi,<br /><br />I am having a little problem solving this issue.<br /><br />Background: I have two exchange 2003 FE servers (NLB) and ISA 2006 server.<br /><br />Plan: I want to configure ISA to accept only https&nbsp;(443)&nbsp;request from external sources and use http (80) to communicate with internal FE servers (in other words, no certificates to be installed on the exchange FE servers).<br /><br />Configuration: I have an internal CA server which I had requested a certificate for the web address, exported it to a pfx&nbsp;file. Imported&nbsp;it to the personal\certficates folder on ISA, removed the certificate from the exchange FE server and published the web address.<br /><br />Tests: When I request <a href="http://&quot;NLB">http://"NLB</a> IP"/exchange from internal system, it works. When I request <a href="http://&quot;IP">http://"IP</a> address of ISA internal LAN"/exchange, not working. When I request <a href="https://webmail.xxx.xom/exchange">https://webmail.xxx.xom/exchange</a> from external source, not working.<br /><br />Question: Any ideas from anyone on this scenerio?<br /><br />Thanks<br />Isaac<hr class="sig">Isaac2k2Wed, 07 Oct 2009 08:26:55 Z2009-10-14T01:50:54Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/5140df09-18c1-488f-98aa-17cc290744ddhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/5140df09-18c1-488f-98aa-17cc290744dddaveHassenhttp://social.technet.microsoft.com/Profile/en-US/?user=daveHassenInternet CONTENT filtering for ISA 2006We've recently installed an ISA server as our firewall / internet gateway to replace a legacy linux system that no-one knows how to use. We wanted to move everything to a windows based system. <br/><br/>We're a school, so internet filtering is very important. Content filtering is the key, and this job was done very well with weighted phrases and banned words by DansGuardian on Linux, previously. <br/><br/>Is there a way to filter web CONTENT - text, meta tags, etc using ISA 2006 (we were told there was, hence we installed it). I can't find anything suitable. I don't want to monitor - I want to filter. Please let me know if you currently use somthing like this in your organisation. <br/><br/>Currently we're banning over a million domains and URLs using ISA firewall rules, but if you type the 'f' word into google image search, guess what you get? Not good. <br/><br/>ThanksThu, 01 Oct 2009 12:28:44 Z2009-10-09T01:44:37Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/6047bb20-17ed-48c2-b26e-53293aa55212http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/6047bb20-17ed-48c2-b26e-53293aa55212mohd zuberhttp://social.technet.microsoft.com/Profile/en-US/?user=mohd%20zuberunable to specify the web access permission to domain users (ISA)Dear Friend,<br /><br />i create a&nbsp; new setup with&nbsp;three server 2003in my domain as follows<br />1. primary domain controller<br />2. as exchanger&nbsp; server<br />3. as ISA server<br /><br />every thing is working fine except ISA server<br />when i allow "all users" to internet everybody can access the internet and it is working<br />i am facing the problem to&nbsp;permit some user to internet,<br />then nighter permited user can access the internet nor othes<br /><br />please help me<br /><br />with rerards<br /><br />Mohd ZuebrMon, 05 Oct 2009 07:12:50 Z2009-10-12T02:23:28Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/427345f2-6a2d-49ed-9ae1-778f6f6b0805http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/427345f2-6a2d-49ed-9ae1-778f6f6b0805Dr. Recaihttp://social.technet.microsoft.com/Profile/en-US/?user=Dr.%20RecaiNAT regarding to ActiveDirectory GroupsHello,<br /> I want to know ; is it (or how) possible to NAT regarding to user accounts/groups?<br /> For example;<br /> if user1 is a member of Group1 will take the IP (192.168.1.1) while user2 is a member of Group2 will take the IP (192.168.1.2).<br /> <br /> I want to know all possibilities. (adding another NIC , or installing a software etc. Hardware and/or Software solutions). <br /> <br /> Best Regards,<br /><hr class="sig">Our Time is Running OutMon, 05 Oct 2009 07:20:07 Z2009-10-07T18:48:56Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/d4244edd-e336-4e96-94db-363ffad29382http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/d4244edd-e336-4e96-94db-363ffad29382TeKi - MXhttp://social.technet.microsoft.com/Profile/en-US/?user=TeKi%20-%20MXSecureNat client not accessing cacheI have a problem with securenat clients accesing caching objects in ISA 2006. I made a test with a Service Pack of 107MB. When i set IE to use the ISA proxy , it downloads the 107MB in 1 second. If i uncheck to use the proxy, the PC begin to download the 107MB from internet. Is this normal ?<hr class="sig">TeKiThu, 27 Aug 2009 17:25:16 Z2009-09-30T15:27:58Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/64db4d85-e2d1-4c5f-bbe6-4edc02fac84ahttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/64db4d85-e2d1-4c5f-bbe6-4edc02fac84ajroc151http://social.technet.microsoft.com/Profile/en-US/?user=jroc151By passing AD authentication in ISA 2006Hello,<br/><br/>I have a domain webserver running IIS6 on a Windows 2003 Std server.  Curerntly, I have published my website via a rule set up on my ISA 2006 server.  Outside of my LAN, when users try to connect to:  <a href="https://xyz123.com">https://xyz123.com</a>, they are greeted with an authentication dialog box, asking users to enter their domain credentails.  Once this is done, all works like a charm.  On the LAN side, you do not get the dialog box for authentication.<br/><br/>I am having a tough time trying to figure out if there is a way to bypass authenticating through Active Directory, just to get to the webserver externally?  Is my only option to put my webserver in a DMZ?  Any tips and advice is greatly appreciated!<br/><br/>Thanks in advance!Mon, 28 Sep 2009 22:51:06 Z2009-09-28T23:48:38Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/1943011c-1d0f-4598-b7f6-a98255cb2b7chttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/1943011c-1d0f-4598-b7f6-a98255cb2b7carvato01http://social.technet.microsoft.com/Profile/en-US/?user=arvato01ISA 2006 - Webproxy BypassHi All, <br/>Can somebody please advise? I have discovered a major problem with our proxy server. Users have discovered the easy way to surf anonymously. <br/><br/>Setup: <br/>ISA 2006, Unihomed, Only providing the Webproxy service. <br/>Browsers configured to &quot;automatically detect settings&quot; (I've confgured the dhcp option), and also checked the box &quot;to use automatic configuration script&quot; <br/>Polcies in ISA server use Active Directory groups. <br/>We have two AD groups, &quot;unrestricted&quot; and &quot;restricted&quot; users. This works without problem and all internet traffic gets proxied via ISA server. <br/><br/>Problem: <br/>I added a http website to the allowed list for restricted users. What I noticed then was very strange, the website in question was <a href="http://login.live.com/"><span style="color:#003399">http://login.live.com</span></a> <br/>(in fact it can be any website where eventually the address bar goes green and changes to https/secure) <br/><br/>The users have worked out that if they go to a https site that is allowed for them to access all they have to do is <br/>enter any username/password, the authentication will fail, but that does not matter as long as the address bar changes <br/>to a secure https connection. <br/>What they then do, without closing the browser, they overtype the address bar with any website they want to go to and IE takes <br/>them there. <br/><br/>for example: <br/><br/>I enter the following url, into ie: <br/><br/><a href="https://www.hsbc.co.uk/"><span style="color:#003399">https://www.hsbc.co.uk</span></a> <br/>wait for the address bar to turn green/https. <br/>then overtype the <a href="https://....,/"><span style="color:#003399">https://....,</span></a> with any url you want. <br/><br/>Internet explorer will take you straight there.... <br/><br/>Now when I enabled monitoring on proxy server, I could see all the web traffic up to the point where the user breaks the policy. <br/>This means that the the client browser goes directly to the website. No record is logged in ISA, in the example above the last <br/>log entry will show <a href="https://www.hsbc.co.uk,/"><span style="color:#003399">https://www.hsbc.co.uk,</span></a> but no webistes after that. <br/><br/>Wireshark has confirmed that the client goes direct to the website, bypassing the proxy server. <br/><br/>Now the webproxy service can be bypassed whenever the &quot;automatically detect settings&quot; and/or &quot;use automatic configuration script&quot; <br/>check boxes are enabled. <br/><br/>The only way I worked out how to prevent this happening is to fill in the proxy server settings ip/name, under the proxy section <br/>by ticking the check box &quot;use a proxy server for your LAN&quot;. In which case the browser/ISA server will think about the website you <br/>are tying to get to then eventually send the browser the &quot;deny&quot; page I've setup. <br/><br/>But I don't want to put in the proxy server ip's into the browser as it affect laptops users.... when they try to connect <br/>to the internet from home. <br/><br/>Conclusion: <br/>It appears that when you use any of the two &quot;automatic configuration&quot; check boxes you can easily bypass the proxy, it looks like the browser waits for a reply to <br/>the url request from the client, it doesn't get one quickly enough, so the client browser says the proxy is not avialable <br/>and decides to go directly to the website. <br/><br/>If you open up another IE session on the same terminal and try to go to a &quot;not&quot; allowed website you get our deny page. <br/>But within the IE window that is now directy accessing the internet you can go to any website you want to. <br/><br/>I thought the simple fix to this was to disable direct access. By unchecking the box, on the internal network properties, Web Browser tab: <br/><br/>&quot;If ISA server is unavailable, use this backup route to connect to the Internet - Direct Access&quot; <br/><br/>But this does not make any difference, even after unchecking the ie network options, auto detect..., then reneabling them. apparently you have to do this <br/>to get the client to fetch the new wpad.dat <br/><br/><br/>Is there any way to force webproxy clients to not access the internet directly if the ISA server is not available/does not reply quickly enough? <br/><br/>please find below my wpad.dat <br/><br/><br/>//Copyright (c) 1997-2006 Microsoft Corporation <br/>BackupRoute=&quot;DIRECT&quot;; <br/>UseDirectForLocal=true; <br/>function MakeIPs(){ <br/>} <br/>DirectIPs=new MakeIPs(); <br/>cDirectIPs=0; <br/>function MakeCARPExceptions(){ <br/>} <br/>CARPExceptions=new MakeCARPExceptions(); <br/>cCARPExceptions=0; <br/>function MakeNames(){ <br/>} <br/>DirectNames=new MakeNames(); <br/>cDirectNames=0; <br/>HttpPort=&quot;8080&quot;; <br/>cNodes=1; <br/>function MakeProxies(){ <br/>this[0]=new Node(&quot;mypxy01.domain.local&quot;,0,1.000000); <br/>} <br/>Proxies = new MakeProxies(); <br/>function Node(name, hash, load){ <br/>this.name = name; <br/>this.hash = hash; <br/>this.load = load; <br/>this.score = 0; <br/>return this; <br/>} <br/>function FindProxyForURL(url, host){ <br/>var hash=0, urllower, i, fIp=false, ip, nocarp=false, skiphost=false; <br/>var list=&quot;&quot;, pl, j, score, ibest, bestscore; <br/>urllower = url.toLowerCase(); <br/>if((urllower.substring(0,5)==&quot;rtsp:&quot;) || <br/>(urllower.substring(0,6)==&quot;rtspt:&quot;) || <br/>(urllower.substring(0,6)==&quot;rtspu:&quot;) || <br/>(urllower.substring(0,4)==&quot;mms:&quot;) || <br/>(urllower.substring(0,5)==&quot;mmst:&quot;) || <br/>(urllower.substring(0,5)==&quot;mmsu:&quot;)) <br/>return &quot;DIRECT&quot;; <br/>if(UseDirectForLocal){ <br/>if(isPlainHostName(host)) <br/>fIp = true;} <br/>for(i=0; i&lt;cDirectNames; i++){ <br/>if(shExpMatch(host, DirectNames<em>)){ <br/>fIp = true; <br/>break;} <br/>if(shExpMatch(url, DirectNames<em>)) <br/>return &quot;DIRECT&quot;; <br/>} <br/>if(cDirectIPs == 0){ <br/>if(fIp) <br/>return &quot;DIRECT&quot;;} <br/>else{ <br/>ip = host; <br/>if(fIp) <br/>ip = dnsResolve(host); <br/>var isIpAddr = /^(\d+.){3}\d+$/; <br/>if(isIpAddr.test(ip)){ <br/>for(i=0; i&lt;cDirectIPs; i += 2){ <br/>if(isInNet(ip, DirectIPs<em>, DirectIPs[i+1])) <br/>return &quot;DIRECT&quot;;}} <br/>else if(isPlainHostName(host)) <br/>return &quot;DIRECT&quot;; <br/>} <br/>if(cCARPExceptions &gt; 0){ <br/>for(i = 0; i &lt; cCARPExceptions; i++){ <br/>if(shExpMatch(host, CARPExceptions<em>)){ <br/>nocarp = true;} <br/>if(shExpMatch(url, CARPExceptions<em>)){ <br/>nocarp = true; <br/>skiphost = true; <br/>break; <br/>}}} <br/>if(!skiphost) <br/>hash = HashString(host,hash); <br/>if(nocarp) <br/>hash = HashString(myIpAddress(), hash); <br/>pl = new Array(); <br/>for(i = 0; i&lt;cNodes; i++){ <br/>Proxies<em>.score = Proxies<em>.load * Scramble(hash ^ Proxies<em>.hash); <br/>pl<em> = i; <br/>} <br/>for(j = 0; j &lt; cNodes; j++){ <br/>bestscore = -1; <br/>for(i = 0; i &lt; cNodes-j; i++){ <br/>score = Proxies[pl<em>].score; <br/>if(score &gt; bestscore){ <br/>bestscore = score; <br/>ibest = i; <br/>}} <br/>list = list + &quot;PROXY &quot; + Proxies[pl[ibest]].name + &quot;:&quot; + HttpPort + &quot;; &quot;; <br/>pl[ibest] = pl[cNodes-j-1]; <br/>} <br/>list = list + BackupRoute; <br/>return list; <br/>} <br/>var h_tbl = new Array(0,0x10D01913,0x21A03226,0x31702B35,0x4340644C,0x53907D5F,0x62E0566A,0x72304F79,0x8680C898,0x9650D18B,0xA720FABE,0xB7F0E3AD,0xC5C0ACD4,0xD510B5C7,0xE4609EF2,0xF4B087E1); <br/>function HashString(str, h){ <br/>for(var i=0; i&lt;str.length; i++){ <br/>var c = str.charAt(i); <br/>if(c ==':' || c == '/') break; <br/>c = CharToAscii(c.toLowerCase()); <br/>h = (h &gt;&gt;&gt; 4) ^ h_tbl[(h ^ c) &amp; 15]; <br/>h = (h &gt;&gt;&gt; 4) ^ h_tbl[(h ^ (c&gt;&gt;&gt;4)) &amp; 15]; <br/>h = MakeInt(h); <br/>} <br/>return h; <br/>} <br/>function Scramble(h){ <br/>h += ((h &amp; 0xffff) * 0x1965) + ((((h &gt;&gt; 16) &amp; 0xffff) * 0x1965) &lt;&lt; 16) + (((h &amp; 0xffff) * 0x6253) &lt;&lt; 16); <br/>h = MakeInt(h); <br/>h += (((h &amp; 0x7ff) &lt;&lt; 21) | ((h &gt;&gt; 11) &amp; 0x1fffff)); <br/>return MakeInt(h); <br/>} <br/>var Chars =&quot; !\&quot;#$%&amp;\'()*+,-./0123456789:;&lt;=&gt;?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~€&#129;???????????&#141;Ž&#143;&#144;????????????&#157;ž? ¡¢£¤¥¦§¨©ª«¬­®¯°±²³´µ¶·¸¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖרÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþ &quot;; <br/>function CharToAscii(c){ <br/>return Chars.indexOf(c) + 32; <br/>} <br/>function MakeInt(x){ <br/>x %= 4294967296; <br/>if(x &lt; 0) <br/>x += 4294967296; <br/>return x; <br/>} <br/><br/><br/>when unchecked the option to directly access the internet, I compared the wpad.dat file with the earlier one, but it was identical. <br/><br/>This is the bit that I think may be causing the problem: <br/><br/>BackupRoute=&quot;DIRECT&quot;; <br/><br/><br/>Please can somebody offer any advise? <br/><br/>Regards </em></em></em></em></em></em></em></em></em></em>Thu, 10 Sep 2009 15:29:19 Z2009-09-24T10:13:20Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/264f3e51-6834-4bee-9037-a0eacc51958bhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/264f3e51-6834-4bee-9037-a0eacc51958bRobert Micallefhttp://social.technet.microsoft.com/Profile/en-US/?user=Robert%20MicallefWeb access and remote work place stopped functioningSetup is on SBS 2003 enterprise edition - ISA<br/><br/>I was editing a rule to block remote access except from one ip address - <br/><br/>The problem i i created a new network and automatically it created a virtual network card.<br/><br/>From that point after my web access and remote work place stoped working.<br/><br/>I deleted the new network and set all the settings back to its place but the problem is still persistent.<br/><br/>i think it is something to do with the new network card creeated - and when i try to uninstall the network card from device manager. it crashes.<br/><br/>Any help please?Tue, 22 Sep 2009 17:47:50 Z2009-09-22T20:02:12Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/e9f38c07-989d-48e0-bf16-50c892889094http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/e9f38c07-989d-48e0-bf16-50c892889094Alex Iarmolioukhttp://social.technet.microsoft.com/Profile/en-US/?user=Alex%20IarmolioukIs it possible to configure a timed exclusion in TMG Web access policies?<p>We'd like to allow our users to access certain site categories for 30-60 minutes per day. <br/>Previously we used SurfControl as a web filtering application, which allows that. Many other web filtering applications also support that.<br/>The question is: is that possible to configure that in TMG Beta 3? If not, will it be possible in production versions?<br/>Regards,<br/>Alex</p>Fri, 18 Sep 2009 13:36:57 Z2009-09-27T10:31:50Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/3bd9fb50-2c01-4fc1-8b99-dfa967e7a77ehttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/3bd9fb50-2c01-4fc1-8b99-dfa967e7a77esalman gilanihttp://social.technet.microsoft.com/Profile/en-US/?user=salman%20gilaniProblem Accessing ftp sites REQUIRE authentication behind ISA 2006I have allowed full access behind isa for webproxy and firewall clients , but when i try to access any ftp site with authentication , isa does not prompt user for authentication and just opens ftp site but i am not able access all folders since they need authentication , is this something a bug in isa that it strips authentication and seems make web proxy clients access external ftp site as integrated authentication mode , i am using isa behind ASA and all clients are routed through router to isa and in isa i have persistent routes configured.<br/><br/>help from Top Micorosoft engineers will be really appreciatedThu, 10 Sep 2009 19:44:57 Z2009-09-18T06:21:42Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/bda71809-d35c-4211-9ac8-1f081071eebahttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/bda71809-d35c-4211-9ac8-1f081071eebaRBansehttp://social.technet.microsoft.com/Profile/en-US/?user=RBanse12209 The ISA Server requires authorization to fulfill the requestCould really use some help. I have a user trying to access an https site through an app, and it's not allowing the connection. I added the site in the Bypass Sites but it still is not allowing the user through. Here is what I am seeing in the log...<br/><br/> <table style="height:100%" border=0 cellspacing=0 cellpadding=0 width="100%"> <tbody> <tr> <td class=dFilter colspan=5 width="100%" height="35%"> </td> </tr> <tr> <td class=Logpane-bar colspan=5><a title="Open / Close Filter"><img class=Logpane-knob src="http://social.technet.microsoft.com/Forums/en-US/_image/LogPane/log-off-up.png" alt=""> </a></td> </tr> <tr> <td colspan=5 height=1> </td> </tr> <tr> <td colspan=5 height=1> </td> </tr> <tr> <td colspan=5 width="50%" height="100%" valign=top> </td> </tr> <tr> <td class=Logpane-bar colspan=5><a title="Open / Close Logging Details Pane"> </a></td> </tr> <tr valign=top> <td colspan=5 height=275 bgcolor="#fffbf7"> <table border=0 cellpadding=0> <tbody> <tr bordercolor="#2e4c75"> <th width="100%" align=left><span style="color:#ff0000">Denied Connection</span></th> <td width="100%" height=20 align=right><strong>LAXINTERNET 9/11/2009 2:23:19 PM</strong></td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Log type: </strong>Web Proxy (Forward)</td> </tr> <tr bordercolor="#2e4c75"> <td title="12209 The ISA Server requires authorization to fulfill the request. Access to the Web Proxy filter is denied. " colspan=2 width="100%" height="100%"><strong>Status: </strong><span>12209 The ISA Server requires authorization to fulfill the request. Access to the Web Proxy filter is denied. </span></td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Rule: </strong>Proxy Outbound</td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Source: </strong>Internal (10.210.11.122)</td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Destination: </strong>Internal (10.210.10.249:443)</td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Request: </strong>directconnect.scramnetwork.com:443</td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Filter information: </strong>Req ID: 192c2173; Compression: client=No, server=No, compress rate=0% decompress rate=0%</td> </tr> <tr> <td width="100%" height="100%" align=left><strong>Protocol: </strong>SSL-tunnel</td> </tr> <tr> <td width="100%" height="100%" align=left><strong>User: </strong>anonymous</td> </tr> <tr> <td colspan=2><dl><dt><a title="Open/Close 'Additional information' section"><img src="http://social.technet.microsoft.com/Forums/en-US/_image/general/minusImg.gif" alt=""> Additional information </a></dt> <ul style=""> <li><strong>Client agent: </strong></li> <li><strong>Object source: </strong>Internet (Source is the Internet. Object was added to the cache.)</li> <li style="word-wrap:break-word"><strong>Cache info: </strong>0x0</li> <li><strong>Processing time: </strong>0 ms</li> <li><strong>MIME type: </strong></li> </ul> </dl></td> </tr> </tbody> </table> </td> </tr> </tbody> </table> <br/> <table border=0 cellpadding=0> <tbody> <tr bordercolor="#2e4c75"> <th width="100%" align=left><span style="color:#ff0000">Denied Connection</span></th> <td width="100%" height=20 align=right><strong>LAXINTERNET 9/11/2009 2:23:19 PM</strong></td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Log type: </strong>Web Proxy (Forward)</td> </tr> <tr bordercolor="#2e4c75"> <td title="12209 The ISA Server requires authorization to fulfill the request. Access to the Web Proxy filter is denied. " colspan=2 width="100%" height="100%"><strong>Status: </strong><span>12209 The ISA Server requires authorization to fulfill the request. Access to the Web Proxy filter is denied. </span></td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Rule: </strong>Proxy Outbound</td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Source: </strong>Internal (10.210.11.122)</td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Destination: </strong>Internal (10.210.10.249:443)</td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Request: </strong>directconnect.scramnetwork.com:443</td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Filter information: </strong>Req ID: 192c2173; Req ID: 192c2173; Compression: client=No, server=No, compress rate=0% decompress rate=0%, Compression: client=No, server=No, compress rate=0% decompress rate=0%</td> </tr> <tr> <td width="100%" height="100%" align=left><strong>Protocol: </strong>SSL-tunnel</td> </tr> <tr> <td width="100%" height="100%" align=left><strong>User: </strong>anonymous</td> </tr> <tr> <td colspan=2><dl><dt><a title="Open/Close 'Additional information' section"><img src="http://social.technet.microsoft.com/Forums/en-US/_image/general/minusImg.gif" alt=""> Additional information </a></dt> <ul style=""> <li><strong>Client agent: </strong></li> <li><strong>Object source: </strong>Internet (Source is the Internet. Object was added to the cache.)</li> <li style="word-wrap:break-word"><strong>Cache info: </strong>0x0</li> <li><strong>Processing time: </strong>0 ms</li> <li><strong>MIME type: </strong></li> </ul> </dl></td> </tr> </tbody> </table> Thanks for any help! We are using ISA 2006.<br/><br/>-RyanFri, 11 Sep 2009 19:33:09 Z2009-09-15T06:43:45Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/83d0859a-a702-4e8e-a476-3be9c628ecd1http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/83d0859a-a702-4e8e-a476-3be9c628ecd1Michael37http://social.technet.microsoft.com/Profile/en-US/?user=Michael37Error Code: 502 Proxy Error. ISA Server is not configured to allow SSL requests from this port<p align=left><font face=Arial size=2></font> </p> <p>I currently have ISA Server 2006 Standard and I am only using as a web proxy on my network.</p> <p align=left> </p> <p align=left>When I am trying to access a website that is using a non-standard SSL Port, ISA is blocking the page due to the port not being configured to be used.</p> <p align=left> </p> <blockquote dir=ltr style="margin-right:0px"> <p align=left><u>Error:</u></p> <p align=left>Error Code: 502 Proxy Error. The specified Secure Sockets Layer (SSL) port is not allowed. ISA Server is not configured to allow SSL requests from this port. Most Web browsers use port 443 for SSL requests. (12204) </p></blockquote> <p> </p> <p align=left>PLEASE HELP</p>Mon, 26 Nov 2007 16:50:18 Z2009-09-11T15:25:13Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/d63d95e4-853f-4387-a1bb-497b046aeeb9http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/d63d95e4-853f-4387-a1bb-497b046aeeb9Keith Alabasterhttp://social.technet.microsoft.com/Profile/en-US/?user=Keith%20AlabasterAsking a question in the Forefront: Edge Forums<p>Before you ask your question, please take a bit of time to think about what it is you are looking to get help on. The more specific you are about what you are trying to achieve - and need help with, the easier it is for us to target the responses.<br/><br/>Tell us about the basic environment in which an error occurs or that you are working in. If you don't tell us then we will make assumptions and this can cause confusion.<br/><br/>Telling us the versions of ISA Server and service pack; whether ISA is a Proxy only or proxy/firewall installation; is the ISA FWC deployed; each of these small bits of information allow respondees to focus on the issue rather than having to make guesses or keep requesting further clarity.<br/><br/>Please be aware that the expectation will be that you have applied ALL ISA/Forefront Service Packs and updates and retested prior to asking the question.........<br/><br/>Keith Alabaster<br/>Moderator</p>Tue, 08 Sep 2009 17:47:07 Z2009-09-27T10:32:59Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/67c8ece4-fe21-4656-933a-891e66b17f76http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/67c8ece4-fe21-4656-933a-891e66b17f76DaveParkes26http://social.technet.microsoft.com/Profile/en-US/?user=DaveParkes26ISA Server 2000 + BBC I-Player and Embedded YouTube Video's<p>Hello,</p> <p>We are running ISA Server 2000 Enterprise with SP2 on Windows 2000 Advanced Server with SP4.  We are running ISA Server in Cache Only Mode. <br/>We are patched to the latest releases.</p> <p>We are unable to get embedded media to play on bbc.co.uk and embedded YouTube Videos on web pages.  The YouTube videos play if you go to the YouTube website and we don't have any problems with the BBC I-player.</p> <p>The issue with the BBC site appears to be with the BBC Media player.  Live and recorded content will not play.  The same is also true of the ITV player on itv.co.uk.  I'm also thinking that the same problem is causing the embedded YouTube issue.</p> <p>The message on the YouTube embedded vidoes is: An error occurred, please try again later.  The BBC Videos simply display the 'rotating dots' and nothing starts.</p> <p>Does anyone know how I can get the embedded videos to play? </p> <p>Thanks.</p> <p>Dave.</p>Thu, 03 Sep 2009 08:33:30 Z2009-09-11T08:21:48Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/a316c850-6cef-480f-9396-a27528ce5928http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/a316c850-6cef-480f-9396-a27528ce5928Mohammad Nasirihttp://social.technet.microsoft.com/Profile/en-US/?user=Mohammad%20NasiriProblem Importing ISA server Array Hello Friedns :<br/><br/>I want ti Import ISa server array backup but i get an error message like this &quot;<br/><br/>You should import files originating from a trusted source<br/><br/>how can i fix the problem ?<br/><hr class="sig">Network is my LOVESun, 02 Aug 2009 11:39:42 Z2009-09-27T10:35:08Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/5de69965-1dc5-409c-8165-a8558dbf7bfbhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/5de69965-1dc5-409c-8165-a8558dbf7bfblrkhanmcsehttp://social.technet.microsoft.com/Profile/en-US/?user=lrkhanmcseIsa server blockingI am facing a problem with outlook and ISA 2006 in our small company here is the details: <br/> <br/> We have subscribed with yahoo domain and email services recently with the following information: <br/> <br/> Pop: pop.gmail.com <br/> SMTP: smtp.gmail.com <br/> Server requires a secure connection (SSL); port number &quot;587&quot; in the &quot;Outgoing mail (SMTP)&quot; . <br/> Server requires a secure connection (SSL); port number &quot;995' in the &quot;Incoming mail (POP3)&quot; <br/> <br/> Before installing the ISA 2006 in the company, the outlook was working fine with above configuration. But after installing the ISA 2006 , the outlook cannot connect the above server.<br/> I already made some rules to allow all traffic from internal to external for all users and also I made rules for ssl smtp and ssl pop3 to be allowed for all users from internal to external network but still it is not working but without Isa it is working fine. <br/> I am looking to know how configure the ISA server to allow outlook clients to connect with the above server.Fri, 21 Aug 2009 16:53:44 Z2009-09-01T19:58:45Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/bf52ee64-5b94-4055-abd0-40788672f4d7http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/bf52ee64-5b94-4055-abd0-40788672f4d7VBJacksonhttp://social.technet.microsoft.com/Profile/en-US/?user=VBJacksonISA 2006 and PPPoEI have a small office, and connect to the Internet using DSL. My area is wired with fiber, so I HAVE to use PPPoE.<br/>I can configure Windows 2003 with RRAS with no problem, but when I tried to install ISA 2006 I can't find a configuration that works.<br/><br/>When I try to use demand-dial connection from the general setup tab in ISA, I get a timeout when I try to access the Internet, and monitoring never seems to show any traffic to that port.<br/><br/>Configuration:<br/>Windows 2003 on a server with 2 NICS.<br/><br/>NIC1: Internal - 1GB on-board, IP 192.168.101.1/255.255.255.0<br/>NIC2: External - 10/100 3Com, tried IP=static IP assigned by ISP and leaving unconfigured outside of ISA.Sun, 30 Aug 2009 17:06:36 Z2009-09-07T02:22:47Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/0781be65-aa49-4fc9-9286-7ce03e8ae40dhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/0781be65-aa49-4fc9-9286-7ce03e8ae40dVadim Rapphttp://social.technet.microsoft.com/Profile/en-US/?user=Vadim%20RappISA 2006: Monitoring Sessions does now show anything as soon as filter is appliedIn ISA 2006, I go to Arrays/&lt;server&gt;/Monitoring/Sessions, and I see all sessions. But if I specify a filter, then no session shows up. Any filter. For example, I can specify &quot;server name contains&quot; or &quot;server name Not Contains&quot;, zero results are displayed. Why?Wed, 05 Aug 2009 15:03:14 Z2009-08-20T15:03:03Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/bb03b12c-8163-4208-93c9-36fcba6cbb28http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/bb03b12c-8163-4208-93c9-36fcba6cbb28Tanishqhttp://social.technet.microsoft.com/Profile/en-US/?user=TanishqA strange problem facing with ISA client?Hi, <br/> I am facing strange problem . Before in client pc user is able to get internet.  Now in internet explorer when he type any web address.  He is getting an error message. <strong>Network Access Message: The page cannot be displayed.</strong> <br/> <strong>Error code: 502 proxy Error. The ISA server denied the specified (URL). (12002)</strong> <br/> <br/> Client Browser: Internet Explorer 6<br/> <strong>Note:</strong> With Mozila firefox internet is working.<br/> <br/> Even if login with other username(Full internet  access username) also its not working.<br/> <br/> <span style="text-decoration:underline">My ISA Server Configuration:</span> <br/> <span style="text-decoration:underline">Hardware:</span>   Intel P4 3.2ghz processor, 1GB RAM, 160GB Hard disk. 1 LAN card<br/> Its ISA Server 2006 standard edition with One NIC. We r using as proxy and firewall. Internet is coming through router to ISA server. All other computers are in side the ISA.  We publish Exchange server 2003 standard edition through ISA. We r using RPC over http and OWA. <br/> <br/> <span style="text-decoration:underline">My firewall policy: </span> <br/> 1. Blocked sites: Deny-&gt; All outbound traffic -&gt; Internal-&gt; URL SET(Blocked sites, Block exception)-&gt; Userset(un autharaised users group) <br/> <br/> 2. Blocked objectss: Deny-&gt; HTTP, MMS Server, MMS, PNM Server, PNM, RTSP Server, RTSP-&gt; Internal-&gt; External-&gt; Userset(Un autharised group)-&gt; <br/> Content type(Audio, Video, Video Stream)<br/> <br/> 3. Blocking Mesngers: Deny-&gt; AOL Instant mesenger, H.323 protocal, ICQ 2000, ICQ, MSN Mesenger, NET2phone, Net2phone Registration -&gt; Internal-&gt; External-&gt; Userset(un autharaised users group)<br/> <br/> 4. Net with restriction:  Allow -&gt; All outband -&gt; Internal-&gt; External -&gt; Userset(un autharaised users group)<br/> <br/> 5. OWA and RPC/HTTP:  Allow -&gt; HTTP -&gt; SSL Listener-&gt; Published sites(owa.domain.com) -&gt; All authanticated users.<br/> <br/> 6.  Open net :  Allow -&gt; All outband -&gt; Internal-&gt; External -&gt; Userset(Autharaised group, IT users)<br/> <br/> <span style="text-decoration:underline">Steps which i Tried:</span> <br/> I check with internet some are telling to uncheck <strong>Enable Integrated authantication  </strong> From Browser (Internet Explorer 6)<br/> Internet Options -&gt; Advance tab-&gt; Security -&gt; Enable Integrated Authantication.<br/> I did same still my problem is not solved. Please some one help me to solve my problem.<br/> Thank you<br/>Sun, 09 Aug 2009 12:37:17 Z2009-08-17T01:37:35Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/4b6bbb3e-70b8-4169-9ca4-cfe8ad60aa49http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/4b6bbb3e-70b8-4169-9ca4-cfe8ad60aa49salim55http://social.technet.microsoft.com/Profile/en-US/?user=salim55How can I Block IDM(Internet download Manager)with Isa server<p align=left><font face=Arial size=2></font> </p> <p>Hello,</p> <div>I saw the link <span><font color="#008000"><a href="http://www.microsoft.com/technet/isa/2004/plan/commonapplicationsignatures.mspx">www.microsoft.com/technet/isa<wbr>/2004/plan/<b>common</b><b>application</b><b>signature</b>s.mspx</a>  </font></span></div> <div><span></span><span><font color="#008000">It is very useful but some application like IDM(Internet download manager ) uses the IE standard User-agent: ,so </font></span><span><font color="#008000">we can not block this software I want block   IDM(Internet download manager ) in my Network </font></span></div> <div><span><font color="#008000">please help me how can i Block this applications ?</font></span></div> <p align=left><br style="font-size:8px" clear=all> </p>Tue, 12 Feb 2008 05:12:21 Z2009-08-11T11:18:45Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/a413cbe2-e6f0-4882-a3f4-4439ab5d8fc2http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/a413cbe2-e6f0-4882-a3f4-4439ab5d8fc2Mstrwhizrdhttp://social.technet.microsoft.com/Profile/en-US/?user=MstrwhizrdISA 2006 Remote Site IssuesI am running an ISA 2006 install on a Win 2k3 box that is joined to the domain. I am using ISA in a single NIC setup as web proxy. My company has a headquarters (HQ) and 15 remote sites (RS). The problem that I am having is that the users at the remote sites can't ping or connect to the ISA server. HQ is fine. I can ping other servers from the the remote sites and I can also ping the remote sites from the ISA server. I ran Wireshark on the ISA server to see what was happening with the ping traffic and I see 4 requests from the RS and 4 replys from the ISA server but for some reason at the RS it says it timed out. I can ping by host name and it will resolve to IP but the request times out. When I try to access a shared folder on the ISA from the RS the ISA Logging shows that the RS is trying to connect but closes the connection. It iniateates the connection and then immediatly closes the connection. <br/> <br/> I currently have 3 rules setup in the firewall policy:<br/> <ol> <li>Allow Microsoft CIFS TCP &amp; UDP/ PING / NetBios Name Service From: (Internal &amp; Local Host) To: (Internal &amp; Local Host) ALL USERS</li> <li>Allow All Outbound Traffic From: (Internal &amp; Local Host) To: (Internal &amp; Local Host) ALL USERS</li> <li>Default rule (Deny All Traffic that isn't handled by the first two rules)</li> </ol> Does anybody have an idea of what I'm doing wrong?Tue, 04 Aug 2009 17:41:51 Z2009-08-10T09:34:26Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/82920dfc-9471-4dbb-97f8-67c0b6fd9391http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/82920dfc-9471-4dbb-97f8-67c0b6fd9391Barrykinghttp://social.technet.microsoft.com/Profile/en-US/?user=BarrykingHOW DO I BLOCK WEBSITES SUCH AS FACEBOOK USING ISA 2000<p>Please understand that i have no experience of isa 2000 , however i did try and set up a rule with the content &amp; rule wizard and a destination set , In the content &amp; rule folder are 3 rules&quot; Spoofed addresses&quot; set to DENY ,&quot; Prevent Adverts &quot;set to DENY and another rule &quot;Allow Rule &quot;set to ALLOW for client sets INTERNAL ,always ,content = all .I created a new rule Selected DENY  selected clients access to all destinations,  then selected the destination set I had created referring to <a href="http://www.bt.com/"><span style="color:#0033cc">www.bt.com</span></a> as an example , apply this to  user /groups , choose myself from active directory , hoiwever when i tried to<br/>browse to the site bt.com a server logon box appeared asking for username and password ,then if i cancel that i still get to browse the net and that bt.com site , and all other users were asked to logon on with username &amp; password if they commenced browsing</p>Wed, 05 Aug 2009 14:16:09 Z2009-08-12T09:30:10Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/428a6c10-3645-4569-90e2-489e879ba87ahttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/428a6c10-3645-4569-90e2-489e879ba87aLukasz Sadownikhttp://social.technet.microsoft.com/Profile/en-US/?user=Lukasz%20SadownikCustom forms don't workHi,<br/><br/>I'm trying to customize logon form to access sharepoint site I'm trying to publish to internet. It works ok with standard forms. I've followed this article: <a href="http://technet.microsoft.com/en-gb/library/bb794733.aspx">http://technet.microsoft.com/en-gb/library/bb794733.aspx</a>.<br/>When I setup to use custom forms I get error 500. When I've tried to change images in default forms it was still showing me default form.Wed, 29 Jul 2009 14:06:46 Z2009-08-06T05:47:01Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/adbf8101-5fda-4702-9e03-98876751f520http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/adbf8101-5fda-4702-9e03-98876751f520ukfletchhttp://social.technet.microsoft.com/Profile/en-US/?user=ukfletchStrange behaviour on our new ISA serverHi There,<br/> <br/> We are experiencing issues with our new ISA2k6/Websense 7.1 set-up.  This is a single server, with one NIC, that we want to use to provide Web Proxy/Filtering.<br/> <br/> As part of the normal day-to-day operations of my company, 2 groups of users (controlled by Websense) need to be able to watch and upload videos to YouTube and Upload pictures to Facebook.<br/> <br/> Our old system, which was hosted on a similar system (ISA2k and Websense 6.x) used to handle both Youtube and Facebook with no problems.<br/> <br/> Since we have switched to the new server, even though the access rules in Websense are effectively the same, we can no longer do either.<br/> <br/> Facebook eventually times out with an ISA generated error page, and Youtube just seems to hang at a &quot;loading&quot; state - the main pages are fine, this happens when you try and watch a video.<br/> <br/> One strange thing though; If you go to video.google.com and try and watch the same video you were trying to play on YouTube - it plays, no problems.  So obviously it's not the protocol being &quot;blocked&quot;.  In fact it looks like it's the page timing out in some way, as we get no block page from Websense as we would expect (blocked pages from other categories) do display the block page as expected.<br/> <br/> One last problem is that the Proxy aslo seems to be giving out &quot;personalised&quot; pages to anyone.  For example, My iGoogle page can be seen by others if they go there after me, until they refresh.  Is there any way to stop this bahaviour in ISA2k6?<br/> <br/> Regards,<br/> <br/> Paul FletcherThu, 23 Jul 2009 09:47:49 Z2009-07-31T08:52:51Z