Forefront Edge Security - Publishing ForumA forum for the discussion of issues and ideas regarding publishing of Web and other servers through Forefront Threat Management Gateway (TMG) and ISA Server© 2009 Microsoft Corporation. All rights reserved.Tue, 01 Dec 2009 16:35:21 Z8544eb90-6708-45b2-8a48-b9c9e915ac9fhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/91cea4aa-7311-4487-a50a-83be3d450128http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/91cea4aa-7311-4487-a50a-83be3d450128Irons1983http://social.technet.microsoft.com/Profile/en-US/?user=Irons1983Cannot open Office documents when publishing Sharepoint through ISA 2006 with OTP/RADIUS<p>Hi all,</p> <p>This is a bit of a tricky one which is slowly driving me mad. I am not sure whether this is more ISA than Sharepoint but I thought I would start here.</p> <p>In a nut shell we have published our intranet site externally using ISA 2006 and are authenticating users against a RADIUS server with a token OTP solution. Everything appears to work fine until we try to open/edit a Word/Excel doc and we first are hit my a normal domain authentication prompts before finally after a minute or two of thinking about it Excel and Word both display an embedded (slightly mangled) ISA FBA form in the middle of the document....unsuprisingly this does not work when you try and authenticate.</p> <p>I understand that this is because when an Office document is open from Sharepoint this is opened in a new Internet session and ISA therefore throws up an HTML Authentication Form again requesting the OTP (along with the AD credentials as we have configured it). In its wisdom it presents the form within the Office document deeming it next to useless.</p> <p>Our environment is trypically Office 2007, IE7 or IE8. I have tested it on IE6 as well, this just fails to open the document without presenting the embedded form. Testing with the RADIUS authentication off we can successfully open the document, though we still get prompted with an additional authentication prompt which we would like to erradicate if possible to create a seamless user experience.</p> <p>Any ideas would be much appreciated.</p> <p>Chris</p>Mon, 03 Aug 2009 12:45:59 Z2009-12-01T16:35:20Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/4070d6c1-ab1b-47b9-a280-09124872aee4http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/4070d6c1-ab1b-47b9-a280-09124872aee4v_2udanhttp://social.technet.microsoft.com/Profile/en-US/?user=v_2udanRouting Internal clients web traffic as original IP to External <p>Hi All, <br/><br/>Following is my network <br/><br/>1. Clients (192.168.150.x) connect TMG on web proxy.  <br/>2. TMG (Internal IP: 192.168.200.1 and External IP: 192.168.50.1) ,which has NAT relationship between Internal to external forwards web traffic to Juniper firewall as ISA external IP. <br/>3. But Juniper does not see the clients original IP and thinks its server IP address an routes data to leased line instead of adsl.<br/><br/>my issue is how to route client traffic to adsl and server traffic to leased line <br/><br/><br/>thanks<br/>uady<br/></p>Sat, 28 Nov 2009 11:03:44 Z2009-12-01T16:24:41Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/aee14f4e-bbe4-4307-bdb3-5ff80bbfce3fhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/aee14f4e-bbe4-4307-bdb3-5ff80bbfce3frjlfchttp://social.technet.microsoft.com/Profile/en-US/?user=rjlfcISA Error HTML Pages and the 1359 (500) errorHi,<br/><br/>Would appreciate some help on the following please.......<br/><br/>When on ISA 2004 we had been using some modified ISA Error Pages to give some more descriptive/relevant information to users accessing our website for certain errors - this included displaying errors when pages could not be found including when our app was down. We have recently moved to ISA 2006 EE and use Web Farms to load balance and publish the website. It looks like due to this, when the app is now unavailable ISA recognises this due to the connectivity verifiers and publishes - Error Code: 500 Internal Server Error. An internal error occurred. (1359). Is there a way we can intercept this and show the same modified error html page(s) as before or are we stuck with the above error?<br/><br/>Many thanks,<br/>RichMon, 23 Nov 2009 10:20:19 Z2009-11-26T11:45:42Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/c2a10baa-f21c-42b2-a07e-e0f17db1374fhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/c2a10baa-f21c-42b2-a07e-e0f17db1374fPrakashkumaarhttp://social.technet.microsoft.com/Profile/en-US/?user=PrakashkumaarRD Web Access through ISA 2006<p>Hi<br/><br/>We are trying to access Remote Web Access from Internet. Ther server is Windows 2008 R2 and behind the ISA 2006. I am using Windows 7 client - Remote apps and Desktop connection.<br/><br/>When I try to setup URL <a href="https://tsweb.domain.com/RDweb/Feed/Webfeed.aspx">https://tsweb.domain.com/RDweb/Feed/Webfeed.aspx</a> I get &quot;An error occured. Contact your system administrator.<br/><br/>I found following log from ISA <br/><br/> <table border=0 cellpadding=0> <tbody> <tr bordercolor="#2e4c75"> <th width="100%" align=left><span style="color:#ff0000">Denied Connection</span></th> <td width="100%" height=20 align=right><strong></strong></td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Log type: </strong>Web Proxy (Reverse)</td> </tr> <tr bordercolor="#2e4c75"> <td title="12202 The ISA Server denied the specified Uniform Resource Locator (URL). " colspan=2 width="100%" height="100%"><strong>Status: </strong><span>12202 The ISA Server denied the specified Uniform Resource Locator (URL). </span></td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Rule: </strong>TS Web Access</td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Source: </strong>External (xxx.xx.x.xx)</td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Destination: </strong>(xxx.xx.xxxx.xxx:443)</td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Request: </strong>GET <a href="https://servername.domain.com:443/RDWeb/FeedLogin/WebFeedlogin.aspx?ReturnUrl=/RDWeb/feed/webfeed.aspx">https://servername.domain.com:443/RDWeb/FeedLogin/WebFeedlogin.aspx?ReturnUrl=%2fRDWeb%2ffeed%2fwebfeed.aspx</a></td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Filter information: </strong>Req ID: 0a6fd796; Compression: client=Yes, server=No, compress rate=0% decompress rate=0% ; FBA cookie: exists=yes, valid=yes, updated=yes, logged off=no, client type=public, user activity=yes</td> </tr> <tr> <td width="100%" height="100%" align=left><strong>Protocol: </strong>https</td> </tr> <tr> <td width="100%" height="100%" align=left><strong>User: domain</strong>\username<br/><br/>I just tested accessing URL <a href="https://tsweb.domain.com/RDweb/Feed/Webfeed.aspx">https://tsweb.domain.com/RDweb/Feed/Webfeed.aspx</a> from external and it gives follwoing error.</td> </tr> </tbody> </table> </p> <li>Error Code: 403 Forbidden. The server denied the specified Uniform Resource Locator (URL). Contact the server administrator. (12202) </li> <p>Note: If I test from internal network I could successfully configure the Remote Apps and Desktop connection wizard and everything works fine.<br/><br/><br/>I guess I'll need to do some configuration on IIS on RD Web Access server.<br/><br/><br/>Please advice<br/><br/>Thanks, Prakash</p>Thu, 12 Nov 2009 14:20:40 Z2009-11-20T02:21:06Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/6597c53d-24ea-4831-9e76-1ab51d983d82http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/6597c53d-24ea-4831-9e76-1ab51d983d82Mary_hhttp://social.technet.microsoft.com/Profile/en-US/?user=Mary_h500 Internal Server Error and active Sync<p align=left><font face=Arial size=2></font> </p> <p class=MsoNormal style="background:white;margin:0in 0in 0pt;line-height:normal;tab-stops:45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt"><span style="font-size:12pt;font-family:'Verdana','sans-serif'">Hi</span></p> <p class=MsoNormal style="background:white;margin:0in 0in 0pt;line-height:normal;tab-stops:45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt"><span style="font-size:12pt;font-family:'Verdana','sans-serif'"> </span></p> <p class=MsoNormal style="background:white;margin:0in 0in 0pt;line-height:normal;tab-stops:45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt"><span style="font-size:12pt;font-family:'Verdana','sans-serif'">I have an issue with my ISA 2006 server single nic</span></p> <p class=MsoNormal style="background:white;margin:0in 0in 0pt;line-height:normal;tab-stops:45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt"><span style="font-size:12pt;font-family:'Verdana','sans-serif'"> </span></p> <p class=MsoNormal style="background:white;margin:0in 0in 0pt;line-height:normal;tab-stops:45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt"><span style="font-size:12pt;font-family:'Verdana','sans-serif'">The ISA server is placed in the DMZ and publish single Exchange 2003 server. OWA, RPC/HTTP and ActiveSync<span style="">  </span>are published successfully </span></p> <p class=MsoNormal style="background:white;margin:0in 0in 0pt;line-height:normal;tab-stops:45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt"><span style="font-size:12pt;font-family:'Verdana','sans-serif'"> </span></p> <p class=MsoNormal style="background:white;margin:0in 0in 0pt;line-height:normal;tab-stops:45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt"><span style="font-size:12pt;font-family:'Verdana','sans-serif'">OWA and Outlook RPC over HTTP/S is working fine.</span></p> <p class=MsoNormal style="background:white;margin:0in 0in 0pt;line-height:normal;tab-stops:45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt"><span style="font-size:12pt;font-family:'Verdana','sans-serif'">But users are getting some errors while they are using their mobiles </span></p> <p class=MsoNormal style="background:white;margin:0in 0in 0pt;line-height:normal;tab-stops:45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt"><span style="font-size:12pt;font-family:'Verdana','sans-serif'">&quot;Technical Information (for support personnel)</span></p> <p class=MsoNormal style="background:white;margin:0in 0in 0pt;line-height:normal;tab-stops:45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt"><span style="font-size:12pt;font-family:'Verdana','sans-serif'">Error Code: 500 Internal Server Error. The data area passed to a system call </span></p> <p class=MsoNormal style="background:white;margin:0in 0in 0pt;line-height:normal;tab-stops:45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt"><span style="font-size:12pt;font-family:'Verdana','sans-serif'">is too small. (122)&quot;</span></p>Sun, 30 Sep 2007 07:08:25 Z2009-11-16T14:40:34Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/acd487cb-d881-451b-9628-819199a31d01http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/acd487cb-d881-451b-9628-819199a31d01rovert506http://social.technet.microsoft.com/Profile/en-US/?user=rovert506ISA HTML Logon TimesEnvironment:<br/>Server 2008 x64 Domain Controllers (qty 3)<br/>ISA Server 2006 SP1 Enterprise (qty 2) - running on Windows Server 2003 x86 SP2<br/>ISA configured in single NIC configuration<br/><br/>Issue:<br/>We have a very simple test ISA setup, but would like to roll into production usage at some point.  I have a single web listener configured to provide forms based authentication.  I have two web publishing rules configured to provide proxying to our internal Exchange Client Access Servers for Outlook Web Access and Exchange ActiveSync.  When the web listener is configured with the &quot;Allow users to change their passwords&quot; setting, the logon time increases to approximately 59 seconds.  When the web listener is not configured with the &quot;Allow users to change their passwords&quot; setting, the logon time is less than 1 second.<br/><br/>Why does this setting increase the logon times so much?  Where can I look at to troubleshoot and determine root cause?  Suggestions welcome.<hr class="sig">TrevorWed, 04 Nov 2009 16:03:37 Z2009-11-12T05:47:14Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/ca8b75fa-c485-451e-aa4e-cf7e7deaa152http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/ca8b75fa-c485-451e-aa4e-cf7e7deaa152Travis Nielsenhttp://social.technet.microsoft.com/Profile/en-US/?user=Travis%20NielsenLink translation for PerformancePoint dashboardsAll,<br> <br>I have a PerofrmancePoint dashboard published on an internal SharePoint server using a web part.  The SharePoint server is configured to accept HTTP.  I'm publishing this server with ISA 2006 and require all client connections to use HTTPS.  So the topology is as follows:<br><br><strong>[WEB CLIENT]</strong> &lt;-- HTTPS --&gt; <strong>[ISA 2006]</strong> &lt;-- HTTP --&gt; <strong>[ SHAREPOINT (MOSS) ]</strong><br><br>Its a pretty straightforward setup and I'm using the SharePoint publishing wizard to make this hapen.  However, it looks like PerformancePoint uses absolute URLs for certain dashboard elements.  This is bad becuase it prevents many of the controls from working.  These absolute URLs are likely found in client-side Javascript (AJAX).<br><br>Other folks have run into a <a href="http://forums.microsoft.com/TechNet/ShowPost.aspx?PostID=4063992&amp;SiteID=17">similar issue</a> and have solved it using link translation capabilities found in 3rd party applicances, like F5.  I want to solve this using ISA 2006, but have been having a hard time figuring it out.  I can confirm that I have all the necessary content types enabled for link translation (including application/x-javascript) and link translation is enabled for the publshing rule.  I have tried various custom link translations but none seem to work.<br><br>What do I need to do to ensure *everyting* in the data stream gets translated from http: to https: so that the client is always using the correct protocol?<br><br>Below are some details of what I'm seeing on the client side.  You will notice the virtual directory at play here is _wpresources.  Interestingly enough, some of that seems to be working for image/gif content types, which are highlighted in green.<br><br><font style="" face="'Tahoma','sans-serif'" color=black size=2><br><font style="background-color:#33ff33">1          False    +0.000 s                  0.000 s        GET     (Cache)                     0         image/gif                 <font color="#0000ff">https://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/toolbarItemhover.gif</font></font>                                                                                                                                                                     <br>-  00:00:02.059    Home - Adatum Intranet  (Count=53, Sent=57.53 K, Received=190.65 K, ElapsedTime=3.635 s)                                                                                                                                                                                                                                                                                                                                                                                                                              <br>2          False    +0.000 s                  0.141 s        GET     401                         16.35 K   text/html                 <font color="#0000ff">https://adatum.com/default.aspx</font>                                                                                                                                                                                                                                                                   <br>3          False    +0.141 s                  0.046 s        GET     304                         2.36 K    text/css                  <font color="#0000ff">https://adatum.com/_layouts/1033/styles/core.css?rev=5msmprmeONfN6lJ3wtbAlA%3D%3D</font>                                                                                                                                                                                                                 <br>4          False    +0.141 s                  0.046 s        GET     401                         1.26 K    text/html                 <font color="#0000ff">https://adatum.com/_layouts/1033/init.js?rev=ck%2BHdHQ8ABQHif7kr%2Bj7iQ%3D%3D</font>                                                                                                                                                                                                                     <br>5          False    +0.188 s                  0.046 s        GET     401                         1.26 K    text/html                 <font color="#0000ff">https://adatum.com/_layouts/1033/core.js?rev=S5dt4K8TJGVTYU9HrW6enw%3D%3D</font>                                                                                                                                                                                                                        <br>6          False    +0.203 s                  0.031 s        GET     304                         2.35 K    application/x-javascript  <font color="#0000ff">https://adatum.com/_layouts/1033/ie55up.js?rev=Ni7%2Fj2ZV%2FzCvd09XYSSWvA%3D%3D</font>                                                                                                                                                                                                                       7          False    +0.219 s                  0.030 s        GET     401                         3.18 K    text/html                 <font color="#0000ff">https://adatum.com/_layouts/1033/search.js?rev=yqBjpvg%2Foi3KG5XVf%2FStmA%3D%3D</font>                                                                                                                                                                                                                   <br><font style="background-color:#33cc00"><font style="background-color:#33ff33">   8          False    +0.266 s                  0.015 s        GET     304                         482       text/css                  <font color="#0000ff">https://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/ppsDashboard.css</font>                                                                                                                                                                          <br>   9          False    +0.266 s                  0.030 s        GET     304                         473       text/css                  <font color="#0000ff">https://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/bsm.css</font>                                                                                                                                                                                   <br>   10         False    +0.266 s                  0.030 s        GET     304                         477       text/css                  <font color="#0000ff">https://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/bsmMenu.css</font>                                                                                                                                                                               <br>   11         False    +0.281 s                  0.015 s        GET     304                         483       text/css                  <font color="#0000ff">https://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/ParameterTree.css</font></font> </font>                                                                                                                                                                           12         False    +0.312 s                  0.016 s        GET     304                         346       application/x-javascript  <font color="#0000ff">https://adatum.com/WebResource.axd?d=mCVG8mnkNmX1Ns-A-EjGOA2&amp;t=633351544768437500</font>                                                                                                                                                                                                                 <br>   13         False    +0.328 s                  0.218 s        GET     304                         11.30 K   application/x-javascript  <font color="#0000ff">https://adatum.com/WebResource.axd?d=3WgfFqpkseMrTxpw4reeBQ2&amp;t=633351544768437500</font>                                                                                                                                                                                                                 <br>   14         False    +0.344 s                  0.015 s        GET     401                         1.26 K    text/html                 <font color="#0000ff">https://adatum.com/ScriptResource.axd?d=TTJgkLM18dS1mcebgiUFPf-w5HQQ_QjU3HObJ7Vjxgcnl15YHUMHHmB2_V2_FmYuvFvnr-Oup9w5_ueI_k0S9z1OsTdEGstb8Zz_55ylM6A1&amp;t=633613878810846148</font>                                                                                                                         <br>   15         False    +0.406 s                  0.016 s        GET     401                         1.26 K    text/html                 <font color="#0000ff">https://adatum.com/ScriptResource.axd?d=TTJgkLM18dS1mcebgiUFPf-w5HQQ_QjU3HObJ7Vjxgcnl15YHUMHHmB2_V2_FmYuvFvnr-Oup9w5_ueI_k0S94DORph4DfRwsP5qCuciYd1BvrFsLtNOLaaUtN-7cB6I0&amp;t=633613878810846148</font>                                                                                                     <br>   16         False    +0.422 s                  0.015 s        GET     401                         1.26 K    text/html                 <font color="#0000ff">https://adatum.com/ScriptResource.axd?d=7E83-fE6t839HHGHys3Zjs-5-EcYiLMejW91rZz0fSR-KbBMTm5z-JGgKcLJkmhHIvuC5Ejz8PHIx4T-Z6z7JiViWFUjDWl3uLPtnwrQbTiwiPnI6Y4X88AgXOo0_oCGSYiu1DpPuOr_yMCevS2RzgBqeX3M1ZFtkzTm3IPRKtGhLemMm8mk-9a9fCHiLfg6OC3CMbyekBuzZSHWvqErJg2&amp;t=633613931471211673</font>               <br>   17         False    +0.453 s                  0.015 s        GET     401                         1.26 K    text/html                 <font color="#0000ff">https://adatum.com/ScriptResource.axd?d=7E83-fE6t839HHGHys3Zjs-5-EcYiLMejW91rZz0fSR-KbBMTm5z-JGgKcLJkmhHIvuC5Ejz8PHIx4T-Z6z7JiViWFUjDWl3uLPtnwrQbTiwiPnI6Y4X88AgXOo0_oCGSYiu1DpPuOr_yMCevS2Rzjdy59Vo3EzuLWf2KMdKW75Be_n7iIRYfZbo3tjzFkkMf-2z6TKEjn0ncnBRjYKdzg2&amp;t=633613931471211673</font>               <br>   18         False    +0.468 s                  0.031 s        GET     401                         1.26 K    text/html                 <font color="#0000ff">https://adatum.com/ScriptResource.axd?d=7E83-fE6t839HHGHys3Zjs-5-EcYiLMejW91rZz0fSR-KbBMTm5z-JGgKcLJkmhHIvuC5Ejz8PHIx4T-Z6z7JiViWFUjDWl3uLPtnwrQbTiwiPnI6Y4X88AgXOo0_oCGSYiu1DpPuOr_yMCevS2Rzjdy59Vo3EzuLWf2KMdKW75mCc24JZXq-YKAU6PRYd1F-QKtueJF2rziG2I8gIBwBw2&amp;t=633613931471211673</font>               <br>   19         False    +0.531 s                  0.015 s        GET     401                         1.26 K    text/html                 <font color="#0000ff">https://adatum.com/ScriptResource.axd?d=7E83-fE6t839HHGHys3Zjs-5-EcYiLMejW91rZz0fSR-KbBMTm5z-JGgKcLJkmhHIvuC5Ejz8PHIx4T-Z6z7JiViWFUjDWl3uLPtnwrQbTiwiPnI6Y4X88AgXOo0_oCGSYiu1DpPuOr_yMCevS2RzjeWd-_zIaJoXLT0otuFGhhZF9mFirhA9HngyOmWi1MFlWWfwWBNanUQnCFBah3MzQ2&amp;t=633613931471211673</font>               <br>   20         False    +0.562 s                  0.000 s        GET     304                         337       image/gif                 <font color="#0000ff">https://adatum.com/_layouts/images/blank.gif</font>                                                                                                                                                                                                                                                       <br>   21         False    +0.562 s                  0.015 s        GET     304                         337       image/gif                 <font color="#0000ff">https://adatum.com/_layouts/images/menudark.gif</font>                                                                                                                                                                                                                                                    <br>   22         False    +0.562 s                  0.015 s        GET     (Cache)                     337       image/gif                 <font color="#0000ff">https://adatum.com/_layouts/images/helpicon.gif</font>                                                                                                                                                                                                                                                    <br>   23         False    +0.562 s                  0.077 s        GET     304                         337       image/gif                 <font color="#0000ff">https://adatum.com/_layouts/images/titlegraphic.gif</font>                                                                                                                                                                                                                                                <br>   24         False    +0.578 s                  0.015 s        GET     304                         337       image/gif                 <font color="#0000ff">https://adatum.com/_layouts/images/gosearch.gif</font>                                                                                                                                                                                                                                                    <br>   25         False    +0.578 s                  0.015 s        GET     304                         337       image/gif                 <font color="#0000ff">https://adatum.com/_layouts/images/whitearrow.gif</font>                                                                                                                                                                                                                                                  <br>   26         False    +0.578 s                  0.031 s        GET     304                         337       image/gif                 <font color="#0000ff">https://adatum.com/_layouts/images/recycbin.gif</font>                                                                                                                                                                                                                                                    <br>   27         False    +0.578 s                  0.031 s        GET     304                         337       image/gif                 <font color="#0000ff">https://adatum.com/_layouts/images/Menu1.gif</font>                                                                                                                                                                                                                                                       <br>   28         False    +0.578 s                  0.046 s        GET     304                         337       image/gif                 <font color="#0000ff">https://adatum.com/_layouts/images/siteTitleBKGD.gif</font>                                                                                                                                                                                                                                               <br>   29         False    +0.593 s                  0.031 s        GET     304                         337       image/gif                 <font color="#0000ff">https://adatum.com/_layouts/images/topnavselected.gif</font>                                                                                                                                                                                                                                              <br>   30         False    +0.593 s                  0.046 s        GET     304                         673       image/gif                 <font color="#0000ff">https://adatum.com/_layouts/images/siteactionsmenugrad.gif</font>                                                                                                                                                                                                                                         <br>   31         False    +0.593 s                  0.063 s        GET                                 0         image/gif                 <font color="#0000ff">https://adatum.com/_layouts/images/pageTitleBKGD.gif</font>                                                                                                                                                                                                                                               <br>   32         False    +0.593 s                  0.063 s        GET     304                         337       image/jpeg                <font color="#0000ff">https://adatum.com/_layouts/images/topshape.jpg</font>                                                                                                                                                                                                                                                    <br>   33         False    +0.609 s                  0.046 s        GET     304                         337       image/jpeg                <font color="#0000ff">https://adatum.com/_layouts/images/navshape.jpg</font>                                                                                                                                                                                                                                                    <br>   34         False    +0.609 s                  0.061 s        GET     304                         337       image/gif                 <font color="#0000ff">https://adatum.com/_layouts/images/navBullet.gif</font>                                                                                                                                                                                                                                                   <br>   35         False    +0.640 s                  0.031 s        GET     304                         337       image/gif                 <font color="#0000ff">https://adatum.com/_layouts/images/pagebackgrad.gif</font>                                                                                                                                                                                                                                                <br><font style="background-color:#33ff33">   36         False    +0.656 s                  0.031 s        GET     401                         3.23 K    text/html                 <font color="#0000ff">https://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/ppsd-throbber.gif</font></font>                                                                                                                                                                         <br>   37         False    +0.671 s                  0.016 s        GET     304                         337       image/gif                 <font color="#0000ff">https://adatum.com/_layouts/images/quickLaunchHeader.gif</font>                                                                                                                                                                                                                                           <br>   38         False    +0.905 s                  0.344 s        POST    ERROR_INTERNET_FORCE_RETRY  27.07 K   text/html                 <font color="#0000ff">https://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/RenderingService.asmx/CreateRenderingInstructions</font>                                                                                                                                         <br>   39         False    +1.342 s                  0.311 s        POST    ERROR_INTERNET_FORCE_RETRY  76.26 K   text/html                 <font color="#0000ff">https://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/RenderingService.asmx/CreateRenderingInstructions</font>                                                                                                                                         <br><font style="background-color:#ff6666">   40         False    +3.511 s                  0.015 s        GET     403                         2.26 K    text/html                 <font color="#0000ff">http://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/ImageStatusFilter.gif</font>                                                                                                                                                                      <br>   41         False    +3.511 s                  0.031 s        GET     403                         2.26 K    text/html                 <font color="#0000ff">http://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/ImageCollapseAll.gif</font>                                                                                                                                                                       <br>   42         False    +3.526 s                  0.031 s        GET     403                         2.26 K    text/html                 <font color="#0000ff">http://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/ImageExpandAll.gif</font>                                                                                                                                                                         <br>   43         False    +3.526 s                  0.063 s        GET     403                         1.02 K    text/html                 <font color="#0000ff">http://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/ImageDefaultRollup.gif</font>                                                                                                                                                                     <br>   44         False    +3.526 s                  0.016 s        GET     403                         2.26 K    text/html                 <font color="#0000ff">http://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/ImageWorstChild.gif</font>                                                                                                                                                                        <br>   45         False    +3.526 s                  0.016 s        GET     403                         2.26 K    text/html                 <font color="#0000ff">http://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/ImageIndicatorCount.gif</font>                                                                                                                                                                    <br>   46         False    +3.526 s                  0.046 s        GET     403                         2.26 K    text/html                 <font color="#0000ff">http://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/icon.filtermode.gif</font>                                                                                                                                                                        <br>   47         False    +3.526 s                  0.078 s        GET     403                         2.26 K    text/html                 <font color="#0000ff">http://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/minus.gif</font>                                                                                                                                                                                  <br>   48         False    +3.542 s                  0.061 s        GET     403                         2.26 K    text/html                 <font color="#0000ff">http://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/IndicatorImage.aspx?id=6c5da588-2f57-4ab6-ae75-ce135347978d&amp;band=2</font>                                                                                                                         <br>   49         False    +3.557 s                  0.046 s        GET     403                         2.26 K    text/html                 <font color="#0000ff">http://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/IndicatorImage.aspx?id=c51c9d42-dbba-4460-b6be-e944eaf3acbf&amp;band=3</font>                                                                                                                         <br>   50         False    +3.557 s                  0.015 s        GET                                 0         (None)                    <font color="#0000ff">http://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/IndicatorImage.aspx?id=ce0a7f56-5cc1-41ee-ba6b-9e5c13e335db&amp;band=2</font>                                                                                                                         <br>   51         False    +3.557 s                  0.046 s        GET     403                         2.26 K    text/html                 <font color="#0000ff">http://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/IndicatorImage.aspx?id=6c5da588-2f57-4ab6-ae75-ce135347978d&amp;band=3</font>                                                                                                                         <br>   52         False    +3.573 s                  0.047 s        GET     403                         2.26 K    text/html                 <font color="#0000ff">http://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/IndicatorImage.aspx?id=39d4ee5d-6e2d-4c8f-86e3-11e5ef9599a6&amp;band=5</font>                                                                                                                         <br>   54         False    +3.589 s                  0.031 s        GET     403                         2.26 K    text/html                 <font color="#0000ff">http://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/IndicatorImage.aspx?id=3a930edc-8979-40c4-9808-dacc8555351b&amp;band=3</font>                                                                                                                         <br>   55         False    +3.604 s                  0.031 s        GET     403                         2.26 K    text/html                 <font color="#0000ff">http://adatum.com/_wpresources/Microsoft.PerformancePoint.Scorecards.WebParts/3.0.0.0__31bf3856ad364e35/IndicatorImage.aspx?id=6c5da588-2f57-4ab6-ae75-ce135347978d&amp;band=1</font>       </font>                                                                                                                  </font> <hr align=left width="25%" size=1> :: Travis NielsenMon, 10 Nov 2008 21:37:10 Z2009-11-09T20:13:57Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/4e71264c-7f9d-437b-a2d1-662316f9e1e0http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/4e71264c-7f9d-437b-a2d1-662316f9e1e0Anthony Murfethttp://social.technet.microsoft.com/Profile/en-US/?user=Anthony%20MurfetTMG HTTP web publishingGreetings All,<br/><br/>inside server|TMGB3|Perimeter|Cisco ASA-5510|Internet<br/>I deleted the Perimeter network that the installation wizard created so now everything on the outside is considered External.<br/><br/>I installed tmg beta 3 and created a web publishing rule for HTTPS and that works fine. Now I want to publish my CRL pages so I need to create an HTTP web publishing rule for that. I create the rule and the rule gets ignored. All I see in the logs is:<br/><br/>Denied Connection XXXSS03 8/28/2009 9:22:47 AM <br/>Log type: Firewall service <br/>Status: The policy rules do not allow the user request.  <br/>Rule: Default rule <br/>Source: External (72.25.192.4:28783) <br/>Destination: Local Host (172.16.0.10:80) <br/>Protocol: HTTP <br/><br/>I guess I am missing something somewhere. Is there something special that needs to be done to allow HTTP inbound beyond the creation of a web publishing rule?<br/><br/>Also: Is this the only place to get support for TMG?<br/><br/>Thanks for any help, Anthony Murfet<br/><br/> <hr class=sig> tmurfetFri, 28 Aug 2009 16:37:50 Z2009-12-01T14:45:43Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/09e15a38-6f1f-4b53-9d50-df5b3d1e9d0chttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/09e15a38-6f1f-4b53-9d50-df5b3d1e9d0cVahid Rashmanihttp://social.technet.microsoft.com/Profile/en-US/?user=Vahid%20RashmaniHelpI need some or any programs like isa server do you know about this?Mon, 02 Nov 2009 15:34:17 Z2009-11-10T06:28:52Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/62dc44aa-fd46-4467-9cc0-a17986b97d9bhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/62dc44aa-fd46-4467-9cc0-a17986b97d9bReefdiverhttp://social.technet.microsoft.com/Profile/en-US/?user=ReefdiverPublish additional external website through Forefront Edge SecurityHi experts,<br/><br/>I have recently switched from SBS 2003 premium to following setup:<br/><br/>EWBS 2008 with Management, Securits and Messaging Servers (obviously ;-) ). The WEBS is an clean, new install on new hardware, the &quot;old&quot; SBS 2003 is still up'n running, though disconnected from the external network and also physically separated from the new WEBS network. On WEBS, OWA &amp; sharepoint-publishing work fine, I don't know of any major errors or misconfiguration. <br/><br/>This said, I have one problem though which I haven't been able to figure out. We used to host another, additional website with some further information for customers (site2.dyndns.org). On the new WEBS-setup, I have copied the website-files to the Messaging Server and added the site there in IIS manager. Furthermore, I have added a Website Publishing rule on the Security server in Forefront TMG. I have configured everything like I used to have on my &quot;old&quot; ISA 2004, but I simply can not access the site from the internet. Since I have spent the last two days trying out, it's useless to state here the many things I have tried to get this to work. <br/><br/>Maybe some expert here can lead me through the necessary steps &amp; settings to get this to work.<br/><br/>ANY help is greatly appreciated,<br/><br/>thanks &amp; greetings from Southern Germany <br/><br/>MarkSat, 17 Oct 2009 16:49:47 Z2009-10-28T07:00:11Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/5aad1d10-c085-4321-965f-7c5a316fb9b0http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/5aad1d10-c085-4321-965f-7c5a316fb9b0rickyjohnhttp://social.technet.microsoft.com/Profile/en-US/?user=rickyjohnDenied Connection - 12232Hi,<br /><br />We have a web publishing rule that has worked fine for weeks/months. For the last few days the external application that regularly connects to our internal application via https POSTS (for which we have a web publising rule) I've noticed is getting a "Denied connection - 12232 The Server denied the specified URL" in our ISA. The URL in the error log seems to be correct (the domain name is correct as per the listener and public name tabs and the path match that in the path tab, all be the case does not match but it never has and I believe ISA does not bother about case sensitivy in the path).<br />Nothing has changed on our ISA server (connectivity verifiers to our back end servers all seem ok). The publishing rule does apply to a user in our AD that has a client certificate associated to it for when the source application connects to it - this cert hasn't expired.<br /><br />Is there any other 'debugging' I can do or other ISA logs I can interrogate (the above errors are from the ISA monitoring section of ISA).<br />Also, when the denied connection is getting hit saying 'the server' denied the URL, is ISA 'the server' that is doing the denial or the destination server?<br /><br />Many thanksWed, 14 Oct 2009 11:03:34 Z2009-10-21T10:02:13Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/8d0f35f1-9496-4c3d-9c8b-a9c175a22a0chttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/8d0f35f1-9496-4c3d-9c8b-a9c175a22a0cReefdiverhttp://social.technet.microsoft.com/Profile/en-US/?user=ReefdiverAllowing POP3-access through Forefront TMGHi experts,<br/><br/>I have recently switched from SBS 2003 premium to WEBS 2008. <br/><br/>Besides sending and receiving our regular company mails with exchange, we have some legacy mail accounts with our old provider, which we used to pull through the SBS PO3-connector and route to the corresponding exchange mail boxes (one POP3-account to one Eschange-user). According to my knowledge, WEBS lacks the POP3 connector I knew from SBS, but I have found a third-party-tool to do the job. The tool (Pullution from Sodacore) is installed on the Messaging server, and I have defined an access rule in Forefront TMG on the Security server to allow POP3-traffic to and from the Messaging server. However, Pullution can't connect through to pop.provider.de, no matter how I configure the access rule on the Security server (currently, I have copied the rules for SMTP and modified the protocoll). I used to have a similar rule on our ISA 2004 on the SBS to allow certain clients to collect POP3 through Outlook, so I don't really know why this rule on FTMG doesn't work.<br/><br/>Maybe some expert here can lead me through the necessary steps &amp; settings to get this to work.<br/><br/>ANY help is greatly appreciated,<br/><br/>thanks &amp; greetings from Southern Germany<br/><br/>Mark<br/><br/>PS:  And yes, I know about the downsides of PO3, please no discussion about it - it's a political decission that &quot;we have to&quot; keep the old mail accounts.Sat, 17 Oct 2009 17:08:11 Z2009-10-18T09:59:29Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/737ff22c-c7a1-44e9-a707-40be0e7b32f2http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/737ff22c-c7a1-44e9-a707-40be0e7b32f2Ian Brogdenhttp://social.technet.microsoft.com/Profile/en-US/?user=Ian%20BrogdenISA 2006 Reverse proxy and user (x.509) certificatesWe need to publish an internal system that will require a user (x.509) certificate for authentication.<br /><br />Is there anything special we need to do on the ISA publishing rule to ensure the requests/responses for the user certificate get passed appropriately?Fri, 16 Oct 2009 20:55:33 Z2009-10-26T02:06:39Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/863f094b-582a-4719-b1df-5c7b49d85c8dhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/863f094b-582a-4719-b1df-5c7b49d85c8dBueschuhttp://social.technet.microsoft.com/Profile/en-US/?user=BueschuPublishing TS Webaccess / TS 2006Gateway with ISA Hello <br /><br />I have a TS Gateway with TS Webaccess Role on a Windows Server 2008 sp1. We have anoter TS Server which has Windows 2008 sp1 installed. We have published multiple application on the TS Webaccess pages. From the LAN everything works fine. <br />Now we would like to publish the TS Webaccess to the Internet vis ISA 2006.&nbsp;We would like to authenticate on the weblistener with a smart card&nbsp;and then start the application on the&nbsp;TS Gateway with&nbsp;a second login.Unfortunaltey I can not achieve this. <br />I configured the listener for SSL Client Authentication&nbsp;and defined the Web Publishing Rule under the Users Tab to grant access to all authenticated Users. The setting for the delegation ist set to <strong>No delegation, but client may authenticate directly.</strong>&nbsp;&nbsp;This szenario works, when the TS Webaccess Page Authentication is set to anonymous enabled. <br /><br />After authentication with the smart card to access the TS Webaccess Page <br />I start a TS Webaccess Application and get immediatly the following error message:&nbsp; <br />"The computer can't connect to the remote computer because the Terminal Services Gateway server is temporarily unavailable. Try reconnecting later or contact your network administrator for assistance" <br /><br />When i check the ISA Monitor I&nbsp; can see that the ISA blocks this traffice, because it is not authenticated <br /><br />I have already checked different articles and blogs in the internet and on technet: <a href="http://technet.microsoft.com/en-us/library/cc731353(WS.10).aspx" target="_blank"><span style="color: #003399;">http://technet.microsoft.com/en-us/library/cc731353(WS.10).aspx</span></a> <br />but could'not help. <br /><br />Maybe I'm running in the wrong direction and my szenario is no supported. <br />Can somebody help me - Thanks in advance. <br /><br />Best Regards - Bueschu <!-- <<< --><hr class="sig">BueschuSat, 10 Oct 2009 17:21:51 Z2009-10-19T07:40:15Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/aec11ce2-324e-4d48-9540-972c3b4a51a3http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/aec11ce2-324e-4d48-9540-972c3b4a51a3Steve Dertienhttp://social.technet.microsoft.com/Profile/en-US/?user=Steve%20DertienWCF NET.TCP Through ISA 2006I'm currently working on a proof of concept for a application that has been written to use the NET.TCP protocol using WCF.&nbsp; We're currently looking at configurations that would allow us to make those URL's (net.tcp://external.host.name:8820/Blah) available externally and then allow them to connect through to the internal host using the ISA basically as a port proxy.&nbsp; I currently have our ISA system configured using a Perimeter configuration.&nbsp; I've defined the new protocol as well as a non-webserver publishing rule.&nbsp;&nbsp;In the firewall logs I basically get the following:<br /><br /> <pre>8820 Unidentified IP Traffic (TCP:8820) Denied Connection Default rule 192.123.123.160 External Local Host</pre> <br />The configuration we have would basically result in the external hostname resolving to the Perimeter IP address on the ISA.&nbsp; Internally the IP on the second network interface in the ISA is in the internal range of IP's.&nbsp; The ISA internal IP is on the same subnet as the internal server hosting the WCF services.&nbsp; Based on the error in the log I'm under the assumption that the ISA is not really listening to port 8820 despite the listener configuration that is setup to do so.&nbsp; Any connection (external or otherwise) basically results in a failure and it never picks up the correct firewall rule that has been defined.<br /><br />I've yet to really find a net.tcp example configured through an ISA to work from.&nbsp; This is my first real in depth exposure to the ISA itself, so if I've made some newbie mistake feel free to let me know where I likely went wrong in the configuration.<br /><br />Thanks in advance.Tue, 13 Oct 2009 17:29:50 Z2009-10-14T21:09:53Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/51c786f8-7911-4363-89a1-45115427662ehttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/51c786f8-7911-4363-89a1-45115427662eMicroTeckhttp://social.technet.microsoft.com/Profile/en-US/?user=MicroTeckISA 2006 Routing Problem<p class="MsoPlainText" style="margin: 0cm 0cm 0pt;"><span style="font-family: Tahoma; font-size: x-small;">Have ancountered a problem with routing traffic from ISA 2006 (LocalHost) to Publish Server. Example: Exchange 2007 forwards traffic to a Public IP address, this intern is NATTED from our ISP to ISA's external NIC (Exchange is able to send External and Internal Outbound mail but unable to recieve External Inbound Mail). I can see the traffic hitting the box but am unable to forwards the traffic from the Local Host to the Published Server (Sitting behind ISA), This problem is persistant with all existing NAT translations that existed on our Linux Firewall. This problem also occurs when traffic cannot be routed from the LocalHost ISA to our Internal Web Server.<br /><br />Your urgent assistance is need to resolve this problem.</span></p>Wed, 14 Oct 2009 09:40:26 Z2009-10-21T09:57:47Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/e9a0731a-3587-4c02-96af-5fc5b87a1eadhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/e9a0731a-3587-4c02-96af-5fc5b87a1eadM. Yousefhttp://social.technet.microsoft.com/Profile/en-US/?user=M.%20Yousefallow http https requests from isa server to specified siteswhen I tring to conect to&nbsp;my mail web&nbsp;site ( <a href="https://mail.*****.com:9068/">https://mail.*****.com:9068</a>&nbsp;) direct from router it is open but behiend ISA it is not open.<br /><br />so how can allow http https requests from isa server to specified site<br /><br /><br />client (HTTP, HTTPS Request) ---------&gt; ISA server ---------&gt; <a href="https://mail.*****.com:9068">https://mail.*****.com:9068</a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ????????????<br /><br />* My ISA version 2004 with last update and worked as a web proxyTue, 13 Oct 2009 16:57:52 Z2009-10-19T07:31:09Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/8d22b6e4-15ac-4a89-91da-f8b5d3cf4fa5http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/8d22b6e4-15ac-4a89-91da-f8b5d3cf4fa5Shahinhttp://social.technet.microsoft.com/Profile/en-US/?user=ShahinOWA in TMG Hi,<br/><br/>I have a question regarding the TMG 3 beta,<br/><br/>I have a test enviorment:<br/>DC                      192.168.1.10  GW:192.168.1.1<br/>Exchange 2007     192.168.1.11  GW:192.168.1.1<br/>TMG Beta3            192.168.1.1 (internal NIC) , 10.0.0.176 (external NIC0<br/><br/>becuse I don't have any certificate, I want to test the owa with http: so I did create an owa rule:<br/><br/>source network: anywhere<br/>destenation network: mailserver.mydomain.local, and also use the IP address of exchange 2007 192.168.1.1, public naame: All request, No delegation and client can not autenticate directlly, and users: All users<br/>weblistener: listen on port 80, users: all users, networks: external,  autentication; no autentication.<br/><br/><br/>but when I try to access the owa from external net 10.0.0.0 I get the error page cannot display.<br/><br/>Any idea why is this heppeing? or could some one direct me on how exactly to do this in right way?<br/><br/>Thanks,<br/><br/>Shahin<hr class="sig">ShahinMon, 14 Sep 2009 12:24:55 Z2009-12-01T14:50:41Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/38ea7b29-5037-439b-9b66-c9d83f839039http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/38ea7b29-5037-439b-9b66-c9d83f839039Alex Osipovhttp://social.technet.microsoft.com/Profile/en-US/?user=Alex%20OsipovProblem publishing a non-web server with ISA 2006Hello,<br/><br/>I run ISA Server 2006 with SP1 which has 3 network interfaces - Internal, External and Perimeter. Internal is a network with public addresses, Perimeter is a private network. Network rules are Internal to External - Route, Perimeter to External - NAT.<br/><br/>I need to publish a RDP server which is in the Internal network to the Internet. I have done the following:<br/><br/>1. Access rule from ISA Server (Localhost) to Internal RDP Server. Outbound RDP (Terminal Services). Applied and tested - I can open RDP session to the Internal server from ISA Server console.<br/>2. Access rule from External to ISA Server (Localhost). Outbound RDP (Terminal Services). Applied.<br/>3. Non-web server publishing rule. Properties are as follows. Traffic: RDP (Terminal Services) Server. From: Anywhere. To: Internal server IP address; Requests appear to come from the original client. Networks: External. Schedule: Always.<br/><br/>For my test Terminal Services at the ISA Server were disabled - nothing listened to tcp:3389 before the ISA rules were configured.<br/><br/>Everything is applied. Now I try to connect with Remote Desktop client to ISA Server external interface. I don't get connected. telnet ISA_Server_external_interface 3389 promptly (no timeout) returns Connect failed error. At the same time ISA Server monitor logs 3 successful pairs of Initiated Connection / Closed Connection events. Network sniffer shows 3 SYN packets followed by ACK-RST packets. So, the ISA Server actively refuses the connection. Why?<br/><br/>Tried the same setup with a RDP server located inside the Perimeter network - it works fine.<br/><br/>What could be the problem? Any ideas are appreciated.<br/><br/>The OS is Windows Server 2003 SP2. I have other publishing rules on the same server, all of them are web servers from both Internal and Perimeter networks - they work fine. Only the non-web publishing doesn't work.<br/><br/>Alex<br/>Mon, 28 Sep 2009 19:18:30 Z2009-11-01T22:24:52Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/dd7fd8f3-d754-43aa-a3d8-a06f181254e9http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/dd7fd8f3-d754-43aa-a3d8-a06f181254e9Shahinhttp://social.technet.microsoft.com/Profile/en-US/?user=Shahinhow to install certificateHi,<br/><br/>We have a test domain with Exchange 2010 and ISA TMG beta3, the internal domain mydomain.local, external domain www.mydomain.com.<br/>I got a SSL certificate mail.mydomain.com, now can some one direct me to an step-by-step doc on what should I do next? <br/><br/>Thanks,<br/><br/>Shahin<hr class="sig">ShahinThu, 17 Sep 2009 12:52:34 Z2009-09-25T05:43:38Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/bff201ac-0173-480a-b9fa-cc62bf56bb0bhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/bff201ac-0173-480a-b9fa-cc62bf56bb0bDavide Gattahttp://social.technet.microsoft.com/Profile/en-US/?user=Davide%20GattaISA Block Legitimate LDAP traffic form Exchange 2003 in DMZHello<br/>i have a situation with Exchange 2003 /windows 2003 in a three way DMZ scenario  - one NIC to the LAN, one to the DMZ and one fo Internet Access (DMZ access LAN by Routing, not by publishing)<br/>sometimes Exchange stop working and investigating i find that ISA block LDAP TCP traffic, both on port 389 that on 3268. UDP Traffic is not blocked.<br/>sometimes this block cause also the block of oll the traffic from the DMZ Exchange Server and the only way to solve this is a restart of Exchange and Isa Service on respetcive machine.<br/>when this happen in the event viewer of ISA Server Machine i find:<br/><span style="font-size:xx-small"> <p>The number of concurrent TCP connections from the source IP address 192.168.2.2 exceeded the configured limit. As a result, ISA Server will not allow the creation of new TCP connections from this source IP. This IP address probably belongs to an attacker or an infected host. See product documentation for more info about ISA flood resiliency.<br/><br/>what can be the cause? is a exchange or a isa Issue?<br/>why ISA truncate GOOD LDAP TCP traffic ?</p> </span><hr class="sig">Davide GattaMon, 14 Sep 2009 14:25:39 Z2009-09-25T05:45:26Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/af43391a-a370-4e73-a62b-84115ffa971bhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/af43391a-a370-4e73-a62b-84115ffa971bRex Wheelerhttp://social.technet.microsoft.com/Profile/en-US/?user=Rex%20WheelerISA 2006 Perimeter Template - Is Proxy ARP supported?I need to publish some services using the Perimeter (3 leg) DMZ configuration and the services I am publishing must have public addresses (no NAT). I currently have single /28 block of public addresses. Does ISA 2006 support Proxy ARP and allow me to divide my /28 block into two /29 subnets (with one on the Internet interface and one on the Perimeter interface - and Proxy ARP &quot;hiding&quot; the fact that I have subneted from my ISP) or do I have to obtain a second public block of IPs from my ISP and have them route the new block through external IP of the ISA server?<br/> <br/>Wed, 16 Sep 2009 18:01:01 Z2009-09-16T18:31:54Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/6500015f-9c14-4c99-aa8a-32521a57b3f9http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/6500015f-9c14-4c99-aa8a-32521a57b3f9Quitchhttp://social.technet.microsoft.com/Profile/en-US/?user=QuitchISA 2004 published OWA producing a 403I have setup the publishing of Outlook Web Access through our ISA 2004 box. The name it is publishing OWA under is different from that of the certificate as we wish to ensure the connection works prior to replacing the existing setup (which is using the certificate name).<br/> <br/> The rule is setup to publish using HTTPS but pass connections through to the Exchange server using HTTP (one step at a time and all that). Connections are received by owa2.domain.co.uk but then passed on to owa.domain.co.uk, an entry exists in the hosts table for this.<br/> <br/> Attempts to connect first produce an expected certificate warning, but upon choosing to continue a 403 Forbidden error crops up<br/> <br/> The logs on the ISA server look as follows<br/> <br/> <pre>Original Client IP Client Agent Authenticated Client Service Server Name Referring Server Destination Host Name Transport MIME Type Object Source Source Proxy Destination Proxy Bidirectional Client Host Name Filter Information Network Interface Raw IP Header Raw Payload Source Port Processing Time Bytes Sent Bytes Received Result Code HTTP Status Code Cache Information Error Information Log Record Type Log Time Destination IP Destination Port Protocol Action Rule Client IP Client Username Source Network Destination Network HTTP Method URL 82.133.108.155 ISA2004BOX - TCP - - 13644 0 0 0 0x0 0x0 0x0 Firewall 15/09/2009 10:09:02 172.172.172.172 443 HTTPS Initiated Connection 82.133.108.155 External Local Host - - 82.133.108.155 ISA2004BOX - TCP - - 13644 2000 712 1782 0x80074e20 FWX_E_GRACEFUL_SHUTDOWN 0x0 0x0 Firewall 15/09/2009 10:09:04 172.172.172.172 443 HTTPS Closed Connection 82.133.108.155 External Local Host - - 0.0.0.0 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.04506.648; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.1) No Reverse Proxy ISA2004BOX owa2.domain.co.uk TCP - - - Req ID: 02b70e13 - - - 0 1 2264 573 12202 The ISA Server denied the specified Uniform Resource Locator (URL). 0x0 0x0 Web Proxy Filter 15/09/2009 10:09:06 172.172.172.172 443 https Denied Connection Default rule 82.133.108.155 anonymous External GET http://owa2.domain.co.uk/ 82.133.108.155 ISA2004BOX - TCP - - 13645 0 0 0 0x0 0x0 0x0 Firewall 15/09/2009 10:09:06 172.172.172.172 443 HTTPS Initiated Connection 82.133.108.155 External Local Host - - 82.133.108.155 ISA2004BOX - TCP - - 13646 0 0 0 0x0 0x0 0x0 Firewall 15/09/2009 10:09:06 172.172.172.172 443 HTTPS Initiated Connection 82.133.108.155 External Local Host - - 82.133.108.155 ISA2004BOX - TCP - - 13645 0 397 294 0x80074e20 FWX_E_GRACEFUL_SHUTDOWN 0x0 0x0 Firewall 15/09/2009 10:09:06 172.172.172.172 443 HTTPS Closed Connection 82.133.108.155 External Local Host - - 82.133.108.155 ISA2004BOX - TCP - - 13646 2000 1067 2703 0x80074e20 FWX_E_GRACEFUL_SHUTDOWN 0x0 0x0 Firewall 15/09/2009 10:09:08 172.172.172.172 443 HTTPS Closed Connection 82.133.108.155 External Local Host - - 82.133.108.155 ISA2004BOX - TCP - - 13621 0 0 0 0xc0040017 FWX_E_TCP_NOT_SYN_PACKET_DROPPED 0x0 0x0 Firewall 15/09/2009 10:11:40 172.172.172.172 80 HTTP Denied Connection 82.133.108.155 External Local Host - -</pre> Adding the Exchange server to the ISA's allowed sites shows that it is able to successfully make the connection to that server on port 80.<br/> <br/> I'm unsure why the connection attempts are falling to the default rule.Tue, 15 Sep 2009 09:22:10 Z2009-09-15T15:20:09Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/a3338995-45af-4998-99c6-c9e555866928http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/a3338995-45af-4998-99c6-c9e555866928Shahinhttp://social.technet.microsoft.com/Profile/en-US/?user=Shahinexchange 2010 and TMGHi,<br/><br/>We try to publish Exchange 2010 in TMG beta 3, but on the page where we can select the exchange server, there is no exchange 2010, only exchange 2007, 2003, 2000 and 5.5.<br/><br/>can I use Exchange 2007, to publish exchange 2010 OWA?<hr class="sig">ShahinMon, 14 Sep 2009 12:55:14 Z2009-09-15T07:25:01Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/bc135a78-68f0-419a-ad90-f238c4050c71http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/bc135a78-68f0-419a-ad90-f238c4050c71Port Douglashttp://social.technet.microsoft.com/Profile/en-US/?user=Port%20DouglasISA 2006 publishing ServersHi, I have just built an ISA2006 SP1 Server Standard Edition<br/>I have assigned 10.10.X and 10.140.x to the internal network and the last Interface is External. <br/>I have created an Inbound network rule from the External Interface to both the Internal Interfaces with a network relationship of Route.<br/>I have created a Friewall rule policy to allow RDP Server protocol (inbound) from External to Internal networks.<br/>I have tested the rule using the Traffic simulator and it returns a success feedback.<br/>Thought all of the above was done, I still cannot access my internal server via RDP. <br/>Can you tell me if I have left something out?Sat, 12 Sep 2009 09:21:59 Z2009-09-22T02:11:43Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/fb13b277-9955-462e-bad4-486c269b588bhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/fb13b277-9955-462e-bad4-486c269b588bMoe ATLhttp://social.technet.microsoft.com/Profile/en-US/?user=Moe%20ATLISA 2006 Custom Login Pages using Single Network Adapter TemplateWe're trying to publish various SharePoint sites through ISA 2006 configured to use the 'Single Network Adapter' template. Ideally, we'd like to show a branded login page (e.g. different corporate logo, etc) for each different published URL.<br/><br/>Following the steps in &quot;<a href="technet.microsoft.com/en-us/library/bb794733.aspx">Customizing HTML Forms in ISA 2006</a>&quot; (technet.microsoft.com/en-us/library/bb794733.aspx) we created our customized pages. In ISA we've tried having the pages being triggered using the &quot;Use Custom Form&quot; area of the Publishing Rule. Once a custom form has been set, the customized login page shows up for all URL's passing through ISA, regardless of whether they have the &quot;Use Custom Form&quot; setting configured or not.<br/><br/>The most confusing thing is that if I switch ISA to use the &quot;Front Firewall&quot; Network Template, leaving all the other settings unchanged, things work perfectly. I'm unable to find any documentation that says custom forms don't work when using the Single Network Adapter template so I'm hoping someone here can shed some light.<br/><br/>Cheers.Tue, 01 Sep 2009 11:37:16 Z2009-09-11T21:06:05Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/73d08636-09cc-4d51-9170-c2039d08bd53http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/73d08636-09cc-4d51-9170-c2039d08bd53AnthonyP100http://social.technet.microsoft.com/Profile/en-US/?user=AnthonyP100Limit the number certificates shown in the client certificate prompt when published through ISA 2006?I'm using smart card authentication and login for everything on my domain.  Each smart card has 3 certificates loaded on it (ID Cert, Email Signature Cert and Encryption cert).  Currently, I have a MOSS farm published through ISA 2006 that is doing all of the Smart card authentication via KCD which is all working correctly.  When the site prompts for the client certificates, I am shown 2 possible certs.. the ID cert and the Signature cert.  Both will work and allow access to the site, if configured correctly.  What I would like to accomplish is to only show the ID certificate to the user instead so they don't see another certificate option.  <br/> <br/> I've looked through IIS and ISA settings, but have not seen anything thus far.  Curious if there was a way for ISA to filter the list of if this is strictly a client thing.   <br/> <br/> Thanks!Thu, 10 Sep 2009 03:09:31 Z2009-09-15T19:09:31Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/ce98da60-6fe8-452b-b89c-8da04cd97c1chttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/ce98da60-6fe8-452b-b89c-8da04cd97c1chappy_20_y2khttp://social.technet.microsoft.com/Profile/en-US/?user=happy_20_y2kOWA2003 not authenticating blank passwordHi<br/> <br/> OWA 2003 is published through ISA 2006. From external OWA does not authenticated user with no/blank password but internally it allows.<br/> Users with passwords have no problem in accessing it.<br/> <br/> Any help would be appreciated.<br/> <br/> <br/> Thanks<br/> HarpreetThu, 02 Apr 2009 06:40:26 Z2009-12-01T14:51:10Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/afe8879b-9794-4a4c-a7a8-2c8c2bf306a7http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/afe8879b-9794-4a4c-a7a8-2c8c2bf306a7def2http://social.technet.microsoft.com/Profile/en-US/?user=def2Can't edit Filtering on published web serverWe are running ISA 2006 as an edge firewall and web proxy. I'm trying to enable High Bits for URLs on a published web server, but neither the &quot;Configure HTTP&quot; context menu is available for the firewall rule, nor is the &quot;Filtering&quot; button enabled on the Traffic pane of the rule's properites dialog (Traffic is using the defalut HTTP protocol.)  How can I get to the dialog that has the checkbox for contolling the high bits?<br/><br/>ThanksTue, 08 Sep 2009 15:24:40 Z2009-09-16T08:34:58Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/90560267-c7b1-4d4f-b576-fd380a0b494bhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/90560267-c7b1-4d4f-b576-fd380a0b494blovebunnyhunterhttp://social.technet.microsoft.com/Profile/en-US/?user=lovebunnyhunterActive Sync Publishing problem with ISA 2006Dear all,<br/><br/>I have a problem regarding publishing Active Sync with ISA Server with single NIC and Exchange 2003.<br/>On the first firewall only https to the ISA server is allowed. On the second Firewall only https from the ISA Server to the Exchange Frontend Server is allowed.<br/>The ISA server is not a member of the domain.<br/>The following picture is an overview of the problem:<br/><img src="http://www.my-heaven.org/problem.jpg" alt=""><br/><br/>If I now try to connect with an Active Sync mobile, I see in the log, that the mobile tries to connect to the exchange server with the user &quot;anonymous&quot;. My question is now, what do I have to configure, that it works without problems. At the moment I used the publishing template from the ISA server. I have also a valid certificate for the ISA server for the external DNS entry. Do I have to have a valid certificate for the Exchange frontend on the ISA server? I imported the computer certificate from the Exchange server on the ISA server.<br/><br/>Thank for your help, Nils<br/><br/>edit: I just have seen, that now the ISA server denies all connection coming from my mobile with the default rule (https denied) although I have created the web listener with basic authentication and also the publishing rule for the active sync.<br/><br/>edit: I just solved the problem with the denied connection, but now my mobile is showing the folling error described in this KB article: <a href="http://support.microsoft.com/kb/919864/en-us">http://support.microsoft.com/kb/919864/en-us</a> Is it possible to solve the problem with this hotfix?<br/>Although the ISA server logs the following: http://XXX/Microsoft-Server-ActiveSync?User=XXX&amp;DeviceId=E1502EXX3CF40&amp;DeviceType=PocketPC<br/>The mobile is giving a username, why does the log on the ISA server say &quot;Client Username=anonymous&quot;?<br/><br/>edit: If I run the TestExchangeConnectivity, the following error occurs: &quot;An HTTP 500 was returned to ISA because the certificate on the published server doesn't match the name in the publishing rule.&quot; I have imported the certificate from the Exchange frontend on the ISA server. Which name in the publishing role is meant by the error?Mon, 07 Sep 2009 06:19:46 Z2009-09-10T02:23:09Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/f193e589-290d-4228-9402-51d6bcdffc67http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/f193e589-290d-4228-9402-51d6bcdffc67Gopinath.Dhttp://social.technet.microsoft.com/Profile/en-US/?user=Gopinath.DISA 2006 Denied Connection Hi <br/>i am geting following Log monitoring <br/><br/>192.168.255.255 137 NetBios Name Service   Denied Connection Default rule       172.16.x.x<br/><hr class="sig">Team LeaderMon, 07 Sep 2009 04:58:52 Z2009-09-11T08:21:31Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/84af7a3d-f132-412a-9595-dd43dcbfbb16http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/84af7a3d-f132-412a-9595-dd43dcbfbb16Shahinhttp://social.technet.microsoft.com/Profile/en-US/?user=ShahinPublish OWAHi,<br/><br/>I want to publish OWA of exchange 2007 through ISA 2006, I don't have any trusted Certificate, could any one direct me to a tutorial on how to do this with self creating CA?<br/><br/><br/>Thanks,<br/><br/>Shahin<hr class="sig">ShahinTue, 01 Sep 2009 14:35:33 Z2009-09-09T10:12:05Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/ad73ee86-6b9e-420e-b6d1-237d5f7e90e5http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/ad73ee86-6b9e-420e-b6d1-237d5f7e90e5Shahinhttp://social.technet.microsoft.com/Profile/en-US/?user=ShahinPublishing sites with single IP<p>Hi,<br/><br/>we are in testing face of ISA 2006, in a test envoirmant, I did setup a network with 4 servers, one is 2008 R2 DC and DNS the secound server is a member server with Exchange 2007 SP1 and the 3rd server is 2008 R2 with ISA 2006 SP1, the ISA has 2 NIC's the external nic has just one public IP (39.1.1.1.) the 4rd server is a mamber server that is a webserver.<br/><br/>we have 4 diffirent websites 2 on the exchange server (just for testing purpose) and 2 on the webserver, we want to access these website from external netwerk (internet), is it possible to publish these 4 websites that are on 2 diffirent servers just useing a single Public IP of external NIC?<br/><br/>Thanks,<br/><br/>Shahin</p><hr class="sig">ShahinTue, 01 Sep 2009 09:10:57 Z2009-09-08T06:27:08Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/cf0ca29d-5ec5-48d0-af92-8cc234a8ab84http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/cf0ca29d-5ec5-48d0-af92-8cc234a8ab84Pants79http://social.technet.microsoft.com/Profile/en-US/?user=Pants79ISA2006 publishing Windows Media Services.Hi all,<br/><br/>I hope some of you can help me with the following:<br/><br/>I have a Sharepoint Farm published by ISA2006. This works great and everything runs as expected. <br/>We recently setup a Windows Media Server on Server 2008 and and use this to publish videos on Sharepoint.<br/>I've used the publish a server wizard to publish the RTSP protocol and it works no problem.<br/><br/>Now my question:<br/><br/>How can i authenticate users on this machine? When the server is published you can just type in the URL for the movie and it works, this is not something i want.<br/>I want it to only play movies when people are authenticated by ISA. Using digest or NTLM auth on the streaming server results in a login window popup. This is less than ideal.<br/><br/>My thinking is as follows:<br/><br/>User logs into sharepoint using ISA FBA.<br/>These credentials should also be used to authenticate on the WMS server. ie no login popups.<br/><br/>Anybody know what i need to do to get this working as seamlessly as possible?<br/><br/>Kind regards,<br/><br/>KorMon, 31 Aug 2009 12:03:50 Z2009-09-08T06:25:49Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/a73a0ccb-bd17-4119-95ef-1195718eaf4ahttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/a73a0ccb-bd17-4119-95ef-1195718eaf4aLeonard McCoyhttp://social.technet.microsoft.com/Profile/en-US/?user=Leonard%20McCoyPUblishing to specific private IP for an IPSEC VPN partner<p>I have an edge only two member load balanced ISA 2004 EE array with only internal and external interfaces. I have a partner site that I need to create an IPSEC VPN tunnel with. They route to a network that has the same IP scheme that I have on my internal LAN, so we will need to NAT to each other. He is going to NAT his side behind a 150.30.0.0/16 and needs me to NAT behind 10.163.195.16/29 (this range works for me).</p> <p>I've created many IPSEC VPNs before but none where the other side routed to a network with the same IP scheme as ours. I've never published a server to a private IP address. The only thing I've published was my e-mail server to a public address.</p> <p>How do I publish an internal server to a specific private IP address for an IPSEC VPN partner site to access? I'm assuming I will need to add an IP address to one of the NICs? If so which one, the external or internal? I guess I'll need to set up a NAT route rule between the VPN network and my internal?</p> <p>Any help would be appreciated.<br/><br/>Oh, I forgot to mention; this is not a web publishing rule, but needs to be a server publishing rule for a protocol that I will define.<br/><br/>Leonard McCoy</p>Sun, 16 Aug 2009 20:56:45 Z2009-09-04T19:50:10Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/3a57e842-71ce-4acd-839f-9ba5b71c9282http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/3a57e842-71ce-4acd-839f-9ba5b71c9282Shahinhttp://social.technet.microsoft.com/Profile/en-US/?user=ShahinPublish OWA on ISA 2006 with HTTP and not HTTPSHi,<br/><br/>We are going to deploy ISA 2006 in our enviorment, I have to publish our exchange server 2007 for using OWA, I did check the net and every where talking about publishing with SSL, but we dont have a CA or lets say, we do not need any CA, and we want to access the OWA just with HTTP, could some one direct me to some tutorial on how to publish OWA throuw HTTP instead of HTTPS.<br/><br/>Thanks,<br/><br/>Shahin<br/><br/><hr class="sig">ShahinMon, 31 Aug 2009 14:08:10 Z2009-09-08T06:26:33Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/2aa9333d-67e7-4c4f-8e07-ee99d79a2964http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/2aa9333d-67e7-4c4f-8e07-ee99d79a2964manuellmchttp://social.technet.microsoft.com/Profile/en-US/?user=manuellmcISA 2006 SSL Bridging Hi all.<br/><br/>This moment I try to publish OWA using SSL Bridging, but when I check the option &quot;Use certificate to authenticate to the SSL Web Server&quot; and then click the option &quot;Select&quot;   I get this messages &quot;No valid certificate were found on the servers in this arrays&quot;. Please help me...  How to create this certificate to complete this procedure.  I was reading some articules and these mention about server certificate for ISA 2006, I guest this certificate is different that web listener? How to create this server certificate for ISA 2006?<br/><br/>please give me any idea.<br/><br/>thks.<br/><br/><br/><br/><br/>Tue, 04 Aug 2009 05:10:05 Z2009-08-24T18:42:37Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/4f792948-9876-496e-8381-ca9242079864http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/4f792948-9876-496e-8381-ca9242079864Morne Fouriehttp://social.technet.microsoft.com/Profile/en-US/?user=Morne%20FourieThe security certificate presented by this website was not issued by a trusted certificate authority.HI. I am using ISA 2006 with windows 2003 std sp2. I published a website on the server with https but get the error above. when i surf the website on the webserver it works fine but not when i surf it from the isa server or external. When I test the rule it give me the error below:<br/><br/>Testing URL <a href="https://myhost.mysite.com:6443/">https://myhost.mysite.com:6443/</a><br/>Category: Published server certificate error<br/>Error details: 0x80090325 - The certificate chain was issued by an authority that is not trusted.<br/>Action: Go to <a href="http://go.microsoft.com/fwlink/?LinkId=115965">http://go.microsoft.com/fwlink/?LinkId=115965</a><br/><br/>The site is published on port 6443 on both the isa server and the web server. The digicert root authority certificate is installed in the &quot;trusted root authority ceritifcates&quot; container on both servers. The certificate *.mysite.com is installed on the &quot;personal&quot; container on both servers and on the IIS website on the webserver.<br/><br/>Any ideas are welcome. thank you.<hr class="sig">Morné Fourie AFRIDATA.net Cell: +27 83 283 5893 Office: +27 83 283 5893 Fax: 086 658 5062 Email: morne@afridata.netTue, 18 Aug 2009 06:30:37 Z2009-08-18T11:33:32Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/f9e7c3d7-0383-4b25-b138-d1d6d4d2a0d2http://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/f9e7c3d7-0383-4b25-b138-d1d6d4d2a0d2Sergey Sypalohttp://social.technet.microsoft.com/Profile/en-US/?user=Sergey%20Sypalo2 factor authentication for SharePoint Server 2007 publishingHi All<br/>I need to publish SharePoint Server 2007 using 2-factor authentication (certificate for computer and FBA for user). Does ISA or TMG provide this functionality or not?<hr class="sig">MCSA, CCNATue, 04 Aug 2009 08:05:51 Z2009-08-18T09:12:34Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/24e554cc-c9e8-4dd3-a942-fc0973c182dbhttp://social.technet.microsoft.com/Forums/en-US/ForefrontedgePub/thread/24e554cc-c9e8-4dd3-a942-fc0973c182dbSt.Sparkyhttp://social.technet.microsoft.com/Profile/en-US/?user=St.SparkyCan't dis-able forms based authentication on exchange and have OWA work as wellHi,<br/> <br/> I set up our OWA and all was working well until an application my company developed for internal use lost some functionality. I discovered the problem was that i had disabled the forms based authentication on exchange 2003 for the OWA to work through isa 2006, naturally you can see that with it enabled the App works and OWA doesn't and the opposite occurs when FBA is disabled. Is there a way around this? I have read that you can disable FBA on isa but that it won't help my OWA not working.<br/> <br/> Any help would be appreciatedWed, 12 Aug 2009 14:49:19 Z2009-08-13T08:21:45Z