Forefront Edge Security TechCenter >
Forefront Edge Security Forums
>
Forefront Edge Security - Firewall Client
>
Windows Update using Web Proxy Clients
Windows Update using Web Proxy Clients
Hello Everyone,
I wanted to confirm if this is issue still an issue with ISA 2006. We have two ISA Server 2006 Std (Member Server) in a production environment. All Clients are running Windows XP Pro. All Users access internet using ISA Firewall Client. With Firewall Client "Windows Update" won't work. If we use Web Proxy Client, "Windows Update" works fine. Even on Servers, it won't work without Web proxy clients. I have gone through the following KB and made exact configuration for ISA Server 2006.http://support.microsoft.com/?id=885819
any recommendation is much appreciated.
Answers
- Have you tried the Proxycfg command to set proxy setting just for the Winhttp requests used by BITS?
Proxycfg - ? will give all options
You can manually set the IE proxy setting and then use proxtcfg -u to import IE proxy setting to Winhttp and then remove IE proxy setting if you dont want IE to have proxy setting
This should make the AU which uses BITS to download from MU using winhhtp proxy settings
Please confirm whether this helps
Thanks
Bala- Marked As Answer byElMajdalMVP, ModeratorMonday, June 01, 2009 9:41 PM
All Replies
- Hi,
for clarification:
Windows Update doesn't work when you use Firewall clients and the Windows Update URL/domain set in the Firewall rule?
Does Windows Update work when you use the network object EXTERNAL instead of the URL/domain set in the Firewall rule which allows Windows Update?
regards Marc
www.nt-faq.de
www.it-training-grote.de - Yes; that KB applies to ISA 2006 and TMG as well.
The problem is not with ISA / TMG, but with the way the WU/BITS services handles these requests.
What you want to do is examine the ISA live logging while you test each client configuration to discover what is failing.
Since all clients are XP, why not allow them to operate as web proxy clients?
Jim Harrison Forefront Edge CS - Thank You for your response Marc. To clarify, All notebooks and worksations has ISA Firewall Client installed. For example, If I configure any client with Web Proxy, windows update would work fine. If I remove the web proxy clinet it wourld fail.
All Notebooks and Worksations has only Firewall Client installed. I have created a rule for windows update and defied all URL according to the KB. Notebooks and Worksatons are really not a big issues since we use WSUS. I thought this issue has been resolved in ISA 2006. For All Servers, we use Web Proxy clients for Windows Update. Servers also have Firewall Client installed. - Thank You for updating Jim. It's good to know that KB applies to ISA 2006 and TMG. Please correct me if I am wrong, as I undetstand the best practice is to have Web Proxy and Firewall Client installed on workstations. When we moved over to ISA 2006 from ISA 2000 I had it confiuged this way, but Web Proxy client started to cause issues with some Internal applications, so we decided to have only Firewall clinet insalled on worksations / notebooks.
- Have you tried the Proxycfg command to set proxy setting just for the Winhttp requests used by BITS?
Proxycfg - ? will give all options
You can manually set the IE proxy setting and then use proxtcfg -u to import IE proxy setting to Winhttp and then remove IE proxy setting if you dont want IE to have proxy setting
This should make the AU which uses BITS to download from MU using winhhtp proxy settings
Please confirm whether this helps
Thanks
Bala- Marked As Answer byElMajdalMVP, ModeratorMonday, June 01, 2009 9:41 PM
- Hi Bala,
Thank you for your response. I manually configued proxy settings under Internet Explorer, and LAN settings. After that I ran proxycfg and checked Direct access (No proxy server).
Ran proxycfg -u, and noticed Proxy Server name and Bypass list: Local. I removed Manually configued proxy settings from Internet Explorer.
Tested Windows Update site and it works fine. It's great, now I can remove the manually proxy settings from Servers and set them using WinHTTPSettings and Windows Update will work fine. The issue we were having is everytime after Windows Update we sometime forget to remove the manually added proxy settings and We have an internal applicaiton that uses Non Standard SSL port which would fail with Web Proxy client. Thomas Shinder has a very good article on Extending the ISA Firewall’s SSL Tunnel Port Range (2004).
http://www.isaserver.org/articles/2004tunnelportrange.html

