Locked ISA 2006 as web proxy and iPhones

  • 2010년 2월 24일 수요일 오전 11:48
     
     
    Hi everyone.

    We use ISA 2006 as our firewall and web proxy. All works well except for our iPhones that use our wireless network for internet access. On the iPhone you can add proxy settings (including proxy authentication details - ad user account) for wireless connections, and this works great when using safari to browse the net and using mail (connected to exchange). However apps on the iPhone that need access to the internet cannot while connected to the wireless network.

    I've checked the ISA logs and connections are denied because the proxy server requires authentication. Obviosuly the apps try and use the internet connection via the wireless connection through the proxy, but don't pass the authentication details.

    Has anyone come across this kind of issue and resiolved it, or could anyone suggest any pointers?

    Thanks

    Dave

모든 응답

  • 2010년 2월 24일 수요일 오후 2:48
    답변자
     
     
    The applications are probably not "proxy aware".
  • 2010년 2월 24일 수요일 오후 4:31
     
     
    Yea exaclty! I was just wondering if anyone's come across this and got around it?
  • 2010년 3월 8일 월요일 오전 3:30
    중재자
     
     답변됨

    Hi,

     

    Thank you for the post.

     

    If the applications not “proxy aware”, the request will not forward by the ISA Server. I thing you may call for iPhone support(http://www.apple.com/support/) and see if they have any workaround.

     

    Regards,


    Nick Gu - MSFT
  • 2010년 10월 25일 월요일 오후 1:39
     
     
    Good afternoon Dave,

    What was the solution informed by Apple for this problem?

    thanks
  • 2010년 10월 25일 월요일 오후 1:55
     
     

    The only real option is to allow anonymous access for iPhones and combine this with some form of destination whitelist or URL filtering. To make things a little easier, you can assign the iPhone IP addresses using DHCP reservations, this then allows specific ISA/TMG rules rather than being able to control based upon username or groups.

    Cheers

    JJ 


    Jason Jones | Forefront MVP | Silversands Ltd | My Blogs: http://blog.msedge.org.uk and http://blog.msfirewall.org.uk
  • 2010년 10월 25일 월요일 오후 5:32
     
     

    Good morning Jason,

    Thanks for the reply. My WI-FI has several different networks, so I have no way to make a reservation in DHCP.

    Thanks.