Here is an example that does work correctly:
Here is an example that does not work:
The default gateway for each client does not permit direct internet access therefore they must go through the proxy. If I set the default gateway to an alternate we use for testing which has unrestricted internet access they all work fine which I guess shows the client tries direct access then the proxy (there are no deny entries in the ISA logging). Setting the default gateway back to the corporate standard restricted gateway these entries are in the ISA log:
Client IP Client Username Client Agent Source Proxy Bidirectional Network Interface Raw IP Header Raw Payload GMT Log Time Log Time URL Referring Server Destination Host Name Object Source Filter Information Cache Information Destination IP Destination Port Protocol Action Rule Source Network Destination Network HTTP Method Original Client IP Authenticated Client Service Server Name Transport Source Port Processing Time Bytes Sent HTTP Status Code Error Information Log Record Type Authentication Server MIME Type Destination Proxy Client Host Name Result Code Bytes Received 172.16.17.40 anonymous Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) - - - - 24/02/2009 0:11 24/02/2009 13:11 http://goku.brightcove.com/1pix.gif?WT.tz=13&WT.bh=13&dcsdat=1235434300234&WT.sr=1280x1024&dcsref=not%20available&dcssip=&playerURL=http%3A//link.brightcove.com/services/player/bcpid4932556001&WT.sp=%7C%7C&WT.fv=WIN%2010%2C0%2C12%2C36&WT.ul=en-nz&WT.fi=Yes&domain=null&WT.js=Yes&WT.pn_sku=1854870565&WT.ti=View%20Video%20Hits&WT.pn_ma=1079060364&lineupId=1847441761&playerId=4932556001&sourceId=1079060364&videoId=1854870565&dcsuri=/viewer/video_view&affiliateId=&playerTag=&publisherId=1079060364 http://admin.brightcove.com/viewer/federated_video_ui_920.swf?&width=798&height=603&flashID=myExperience&bgcolor=%23FFFFFF&playerID=49325560 localhost Upstream Req ID: 1e069906; Compression: client=No, server=No, compress rate=0% decompress rate=0% 0x40800000 127.0.0.1 8088 http Allowed Connection Allowed sites for any user Internal Internal GET 0.0.0.0 Yes Proxy WHGISA01 TCP 0 438 323 200 OK. 0xc80 Web Proxy Filter text/plain - - 1192 172.16.17.40 anonymous Shockwave Flash - - - - 24/02/2009 0:11 24/02/2009 13:11 http://brightcove.fcod.llnwd.net/fcs/ident2 localhost Upstream Req ID: 1e069a49; Compression: client=No, server=No, compress rate=0% decompress rate=0% 0x40040004 127.0.0.1 8088 http Allowed Connection Allowed sites for any user Internal Internal POST 0.0.0.0 Yes Proxy WHGISA01 TCP 0 313 201 200 OK. 0xf80 Web Proxy Filter text/plain - - 223
Whenever the client agent gets flagged as Shockwave Flash there are no more log entries and the video is never loaded - why?
ISA is set to allow all content types for all users and given it is uni-homed it allows internal to local host and local host to internal.
The same also applies to videos on www.bbc.co.uk
ThanksWednesday, February 25, 2009 2:04 AM
Since the destination IP in the logs indicates "127.0.0.1", it's time to start looking at the additional filtering mechanism you have installed on the ISA for which you've configured web chaining.
If you can, disable or remove this, configure ISA for direct access and see how things progress.
Jim Harrison Forefront Edge CSFriday, March 06, 2009 8:19 PM