..because you changed your "allow all" to "allow them". SecureNAT clients can't authenticate. ------------------------------------------------------- Jim Harrison MCP(NT4, W2K), A+, Network+, PCG http://isaserver.org/Jim_Harrison/ http://isatools.org Read the help / books / articles! ------------------------------------------------------- -----Original Message----- From: James May [mailto:Jmay@xxxxxxxxxx] Sent: Monday, October 03, 2005 07:14 To: [ISAserver.org Discussion List] Subject: [isalist] RE: Changing Protocal access rules http://www.ISAserver.org I want to use the http filter to stop most users from downloading certain file extensions and limit their protocols to a selected set. My question is why all the secureNat computers stop working when I change the all users to a windows group or a specific set of users -----Original Message----- From: Jim Harrison [mailto:Jim@xxxxxxxxxxxx] Sent: Monday, October 03, 2005 6:49 AM To: [ISAserver.org Discussion List] Subject: [isalist] RE: Changing Protocal access rules http://www.ISAserver.org You might want to clarify what it is you're trying to solve. "Im trying to use the http filter in isa 2004" is completely unrelated to SMTP traffic. -----Original Message----- From: James May [mailto:Jmay@xxxxxxxxxx] Sent: Monday, October 03, 2005 6:42 AM To: [ISAserver.org Discussion List] Subject: [isalist] RE: Changing Protocal access rules http://www.ISAserver.org Tom, Ok I got the book out this morning I have no problem with the lay out you suggested. Here's what happens I can not send mail from my exchange server behind the isa2004. The isa2004 server is relaying the email to the internal exchange 2000 server which is SBS2000.Only OWA is published my thinking is I've got something wrong in the ISA2004 setup that's causing all secureNAT clients and servers to stop working when the all users is removed from the default protocol rule. Even if an exception is added to the default rule the same thing happens. Jim -----Original Message----- From: Thomas W Shinder [mailto:tshinder@xxxxxxxxxxx] Sent: Monday, October 03, 2005 6:08 AM To: [ISAserver.org Discussion List] Subject: [isalist] RE: Changing Protocal access rules http://www.ISAserver.org Hi Jim, 1. Configure clients as Web proxy clients 2. Configure clients as Firewall clients 3. SecureNAT clients are for servers and non-Windows OS. Laterz, Thomas W Shinder, M.D. Site: www.isaserver.org Blog: http://spaces.msn.com/members/drisa/ Book: http://tinyurl.com/3xqb7 MVP -- ISA Firewalls > -----Original Message----- > From: Jim [mailto:jmay@xxxxxxxxxx] > Sent: Monday, October 03, 2005 1:08 AM > To: [ISAserver.org Discussion List] > Subject: [isalist] Changing Protocal access rules > > http://www.ISAserver.org > > Im trying to use the http filter in isa 2004, when I change > the default > rule by changing the all users to a windows AD group all secure nat > clients loose connectivity you have to enable the proxy > settings in IE to > get to the internet. I don't have the firewall client > installed on any of > the machines. Thanks Jim > > ------------------------------------------------------ > List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist > ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp > ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ > ------------------------------------------------------ > Visit TechGenix.com for more information about our other sites: > http://www.techgenix.com > ------------------------------------------------------ > You are currently subscribed to this ISAserver.org Discussion > List as: tshinder@xxxxxxxxxxxxxxxxxx > To unsubscribe visit > http://www.webelists.com/cgi/lyris.pl?enter=isalist > Report abuse to listadmin@xxxxxxxxxxxxx > > ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Visit TechGenix.com for more information about our other sites: http://www.techgenix.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: jmay@xxxxxxxxxx To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist Report abuse to listadmin@xxxxxxxxxxxxx ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Visit TechGenix.com for more information about our other sites: http://www.techgenix.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: jim@xxxxxxxxxxxx To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist Report abuse to listadmin@xxxxxxxxxxxxx All mail to and from this domain is GFI-scanned. ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Visit TechGenix.com for more information about our other sites: http://www.techgenix.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: jmay@xxxxxxxxxx To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist Report abuse to listadmin@xxxxxxxxxxxxx ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Visit TechGenix.com for more information about our other sites: http://www.techgenix.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: jim@xxxxxxxxxxxx To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist Report abuse to listadmin@xxxxxxxxxxxxx All mail to and from this domain is GFI-scanned.