RE: Help with the web proxy setup in ISA 2004

  • From: tim S <tim724342@xxxxxxxxx>
  • To: "\[ISAserver.org Discussion List\]" <isalist@xxxxxxxxxxxxx>
  • Date: Tue, 24 May 2005 16:49:32 -0700 (PDT)

Thanks Tom that works like charm. I follwed the instructions on your book.  
They can access the local FQDNS like http://intranet.company.org without going 
through proxy.  One problem I have now is if the users type http://10.10.5.2 
which resolves to intranet.company.org, they get:
 
Error Code: 502 Proxy Error. The ISA Server denied the specified Uniform 
Resource Locator (URL). (12202) 
 
Obviously the browser is not recognizing the IP as local.  What can I do?  
If I tried FTP://10.10.5.10 in the browser that works fine.   If I tried FTP 
10.10.5.10 in the command prompt, it works fine too.  so I know firewall client 
doesn't deal with local addresses. 
 
 
Thanks for your help.   

Thomas W Shinder <tshinder@xxxxxxxxxxx> wrote:
http://www.ISAserver.org
Hi Tim,
 
In order to use the settings you configured for Web Proxy Direct Access in the 
ISA firewall console, you need to complete the process by configuring the Web 
proxy clients to use the autoconfiguration script. Autodiscovery will 
accomplish this just fine, or you can do it manually or through Group policy.
 
HTH,

Tom
www.isaserver.org/shinder
Tom and Deb Shinder's Configuring ISA Server 2004
http://tinyurl.com/3xqb7
MVP -- ISA Firewalls
 


---------------------------------
From: tim S [mailto:tim724342@xxxxxxxxx] 
Sent: Monday, May 23, 2005 8:15 PM
To: [ISAserver.org Discussion List]
Subject: [isalist] Help with the web proxy setup in ISA 2004



http://www.ISAserver.org I have ISA 2004 on w2k3 and it's an edge firewall.  I 
allow all protocol from Internal to External (this will soon be changed). All 
three client types are configured in each workstation.  My Internal machines 
have problem accessing internal websites (No looping through firewall).  If I 
disable the proxy setting in the browser, workstations have no problem.  I 
check marked 'By pass addresses found in the Domain Tab"  and also entered my 
internal domain name in the Web browser tab of "Internal" network properties. I 
still can't get the web proxy clients not to contact ISA for internal websites. 
 If I use the computer name instead of http://some.http.address.local, 
everything works fine too.  I was able to solve  the problem (for the time 
being) by modifying the "Allow all outbound traffic" rule with FROM: Internal 
and TO: Anywhere.  I had it preveoulsy as FROM: Internal and TO: External. I 
think my solution is bit convulated.  After reading Tom's book, I didn't
 want to install Ethereal on my firewall but Network monitor has a big learning 
curve.  Your help is greatly appreciated.

__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around 
http://mail.yahoo.com ------------------------------------------------------ 
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server 
Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: 
http://www.isaserver.org/pages/larticle.asp?type=FAQ 
------------------------------------------------------ Other Internet Software 
Marketing Sites: World of Windows Networking: http://www.windowsnetworking.com 
Leading Network Software Directory: http://www.serverfiles.com No.1 Exchange 
Server Resource Site: http://www.msexchange.org Windows Security Resource Site: 
http://www.windowsecurity.com/ Network Security Library: http://www.secinf.net/ 
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com 
------------------------------------------------------ You are currently 
subscribed to this ISAserver.org Discussion List as: 
tshinder@xxxxxxxxxxxxxxxxxx To unsubscribe visit 
http://www.webelists.com/cgi/lyris.pl?enter=isalist Report abuse to 
listadmin@xxxxxxxxxxxxx
------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
World of Windows Networking: http://www.windowsnetworking.com
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as: 
tim724342@xxxxxxxxx
To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist
Report abuse to listadmin@xxxxxxxxxxxxx 
__________________________________________________
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around 
http://mail.yahoo.com 

Other related posts: