RE: SSL publishing on two internal servers

  • From: marc.boutin@xxxxxxxxx
  • To: isalist@xxxxxxxxxxxxx
  • Date: Tue, 23 Oct 2001 11:38:15 -0400

Thanks for the input...my SSL works fine on three of the sites it is only on
one of the french sites that doesn't work....

Here is the setup : 

ISA dual NIC (example)
internal 10.x.x.x
external 172.x.x.1 and 172.x.x.2


two internal web servers :

1rst)  www.english1.net SSL port - 443
         www.french1.net  SSL port - 444

server publishing rules bound to first external IP address




second) www.english2.net SSL port - 443
          www.french2.net  SSL port - 444

server publishing rules bound to second IP address





All sites work fine on the first server, but on the second one port 444 is
not open trough ISA cannot access it from the internet ????


Any solutions ?



TIA !



-----Original Message-----
From: Thomas Ratz [mailto:tratz@xxxxxxxxxxxx]
Sent: Tuesday, October 23, 2001 8:22 AM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: SSL publishing on two internal servers


http://www.ISAserver.org


Repost...

This "problem" was also encountered by myself. I was ready to kick myself
square in the rear when I figured out the solution:

The ISA is assumed to be dual homed with the default gateway pointing to
the external NIC and a persistant route established for all internal
"default" routes.

The SSL certificate installed on the ISA server contains a "friendly" name
or url. This name must match the name defined in the redirect area of the
web publishing rule as well as in the https [protocol] allow filter
section.

Modify your /winnt/system32/drivers/etc/hosts file to include the same
name used in the step above and bind it to the internal IP address of the
destination site.

All will be well with the world at this point.

------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
marc.boutin@xxxxxxxxx
To unsubscribe send a blank email to $subst('Email.Unsub')


Other related posts: