[isapros] Re: Fw: Re: Web Filter with HTTPS

  • From: "Gerald G. Young" <g.young@xxxxxxxx>
  • To: <isapros@xxxxxxxxxxxxx>
  • Date: Wed, 20 Jun 2007 17:27:25 -0400

Is all filtering based off of the web filter?  I haven't really looked
at it this deeply but since ISA can check HTTPS OWA connections to make
sure they're all formed correctly, there is some kind filtering going
on.  Is the web filter responsible for this or is that something else?

Any HTTPS publishing rule essentially terminates the TCP connection at
the ISA server, yes?  The traffic is then decrypted, examined, and then
passed on its way, either over HTTP or HTTPS as dictated by the bridging
configuration (terminology is probably messed up).

Sorry about the silly questions. :(

Cordially yours,
Jerry G. Young II
Application Engineer
Platform Engineering and Architecture
NTT America, an NTT Communications Company

22451 Shaw Rd.
Sterling, VA 20166

Office: 571-434-1319
Fax: 703-333-6749
Email: g.young@xxxxxxxx


-----Original Message-----
From: isapros-bounce@xxxxxxxxxxxxx [mailto:isapros-bounce@xxxxxxxxxxxxx]
On Behalf Of Thor (Hammer of God)
Sent: Wednesday, June 20, 2007 5:05 PM
To: isapros@xxxxxxxxxxxxx
Subject: [isapros] Fw: Re: Web Filter with HTTPS

OK, so you are saying that if I unbind the Web Filter from HTTPS, and
create 
a pub rule for HTTPS, then the filter will still be used for the Pub
rule?

t


-----Original Message-----
From: isapros-bounce@xxxxxxxxxxxxx [mailto:isapros-bounce@xxxxxxxxxxxxx]
On Behalf Of Jim Harrison
Sent: Wednesday, June 20, 2007 5:43 PM
To: isapros@xxxxxxxxxxxxx
Subject: [isapros] Re: Web Filter with HTTPS

The web filter is the part that expects to watch the HTTP traffic as it
flows through ISA.
With the exception of web publishing, HTTPS traffic is effectively
invisible to ISA and therefore any policies enacted via the web filter
(think HTTP Filter, too) cannot be applied and ISA will default to "when
in doubt, trash it" mode.

-----Original Message-----
From: isapros-bounce@xxxxxxxxxxxxx [mailto:isapros-bounce@xxxxxxxxxxxxx]
On Behalf Of Thor (Hammer of God)
Sent: Wednesday, June 20, 2007 1:15 PM
To: isapros@xxxxxxxxxxxxx
Subject: [isapros] Web Filter with HTTPS

Just a sanity check here... why would all HTTPS traffic fail if the Web
Filter was bound to the HTTPS protocol?

t

All mail to and from this domain is GFI-scanned.




Other related posts: