ISA 2004 and SSL-Tunnel Protocol



I have an issue when clients are trying to connect to a HIPPA secure email
server. The clients are connecting on port 443 and we use ISA to proxy the
port. The issue is that the clients get a "nonstandard port error", but the
log shows authentication issues with SSL-Tunnel protocol. I have included
the log below. The interesting thing is that the client can connect (with a
certificate warning) if I replace the url with the actual IP address of the
secure email server. Here is the log.

Denied Connection GRANTESD-ISA2 5/28/2008 2:15:03 PM
Log type: Web Proxy (Forward)
Status: 12209 The ISA Server requires authorization to fulfill the request.
Access to the Web Proxy service is denied.
Rule:
Source: ( 10.2.80.68:0)
Destination: ( 10.2.80.141:443)
Request: CONNECT
Filter information: Req ID: 0d7a2df4; Compression:None
Protocol: SSL-tunnel
User: anonymous
Additional information
Client agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR
1.1.4322; .NET CLR 2.0.50727; InfoPath.2)
Object source: Processing time: 1
Cache info: 0x0 MIME type:


Failed Connection Attempt GRANTESD-ISA2 5/28/2008 2:15:03 PM
Log type: Web Proxy (Forward)
Status: 5 Access is denied.
Rule:
Source: ( 10.2.80.68:0)
Destination: ( 10.2.80.141:443)
Request: CONNECT
Filter information: Req ID: 0d7a2df6; Compression:None
Protocol: SSL-tunnel
User: anonymous
Additional information
Client agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR
1.1.4322; .NET CLR 2.0.50727; InfoPath.2)
Object source: Processing time: 1
Cache info: 0x0 MIME type:


Failed Connection Attempt GRANTESD-ISA2 5/28/2008 2:15:03 PM
Log type: Web Proxy (Forward)
Status: 12204 The specified Secure Sockets Layer (SSL) port is not allowed.
ISA Server is not configured to allow SSL requests from this port. Most Web
browsers use port 443 for SSL requests.
Rule:
Source: ( 10.2.80.68:0)
Destination: ( 10.2.80.141:0)
Request: https://secureemail.hr.state.or.us:443
Filter information: Req ID: 0d7a2df7; Compression:None
Protocol: SSL-tunnel
User: ESDDOM\waltenburgr
Additional information
Client agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR
1.1.4322; .NET CLR 2.0.50727; InfoPath.2)
Object source: Internet Processing time: 0
Cache info: 0x0 MIME type:


Failed Connection Attempt GRANTESD-ISA2 5/28/2008 2:15:03 PM
Log type: Web Proxy (Forward)
Status: 12204 The specified Secure Sockets Layer (SSL) port is not allowed.
ISA Server is not configured to allow SSL requests from this port. Most Web
browsers use port 443 for SSL requests.
Rule:
Source: ( 10.2.80.68:0)
Destination: ( 10.2.80.141:0)
Request: https://secureemail.hr.state.or.us:443
Filter information: Req ID: 0d7a2df7; Req ID: 0d7a2df7; Compression:None,
Compression:None
Protocol: SSL-tunnel
User: ESDDOM\waltenburgr
Additional information
Client agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR
1.1.4322; .NET CLR 2.0.50727; InfoPath.2)
Object source: Internet Processing time: 0
Cache info: 0x0 MIME type:

Any help is greatly appreciated!
Robert

.



Relevant Pages

  • RE: ISA Server Web Proxy and port usage
    ... Microsoft ISA Server Web Proxy ... The Web Proxy filter failed to bind its socket to 81.4.*.* port 80. ... ISA service will listening on the configured web proxy port. ...
    (microsoft.public.windows.server.sbs)
  • Firewall access rule on ISA2004 for web proxy
    ... I need help getting the web proxy working for browsing the web. ... Connections to port 8080 get denied by a rule further down in the rule list ... All failed entries are client user anonymous. ...
    (microsoft.public.isa)
  • Re: ISA Server Web Proxy and port usage
    ... please note that now my clients work as gateway and proxy clients and they are ok with Internet access. ... As you can see in the error description, it is the web proxy filter that fails to bind. ... I already use port 8080 for proxy from the standard installation of ISA and this is the port I configure the clients to use in IE. Can it be used here again? ...
    (microsoft.public.windows.server.sbs)
  • Re: Problem with ISA Server and autoconfig - manual works
    ... outbound HTTP, you'll control it on a per site basis, and use the deep ... Tom and Deb Shinder's Configuring ISA Server 2004 ... to 3128 - to make sure it was not listening on a port users would have ... they can reach the ports using web proxy. ...
    (microsoft.public.isa)