Re: Firewall client and authentication

From: Jim Harrison [MSFT] (jmharr_at_online.microsoft.com)
Date: 12/24/04


Date: Fri, 24 Dec 2004 09:37:23 -0800

This is a known issue.
Currently, the workaround is this:
- Configure your rules to apply to "authenticated users"
- Uncheck "Require all users to authenticate"

-- 
 Jim Harrison [ISASE]
 Read the help, books and articles!
 This posting is provided "AS IS" with no warranties, and confers no rights.
"Philip Colmer" <pcolmer@newsgroups.nospam> wrote in message news:%23OHL9u35EHA.2012@TK2MSFTNGP15.phx.gbl...
I've set up a test domain where ISA 2004 is installed and a client PC has
installed the firewall client through Group Policy. I've configured DNS to
give out the IP address for WPAD.
The logging shows that the the request for http://wpad/wpad.dat comes from
"anonymous" - not surprising since no-one is logged into the PC. However,
this means that if I configure the network entry to require all users to
authenticate, the request fails.
Annoyingly, the request fails, even though I've got a rule that allows HTTP
access to "Local Host" for all users!
The logging for the anonymous request does not specify which rule is
granting or denying access.
Can anyone suggest how I improve on this configuration? I was trying to get
authentication in place because I want to have restricted access for certain
users but full access for other users.
--Philip


Relevant Pages

  • Re: IAS Athentication via ODBC
    ... that paper talks about Logging (doing the ... accounting) what I am interested in is how to authenticate via an ODBC data ...
    (microsoft.public.internet.radius)
  • IAS server doesnt log
    ... I installed a ias server on a windows 2000 domain controller. ... but no logging ... whatsoever shows up when i try to authenticate a user, ...
    (microsoft.public.internet.radius)
  • RE: Unexpected client authentication popup when using IE
    ... The behaviour you suggest regarding the logging of anonymous access is ... Why should IE authenticate if you have not told it to? ... You will always have a couple of anonymous requests logged first ... IE requests the site anonymously, ...
    (microsoft.public.isa)
  • PEAP and new users
    ... it seems that users still not having a profile on the client ... (logging in for the first time) ... cannot authenticate against 802.1x/PEAP + ...
    (microsoft.public.internet.radius)
  • Re: Outlook 2003 sporadically fails POP authentication
    ... Thanks, neo. ... the "sporadic" failure to authenticate does have a pattern. ... I do have logging on now and will post the log after my next failed ...
    (microsoft.public.outlook.general)

Loading