Re: IE Authentication dialog showed in ISA2000 but will not in ISA2004



Sounds like the following situation:

ISA 2004 does 502s rather than 407s if you're already authenticated
http://blogs.technet.com/tristank/archive/2004/11/01/250312.aspx

As a note, you may need to fiddle with rule ordering after toggling this
setting.

HTH
--
http://blogs.technet.com/tristank/
--
This post is provided "AS-IS", and confers no warranty.


"Jon" <Jon@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:64377676-ED9A-4C86-9936-CDFBD6BA1049@xxxxxxxxxxxxxxxx
> We are upgrading from ISA 2000 to ISA 2004. At Fire Stations, PCs are
> configured with a generic login. The generic login does not have
> permissions
> to access the internet. On ISA 2000 this is controlled by a protocol rule
> that 'Applies To' an Active directory security group. Further - under ISA
> server properties/Outgoing Web Requests the 'Ask unauthenticated users for
> identification' check box is checked. The web proxy ISA client is used.
>
> When a user at a Fire Station starts IE an authentication dialog box
> appears
> and they are able to enter their own login account details (that is in the
> approved group) and then they can access the internet and web sites they
> visit are tracked to their account.
>
> Now with ISA 2004 this process is not working.
>
> We have setup an access rule that is conditional on the user being in the
> same group as above (by creating a new 'user set' and adding it to the
> 'Users' page of the access rule). We are still using the web proxy ISA
> client.
>
> However, access to the internet is blocked and no dialog appears.
> Further,
> if we login to the PC using an account in the approved group, access to
> the
> internet is still blocked. The only way we can get access using the web
> proxy client is to add the 'All Users' user set to the Users page. This
> is
> behavior that we would expect with the Secure NAT client but should not
> occur
> with the web proxy client.
>
> We have experimented with the firewall client. The firewall client
> authenticates correctly (if we login using an account in the approved
> group
> then we can browse the internet). However, still there is no IE
> authentication dialog if we login using the generic unapproved account.
> We
> are simply blocked in that case.
>
> We have tried various authentication methods offered by the Web Proxy page
> on the Internal Network properties form. We tried the different options
> both
> for the web proxy client and the firewall client. None of the
> combinations
> produced an IE authentication form.
>
> How can we get the authentication functionality that we have in ISA 2000
> to
> work in ISA 2004?
>
> Thanks
> Jon


.



Relevant Pages

  • RE: Force use of ISA Firewall Client
    ... You see three types of ISA 2004 firewall clients in ISA console, ... the system will use Web Proxy ... protocols, this need Firewall client. ...
    (microsoft.public.windows.server.sbs)
  • RE: Restrict group to two web sites.
    ... is used to force authentication for outgoing traffic in ISA, ... how the web proxy works when the client is configured as Web Proxy Client: ... How does the IE judge whether the URL is an internet website or an internal ...
    (microsoft.public.windows.server.sbs)
  • RE: ISA 2004 - Anonymous Connection
    ... By default in ISA 2004 with SBS, after you run the CEICW, the ISA will ... to Internet and do not prompt user input credentials. ... For ISA Firewall client and Web proxy client: ...
    (microsoft.public.windows.server.sbs)
  • RE: Add network connection fails
    ... place" in the network neighbourhood on a client. ... > been configured as both Web Proxy client and Firewall client. ... configure ISA server as your Proxy ... > Application Filters, ...
    (microsoft.public.windows.server.sbs)
  • Re: Authentication Rule Blocks Telnet
    ... Check your FWC application settings at the ISA; ... Original Client IP Client Agent Authenticated Client Service Server Name ... Type Log Time Destination IP Destination Port Protocol Action Rule Client IP ... >>> or firewall logs that can show the source of the authentication problem? ...
    (microsoft.public.isa)