Re: Gateway Time out Issue Single NIC Web Proxy Config



Hi,

Thank you for your help today with this.

The upstream firewall is a firewall ( no proxy ) Checkpoint Guardian.

If I shut down ISA server services, go to I.E. and enter upstream firewall
ip in proxy settings with port 8080 I get internet.

So since ISA is proxying the request and not NATing it.

Why is the upstream firewall not allowing the request.

Rather then just routing it I am confused as to why ISA will not work.

I am suspecting the upstream firewall will need to have a rule set enabled
for ISA?

That or this configuration will not work.

Which I hope, defense in dept is the approach here.

I read your post one more time and I Agree ISA should not care about the
next hop being a firewall.

I think we've nailed it down.
There is no way to proxy chain isa with guaradian I'd imagine.


"Phillip Windell" wrote:


"Kyle Blake" <KyleBlake@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:BC74E11F-E2C7-405B-ADF4-C612B9361EFA@xxxxxxxxxxxxxxxx
PHILLIP, you are correct!

I believe what is happening is the UPSTREAM firewall is receiving traffic
from ISA on PORT 80.
The upstream firewall only accepts traffic on port 8080.

It is not doing that if it is a traditional NAT based Firewall. Only Proxy
Servers are capable of (and expect) to receive traffic in that manner.
When you send traffic to a specific Port you are directing the traffic at a
particular Applcation (a proxying service) running on that port.

IS there anyway that you know of to get ISA to change destination port to
accomodate upstream firewall?

ISA in such a case would have to be configured to use and upstream proxy
(known as Proxy Chaining).

On the other hand, if you are wrong about this other firewall,.. an upstream
NAT based Firewall is "seen" as nothing more than the "next hop" Router.
Downstream devices such as ISA do not know (or care) that it is a firewall
or just a simple LAN Router.

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.asp

Microsoft ISA Server Partners: Partner Hardware Solutions
http://www.microsoft.com/forefront/edgesecurity/partners/hardwarepartners.mspx
-----------------------------------------------------



.



Relevant Pages

  • Re: Gateway Time out Issue Single NIC Web Proxy Config
    ... The upstream firewall only accepts traffic on port 8080. ... ISA in such a case would have to be configured to use and upstream proxy ... Microsoft ISA Server Partners: Partner Hardware Solutions ...
    (microsoft.public.isa.configuration)
  • Re: Gateway Time out Issue Single NIC Web Proxy Config
    ... PHILLIP, you are correct! ... The upstream firewall only accepts traffic on port 8080. ... IS there anyway that you know of to get ISA to change destination port to ...
    (microsoft.public.isa.configuration)
  • Re: Removing ISA FWC
    ... then it will be used as a CERN Compliant Web Proxy with a single nic? ... If it is the ISA with SBS you will loose it when you loose SBS. ... Microsoft Internet Security & Acceleration Server: Partners ... Microsoft ISA Server Partners: Partner Hardware Solutions ...
    (microsoft.public.isa.clients)
  • Re: ISA server 2004 and Bluecoat proxy
    ... i want to mention that we have configured a backup rout (backup bluecoat ... i want to ask about event 14130 that related to web proxy chain fauilire. ... If you were able to work around the upstream proxy server, ... upstream ISA Server, you might want to change it back. ...
    (microsoft.public.isa.configuration)
  • Re: ISA 2006 und SFirm32
    ... Trage einfach keinen Proxy ein und setze das Standardgateway auf den ISA, ... [MVP ISA Server] ...
    (microsoft.public.de.german.isaserver)

Loading