Re: SSL Bridging & Tunnelling

Tech-Archive recommends: Fix windows errors by optimizing your registry



Hi Jim,
Thanks for the reply.
q1 - This is now it was setup when I started here. I believe it was done
this way as originally just one site was using ssl and server publishing was
the easiest way to tunnel the ssl as opposed to bridging. To be honest I
don't know and it puzzled me.

q2 - the inbound web listener is configured individually per IP address (we
only have one address tho) and it *does* include the external IP address that
is used by the server publishing rule. I also noticed that 'Enable SSL
listeners' is *not* checked and no certificate is installed in the listener.

Should I then add the two imported certificates to the listener and confiure
to use SSL? This seems to be the right thing to do as per
http://www.microsoft.com/technet/archive/isa/2000/isafp1/piw.mspx?mfr=true
If so, thanks for pointing me in the direction of the listener
Rob

"Jim Harrison (ISA SE)" wrote:

Q1 - why are you using server publishing?
Q2 - have you checked that the inbound web listener does *not* include the
external IP used by the server publishing rule?

--
Jim Harrison (ISA SE)


.



Relevant Pages

  • Re: Wind Mobile Pushservice verweigerte Verbindung
    ... sobald du mit ihm auf den isa listener zugreifst wird der sogenannte user-agent-string ausgewertet. ... sobald der isa feststellt, das es sich hierbei nicht um einen browser handelt versucht er dir nicht die fba sondern die standardauthentifizierung anzubieten. ... das fba mit ldap funzt beweist dein owa. ... Client over SSL zu ISA - stop - ISA over SSL zu XMS vorher noch per LDAP gucken, ...
    (microsoft.public.de.german.isaserver)
  • Re: Wind Mobile Pushservice verweigerte Verbindung
    ... sobald du mit ihm auf den isa listener zugreifst wird der sogenannte user-agent-string ausgewertet. ... sobald der isa feststellt, das es sich hierbei nicht um einen browser handelt versucht er dir nicht die fba sondern die standardauthentifizierung anzubieten. ... das fba mit ldap funzt beweist dein owa. ... Client over SSL zu ISA - stop - ISA over SSL zu XMS vorher noch per LDAP gucken, ...
    (microsoft.public.de.german.isaserver)
  • RE: unable to connect to do a SSL conection through the ISA
    ... When you are publishing an SSL website through ISA there are a couple of ... You can either use Web Publishing or Server Publishing, ... difference being that when Web Publish the SSL connection is broken ISA, ...
    (microsoft.public.isaserver)
  • Re: ewb listerner problems
    ... abdicate of the web forms auth and leave Exchange only with SSL? ... > I'has a ISA 2004, with two ip, one public and one private, and I want to ... > public my exchange 2003, my Sharepoint Portal, and others web page. ... > so, I create a web listener in ISA, that use ssl and por 443, with OWA ...
    (microsoft.public.isaserver)
  • HTTPCFG - Unable to disable Socket Pooling for SSL
    ... can configure a website for another port... ... When configuring HTTPS listeners, ... I can verify that with no SSL ... I configure an SSL listener, I find that IIS does not map ...
    (microsoft.public.inetserver.iis)