Re: Using external IP/DNS name for accessing internal resources

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



A few clarification questions.

Is 100.100.100.100 an IP owned by ISA (used for publishing
www.myserver.com)?
When the proxy relays the requests to other servers, are there any rules to
allow these requests to pass through ISA?
Did you check the logviewer if there is any denied traffic? This may provide
some help as to what traffic is denied and why. You can also use the
logviewer to make sure that the traffic is routed properly to the machine,
and that there are no routing problems from the internal to 100.100.100.100.

HTH,

Ori.


--
Please do not send email directly to this alias. This alias is for newsgroup
purposes only.This posting is provided "AS IS" with no warranties, and
confers no rights.


"Eivind Brenningen" <fornavn punktum etternavn hos gmail punktum com> wrote
in message news:OgtVC42QGHA.1688@xxxxxxxxxxxxxxxxxxxxxxx
Hi,

I'm scrathing my head trying to figure out how to set the roules for the
following scenario:

We have a defined DNSname www.myserver.com with official IP
100.100.100.100
The ISA Server is located at 100.100.100.1

In DMZ we have a web and reverse proxy server with name myproxy.internal
and IP 10.0.0.50

The proxy relays requests to other internal servers in DMZ or o another
network (managed by ISA).

We have set up rules for the appropriate ports (HTTP,HTTPS) which listens
to the IP 100.100.100.100 and sends the requests to 10.0.0.50
(It's an array rule, not web chaining). All networks are allowed. Original
header is passed through.

When connecting from external sites things are OK. But when connecting
from the internal nets we get the 10061 error message in IE (from ISA, I
belive).

How do I correct this?

Also we use aliases for www.myserver.com which is used by the reverse
proxy to relay requests to other servers with the same result as above.


Any ideas?

-Eivind Brenningen



.



Relevant Pages

  • Re: ISA configuration question
    ... Are you talking about web published content (inbound requests to internal servers) or web proxy requests (outbound to external ... Web published content is indeed available for ISA perusal, ... up to redirect HTTP requests as SSL requests, and SSL requests and SSL requests. ...
    (microsoft.public.isa.configuration)
  • Re: Error 414
    ... Those are SSL-tunnel requests, which the ISA Web Proxy filter cannot ... Jim Harrison (ISA SE) ... "Jim Harrison " wrote: ... It works fine on the other proxy servers in the organisation but not the ...
    (microsoft.public.isa)
  • Re: Web Chaining - Ausgehender Port für SSL
    ... den isa, weil du ihre browserkonfigurationen angepasst hast. ... somit schickt dein isa die requests an den squid und bittet jenen ... auseinandernimmt und je nach Aufbau an den entsprechenden Port ... Also bekommt der upstream-Proxy das nur auf die entsprechenden Ports ...
    (microsoft.public.de.german.isaserver)
  • Re: Web Chaining - Ausgehender Port für SSL
    ... isa, weil du ihre browserkonfigurationen angepasst hast. ... somit schickt dein isa die requests an den squid und bittet jenen wiederum ... dass der ISA auf Port 80 ein HTTP-Connect an den Squid stellt.. ... Also bekommt der upstream-Proxy das nur auf die entsprechenden Ports ...
    (microsoft.public.de.german.isaserver)
  • Re: ISA configuration question
    ... - create a certificate that uses either the name or IP of the ISA web proxy listener (depends on how you want the clients to ... - configure the web proxy listener to listen for SSL connections and choose the port you want ... For clients that support secure communication directly with ISA Server, ... > I'm referring to web proxy requests. ...
    (microsoft.public.isa.configuration)