Re: HTTPS; SSL-Tunnel

From: David (NOSPAMDavidGerst_at_anti-spam.tempco.com)
Date: 06/02/04


Date: Wed, 2 Jun 2004 10:51:13 -0500

This is another sample of the ISA logs. 172.16.0.3 is the ISA Server
internal NIC. 172.16.0.1 is the DNS server on the internal network. I
created a rule to allow DNS from the local host to the internal network, but
as you can see it's still getting denied for some reason. any thoughts?

Original Client IP Client Agent Authenticated Client Service Server Name
Referring Server Destination Host Name Transport MIME Type Object Source
Source Proxy Destination Proxy Bidirectional Client Host Name Filter
Information Network Interface Raw IP Header Raw Payload Source Port
Processing Time Bytes Sent Bytes Received Result Code Cache Info Error Info
Log Record Type Log Time Client IP Destination Host IP Destination Port
Protocol Action Rule Client Username Source Network Destination Network HTTP
Method URL
172.16.0.3 GATEWAY - TCP - - 16753 0 0 0 0xc0040017 0x0 0x0
Firewall 6/2/2004 10:49:55 AM 172.16.0.3 172.16.0.1 53 DNS Denied Connection
Local Host Internal - -

"Jim Harrison [MSFT]" <jmharr@online.microsoft.com> wrote in message
news:u6qZLoDREHA.1276@TK2MSFTNGP11.phx.gbl...
> What's in the ISA web proxy logs for those requests?
>
> --
> Jim Harrison [ISASE]
> Read the help, books and articles!
>
> This posting is provided "AS IS" with no warranties, and confers no
rights.
>
>
> "David" <NOSPAMDavidGerst@anti-spam.tempco.com> wrote in message
news:OdEx18BREHA.3140@tk2msftngp13.phx.gbl...
> OK,
>
> I've even gone as far as giving cart-blanche access to the site and it's
> still a no go. all protocols, all users, from internal to all external.
I
> know it's not a problem with the site because I can run through a
different
> gateway that does not have ISA on it and it works fine. now I'm really
> baffled!
>
>
>
>
> "Tony Su" <anonymous@discussions.microsoft.com> wrote in message
> news:13a0201c44412$e50d2300$a001280a@phx.gbl...
> > If you're accessing remote SSL sites using the standard
> > port (443), you shouldn't be running into any special
> > problems.
> >
> > If you're accessing an SSL site using a non-default port,
> >
> > http://support.microsoft.com/default.aspx?scid=kb;en-
> > us;283284
> >
> > Tony Su
> >
> >
> >
> >
> >
> > >-----Original Message-----
> > >Hi,
> > >
> > >I'm relatively new to this, so here goes...
> > >
> > >
> > >I have ISA server setup to block all web traffic by
> > default and I'm making
> > >rules to allow traffic. This is working great for the
> > HTTP protocol. The
> > >problem I am running into is for HTTPS sites. Even
> > though I have a rule
> > >saying allow userx to go from the internal network using
> > the HTTPS protocol
> > >to destination setX, for some reason it's just not
> > working. what am I
> > >missing? I also see in the log files that it's using SSL-
> > Tunnel.
> > >
> > >thanks!
> > >
> > >- david
> > >
> > >
> > >.
> > >
>
>
>



Relevant Pages

  • Re: ISA 2006 configuration question - multiple VLANs and domains
    ... very familiar with network segments vs. domains et. al. ... multihomed ISA 2006 server forward a DHCP request to the proper VLAN ... ISA is a Firewall Product designed to protect a network from the Internet. ...
    (microsoft.public.isa.configuration)
  • RE: Firewall service and remoteaccess service shut down frequently
    ... Do you have run the CEICW after installing the ISA components? ... please open SBS server management console, ... Click the Add Adapter button, and add your internal network adapter ... Meanwhile, from the subject, you said you the firewall service and RRAS ...
    (microsoft.public.windows.server.sbs)
  • Re: Strange problem with opening a network place could be ISA 2004 or XP SP2 Problem
    ... Since the error may be recorded in the ISA logs, ... Expand the server node and highlight 'Monitoring'. ... The VPN connection was created manually (using the add a new ...
    (microsoft.public.windows.server.sbs)
  • RE: isa 2004 & external website access issue
    ... emailed the logs to you as requested. ... each web server has its own public IP ... > headers in ISA Server ... > 'Microsoft Firewall' service. ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN breaks after installing patches
    ... I have just received your email due to some network traffic problems. ... access the network shares was denied by ISA Server. ... Open the Server management console, navigate to "Internet and E-mail", ...
    (microsoft.public.windows.server.sbs)