Re: Problem with ISA Server and autoconfig - manual works

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Povl H. Pedersen (pope_at_my.terminal.dk)
Date: 07/14/04


Date: 13 Jul 2004 22:46:15 -0700

Could somebody please confirm if this if fixed in ISA Server 2004, or
if it is the same ?

Since I have not looked in the Mozilla source code, it could be the
browsers doing this, but I find it more likely that it is in a Windows
.DLL that that is used by both programs, thus being a client side
problem.

We discovered the problem when moving the upstream proxy from port 80
to 3128 - to make sure it was not listening on a port users would have
normal access to. The problem with the old setup (port 80) was that
users could bypass the web proxy - and detailed logging, by entering
the address of the upstream proxy in their browser, and fall back to
tunelling through the ISA to the upstream server.

I have had a supportcase before with MS that the ISA server did not
look at port numbers in URLs, so you can not limit users to ports if
they can reach the ports using web proxy. Port 80 and web proxy gives
access to all ports on the Internet. MS promised that this is fixed in
ISA Server 2004.

Povl



Relevant Pages

  • Re: Problem with ISA Server and autoconfig - manual works
    ... We discovered the problem when moving the upstream proxy from port 80 ... I have had a supportcase before with MS that the ISA server did not ... they can reach the ports using web proxy. ...
    (microsoft.public.isa)
  • Re: Microsoft SBS 2000 Internet Permissions Problem
    ... The web site logon page is access via HTTPS port 85: ... If Microsoft Internet Explorer is configured to reference a server that is ... ISA Server 2000 Standard Edition, ...
    (microsoft.public.windows.server.sbs)
  • Re: Problem with ISA Server and autoconfig - manual works
    ... outbound HTTP, you'll control it on a per site basis, and use the deep ... Tom and Deb Shinder's Configuring ISA Server 2004 ... to 3128 - to make sure it was not listening on a port users would have ... they can reach the ports using web proxy. ...
    (microsoft.public.isa)
  • port forwarding (rerouting) with isa server.
    ... I have a question about port forwarding with isa server. ... external nic connected to the router and one internal nic ...
    (microsoft.public.isa)
  • Re: Trying to understand this behavior, Ports in IIS
    ... That tells me the ISA server was accepting the connections. ... assign port 8080. ... In the border router and in the PIX firewall (both devices are "in front of" ...
    (microsoft.public.inetserver.iis.security)