Firewall access rule on ISA2004 for web proxy

From: Jim H (nospam_at_jimsaccount.com)
Date: 02/04/05


Date: Fri, 4 Feb 2005 08:47:50 -0500

I need help getting the web proxy working for browsing the web.

I keep seeing entries in the log that connections to port 8080 are being
denied. The clients are internal workstations and the destination in the
internal IP of the ISA server.

I have an allow rule for all internal to internal for all outbound traffic
set for all users. Am I missing something?

Connections to port 8080 get denied by a rule further down in the rule list
that permits all outbound TCP traffic from all protected networks to
external and all networks for authenticated users only. shouldn't the
internal rule have allowed the connection on port 8080?

ISA server and workstations belong to the same domain. All users log in
with domain logins. All failed entries are client user anonymous. Do I
need to force the client browsers to authenticate? How do I do this?

I have the firewall client installed and the request will succeed on the
next attempt using port 80 and the authenticated user. I'm guessing this is
the firewall client working.

HTTP Status code
12209 The ISA Server requires authorization to fulfill the request. Access
to the Web Proxy service is denied.

Any help would be greatly appreciated.

jim



Relevant Pages

  • RE: [Full-Disclosure] A rather newbie question
    ... show a few different ports but port 60096 stands out. ... Common name: client-port on Red Hat Linux 9.0, Fedora Core 1, Red Hat ... Outgoing client connections from systems. ...
    (Full-Disclosure)
  • Re: Airport e Skype
    ... Common name: client-port on Red Hat Linux 9.0, Fedora Core 1, Red ... Outgoing client connections from systems. ... Port 32768 is the first port used by the operating system ...
    (it.comp.macintosh)
  • Re: Listening and Establish TCP connections on/from the same IP end po
    ... and accept client connections as well as be able to establish connections to ... The application needs to listen on a specific port because that's where the ... But it does not allow both sockets to actually _use_ that IP/port at the same time, nor would there be any reliable way to let that happen. ... Client ports are pretty much _never_ assigned according to protocol, and firewalls don't block inbound traffic based on the sender's port at all. ...
    (microsoft.public.dotnet.framework)
  • Re: ISA not authenticating....
    ... I created a protocol rule for tcp outbound 8080 named Web Proxy ... Connections and now the logs show up as Web Proxy Connections. ... > This is the client at 172.18.5.53 making connections to the web proxy ...
    (microsoft.public.isaserver)
  • Re: ISA not authenticating....
    ... I created a protocol rule for tcp outbound 8080 named Web Proxy ... Connections and now the logs show up as Web Proxy Connections. ... > This is the client at 172.18.5.53 making connections to the web proxy ...
    (microsoft.public.isa)