Re: ISA2004 issues (pretty detailed description and therefore much reading :)



"A. Klimkin" <aklimkin at mail dot ru> wrote in message
news:uvB13Ky9FHA.1020@xxxxxxxxxxxxxxxxxxxxxxx
> Hello everybody.
>
> I'm facing a trouble I can't resolve by myself, so I try to ask the gurus.
> Here we go.
>
> My configuration:
> I have an ISA2004SP1 installed and configured on Win2003SrvSP1 machine
> within AD environment (member server).
> Effective access policy allows some sites to be hit anonymously (namely,
> there are windowsupdate sites) and the rest of the web requires user
> identification via integrated authentification against AD.
> All the users are configured to be web proxy clients of the ISA server and
> to autodetect proxy settings. Local DNS server configured to return my ISA
> server address in response to WPAD entry queries. ISA server is configured
> to publish autodiscovery information on sandard port 80.

Very good explanation so far. I wish all people posting here would give such
detailed descriptions of their environment.

> My first question:
> Is there a way to force IE browser to redetect its proxy settings?

Yes and you already found it - you need to tick/untick the "Autodetect Proxy
Settings" checkbox. That is the only way you can force it. Not the most
convenient way I know but read on for a workaround.

> I've heard that this should happen every time you restart browser. But it
> seems to not happen.

No it's not supposed to work that way. The purpose of the proxy cache in IE
(which btw was introduced in v5.5 AFAIK) is to serve the 'usual' network
environment for which the proxy settings hardly ever change. Of course there
would be very little caching benefits if the re-detection occured every time
the browser was restarted.

However, in a network environment where there's lots of changes (like for
example during a major systems upgrade) this caching feature can become an
annoyance. Fortunately it can be turned off completely by means of a
registry setting. See the following article for details:
http://support.microsoft.com/?kbid=271361

> Proxy redetection seems to not happen even if I restart the computer. The
> only thing that helps is to go to IE connections settings, unticle
> 'autodetect' option, restart the browser and then check the 'autodetect'
> option on again. It's pretty boring procedure to configure this way every
> given client computer of a list of two hundreds comps, you know.

Of course. You can configure the registry settings mentioned above on all
the computers in the domain by means of a GPO. Next time IE is started on
any of those computers, it will not cache the proxy settings anymore.

> And the second issue.

<snip>

> Initially, IE (as usual) tries the destination anonymously, then, being
> asked for identification, passes the credentials and ISA allows the
> connection (as we can see). But the page won't be displayed with above
> mentioned HTTP 404 error. Is there a problem with ISA or IE? Or maybe
> both?
> Please bear in mind that there is public free web service, so I don't see
> much sense to bother their support with this issue, taking into account
> the fact that the service works just fine when you directly accessing it
> (without authenticating proxy).

Can you please create a rule allowing anonymous access to those sites, then
post the results here? I'm curious whether it works when authentication is
not required.

Virgil


.



Relevant Pages

  • Re: ISA 2004 & companyweb
    ... Server, the traffic will still be handled by the ISA Server because the ... "Bypass proxy server for local addresses" option is disabled, ...
    (microsoft.public.windows.server.sbs)
  • Re: ISA server 2004 and Bluecoat proxy
    ... i want to mention that we have configured a backup rout (backup bluecoat ... i want to ask about event 14130 that related to web proxy chain fauilire. ... If you were able to work around the upstream proxy server, ... upstream ISA Server, you might want to change it back. ...
    (microsoft.public.isa.configuration)
  • RE: Proxy Server in SBS 2000
    ... sites through port 443. ... If you install ISA 2000 on the SBS 2000 server, ... Connections->LAN Settings, tick the Use proxy server for your LAN, and then ... Is ISA 2000 installed on the SBS Server? ...
    (microsoft.public.windows.server.sbs)
  • Poor client web browsing performance
    ... I've switched all our users from an old proxy 2.0 server to ISA 2004, ... That DNS server is configured with the ISA server's internal NIC ... The first firewall policy rule is called "unrestricted internet ...
    (microsoft.public.isa.configuration)
  • Re: Need help with ISA setup.
    ... Key in your SBS (ISA) Server's NetBIOS name and port 8080 in the Proxy Settings boxes. ... Click the Action tab and choose Routing them to a specified upstream server. ... Point the default gateway to the ISA Server and the clients will be a SecureNAT client. ...
    (microsoft.public.windows.server.sbs)