Unable to block domains using domain name set

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



am trying to block access to particular domains for secure nat clients.

I have a rule called "blocked web sites" and it is first in the list of
rules. It is set to deny all traffic from Internal network to particular
domain name set

(screen shot at http://img390.imageshack.us/img390/8273/isa8zn.jpg).

I have another rule called "Full access" next in the list to allow full
access from Internal network to External network.



Now if I go to my workstation and set ISA as proxy server in IE properties I
cannot get web access to domains from blocked list.

But if clear all setting in IE it will allow me to open web site from
blocked domain list.



I tried to monitor connections in ISA logging tab and I figured that if I
try to access blocked domain from workstation without proxy settings - ISA
will ignore "Blocked web sites" rule and will use "Full access" rule to
give this workstation access to Internet (screen shot
http://img145.imageshack.us/img145/773/isa23iz.jpg).



I can see some packets blocked by "Blocked web sites" rule, but these done
have any information in "URL" column and I am still successfully can open
any domain from blocked domains list.



How can I block access to particular domain without setting all my
workstations to use ISA as proxy and without installing Firewall clients on
all workstations?



.



Relevant Pages

  • Unable to block domains using domain name set
    ... I am trying to block access to particular domains for secure nat clients. ... Now if I go to my workstation and set ISA as proxy server in IE properties I ... I can see some packets blocked by "Blocked web sites" rule, ...
    (microsoft.public.isa.configuration)
  • RE: CEICW KEEPS GIVING ERRORS
    ... There are many articles and documents for ISA 2004 and SBS 2003. ... Troubleshooting Network Configuration in ISA Server 2004 ... How to configure Web publishing rules to host multiple Web sites with host ...
    (microsoft.public.windows.server.sbs)
  • RE: Access rule for Hotmail & Yahoo mail in ISA 2000 server
    ... I understand that you want Business office ... group only to access 3 web sites, but you get error page when logon yahoo ... As I know, the logon pages for yahoo mail and hotmail thru HTTPS, so I ... Please help to gather the ISA Info: ...
    (microsoft.public.windows.server.sbs)
  • RE: isa 2004 & external website access issue
    ... internal web sites are no longer accessible, ... Does each internal web server ... headers in ISA Server ... List' and click 'Connect to the internet' in the right panel. ...
    (microsoft.public.windows.server.sbs)
  • RE: Restrict group to two web sites.
    ... firewall client installed. ... rule to restrict a group of users who can not access two web sites. ... Destination: External (Exception: the URL Set that you want to the users to ... And input correct ISA server information here. ...
    (microsoft.public.windows.server.sbs)