How to Prevent Non Proxy Use of Web Browsers

Tech-Archive recommends: Speed Up your PC by fixing your registry



I'm configuring several network segments behind our ISA to use web proxy.
So far I like that and really like being able to use DNS names instead of
IPs in my firewall rules through use of DNS objects. What is required to
*force* all web browsing to go through web proxy and forbid direct browsing
without web proxy?

Right now our firewall rules for browsing are access rules that specify the
specific clients that are authorized out as the "From" and the specific DNS
names or IPs that are allowed in the "To" part of rule. Such a rule
appears to support both web proxy and direct HTTP access from the client.
Probably there is a different way to write this if you want to force use of
web proxy?

Some things about this web proxy do confuse me:

1) We have web proxy enabled on the ISA on port 8080. So how is it that
firewall rules that authorize HTTP (port 80) access and HTTPS (port 443)
access are working through a web proxy on port 8080. Is there some kind of
implicit cooperation of the firewall rules for http/https/ftp when web proxy
is enabled?

2) I am quite confused by the option in web proxy configuration to allow
HTTPS as a separate proxy, with a certificate supplied. If we do NOT
configure that option, is HTTPS access simply bypassing web proxy and
reverting to direct HTTPS access?

--
Will


.



Relevant Pages

  • Re: How to Prevent Non Proxy Use of Web Browsers
    ... IPs in my firewall rules through use of DNS objects. ... to *force* all web browsing to go through web proxy and forbid direct ... go through the ISA and somehow "not" use its services. ... Client or as a Firewall Client. ...
    (microsoft.public.isa)
  • Re: ISA web proxy slowdown
    ... DNS was flushed - no DNS issues that I can see. ... I understand the issue to be: Internet access is ... quite slow when IE is configured to use the ISA web proxy server. ...
    (microsoft.public.windows.server.sbs)
  • Re: ISA stops working...sorta
    ... card within RRAS cause DNS problem and/or causing web proxy problems? ... >> Tom and Deb Shinder's Configuring ISA Server 2004 ... Terminal services, DNS resolution, and ping work just fine. ...
    (microsoft.public.isa)
  • Re: Firewall Client disconnects?
    ... If you disabled the Web Proxy, ... To use "Automatically detect connection settings", ... We need to configure either on DHCP or on DNS for the WPAD record. ...
    (microsoft.public.windows.server.sbs)
  • Re: Internal Webpage
    ... Is the workstation's browser configured to use a web proxy? ... resolution should be handled by the web proxy server. ... I have flushed the DNS on that PC, ... > have even changed nic cards just incase the mac was a bad ...
    (microsoft.public.win2000.networking)