RE: Webrouting to a SQUID-proxy

From: Kristin Thomas [MSFT] (kthomas_at_online.microsoft.com)
Date: 03/18/04


Date: Thu, 18 Mar 2004 16:27:55 GMT

Greeting Oli,

You would only need to put the * in, not the // so *.blackwell-synergy.com
would be correct in the destination set.

You can route to a Squid server, but if it requires authentication you
would need to enter one account's credentials and password on the upstream
proxy server settings page, it cannot pass authentication from a user.
Because of this, I'm not sure you wouldn't need to make allow all rules for
your client machines otherwise authentication of a user to verify it had
rights to browse a site in ISA might not work with the Squid Server. I
assume since you are making sure no one goes to porn sites, you aren't
allowing all for your clients. This might cause the routing to the SQuid
server not to work. Please post back what rules you have for site and
content and protocol and I will try to figure out what will/will not work
for you.

Best Regards,

Kristin Thomas, MCSE, MCP
Microsoft Enterprise Network Support

Get Secure! - www.microsoft.com/security

=====================================================
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.

--------------------
From: "Oliver Stadler" <ostSPAMadler@bridspamge.de>
Subject: Webrouting to a SQUID-proxy
Date: Thu, 18 Mar 2004 08:10:13 +0100

Hello all,

I have the following problem: Here at our clinic we have a back-to-back
firewall system (both are ISA-servers).
On the outer ISA-server I have a webfilter software installed. All of our
clients in our internal networks have the firewall-client installed.

When accessing special sites (electronic magazines) we need to use a special
proxy-server (Squid), for all other sites we dont need another
upstream-proxy.
Normally we accomplish this by configuring our IE with an autoconfiguration
script (PAC).
Now this works fine, but when people try to access pornographic sites the
webfilter cant block the site because its "hidden" or masked within the
request to the Squid-proxyserver (and this renders the webfilter useless).
So I wanted to create a routing-rule on our outer ISA-server. Now here are
my special questions:

- When creating destination-sets for external computers (external servers),
do I have to enter the sites as:
"*.blackwell-synergy.com" or as "//*.blackwell-synergy.com" ?

- When creating a routing rule I can only use ISA or MS-Proxy-servers as
upstream-servers. How can I route all traffic for the above destination set
to a Squid-upstream-proxy?
(While searching a forum on isaserver.org for a possible answer to this I
found an answer stating: "The squid does not understand carp or
authentication, but you can make the downstream a SecureNAT client." -> Now
what exactly is meant by this?)

Thanks a LOT in advance for help on this subject,

Greetings from Germany,

Oli



Relevant Pages

  • Re: Kerberos machine authentication - apparent authentication fail
    ... > until logon), the wireless connection can kick off when it is ready. ... > was confirmed in the server event logs with IAS (i set that up as the radius ... > as an ordinary user kicks in and takes over from the machine authentication. ... > while the network sorts itself out and a double click on a network link of ...
    (microsoft.public.windows.server.security)
  • Re: Basic Authentication + IIS 5 + Windows 2000 + Frontpage 2002 = failure?
    ... SYSTEM account. ... In IIS I took the virtual server that I was testing, ... Authentication premise. ... From a website perspective, I ...
    (microsoft.public.inetserver.iis.security)
  • Need help configuring Wireless Connection profile
    ... I have an SBS 2003 server and a Server 2003 member server set up using RADIUS ... Windows authentication for all users,4129,LRG\ryanv,4149,Wireless WPA2 PEAP ... Certificate Services ...
    (microsoft.public.windowsxp.general)
  • Re: Remote Web Workplace Issues-Please help!
    ... Open the Server Management Console, ... client after Authentication" right. ... permissions, and Microsoft Windows user rights according to the KB 812614. ... Download the IIS Resource Kit tools from the following page: ...
    (microsoft.public.windows.server.sbs)
  • [REVS] NTLM HTTP Authentication is Insecure By Design
    ... in front of a web server, and that proxy server shares a single TCP ... These are attacks that make use of non-RFC HTTP requests (HTTP Request ... the authentication is associated with the ...
    (Securiteam)