RE: Unable to allow Internet Access from ISA Server Machine



Thanks for the info. I've got my ISA Server setup exactly this way. I would
love to be able to allow Basic Auth only on the Local Host and get it to work
for traffice from the ISA Server itself. It doesn't seem to be able to.
--
Sandy Wood
Orange County District Attorney


"Ash" wrote:

Maybe this can explain this.

http://www.microsoft.com/technet/isa/2004/plan/single_adapter.mspx#EGC

Configuring ISA Server with a Single Network Adapter
When you install ISA Server on a computer with a single network adapter, ISA
Server is only aware of two networks: the Local Host network that represents
the ISA Server computer itself, and the Internal network, which includes all
unicast Internet Protocol (IP) addresses that are not part of the Local Host
network. In this configuration, when an internal client browses the Internet,
ISA Server sees the source and destination addresses of the Web request as
belonging to the Internal network.

HTH

"Sandy Wood" wrote:

I've got an app on my ISA server (unihomed) that needs to access the web to
download database updates nightly. It requires Basic Authentication.

On our ISA 2004 SP3, we've got the Internal network configured with NT
Authentication only. The app we're using needs Basic but we don't want Basic
turned on for our Internal network.

I configured the Local Host network to enable Web Proxy client connections
to allow the ISA Server web access. I've configured authentication with Basic
only, Basic and NT and I cannot get out. The logs show two entries:

Denied Connection ISASERVER 5/25/2007 2:58:32 PM
Log type: Web Proxy (Forward)
Status: 12209 The ISA Server requires authorization to fulfill the request.
Access to the Web Proxy service is denied.
Rule:
Source: ( 172.23.4.34:0)
Destination: ( 172.23.4.34:80)
Request: POST http://ddsdom.websense.com/cgi-bin/nph-wsget20.exe
Filter information: Req ID: 123641ee
Protocol: http
User: anonymous


If I turn on Basic Authentication on the Internal Network, I get in, the
logs show:

Denied Connection ISASERVER 5/25/2007 2:58:32 PM
Log type: Web Proxy (Forward)
Status: 12209 The ISA Server requires authorization to fulfill the request.
Access to the Web Proxy service is denied.
Rule:
Source: ( 172.23.4.34:0)
Destination: ( 172.23.4.34:80)
Request: POST http://ddsdom.websense.com/cgi-bin/nph-wsget20.exe
Filter information: Req ID: 123641ee
Protocol: http
User: anonymous

Allowed Connection ISASERVER 5/25/2007 3:00:12 PM
Log type: Web Proxy (Forward)
Status: 200 OK
Rule: Default DA Access
Source: Local Host ( 172.23.4.34:0)
Destination: External ( 204.15.67.80:80)
Request: POST http://ddsdom.websense.com/cgi-bin/nph-wsget20.exe
Filter information: Req ID: 12364d25
Protocol: http
User: my.domain.com\my.loginname@xxxxxxxxxxxxxxxxx

Do I need to take the ISA Server out of the Internal network to make this
work? It seems like traffic from the ISA Server is always getting routed to
the Internal Network despite what I configure in the Local Host network.

--
Sandy Wood
Orange County District Attorney
.



Relevant Pages

  • Re: WMI remote access on ISA 2004
    ... When the ISA server has only 1 NIC, it can only act in cache mode. ... >> If you allow all access from internal Network to local host, ... >> Please create a rule to allow internal network to local host for RPC ... >> Microsoft Online Partner Support ...
    (microsoft.public.isa)
  • Re: Intermittent Firewall 15108 Events on SBS2003/ISA2004
    ... This newsgroup only focuses on SBS technical issues. ... of |> the internal network object). ... If the ISA server receives a package with an |> internal IP as source address from the external port, the package would be |> treated as a spoof attack. ... |> 825763 How to configure Internet access in Windows Small Business ...
    (microsoft.public.windows.server.sbs)
  • Re: Eventid 15108... spoof address ????
    ... This newsgroup only focuses on SBS technical issues. ... the ISA server identifies the spoof attacking according to ... |> the internal network object). ... |> server could receive some spoof attacks from the internet. ...
    (microsoft.public.windows.server.sbs)
  • VPN only permitted to local host not internal network
    ... network to connect using all outbound protocols to the internal network ... I can connect using remote desktop to the local host and ping its ... whether I Remote Desktop to the ISA server (local ...
    (microsoft.public.isa.vpn)
  • RE: Intermittent Firewall 15108 Events on SBS2003/ISA2004
    ... Thank you for posting in SBS newsgroup. ... the ISA server identifies the spoof attacking according to the ... the internal network object). ... 825763 How to configure Internet access in Windows Small Business Server ...
    (microsoft.public.windows.server.sbs)

Loading