ADFS, ISA and SSL offloading

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



I have an ADFS enabled web server configured behind ISA Server 2006. The web
agent is configured to communicate with a resource federation server which is
hosted elsewhere.

All communications work without issues for SSL i.e the client gets
authenticated with the account partner and gets access to the protected
resource on the web server.

Things go wrong when I change the configuration slightly i.e instead of SSL
traffic from ISA to the web server I offload SSL on ISA and make it plain
http. With this configuration, authentication with the account partner works
fine but the redirection from the resource federation server back to the web
site fails. ISA server log indicates that it is trying to resolve the web
site url with external ip of the web site configured in the web publishing
rule on ISA in combination with the internal web site port.

For example, if the external ip for the published web site is 10.32.181.1 on
port 80 and the internal ip for the web site is 172.20.1.1 on port 81, ISA
tries to resolved it as 10.32.181.1:81 and fails with the message
unidentified ip traffic : 81. Whereas, everything works fine if SSL
offloading is not performed.

Can someone help me in understanding what's happening and how to fix it? I
really want to offload SSL on the firewall and have only http requests
hitting the webserver.
.



Relevant Pages

  • RE: SBS 2003 SP1 Upgrade - MSDE 2000 Service Pack 4 did not instal
    ... C:\Program Files\Microsoft SQL Server ... you can directly insert the ISA 2004 installation CD ... import the ISA configuration information to restore back all configurations. ... following registry subkey on the server, ...
    (microsoft.public.windows.server.sbs)
  • RE: Website Not loading
    ... Is the web site: http://xyz.com is your default web site? ... what you input as the web server certificate? ... please help me gather the ISA Web Proxy and Firewall ... PLEASE NOTE the newsgroup SECURE CODE and PASSWORD will be updated at 9:00 ...
    (microsoft.public.windows.server.sbs)
  • RE: CEICW KEEPS GIVING ERRORS
    ... For you have installed ISA 2004 on ... the SBS server box, the default web site should listen on the internal IP ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: Help Please - no access to Web Sites
    ... > internet web sites using IE after installed Cisco VPN client on the server ... > files and ISA cache to see if ... Can you access internal web site such as Companyweb site, ... Try to access internet web site. ...
    (microsoft.public.windows.server.sbs)
  • RE: Getting rid of a rogue SSl certificate
    ... > Please follow the steps below to check the certificate on ISA. ... > server name, select prop. ... network, firewall, secure Web site, and e-mail. ...
    (microsoft.public.windows.server.sbs)