Re: ISA/Proxy problem

From: Chad A. Gross [SBS MVP] (chad.gross_at_laytonflower.nospam.com)
Date: 12/17/04


Date: Fri, 17 Dec 2004 13:22:11 -0600

I'll have to double check - but I don't think you need to remove browser
proxy settings. Matter of fact, I'm sure that you don't. I'm thinking it
may be as much of the HTTP Redirector's fault as Ad-Aware's. I know I've
seen documentation stating that the redirector can't pass credentials to the
proxy service - so if your proxy service requires outbound authentication
(separate from your protocol rules), then apps like this will fail because
the credentials originally supplied by the Firewall Client are submitted to
the HTTP Redirector, which fails to forward those credentials to the Web
Proxy Service.

-- 
Chad A. Gross - SBS MVP
SBS ROCKS!
www.msmvps.com/cgross
www.gosbs.org
Phillip Windell wrote:
> "SuperGumby [SBS MVP]" <not@your.nellie> wrote in message
> news:ODtNPw64EHA.2568@TK2MSFTNGP11.phx.gbl...
>> I have not adjusted the default behaviour of the HTTP redirector.
>
> The Protocol rule they suggest is an "anonymous" rule, as indicated
> by the "Any Request".   This allows it to work because Ad-Aware's
> problem in the first place is its inability to properly pass the
> credentials to the Web Proxy Service in the proper manner.   The
> suggested Rule causes ISA to not ask for credentials when going to
> Lavasoft's URLs,...hence it works.
>
> If someone is not willing to use Anonymous Rules, then they must
> adjust the Redirector to not send to the Web Proxy Service, remove
> the Browser's Proxy Settings and run the Clients as Firewall Clients
> only. SecureNAT doesn't authenticate and is effectively anonymous so
> isn't a viable solution if authentication is required by company
> policy.
>
> In the end, it is a lot of "crap" to go through for just one stupid
> application because some programmer didn't write their code properly.
>
> Other products will have similar problems if they use FTP to transfer
> the update using FTP methods that aren't compatible with the
> "encapsulated read-only FTP" that is used by the CERN web proxy
> standard.  In those cases the client has to run as a Firewall Client
> or SecureNAT client to be able run standard FTP.
>
> Even the newset version of Windows Update doesn't work properly with
> their own ISA, and I believe again it is an authentication issue (but
> a different type).  I suspect it is because one division of a large
> company did not collaborate properly with another division in the
> same large company so that their production methods agreed with each
> other.
>
> Here is their article on that. You will notice that their solution is
> to create an "anonymous" rule as did Lavasoft. In this case, with one
> of the two scenarios, they seem to want to blame Internet Explorer
> and have a patch for it.  In the other scenario they say the root
> cause is still being investigated.
>
> You experience problems when you access the Windows Update Version 5
> Web site through a server that is running ISA Server
> http://support.microsoft.com/default.aspx?scid=kb;en-us;885819 


Relevant Pages

  • RE: ISA Not allowing clients to browse
    ... The clients are using the firewall client and have proxy set to myserver ... I have one protocal rule that allows everyone everything. ... > Microsoft Online Partner Support ...
    (microsoft.public.windows.server.sbs)
  • Re: Laptops with ISA Client installed - how do users out on the road operate?
    ... computers have the firewall client installed and running, ... the WPAD entry in DNS to advertise the proxy. ... You may have configured WPAD on the DNS and DHCP (you did do the DHCP part ... blank and not filled in,...and really only the first checkbox is required. ...
    (microsoft.public.isa.configuration)
  • Re: SBS 2003 ISA proxy for FTP fails
    ... Because that is the way ISA works;-) Install the Firewall Client on the ... workstations and set the proxy to your server and port 8080. ... > Why is the firewall client required for FTP proxy access via SBS's ISA? ...
    (microsoft.public.isa)
  • Re: SBS 2003 ISA proxy for FTP fails
    ... Because that is the way ISA works;-) Install the Firewall Client on the ... workstations and set the proxy to your server and port 8080. ... > Why is the firewall client required for FTP proxy access via SBS's ISA? ...
    (microsoft.public.windows.server.sbs)
  • Re: Web Proxy client vs. Firewall client for web access
    ... I ended up putting the domain names in the Proxy Settings ... Exceptions box so the web sites that I manage that are on Windows Servers ... Windows XP Pro SP2 + ISA Firewall Client ... Scenario #1: ...
    (microsoft.public.windows.server.sbs)