Internet Related/Filtering/Firewall Thread, Using TMG Server as a Transparent Proxy in Technical; Hi,
We're also trying to setup TMG as a transparent proxy however we're having problems with HTTPS traffic. We also ...
-
31st January 2012, 02:02 PM #16
- Rep Power
- 0
Hi,
We're also trying to setup TMG as a transparent proxy however we're having problems with HTTPS traffic. We also have a squid based RM proxy (SEGfL) and have specified it as an upstream proxy for external connections (proxy.segfl.ifl.net). We've purchased IsaScript and entered the script recommended in the previous post which seems to be working properly with HTTP traffic but we get timeouts when trying anything HTTPS.
For the upstream proxy we've tried the default of 8443 for SSL and also changed it to 8080 but it doesn't seem to make any difference. We've also set TMG to route the traffic from our WiFi network to the External connection but this hasn't had any effect either. Is there anything else we may need to change to get this working?
Any ideas anyone?
Cheers
-
-
IDG Tech News
-
8th February 2012, 02:52 PM #17
- Rep Power
- 10
I'm also trying to setup a transparent proxy with seperate VLAN network & IP range on an open SSID, when i direct the default gateway via DHCP to the forefront TMG server i get this on on an open client device:
IMG_0004[1].PNG
We're using ubiquiti unifi APs and the physical server running the controller software has two network cards 10.11.216.1 (open) and 10.11.227.14 (secure) - its also my DHCP server for the open network of which the gateway is set to 10.11.216.2 that is the third network card i setup in my TMG server, should I at least be getting http traffic with this setup?
-
-
8th February 2012, 02:55 PM #18 
Originally Posted by
jwood
Strange - still not working here. Again, it works if you enter the TMG server as the client's proxy but not without. I'll keep experimenting though.
I can't remember where I read it, but I saw somewhere that TMG doesn't work as a Transparent proxy with web chaining is the upstream proxy is running squid. I'm assuming your on SWGfL who use squid.
-
-
8th February 2012, 02:57 PM #19
- Rep Power
- 0
Have you setup a rule to NAT the traffic from the seperate VLAN to your external connection?
-
-
8th February 2012, 03:08 PM #20
- Rep Power
- 10
yes the source network is "sjwifi" and set to route relation
Capture6.PNG
-
-
23rd February 2012, 03:28 PM #21
- Rep Power
- 0
We have a similar problem with TMG acting as a transparent proxy for our guest wifi. We have a direct Internet connection so don't have any of the upstream issues that some are facing but still have an issue with SecureNAT clients accessing secure websites. http works fine. I wonder if Jamesfed or Jwood or anyone else who has this sorted are able to offer any assistance on this? We're beginning to think that we will have to require clients to enter proxy settings which as far as I can see would mean that Android users wouldn't be able to use the wifi.
Many thanks,
Richard
-
-
23rd February 2012, 10:17 PM #22 Sorry I only have experiance with the problems that Squid gave us - maybe it would be worth getting a trial of ISA Script and seeing if the script thats in a link in my previous posts will work?
All the same over the past few months we've noticed a decline in the number of Droid users with phones that don't support proxys so I can imagine within the next 6months-1 year we will be rid of this problem anyway.
-
-
24th February 2012, 04:18 PM #23
- Rep Power
- 0
Thanks for responding. I will have a look at the script and see if that helps. We are already using some software called captivate by the same company to get the SecureNAT clients to authenticate before they access the Internet.
I had a look at what devices were using the guest network and only about 13% were running Android. My understanding is that it's only Ice Cream Sandwich that supports proxy settings on Android or have you found that earlier versions allow users to put in Proxy info?
Cheers.
-
SHARE:
Similar Threads
-
By FN-GM in forum Networks
Replies: 30
Last Post: 25th February 2008, 05:33 PM
-
By Midget in forum Hardware
Replies: 6
Last Post: 16th February 2007, 04:15 PM
-
By SimpleSi in forum *nix
Replies: 9
Last Post: 22nd September 2006, 04:51 PM
-
By Geoff in forum How do you do....it?
Replies: 8
Last Post: 11th April 2006, 01:57 PM
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules