Jump to content

Recommended Posts

Posted

Hi

 

I am not to hot on this subject but is it possible to make ISA a transparent proxy? If so how is it done please?

 

I have googled abit cannot find much, what i have found has gone over my head.

 

cheers

 

Z

Posted

Ok if that can’t be done what can I do so you don’t have to make any configuration on client machines? IE not having to put the proxy address in internet explorer etc.

 

Thanks

Posted
Ok if that can’t be done what can I do so you don’t have to make any configuration on client machines? IE not having to put the proxy address in internet explorer etc.

 

Thanks

Just out of interest what is wrong with having to do that?

Posted

Thats a point really Edu-IT, I supose if it is only on a few machines then it could be no problem putting in the proxy. but if its on a wide range of client machines then supose it could be a bit of a hassel.

 

Regards

 

James

Posted
Thats a point really Edu-IT, I supose if it is only on a few machines then it could be no problem putting in the proxy. but if its on a wide range of client machines then supose it could be a bit of a hassel.

 

Regards

 

James

You can use policies to apply proxy settings.

Posted
You can use policies to apply proxy settings.

 

I was just about to edit my post saying that lol, but i got an email saying what you put before i pressed Submit hehe, :p

 

regards

 

James

Posted (edited)

Policies work well and generally in most cases are adequate.

 

Other than that setting up a WPAD file on your network will point any client connected to the proxy server you would like. Google WPAD your find information on setting this up.

 

This site might be a starting point:

 

http://www.isaserver.org/tutorials/Configuring-WPAD-Support-ISA-Firewall-Web-Proxy-Firewall-Clients.html

Edited by plock
URL addition
Posted

Well we are a domain in a multiple forest, so users can logon our machines from another domain. But on some of these other domains there IP range is filtered by the LEA. They will not have any proxy server address typed in. so they could possibly get unfiltered internet. WPAD we cannot use either because guest laptops might not have automatically find the proxy server check box ticked. Also we cannot put policies on there computers. We can’t set the firewall so it will only accept traffic that has been through out proxy because other users from other domains will have there proxy server onsite and will want there users to go through there proxy. We do set our users to go through the proxy server in GPO.

 

I will attach a diagram soon.

Posted
My understanding is if the client browser doesn't have any Proxy Server defined then regardless of 'Automatically detect...' being ticked it'll use the WPAD?
Posted

Without a proxy server in the configuration it will first hit the default gateway on the highest priority active network adapter and see if it can get the pages directly otherwise if it is set to automatically detect it will look for a proxy.

 

You can setup ISA as a transparent firewall that should run your traffic through filtering but I have not set it up transparently with a proxy. To enable it as a transparent firewall just add a rule that allows HTTP/HTTPs access from the internal network to the external network. You must have it as the default gateway of either the workstations that are trying to connect to it or as the default gateway in your top level router so that any traffic that cannot be serviced locally is sent to the ISA server for routing.

Posted
By default, any client that uses ISA as its gateway will act as a 'Secure-NAT' client so any URLs that you block will not be accessible from those clients. However, this will not forward to an upstream proxy.
Posted (edited)

Thanks for the comments guys

 

My understanding is if the client browser doesn't have any Proxy Server defined then regardless of 'Automatically detect...' being ticked it'll use the WPAD?

 

I was told it does need to be checked, can anyone confirm if it does or doesn't please?

 

By default, any client that uses ISA as its gateway will act as a 'Secure-NAT' client so any URLs that you block will not be accessible from those clients. However, this will not forward to an upstream proxy.

 

So does that mean if i set the clients to use the proxy as the default gateway traffic will pass through it?

 

Thanks

 

Z

Edited by FN-Greatermanchester
Posted
Without a proxy server in the configuration it will first hit the default gateway on the highest priority active network adapter and see if it can get the pages directly otherwise if it is set to automatically detect it will look for a proxy.

 

According to this then for the WPAD to take effect 'Automatically detect...' would need to be ticked.

 

If it isn't then it's using the default gateway rather than the WPAD which I had thought was the case.

Posted

So does that mean if i set the clients to use the proxy as the default gateway traffic will pass through it?

 

Yes... unless of course ISA isn't set up in firewall mode.

  • Thanks 1
Posted
Thanks for the comments guys

 

 

 

I was told it does need to be checked, can anyone confirm if it does or doesn't please?

 

 

 

So does that mean if i set the clients to use the proxy as the default gateway traffic will pass through it?

 

Thanks

 

Z

 

 

It only needs to be checked if you are using an automatic proxy configuration file on your network otherwise it just slows the initial connection to the web down.

 

As Ric says so long as it is in firewall mode (has the rules that I talked about eairlier) it will allow the clients to access the web.

Posted

@psydii Yes this method will work with any browser on the network with no configuration as it is not seen as a proxy but just as the default path for internet traffic.

 

@FN-Greatermanchester Is the router in the diagram your own locally managed one or the LEA one and are you subnetted inside your school.

 

If you are not subnetted inside your school simply changing the Default gateway provided by DHCP to your ISA Box should ensure that they are all filtered. If your LEA proxy can be accessed transparently you could chain to that by setting the default gateway address on your ISA box to the LEA Proxy.

 

If you are divided into more than one subnet inside your school then it becomes a little more complicated as you must change the routing configuration to put your ISA box as the default gateway for your networks to access the outside world and a separate rule for your ISA server to allow it to send its outbound traffic via the LEA.

Posted

Hi

 

That is our router, and we are over 5 subnets. We only use 3 though. 2 For DHCP machines and the other one for Servers. Hopefully i can get someone from the LEA to come and set it all up for us :D

 

Cheers

 

Z

  • 2 weeks later...
Posted

Hi guys

 

Well, I now point the default gateway to the ISA server. Works fine. One more snag is that the proxy settings must be set to have a connection to the internet. How would I configure ISA so I do not need to configure the proxy settings on the client machines? Thanks.

Posted
Hi guys

 

Well, I now point the default gateway to the ISA server. Works fine. One more snag is that the proxy settings must be set to have a connection to the internet. How would I configure ISA so I do not need to configure the proxy settings on the client machines? Thanks.

 

So long as you have set up a rule allowing all HTTP/HTTPS traffic from the internal network to the external + internal networks in the firewall policy you will not need any proxy settings.

 

This is because their browser will look up the site via DNS, resolve it to an external IP address and then will send the request to the default gatewat (your ISA) as it is the only way that it knows of to get to the outside address. Your ISA server will see that it is HTTP from the internal network headed out to the external network and handle the rest for you.

Posted
allowing all HTTP/HTTPS

 

We are running ISA 2000, please can you give me a clue of where to look and what i am looking for please?

 

Thanks

Posted
We are running ISA 2000, please can you give me a clue of where to look and what i am looking for please?

 

Thanks

 

Sorry FN its been that long since I have used ISA 2k that I can't recall the way that it is layed out. I'd have to dig out a copy of it and have a look. If you could post some screen shots of the ISA managment console with the options tree down the left hand side expanded I'm pretty sure that I can still point you in the right direction.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...