pantscat Posted November 21, 2008 Posted November 21, 2008 Hi All, I'm having a friday moment. My brain is winding down ready for the weekend... Currently we have ISA 2006 setup as firewall and proxy (two NICs, one internal and one straight out to the 'net). We have an access rule that currently allows the 'internal' network to get HTTP access to the 'external' network. At present if a PC is configured with the ISA box as its default gateway it will happily get out to the internet without any proxy settings. I want this to stop. Obvious answer is to remove the D/G from DHCP - but surely there must be a way to allow only proxy requests out to the internet? I've tried changing the access rule to remove 'internal' and replace it with 'local host' but this doesn't work. I'm sure I'm missing something really obvious... but I can't figure it out! Any suggestions would be gratefully received... Ta, Ant
leegcvcc Posted November 21, 2008 Posted November 21, 2008 Hi, Where is your router then? Is the ISa server acting as a router? I assume you have the clients proxy server settings in IE set to your ISA server and the users cannot change the proxy settings? If not I would do that firstly. If you could elaborate a bit more on your setup it would be useful to sugest a solution. Cheers
tom_newton Posted November 21, 2008 Posted November 21, 2008 Hi All, We have an access rule that currently allows the 'internal' network to get HTTP access to the 'external' network. Ant Does this rule specifically allow only this (ie port 80 only) or is it a general NAT rule? Unfortunately, our copy of ISA is currently kaput, so I have no test net to play with (not that I am much cop at ISA.. RobF is the man for that!)
tom_newton Posted November 21, 2008 Posted November 21, 2008 If you have a web access rule like the one described here: Configuring ISA Server 2006 Firewall Rules you might edit it and rein in the "Internal" part to just IPs of your proxy.
pantscat Posted November 21, 2008 Author Posted November 21, 2008 @leegcvcc - Yep proxy settings are set by GPO - but teachers occasionally bring in their own devices and like to hop on our wifi now and again. Yes the ISA box is acting as the router too. @Tom - at the moment the rule allows all outgoing protocols, but I'm going to restrict it to just port 80 and 443 traffic. Your suggestion to edit the 'internal set' gives me an idea... I could create a custom 'network set' that only contains the IP of the proxy... it might work. Hmm... <\strokes chin>
bio Posted November 24, 2008 Posted November 24, 2008 You should configure your rule to use authenticated users and not All users. This way only active directory users will be able to use the internet. Also you could segment your network by placing the isa internal nic on a seperate subnet. configure routing on your core switch. This way the internal client have a different ip as default gateway. Now you can use a GPO to configure the clients as proxy clients. bio..
pantscat Posted November 24, 2008 Author Posted November 24, 2008 Have changed the firewall rule so that only the proxy is allowed through but I still get a 502 error from a proxying client. Very odd...
tom_newton Posted November 24, 2008 Posted November 24, 2008 Your proxy definitely has the ISA box set as its gateway? Which proxy are you using right now? Might be able to point out some troubleshooting tools if I know the proxy.
tom_newton Posted November 24, 2008 Posted November 24, 2008 can the ISA server itself still browse the web? Are there also rules for who may access the proxy?
pantscat Posted November 24, 2008 Author Posted November 24, 2008 The ISA server itself can still browse the web... That's interesting... there aren't any specific access rules for who can access the proxy. What type of rule would be required for that?
tom_newton Posted November 24, 2008 Posted November 24, 2008 ***invoke*** (I've just summoned RobF... he's better at ISA than me) 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now