Jump to content

Recommended Posts

Posted (edited)

I have a site published now on port 2381, and it works fine from an external connecting computer. I now want the internal connecting computers to also get to the site via the same address. I have a DNS record set up in our DNS server pointing the web address at our TMG server which is doing the publishing/forwarding, and this works - so long as the clients don't have that TMG server set up as their web proxy.

 

If I set it up as their web proxy, it obviously then tries to act as a proxy - and ignores the publishing rule. Setting up exceptions in the proxy settings on the client, and tick the 'bypass for local addresses' works, but I don't want to have to do this!

 

How can I get TMG to not proxy that address?

Edited by localzuk
Posted
Is the server internal?

I would just put the internal ip as the dns entry rather then the external ip.

 

It is internal, yes. But without a per-client rule stating to bypass the server for it, it proxies it. I want the proxy server to simply return the same thing it does when an external person connects.

Posted
It is internal, yes. But without a per-client rule stating to bypass the server for it, it proxies it. I want the proxy server to simply return the same thing it does when an external person connects.

 

So does that mean you want it to route through TMG?

Can you make a rule saying from Internal->The site allow and put it above the general rule allowing users onto the net?

Posted
So does that mean you want it to route through TMG?

Can you make a rule saying from Internal->The site allow and put it above the general rule allowing users onto the net?

 

Doesn't seem to make a difference. The TMG box simply tries to proxy it via the upstream server, rather than just going direct to it.

 

Just checked the log and I'm getting the following:

 

Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 No Proxy portal.mineheadmiddle.somerset.sch.uk TCP

Req ID: 0a25bc74; Compression: client=No, server=No, compress rate=0% decompress rate=0% Internet 0x0 0x0 65101 Web Proxy - - - 0 1153 0 -

15/10/2010 14:20:40 0 0 0 0 - - - - - - - -

15/10/2010 15:20:40 10.5.142.20 10.5.143.180 2381 SSL-tunnel Failed Connection Attempt Inspected

12204 The specified Secure Sockets Layer (SSL) port is not allowed. Forefront TMG is not configured to allow SSL requests from this port. Most Web browsers use port 443 for SSL requests.

anonymous Internal

portal.mineheadmiddle.somerset.sch.uk:2381 SERVICES Unknown Web Proxy Filter 0 - -

 

So it just doesn't seem to like that it is HTTPS over port 2381. Any idea how to enable 2381 for SSL?

Posted

I've now added a rule using the ISA tunnel tool, and now receive the following:

 

Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Yes Proxy proxy.swgfl.org.uk TCP Req ID: 09240d98; Compression: client=No, server=No, compress rate=0% decompress rate=0% Upstream 0x0 0x102 1154 Web Proxy - - - 0 0 0 - 15/10/2010 15:03:37 0 0 0 0 - - - - - - - Web service down - portal.mineheadmiddle.somerset.sch.uk 15/10/2010 16:03:37 10.5.142.20 213.18.249.14 8080 SSL-tunnel Failed Connection Attempt Inspected Allow Web Access for All Users 995 The I/O operation has been aborted because of either a thread exit or an application request. anonymous Internal Internal portal.mineheadmiddle.somerset.sch.uk:2381 SERVICES Unknown Web Proxy Filter Allowed No Violation Detected 1 - -

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...