sultan966 Posted November 21, 2012 Posted November 21, 2012 We access internet through LA proxy. We configure client browser settings via gpo. I need to setup a ISA server with only one objective: -Client Browsers will not require any proxy settings (Only for a separate network - Test Network : Address range 192.168.1.0/24). Configuration of isa server (so far): Internal network card address: 192.168.1.1/24 External network card address: 172.18.1.1/24 Web chaining rule: Forwards all traffic to LA proxy Firewall Policy: Access rule configured to allow traffic from internal to external network. In the node Configuration --Networks --Internal -->Properties there are 6 tabs. Two of them are: Firewall Client, Web Proxy. With this setup I have not achieved my objective. I still need to configure proxy settings in client browser to access internet. If I take out the proxy settings from the browser then client can not access internet. Proxy settings in browser is 192.168.1.1 port 8080. I am not sure if this is possible at all. If anybody has ever done it please let me know.
chazzy2501 Posted November 21, 2012 Posted November 21, 2012 you can automatically populate the proxy settings by creating a wpad file. Otherwise you'll need to create an intercepting proxy.
sultan966 Posted November 21, 2012 Author Posted November 21, 2012 WPAD will not work in my environment. Client browsers do not support proxy at all. How to make intercepting proxy ?
sultan966 Posted November 23, 2012 Author Posted November 23, 2012 I have installed CentOS and then SQUID. Configured SQUID as transparent proxy. Turned on routing on CentOS. Used iptables command to redirect all http traffic to SQUID. Configured SQUID to contact the LEA proxy. It is working now. No configuration is required on client browsers.
Bruce123 Posted December 2, 2012 Posted December 2, 2012 (edited) I can confirm that what you're trying to do is possible with ISA 2006. It can be configured to permit web client access at both via layer 7 (proxy) and layer 3/4 (routed - no proxy required) concurrently. For the latter, have you installed the ISA firewall client onto the PCs that require direct (layer 3/4) access? Not strictly necessary in some configuations, but it helps. The firewall client .EXE is stored on the ISA server somewhere, or can be downloaded from MS website. It's been a while since I have done this, but you may also need to add a NAT routing rule from Test Range to External. I notice that your test IP range is the same network as your ISA Server, is this really what you intended? Thanks, Bruce. Edited December 2, 2012 by Bruce123
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now