• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Direct not working with WPAD and IP

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 Firewall] >> Firewall Client >> Direct not working with WPAD and IP Page: [1]
Login
Message << Older Topic   Newer Topic >>
Direct not working with WPAD and IP - 16.Jan.2006 6:59:25 PM   
LLigetfa

 

Posts: 2187
Joined: 10.Aug.2004
From: fort frances.on.ca
Status: offline
I have WPAD DHCP 252 setup and working fine.  The FWC detects ISA.  I also have the FWC set IE to "Use automatic configuration script" and this is where it is letting me down.  It does not allow me to manage exceptions at the client and exceptions at the server are not working for me.

My ISA internal NIC is in the 10.198.0.0 subnet which is defined in ISA as Internal.  On this Internal network, I also have the IP range 192.168.0.0 - 192.168.255.255 defined.  I have several internal 192.168.y.z subnets as network-behind-network and do not want ISA to get involved but yet if I try to access anything using the IP in the URL, ISA is intercepting it.

This particular 192. network sits behind a CheckPoint firewall and does not have a route through ISA.  While we do NAT many of the 192 numbers into our 10 scope, there are a couple or servers we don't NAT and want to access direct.  One in particular is our eSafe server that we use a non-standard port for SLL.  I don't want to put in an 'A' record in our DNS.  Why will ISA not play nice if I use the IP?

_____________________________

The School of Hard Knocks is a mean teacher. She gives the exam before the lesson.
Post #: 1
RE: Direct not working with WPAD and IP - 16.Jan.2006 8:25:40 PM   
spouseele

 

Posts: 12830
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Les,

why are exceptions defined on ISA not working for you?

Stefaan

(in reply to LLigetfa)
Post #: 2
RE: Direct not working with WPAD and IP - 16.Jan.2006 8:46:26 PM   
LLigetfa

 

Posts: 2187
Joined: 10.Aug.2004
From: fort frances.on.ca
Status: offline
quote:

ORIGINAL: spouseele
why are exceptions defined on ISA not working for you?


If I had the answer to your question, I would be asking different questions. :(
If I were half as smart as I think I am, I might even answer my own questions.

Exceptions based on domain are working and the default 10. network is excepted.

Care to grace me with your wisdom?

_____________________________

The School of Hard Knocks is a mean teacher. She gives the exam before the lesson.

(in reply to spouseele)
Post #: 3
RE: Direct not working with WPAD and IP - 16.Jan.2006 10:02:31 PM   
LLigetfa

 

Posts: 2187
Joined: 10.Aug.2004
From: fort frances.on.ca
Status: offline
quote:

why are exceptions defined on ISA not working for you?

I guess I do have the answer for you and I might even answer my own question.

On the Internal properties, Web Browser tab, I added today, the IP range 192.168.0.0 - 192.168.255.255 and then refreshed the FWC and did not get the expected result.  Being the impatient person I am, I then posted here.  I guess if I had waited long enough, I would not have wasted time posting since it works now.

I read on this forum that the FWC settings are refreshed at the client when you click "Detect Now" or "Test Server".  Well... somebody lied... I clicked both of them many many times to no avail.  I even clicked on "Configure Now" so much my mouse button is now shiny.

Hours later, my user for whom I was doing this change called to say I fixed it.  I guess the FWC has an attitude and simply cannot be rushed.

Thanks

_____________________________

The School of Hard Knocks is a mean teacher. She gives the exam before the lesson.

(in reply to LLigetfa)
Post #: 4
RE: Direct not working with WPAD and IP - 16.Jan.2006 11:33:52 PM   
spouseele

 

Posts: 12830
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Les,

quote:

On the Internal properties, Web Browser tab, I added today, the IP range 192.168.0.0 - 192.168.255.255 and then refreshed the FWC and did not get the expected result. 

A refresh of the FWC will not help to update the Web Browser settings.

As written in http://www.isaserver.org/articles/ISA2004_ClientAutoConfig.html about the wpad.dat or array.dll?Get.Routing.Script:

quote:

If you look at the HTTP headers in the HTTP response, you will see a parameter Cache-Control as highlighted in the figure above. The value of this parameter is max-age=3000 what means that the downloaded wpad.dat file has a time-to-live of 50 minutes in the Internet Explorer cache. After that time the cached wpad.dat file is no longer valid and will be flushed from the Internet Explorer cache. You can monitor the content of the Internet Explorer cache at the location C:\Documents and Settings\<user>\Local Settings\Temporary Internet Files.


HTH,
Stefaan

(in reply to LLigetfa)
Post #: 5
RE: Direct not working with WPAD and IP - 17.Jan.2006 2:52:39 PM   
LLigetfa

 

Posts: 2187
Joined: 10.Aug.2004
From: fort frances.on.ca
Status: offline
I have read that article several times but somehow never connected those words to my situation.  On an interesting side note... In looking at my wpad.dat file, I notice that if I populate the domains exceptions in the Web Browser tab, I get them doubled up from the Domains tab into wpad.  So why then do the IPs not get picked up from the Addresses tab?
//Copyright (c) 1997-2004 Microsoft Corporation
BackupRoute="DIRECT";
UseDirectForLocal=true;
function MakeIPs(){
this[0]="10.0.0.0";
this[1]="255.0.0.0";
this[2]="192.168.0.0";
this[3]="255.255.0.0";
}
DirectIPs=new MakeIPs();
cDirectIPs=4;
function MakeNames(){
this[0]="*.cacc.local";
this[1]="*.abitibiconsolidated.com";
this[2]="*.abicon.com";
this[3]="*.localhost";
this[4]="*.cacc.local";
this[5]="*.abicon.com";
this[6]="*.abitibiconsolidated.com";
}
DirectNames=new MakeNames();
cDirectNames=7;
... 


Dare I call it a bug or a *feature*?

_____________________________

The School of Hard Knocks is a mean teacher. She gives the exam before the lesson.

(in reply to spouseele)
Post #: 6
RE: Direct not working with WPAD and IP - 17.Jan.2006 7:07:25 PM   
LLigetfa

 

Posts: 2187
Joined: 10.Aug.2004
From: fort frances.on.ca
Status: offline
Hmmm...
I thought I could at least get a response from Clint by using the *bug* word.

Not much of a fight if nobody punches back.

_____________________________

The School of Hard Knocks is a mean teacher. She gives the exam before the lesson.

(in reply to LLigetfa)
Post #: 7
RE: Direct not working with WPAD and IP - 17.Jan.2006 8:22:47 PM   
spouseele

 

Posts: 12830
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Les,

in the wpad.dat file you should find all the entries you have specified in the domain tab plus all the entries you have specified in the Web Browser tab. If there are double entries then you have configured that yourself. Therefore, I consider it a feature!

HTH,
Stefaan 

(in reply to LLigetfa)
Post #: 8
RE: Direct not working with WPAD and IP - 17.Jan.2006 8:32:43 PM   
LLigetfa

 

Posts: 2187
Joined: 10.Aug.2004
From: fort frances.on.ca
Status: offline
OK, that I can accept as a *feature* but...
quote:

So why then do the IPs not get picked up from the Addresses tab?

Is that too a *feature* in reverse or a bug?

_____________________________

The School of Hard Knocks is a mean teacher. She gives the exam before the lesson.

(in reply to spouseele)
Post #: 9
RE: Direct not working with WPAD and IP - 17.Jan.2006 8:56:06 PM   
spouseele

 

Posts: 12830
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Les,

euh.... it's by design!

Indeed, that could have simplified the setup and make the reasoning consistent. Good point! So, maybe it's a shortcoming...

HTH,
Stefaan

(in reply to LLigetfa)
Post #: 10
RE: Direct not working with WPAD and IP - 19.Jan.2006 4:31:22 PM   
ClintD

 

Posts: 1848
Joined: 26.Jan.2001
From: Keller, TX
Status: offline
Sorry - I missed this thread.

quote:

Hmmm...
I thought I could at least get a response from Clint by using the *bug* word.


I deserved that.... :P neener, neener. That thread was one of the few moments I regret on this forum. Sigh...

(in reply to spouseele)
Post #: 11
RE: Direct not working with WPAD and IP - 19.Jan.2006 5:19:50 PM   
LLigetfa

 

Posts: 2187
Joined: 10.Aug.2004
From: fort frances.on.ca
Status: offline
quote:

That thread was one of the few moments I regret on this forum. Sigh...

Hey... didn't mean to bring up a sore point.

We all have personalities and convictions that do not always align with others.  That is what makes us human and life interesting.  I look forward to your sometimes colourful and always enlightening responses.

Keep them coming!

_____________________________

The School of Hard Knocks is a mean teacher. She gives the exam before the lesson.

(in reply to ClintD)
Post #: 12

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 Firewall] >> Firewall Client >> Direct not working with WPAD and IP Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts