edfirst
Posts: 12
Joined: 2.Jun.2005
From: UK
Status: offline
|
Ok Guys… Can anyone assist me with this weird problem, first the configuration: 1, ISA server 2004, 2003 standard server, loads of memory and dual Xeon server. 2, Intel SX fibre Nic card with multiple Vlans configured and connected all aok so far. 3, Public 10.*.*.* address to external interface, private 172.16.*.* ip addresses configured on the internal networks. 4, DNS and Domain comms are all good internally. All works great internally all policies work great internally and the network traffic does what it supposed to do. “Now the problem”, when this was in the development lab this isa server was great, now it is in production the issue is this, when I try to use the web proxy filter to deny sites, methods, strings well basically anything, I just get “error 10060 connection timeouts”. The major difference is that we now have to push traffic to an external perimeter proxy server, as this is a college network protected by a corporate system. So here is the original development design configuration: 1, Web proxy enabled and set at port 8080 (standard config) 2, Firewall client enabled and auto detect ticked, and the correct ISA-server name is in the box with the domain suffix correct. 3, Auto discovery is ticked, and firewall clients auto detect the ISA server fine using the DNS “WPAD” entry. 4, All clients are pointing to this ISA as default gateway, all client proxy settings point to this ISA with port 8080. Under this configuration the proxy filter works great and the list of URL’s in a denied access policy work great along with the redirection to error pages we have designed. Connection to sites is great that are supposed to be connected to as allowed. Now the production configuration: 1, Web proxy enabled and set at port 8080 (standard config) 2, Firewall client enabled and auto detect ticked, and the correct ISA-server name is in the box with the domain suffix correct, now in the lower box I have told ISA to use a proxy server ticked and the address of the corporate proxy in the box, I notice that the greyed out custom URL appends the corporate proxy address also with the port 8080 (above box) which is their correct port number we have to use. 3, Auto discovery is ticked, and firewall clients auto detect the ISA server fine using the DNS “WPAD” entry. 4, All clients are pointing to this ISA as default gateway, all client proxy settings point to this ISA with port 8080. Under this configuration we have the same result, the filters work the banned sites work, the redirectors work, but when we try to access any other sites we get error 10060 connection timeout. Next we tried the proxy settings on clients pointing instead to the corporate proxy on port 8080, now we have connectivity but now no filters work, no banned sites, so I am assuming this is now bypassing the proxy filter and so here is the next setup tried, in the monitoring logs I noticed there were a lot of port 8080 entries failing to connect: 1, Web proxy enabled and set at port 8080 (standard config) 2, Firewall client enabled and auto detect ticked, and the correct ISA-server name is in the box with the domain suffix correct, now in the lower box I have told ISA to use a proxy server ticked and the address of the corporate proxy in the box, I notice that the greyed out custom URL appends the corporate proxy address also with the port 8080 (above box) which is their correct port number we have to use. 3, Auto discovery is ticked, and firewall clients auto detect the ISA server fine using the DNS “WPAD” entry. 4, All clients are pointing to this ISA as default gateway, all client proxy settings point to this ISA with port 8080. 5, Now created a protocol “Proxy” outbound port 8080 and applied the proxy filter to this. 6, Had to remove the http protocol and replace with the proxy one above, or no filters work. Now traffic is denied point blank, the proxy filter works again redirects to all the correct places and all the http filters work great, all the correct error messages are displayed, but this time I get denied messages to all other pages that should be allowed. Next I replaced the proxy settings to the clients pointing to the corporate proxy and ISA as the gateway as before, but this time I tried it with the Proxy protocol only instead of the http, I now have similar symptoms as the http protocol except this time I get the connection timeout errors for all the none filtered or banned pages. Fwengmon tool reports everything working, proxy is listening, firewall client is listening, shows connections to redirected pages on internal intranet site. There are no reported resource errors or config errors in events or alerts panel. So if any one could point me to info using an upstream proxy server through ISA server, or some help walking through the config, as I am now almost bald and about to get the knives out of the draws to end my misery……lol…. Seriously I would greatly appreciate any help, and if you need any further info into this nightmare then please let me know.
_____________________________
he who asks a question now is a fool for five minutes, he who does'nt is a fool forever..........
|