Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

SSL-Tunnel

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 Firewall] >> Access Policies >> SSL-Tunnel Page: [1]
Login
Message << Older Topic   Newer Topic >>
SSL-Tunnel - 4.Dec.2006 11:11:16 AM   
mistafrenzy

 

Posts: 1
Joined: 4.Dec.2006
Status: offline
Over the weekend we installed ISA 2006 (previous was 2000). This morning we had a few problems the main one been HTTPS been denied by the default rule even though is was allowed in the main access policy. The logging reported SSL-Tunnel as the protocol and not HTTPS.

We had restricted HTTP content to all but audio and video and it turned out to be this that caused the problem. I set an new access policy to block audio and video before the main polocy then allowed all content for the main policy.

Has anyone else encoutered this problem or similar before?
Post #: 1
RE: SSL-Tunnel - 7.Dec.2006 7:47:34 PM   
tshinder

 

Posts: 47659
Joined: 10.Jan.2001
From: Texas
Status: offline
This is normal. Since the connection is an SSL tunnel, the ISA Firewall can't see what content is being allowed or blocked, so it blocks everything.

You should allow SSL access only to approved sites, otherwise users can do anything they like inside SSL tunnels.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to mistafrenzy)
Post #: 2
RE: SSL-Tunnel - 6.Feb.2007 10:55:09 AM   
aheusdens

 

Posts: 12
Joined: 2.Jan.2007
Status: offline
How would I approve SSL access to specific sites?

-Adam

(in reply to tshinder)
Post #: 3
RE: SSL-Tunnel - 7.Feb.2007 11:09:31 AM   
tshinder

 

Posts: 47659
Joined: 10.Jan.2001
From: Texas
Status: offline
Create an Access Rule.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to aheusdens)
Post #: 4

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 Firewall] >> Access Policies >> SSL-Tunnel Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts