Welcome to ISAserver.org
Forums |
Register |
Login |
My Profile |
Inbox |
RSS
|
My Subscription |
My Forums |
Address Book |
Member List |
Search |
FAQ |
Ticket List |
Log Out
WEBSENSE
|
Users viewing this topic:
none
|
Logged in as: Guest
|
Login | |
|
WEBSENSE - 26.Feb.2007 11:09:05 AM
|
|
|
TripAces
Posts: 3
Joined: 26.Feb.2007
Status: offline
|
I have a customer who wants to filter HTTP requests of a guest network. The users browser would not necessarily have auto detect or manual proxy settings configured. However the users are expected to receive DHCP for IP, gateway and DNS server details. So my question is this: If ISA server is configured as a firewall (possibly with DNS forwarding) and so is transparent to the client can WEBSENSE still work and wil it receive URLs with names and not resolved IP addresses? Mny thanks
|
|
|
|
RE: WEBSENSE - 6.Mar.2007 10:23:12 AM
|
|
|
tshinder
Posts: 47490
Joined: 10.Jan.2001
From: Texas
Status: offline
|
I don't see how SecureNAT clients on the internal Network would affect inbound VPN connections to the ISA Firewall. That sounds more like a coincidence. The default settings on IE is to use autodiscovery. The users would have had to make a change to their settings manually to not have autodiscovery enable, in which case, they would not be able to connect anyhow because the SecureNAT client configure would be overridden by the incorrect Web proxy settings. HTH, Tom
_____________________________
Thomas W Shinder, M.D. Sr. Consultant/Technical Writer Prowess Consulting http://www.prowessconsulting.com/ Blog: http://blogs.isaserver.org/shinder/ GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8
|
|
|
|
RE: WEBSENSE - 6.Mar.2007 11:48:08 AM
|
|
|
tshinder
Posts: 47490
Joined: 10.Jan.2001
From: Texas
Status: offline
|
Hi Trip, OK, these sound like outbound VPN connections. In order to allow outbound VPN connections, the ISA Firewall needs to be configured in full firewall mode, with at least an internal and external interface, then the rules on the ISA Firewall need to be configured to allow the outbound VPN protocols they need to use. The ISA Firewall allows SecureNAT clients to be Web proxy clients without Web proxy configuration client configuration, but you won't get the FQDNs becasue the SecureNAT client doesn't send that information to the ISA Firewall's Web proxy filter. In addition, I believe that Websense requires the clients to be configured as Web proxy clients, in which case autodiscovery via WPAD works fine. HTH, Tom
_____________________________
Thomas W Shinder, M.D. Sr. Consultant/Technical Writer Prowess Consulting http://www.prowessconsulting.com/ Blog: http://blogs.isaserver.org/shinder/ GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8
|
|
|
|
New Messages |
No New Messages |
Hot Topic w/ New Messages |
Hot Topic w/o New Messages |
Locked w/ New Messages |
Locked w/o New Messages |
|
Post New Thread
Reply to Message
Post New Poll
Submit Vote
Delete My Own Post
Delete My Own Thread
Rate Posts |
|