Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Web Proxy filter and IPSEC site-to-site tunnels

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 Firewall] >> HTTP Filtering >> Web Proxy filter and IPSEC site-to-site tunnels Page: [1]
Login
Message << Older Topic   Newer Topic >>
Web Proxy filter and IPSEC site-to-site tunnels - 3.Feb.2007 12:19:49 PM   
gijsbert

 

Posts: 24
Joined: 5.Nov.2004
Status: offline
Hi,

I have an ISA 2006 server used among others for outbound web proxy, web publshing and IPSEC tunnels. I have an issue with HTTP traffic through the IPSEC tunnel.

I enabled the web proxy filter on the HTTP protocol, so I could configure HTTP policies for my web publishing rules (e.g. allowing 8bit characters for OWA). Once I enabled the web proxy filter I could not reach web sites behind the IPSEC tunnel from the internal network anymore (HTTP traffic to the external network worked fine as well as all other protocols through the IPSEC tunnel).

I resolved this by disabling the web proxy filter on the HTTP protocol again. And to my surprise the HTTP policies on my web publishing rules still seemed to work. But to be able to change its settings I have to temporary enable the web proxy filter again.

Although it seems to do what I want, to me this appears quite strange an buggy.
Tom, can you shed some light on this?

Gijsbert

Post #: 1
RE: Web Proxy filter and IPSEC site-to-site tunnels - 20.Feb.2007 8:12:24 AM   
tshinder

 

Posts: 47439
Joined: 10.Jan.2001
From: Texas
Status: online
Hi Gijsbert,

IIRC, in order for this to work, you need to include the remote site's external IP address in the definition of the remote site network in order to get this to work. I know I included information in our book on this, because it is indeed strange behavior.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to gijsbert)
Post #: 2

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 Firewall] >> HTTP Filtering >> Web Proxy filter and IPSEC site-to-site tunnels Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts