Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Web browser configuration

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2000 Firewall] >> SecureNAT Client >> Web browser configuration Page: [1]
Login
Message << Older Topic   Newer Topic >>
Web browser configuration - 26.Jun.2003 8:38:00 AM   
fadfoud

 

Posts: 91
Joined: 10.Jun.2003
From: Lebanon
Status: offline
Dear all,
Regarding the SecureNAT client, should I configure its web browser to use the proxy and create a protocol rule to allow HTTP and HTTPS and name resolving, or just create a protocol rule that allow HTTP and HTTPS and name resolving?
Did the SecureNAT work without configure its web browser to use proxy server?
Post #: 1
RE: Web browser configuration - 26.Jun.2003 3:08:00 PM   
tshinder

 

Posts: 47668
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Sano,

You'll get much better performance if you configure the browser as a Web Proxy client.

HTH,
Tom

(in reply to fadfoud)
Post #: 2
RE: Web browser configuration - 26.Jun.2003 4:33:00 PM   
fadfoud

 

Posts: 91
Joined: 10.Jun.2003
From: Lebanon
Status: offline
Dear Tom,
Regarding the SecureNAT clients, I tried to access the internet whithout configure their web browser to use the proxy server. I creates a protocol rule that allow HTTP, HTTPS and name resolving, and I made it applied to the client set address( Range of IPs of the SecureNAT clients), but it failed unless if I configured their web browser to use proxy server.
So did I miss something regarding the configuration?

(in reply to fadfoud)
Post #: 3
RE: Web browser configuration - 27.Jun.2003 2:46:00 AM   
AHIT

 

Posts: 1561
Joined: 22.Jul.2002
From: Sydney, Australia
Status: offline
Sano,

SecureNAT and Webproxy are 2 different client types... Although a machine can be both at the same time.

Without looking at a web-browser at all, how does a client machine resovle names? Internal DNS Server, ISP's DNS? Can you ping a name from a DOS prompt and hanve it resovle the name back to an IP (even if your don't get an actual response). One of the biggest an dmost notable mistakes I see fo ppl who try to impliment as securenat is they have default GW set correctly... but no method of DNS name resolution - makes it hard to get to URL's!

As a webproxy client (with the ip/port in the web-browser proxy section) all the requests are just sent to ISA and it does all the name resolution, requesting, retrieval and ultimate delivery to user/client (Along with caching along the way if in cache/integrated mode)

Configure as webproxy client and take afvantage of teh cache as well.... It can dramatically affect performance.

(in reply to fadfoud)
Post #: 4
RE: Web browser configuration - 27.Jun.2003 7:52:00 AM   
fadfoud

 

Posts: 91
Joined: 10.Jun.2003
From: Lebanon
Status: offline
HI Tolk,
My configuration consist an internal DNS and I enabled forwarders on it to a external DNS, and in the ISA server I created a protocol rule that allow DNS query for this internal DNS [Razz] .
My SecureNAT client configuration is the follow,
(Gateway IP is the internal interface of the ISA server; DNS IP is the IP of the internal DNS, which has forwarders).
My ISA server configuration is
One rule for my Firewall client (Domain users)
Second rule for my SecureNAT client (Fixed IP)
Third rule for my internal DNS server (DNS query).
So please any idea, did I miss something else?

(in reply to fadfoud)
Post #: 5
RE: Web browser configuration - 4.Jul.2003 8:38:00 AM   
fadfoud

 

Posts: 91
Joined: 10.Jun.2003
From: Lebanon
Status: offline
HI all,
I configured RRAS to dial out for internet access for all clients, because Exchange sever intalled in the same machine of ISA server and the exchange cannot automatic dial-out using ISA server. So I configured RRAS for this issue. In the network connection in ISA server, I checked the "use primary connection" without checking the "use dial-up entry", because i want the request will route to the internet via RRAS.
I found that all my clients access the internet unless the SecureNAT clients, but If I checked-up the "use daip-up entry" so my SecureNAT can access the internet.
So any idea regarding this issue.

(in reply to fadfoud)
Post #: 6

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2000 Firewall] >> SecureNAT Client >> Web browser configuration Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts