Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Why does ISA want to authenticate

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2000 General] >> Web Publishing >> Why does ISA want to authenticate Page: [1]
Login
Message << Older Topic   Newer Topic >>
Why does ISA want to authenticate - 3.Feb.2003 10:23:00 PM   
skipster

 

Posts: 550
Joined: 12.Oct.2001
From: newport beach
Status: offline
Hi all

I have feature pack one installed, and i publish OWA on an intenal machine. what i cant figure out is why ISA wants to ask for credentials when a user who is also behind isa goes to the internal ip\exchange of the machien hosting OWA? I have checked bypass proxy for local addresses, and directly access computers in the LDT, and i have configured IE to use the proxy script. If ISA is asking for credentials then thsi tells me that the request is firts being sent to the ISA server, but why?

thanks for any help
Post #: 1
RE: Why does ISA want to authenticate - 3.Feb.2003 10:37:00 PM   
skipster

 

Posts: 550
Joined: 12.Oct.2001
From: newport beach
Status: offline
I also have the request set to any in the web publishing rule.

(in reply to skipster)
Post #: 2
RE: Why does ISA want to authenticate - 4.Feb.2003 3:16:00 AM   
AHIT

 

Posts: 1561
Joined: 22.Jul.2002
From: Sydney, Australia
Status: offline
Greetings skipster from down under, [Cool]
Try accessign your OWA server from inside, enter soem crednetials with access that your haven't used in a few minutes (makes finding them inthe log easier) and then take a look at your webproxy logs and see what rules are being applied for the request.
Does this sill happen if you try to get to OWA via the machines IP instead of name? If so, Perhaps the local address' setting in the client is not corect. ? Try putting the servername manually into 'do not us eproxy for address' beginning with' and see if it still wants to go through the proxy.
If so... ahh.. is the internal name the same as the external name? A DNS type issue perhaps?

That's about it for my sugegstions for the moment.

(in reply to skipster)
Post #: 3
RE: Why does ISA want to authenticate - 4.Feb.2003 6:41:00 AM   
tshinder

 

Posts: 47669
Joined: 10.Jan.2001
From: Texas
Status: online
Hi Skip,

Have you confirmed that the internal client has bypassed the Web Proxy service? At times the proxy settings get sort of "tattooed" into the Registry. What you should do is disable all proxy settings on the client and then restart the client. Then right click on the IE icon on the desktop and configure the client to use the autoconfiguration script. Then start the browser and connect to the OWA site. Make sure you have a split DNS so that the client doesn't loop back through the external interface of the ISA Server.

HTH,
Tom

(in reply to skipster)
Post #: 4
RE: Why does ISA want to authenticate - 4.Feb.2003 8:47:00 PM   
skipster

 

Posts: 550
Joined: 12.Oct.2001
From: newport beach
Status: offline
Thanks Tom for the replay. I did try what you suggested short of restarting the client machine (couldnt do that right now) I think the prob is with DNS. Currently my ISP host all the public records for our domain. We use an internal DNS server for all internal name resolution, and it is set to forward any request that it cant deal with to our ISP. I made an A record and a revers record on the ISP DNS server, it is exchwin2k.domainname.com, and it points to the external interface of ISA. Exchwin2k is my exchange server. I also created another record called sentinel.domainname.com, and this points to the external interface of ISA also. Sentinal is the name of ISA. I mad a destination set in ISA for OWA, in the form of exchwin2k.domainname.com. I did this for public, exchangeweb, and exchange. In the web publishing rule i selected the destination set, and in the action tab i said to redirect request to this intenal web server, which is exchwin2k.domainanme.com. When the internal clients go to OWA they go to 192.168.0.2\exchange. 0.2= exchwin2k. This setup works fine except when cleitns want to hit OWA from inside the get prompted by ISA.

(in reply to skipster)
Post #: 5
RE: Why does ISA want to authenticate - 4.Feb.2003 11:03:00 PM   
tshinder

 

Posts: 47669
Joined: 10.Jan.2001
From: Texas
Status: online
Hi Skip,

The clients need to use a name that resolves to the OWA machine's internal IP address.

For example, at your ISP, owa.domain.com resolves to public address 222.222.222.2

On your internal DNS server, the name owa.domain.com resolve to 192.168.1.1

Configure domain.com for Direct Access. configure the clients to use your internal DNS server, and it just works [Big Grin]

HTH,
Tom

(in reply to skipster)
Post #: 6

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2000 General] >> Web Publishing >> Why does ISA want to authenticate Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts