client are not able to browse and even not resolve (Full Version)

All Forums >> [ISA Server 2004 Firewall] >> Firewall Client



Message


z_haseeb -> client are not able to browse and even not resolve (27.Nov.2006 2:07:01 AM)

I have two ISA 2004 servers Enterprise Edition on my LAN.

My all users are accessing internet if they want to go by ISA1 or by ISA2 from changing the name of ISA server from firewall client BUT!!!

I have 2 users one has winXP home addition and another has winXP professional edition but winXP professional edition is not a part of my domain both are accessing internet from ISA1 but not from ISA2 when I put the name of ISA2 in the firewall and click on test it gives an error unable to resolve. even I have added both (winXP home and pro) users host entry in my local DNS.




tshinder -> RE: client are not able to browse and even not resolve (9.Dec.2006 8:53:38 AM)

Clients shouuld be using the array name, not the server names to connect to the ISA Firewall array.

HTH,
Tom




z_haseeb -> RE: client are not able to browse and even not resolve (12.Dec.2006 4:26:22 AM)

i know that we have to use the array name and I am using the array name sir.




tshinder -> RE: client are not able to browse and even not resolve (12.Dec.2006 6:28:52 AM)

What isn't working?

Tom




z_haseeb -> RE: client are not able to browse and even not resolve (13.Dec.2006 1:16:40 AM)

Sir in short i mean to say my domain members are easily using the internet from ISA Server2004 (EE) but if any user comes from outside with laptop or a computer which is not the domain part wants to use internet from ISA Server 2004 (EE) so those PC,s  or Laptops are not able to resolve the array name when they click on TEST SERVER from the firewall client.

how to resolve array name from the firewall client from the PC,s who are not the members of domain




z_haseeb -> RE: client are not able to browse and even not resolve (28.Dec.2006 12:58:34 AM)

?????
have U Give UP Sir




tshinder -> RE: client are not able to browse and even not resolve (28.Dec.2006 11:51:13 AM)

I haven't given up, I just don't see what the problem is.

Tom




z_haseeb -> RE: client are not able to browse and even not resolve (30.Dec.2006 8:06:24 AM)

Sir plz help me out......




tshinder -> RE: client are not able to browse and even not resolve (31.Dec.2006 9:52:17 AM)

Hi Z,

Non-domain members should not have the Firewall client installed, since they will not be able to authenticate to the ISA Firewall array.

HTH,
Tom




z_haseeb -> RE: client are not able to browse and even not resolve (9.Jan.2007 5:55:24 AM)

How can I authenticate.
I have a little idea that I must ISACertTOOL.exe but Kindly throw some light how can I do this




Guest -> RE: client are not able to browse and even not resolve (9.Jan.2007 6:34:20 AM)

Hi Z,
no. not with ISACertTOOL.exe. it is for ISA array members.
what exactly do you want to authenticate?
http traffic?
very simple. configure the clients to use ISA as proxy and they will be promted to enter their credentials and after that they can surf the web(if they using linux or other OS check the basic authentication too).
if the user name and password of those clients match a local user name and password on ISA they will not be promted, they can acces Internet direct with no problem.
if they are not domain members: they are not trusted -> so they should be on a different network, implicit in a different security/trust zone.




z_haseeb -> RE: client are not able to browse and even not resolve (9.Jan.2007 7:37:49 AM)

thanks you gave me the tip regarding http traffic if I wana authenticate the Sock traffic like Yahoo messenger or download accelerator




Guest -> RE: client are not able to browse and even not resolve (9.Jan.2007 7:58:35 AM)

no chance with that.
the only way to do it is with FWC in place.
you will have to decide if those computers can be member of the domain or not.
if not, your control over them is at a low level. this means a lot of things.
you can put them on a separate network since they are not domain members and just give them access to what they strictly need.
a walk-arround is possible playing with security zones but not having such a granular control over them as described by you above.




Page: [1]