• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

problem isa server routing and web proxy

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 General] >> General >> problem isa server routing and web proxy Page: [1]
Login
Message << Older Topic   Newer Topic >>
problem isa server routing and web proxy - 28.Apr.2008 2:24:35 AM   
kamalM

 

Posts: 8
Joined: 13.Apr.2008
Status: offline
Hi all
I install isa server 2006 with surfcontrol for filtering,
I setup
-all users have invalid IP 172.16.207.2-250
- external lan have invalid ip 10.20.30.2
-IP on internal lan's router is 10.20.30.1
-all external traffic Route to my router for natting and routing to internet by network rule (Route)
But after analysis it I see all traffic whas send to port 80 in ISA (by web proxy service) NAT to 10.20.30.2 and then go to router
anothers ports are going to router and NAT into this.
for example:
on port 80 see 172.16.207.2->NAT in ISA with 10.20.30.2 -> NAT in router with valid IP
another ports 172.16.207.2->route with ISA to Router-> NAT in router
Can I omit NAT in ISA server ,(I want NAtting do in router and filtering, firewalling do in ISA).
Best Regards
Kamal
Post #: 1
RE: problem isa server routing and web proxy - 29.Apr.2008 6:40:40 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
You can define the 10.20.30.0 network as an ISA Firewall Network and then configure a Route Relationship between that and the default Internal Network. Then you will see the original source IP address on the NAT device in front of the ISA Firewall.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to kamalM)
Post #: 2
RE: problem isa server routing and web proxy - 1.May2008 4:04:15 AM   
kamalM

 

Posts: 8
Joined: 13.Apr.2008
Status: offline
Thank you tshinder for your replay

I check it and all 10.20.30.0 IP's for all ports route to NAT Router but in port 80
it isnot correct all IP's NAT to 10.20.30.2 and after that route to NAT Router
I also try to define a seperated rule but my problem is existing  now.
all problem on port 80 and web proxy!!!!
PLZ help me.
Thanks
Kamal

(in reply to tshinder)
Post #: 3
RE: problem isa server routing and web proxy - 1.May2008 10:21:23 AM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Good point. All Web proxies (not just the ISA Firewall) will use their own IP address when forwarding connections. That's because the Web proxy is the actual machine issuing the request. The Web proxy requests the content on behalf of the client, so that's why the ISA Firewall's external IP address appears to the upstream device for connections that go through the ISA Firewall's Web Proxy filter.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to kamalM)
Post #: 4
RE: problem isa server routing and web proxy - 3.May2008 12:28:01 AM   
kamalM

 

Posts: 8
Joined: 13.Apr.2008
Status: offline
Thank you agian  tshinder for your replay W
What can I do? Web proxy filter does not disable item and I need to all client IP's in NAT Server for my policies.
Is solution exist for this problem?
Best Regards
Kamal

(in reply to tshinder)
Post #: 5
RE: problem isa server routing and web proxy - 6.May2008 11:49:15 AM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
What you can do is unbind the Web Proxy Filter from the HTTP protocol.

http://support.microsoft.com/kb/838708

Then you need to define an ISA Firewall Network for the network ID that the LAN interface of the upstream router is located where you want to see the original source IP address. After creating the ISA Firewall Network, create a ROUTE Network Rule connecting the default Internal Network and the new ISA Firewall Network you created.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to kamalM)
Post #: 6
RE: problem isa server routing and web proxy - 11.May2008 2:06:06 AM   
kamalM

 

Posts: 8
Joined: 13.Apr.2008
Status: offline
Hi Thomas W Shinder,
Thank you for your replay,
after I do it I can resolve my problem but now I have a new problem,
when I do not use web proxy the user connection very slow?!!! but he can use internet and all protocol are routed to my NAT server(Cisco router)
Thank you again for your attention
Best Regards
Kamal

(in reply to tshinder)
Post #: 7
RE: problem isa server routing and web proxy - 14.May2008 9:21:46 AM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
The performance issue might be related to name resolution.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.

(in reply to kamalM)
Post #: 8

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 General] >> General >> problem isa server routing and web proxy Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts