• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Clients bypassing proxy

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 Web Proxy] >> Web Proxy Client >> Clients bypassing proxy Page: [1]
Login
Message << Older Topic   Newer Topic >>
Clients bypassing proxy - 1.Sep.2009 4:56:33 PM   
jerwhite

 

Posts: 4
Joined: 1.Sep.2009
Status: offline
When a user turns off the proxy settings in a web browser, they still get access to the web. How do I prevent this? I would like to block users who install third party browsers from getting around the proxy also. Thanks in advance.
Post #: 1
RE: Clients bypassing proxy - 1.Sep.2009 5:47:07 PM   
richardhicks

 

Posts: 477
Joined: 20.Jan.2009
From: Southern California
Status: offline
Removing the default gateway from the client workstation would resolve your issue.  You can also use the ISA HTTP filter to block requests from third-party web browsers.

More information...

http://technet.microsoft.com/en-us/library/cc302627.aspx (applies to ISA 2006)

http://www.isaserver.org/tutorials/Configuring-ISA-Server-2006-HTTP-Filter.html



_____________________________

Richard Hicks - Forefront MVP
http://tmgblog.richardhicks.com/
http://directaccess.richardhicks.com/

(in reply to jerwhite)
Post #: 2
RE: Clients bypassing proxy - 2.Sep.2009 9:52:06 AM   
jerwhite

 

Posts: 4
Joined: 1.Sep.2009
Status: offline
When I remove the default gateway of a client I cannot gain access to the web at all. Even with my proxy settings turned on. I pointed my gateway to the proxy to try this and it worked but then I was able to bypass the proxy in my web browser. When I say bypass, I'm not sure it's really bypassing the proxy. When I set the browser to no proxy I am able to get to the internet. I failed to mention that my ISA 2006 proxy has two NICs. So they can't really go around it but it seems as though they are not subject to certain rules when they turn it off. 

(in reply to richardhicks)
Post #: 3
RE: Clients bypassing proxy - 2.Sep.2009 4:24:02 PM   
paulo.oliveira

 

Posts: 3470
Joined: 3.Jan.2008
From: Amazon, Brazil
Status: offline
Hi,

altough proxy is not configured on client´s web browsers, ISA firewall is still inspecting web requests.

ISA has three type of clients. The basic description is as follow:

FWC - intercept winsock connections and forward to ISA firewall service;
Web proxy client - clients with ISA firewall internal IP configured on their web browsers;
SecureNAT - clients configured with their default gateway pointing to ISA firewall internal IP.

For more information: http://technet.microsoft.com/en-gb/library/bb794762.aspx

Regards,
Paulo Oliveira.

_____________________________

Microsoft MVP - Forefront
MCP - ISA Firewall 2004
Blog: http://poliveirasilva.wordpress.com/
Twitter: https://twitter.com/poliveirasilva

(in reply to jerwhite)
Post #: 4
RE: Clients bypassing proxy - 3.Sep.2009 9:46:40 AM   
jerwhite

 

Posts: 4
Joined: 1.Sep.2009
Status: offline
About the Secure NAT. Do I need to have NAT configured on the routers or is the NAT built into the proxy itself?

(in reply to paulo.oliveira)
Post #: 5
RE: Clients bypassing proxy - 3.Sep.2009 5:18:34 PM   
paulo.oliveira

 

Posts: 3470
Joined: 3.Jan.2008
From: Amazon, Brazil
Status: offline
Hi,

ISA applies Network Relationship (Route or NAT) according to the rules defined on Configuration node - Networks - Network Rules tab.

Regards,
Paulo Oliveira.

_____________________________

Microsoft MVP - Forefront
MCP - ISA Firewall 2004
Blog: http://poliveirasilva.wordpress.com/
Twitter: https://twitter.com/poliveirasilva

(in reply to jerwhite)
Post #: 6
RE: Clients bypassing proxy - 4.Sep.2009 9:37:21 AM   
jerwhite

 

Posts: 4
Joined: 1.Sep.2009
Status: offline
Paulo Oliveira you seem to know quite a bit about ISA. I have been in the desktop support world for over ten years and have a CCNA. I am pretty good with networking and router configs however servers and ISA to be specific is a week point. I have just been given the extra duty of learning the ISA server and managing it. We have no test environment so I can't just try things unless we have down time. This has nothing to do with the post however after asking my questions I feel as though I'm over my head on this due to the circumstances. Would you have any recommendations on a starting point to help me understand this ISA environment better.

(in reply to paulo.oliveira)
Post #: 7
RE: Clients bypassing proxy - 4.Sep.2009 11:59:13 AM   
paulo.oliveira

 

Posts: 3470
Joined: 3.Jan.2008
From: Amazon, Brazil
Status: offline
Hi,

here are some great resources:

http://www.isaserver.org/tutorials/2004bestpractices-p1.html

http://www.isaserver.org/tutorials/Overview-ISA-TMG-Networking-ISA-Networking-Case-Study-Part1.html

http://blog.msfirewall.org.uk/2008/06/isa-servers-recommeded-network-card.html

http://www.isaserver.org/tutorials/Teaching-Boss-Network-ISA-Firewall-Part1.html

http://technet.microsoft.com/en-gb/library/bb838642.aspx

Regards,
Paulo Oliveira.

< Message edited by paulo.oliveira -- 4.Sep.2009 12:01:03 PM >


_____________________________

Microsoft MVP - Forefront
MCP - ISA Firewall 2004
Blog: http://poliveirasilva.wordpress.com/
Twitter: https://twitter.com/poliveirasilva

(in reply to jerwhite)
Post #: 8
RE: Clients bypassing proxy - 19.Oct.2009 5:54:40 PM   
axemte

 

Posts: 2
Joined: 19.Oct.2009
Status: offline
Thanks for your reply Paulo.

I followed the links posted here but still can't solve the problem (When a user turns off the proxy settings in a web browser, they still get access to the web.) :(

I'm using ISA Server 2006 Standard with 2 NICs.

(in reply to paulo.oliveira)
Post #: 9
RE: Clients bypassing proxy - 20.Oct.2009 8:58:41 AM   
paulo.oliveira

 

Posts: 3470
Joined: 3.Jan.2008
From: Amazon, Brazil
Status: offline
Hi,

when an ISA client turn off the browser settings, it becomes a SecureNAT client. If there´s an access rule allowing access to his machine, ISA will allow the access.

More info about ISA clients check here: http://technet.microsoft.com/en-gb/library/bb794762.aspx

Regards,
Paulo Oliveira.

_____________________________

Microsoft MVP - Forefront
MCP - ISA Firewall 2004
Blog: http://poliveirasilva.wordpress.com/
Twitter: https://twitter.com/poliveirasilva

(in reply to axemte)
Post #: 10

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 Web Proxy] >> Web Proxy Client >> Clients bypassing proxy Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts