• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

ISA 2006 access rule help

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 Web Proxy] >> Web Proxy Client >> ISA 2006 access rule help Page: [1]
Login
Message << Older Topic   Newer Topic >>
ISA 2006 access rule help - 2.Dec.2011 10:57:49 AM   
JimMueller

 

Posts: 9
Joined: 5.Jun.2002
From: Orlando FL
Status: offline
We have two ISA 2006 SP1 proxy servers, but they are not in an array. One server is our normal production proxy, and the other is configured as wide 'open' access (for testing and/or when we can't get it to work through the normal proxy). Both proxy's are configured in single NIC mode. The person who primarily handled the configuraion left back in May.

We have recently begun receiving complaints from various users that when they login to specific websites, they receive a page cannot be displayed error instad of the successful login page. The browsers are set through GP to use automatic detect. When we change the proxy setting to use the open proxy, everything works normally.

One of the sites is Facebook. We've recently had a policy change to allow social media for marketing, but we are going through another vendors website to access the FB resources. We only need 3 URL's defined according to that vendor. In the vendors site, part of the screen shows the FB Wall entries. Through the open proxy the wall is displayed, but through the normal proxy it just continues to attempt to load.

How can I isolate where the problems lie?

Thanks!
Post #: 1
RE: ISA 2006 access rule help - 2.Dec.2011 6:07:47 PM   
JimMueller

 

Posts: 9
Joined: 5.Jun.2002
From: Orlando FL
Status: offline
It looks like I may have posted this in the wrong forum; if you're able to move it please feel free to do so.

Our president needed to view a business-related video on Facebook late today so we set him up through the open proxy. What I've tried so far on a test client without any change:

- Applied KB2551554
- Insured Use HTTP 1.1 thru proxy connection was enabled in IE settings
- Disabled Symantec Endpoint Protection
- Disabled proxy autocaching, and re-enabled after it didn't help

Wireshark first showed a bad header, possibly due to offloading. I disabled all offloading on the adapter and that message disappeared.

When logging into Facebook and getting the page cannot be displayed, Wireshark shows the following:

HTTP - Connect www.facebook.com:443 HTTP/1.0 (client>proxy)
HTTP - HTTP/1.1 302 redirected (proxy>client)
DNS - Std query A www.facebook.com (client>DNS)
DNS - Std query response 69.171.229.15 (DNS>client)
TCP - 64798 > https [SYN](client>FB)
TCP - https > 64798 [RST, ACK] (FB>client)
TCP - 64797 > http-alt [ACK] (client>proxy)
TCP - http-alt > 64797 [FIN, ACK] (proxy>client)
TCP - 64797 > http-alt [ACK] (client>proxy)
TCP - 64798 > https [SYN] (client>FB)
TCP - https > 64798 [RST, ACK] (FB>client)
TCP - 64798 > https [SYN] (client>FB)
TCP - https > 64798 [RST, ACK] (FB>client)
TCP - 64797 > http-alt [RST, ACK] (client>proxy)

(in reply to JimMueller)
Post #: 2

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 Web Proxy] >> Web Proxy Client >> ISA 2006 access rule help Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts