• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Cannot connect using SSL bridging

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 General ] >> Web Publishing >> Cannot connect using SSL bridging Page: [1]
Login
Message << Older Topic   Newer Topic >>
Cannot connect using SSL bridging - 27.Oct.2005 6:20:00 AM   
kiekar

 

Posts: 55
Joined: 23.May2005
From: Montreal, Canada
Status: offline
Hello,

Let me start by saying, when I use SSL to HTTP
bridging I do not have any problems connecting.

The problem I have is using SSL to SSL bridging.
When I use the domain name (the same as the certificate) in the To tab of the secure web publishing rule I get error 12206 proxy chain loop error. If I replace the domain name with a IP address or computer name I get error 500.
I've been trying to find the root cause of this error "12206" for some time now, but no luck.

My setup

ISA 2004 with SP1
WAN: 216.xxx.xxx.82,216.xxx.xxx.83
LAN: 192.168.1.1
DMZ: 172.16.0.1

Web Server W2K3 SP1
DMZ: 172.16.0.2
Installed stand-alone root ca
Created certificate www.mydoamin.com
mydomain properties:
checked require a secure channel
checked require 128 bit encryption
checked basic authentication

Exported certificate to PFX file

Imported PFX file to certificate store in isa 2004
Added certificate www.mydomain.com to certificate folder under the personal folder
Added the ca certificate under the Trusted Root Certificate Authorties folder

Created a secure web publishing rule
Selected SSL Bridging
Rule Action: Allow
Selected connection to clients and web server
Computer name or IP address: www.mydomain.com
path:/*
Accepted request for: www.mydomain.com

Created SSL Listener
External network listener: 216.xxx.xxx.83
Enabled SSL for port 443
Selected certificate: www.mydomain.com

Is there anyone who can point me in the right direction. Any help would be much appreciated.

Thanks
Post #: 1
RE: Cannot connect using SSL bridging - 27.Oct.2005 8:17:00 AM   
winoto

 

Posts: 125
Joined: 10.Sep.2002
From: Montreal
Status: offline
http://support.microsoft.com/?kbid=296202

(in reply to kiekar)
Post #: 2
RE: Cannot connect using SSL bridging - 27.Oct.2005 8:52:00 AM   
kiekar

 

Posts: 55
Joined: 23.May2005
From: Montreal, Canada
Status: offline
Hello Winoto,

Thanks for the help but unfortunitly this article
won't help since my external dns address is not listed on the external network adapter and my internal network adapter is at the top of the list. As I said before this error only happens
with ssl to ssl bridging. If I use non ssl web
publishing rule or ssl to http secure publishing
rule every thing works well.

Karl

(in reply to kiekar)
Post #: 3
RE: Cannot connect using SSL bridging - 29.Oct.2005 1:26:00 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Karl,

What are the exact entries on the "To" tab and the "Public name" tab?

Thanks!
Tom

(in reply to kiekar)
Post #: 4
RE: Cannot connect using SSL bridging - 29.Oct.2005 9:48:00 PM   
kiekar

 

Posts: 55
Joined: 23.May2005
From: Montreal, Canada
Status: offline
Hello Tom,

Thanks for the fast reply. The exact name in the
To Tab is www.centuryit.com and for the public name its www.centuryit.com.

Karl

(in reply to kiekar)
Post #: 5
RE: Cannot connect using SSL bridging - 31.Oct.2005 8:46:00 AM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Karl,

OK, good.

Now, what is the common/subject name on the certificate bound to the Web listener and the certificate bound to the Web site behind the ISA firewall?

Thanks!
Tom

(in reply to kiekar)
Post #: 6
RE: Cannot connect using SSL bridging - 31.Oct.2005 10:11:00 AM   
kiekar

 

Posts: 55
Joined: 23.May2005
From: Montreal, Canada
Status: offline
Hello Tom,

Thanks for the reply. The common subject name bound to the web listner and the certificate bound to the web site behind ISA firewall is www.centuryit.com

Thanks

Karl

(in reply to kiekar)
Post #: 7
RE: Cannot connect using SSL bridging - 3.Nov.2005 7:01:00 PM   
kiekar

 

Posts: 55
Joined: 23.May2005
From: Montreal, Canada
Status: offline
Hello Tom,

FYI I found the solution for the Proxy Chain Loop. I added a entry of my internal ip address to my website in the Host file in ISA 2004.

Regards

Karl

(in reply to kiekar)
Post #: 8

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 General ] >> Web Publishing >> Cannot connect using SSL bridging Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts