• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Firewall Client and Intranet

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 Firewall] >> Firewall Client >> Firewall Client and Intranet Page: [1]
Login
Message << Older Topic   Newer Topic >>
Firewall Client and Intranet - 23.May2005 6:43:00 PM   
eminent

 

Posts: 19
Joined: 29.Jul.2004
Status: offline
Hi,

I have recently setup ISA Server 2004 and everything is working great except for one problem. Firewall clients and Web Proxy clients cannot access the intranet. They get an error saying the request has been denied by the ISA server. Everything works fine for the secure-NAT. Am I forgetting something? What do I need to do the enable Firewall clients and Web Proxy clients to be able to access the internal web sites?

Thanks!
Post #: 1
RE: Firewall Client and Intranet - 23.May2005 7:00:00 PM   
LLigetfa

 

Posts: 2187
Joined: 10.Aug.2004
From: fort frances.on.ca
Status: offline
Set them up in the exclusion lists.

(in reply to eminent)
Post #: 2
RE: Firewall Client and Intranet - 24.May2005 10:20:00 AM   
Guest
and where is this list ??

is it in the isa server 2004 ??

or manually on each computer in IE Lan Settings ?

(in reply to eminent)
  Post #: 3
RE: Firewall Client and Intranet - 24.May2005 1:08:00 PM   
LLigetfa

 

Posts: 2187
Joined: 10.Aug.2004
From: fort frances.on.ca
Status: offline
Are you talking about FWC or WP?

In the ISA console, under Configuration, Networks, Internal, Properties, there are several tabs. Follow your nose for settings on Addresses, Domains, and Web Browser.

These of course all depend on how you setup your autodiscovery and/or FWC deployment.

You can also use GPO and/or FWCTool to configure.

(in reply to eminent)
Post #: 4
RE: Firewall Client and Intranet - 27.May2005 4:40:00 AM   
Guest
To Answer u :

There are no exclusion list in the Network > Internal > Properties > Tabs

if u ever used GPO , u would know at least that the ISA 2004 Client Firewall overwrites the GPO setting in Internet Explorer Proxy Settings.

and last for the FWCTool > i need something central , i dont need to go to each machine and configure it.

The Answer is with Direct Access :

http://www.isaserver.org/articles/2004directaccessp1.html

http://www.isaserver.org/articles/2004directaccessp2.html

[ May 27, 2005, 04:43 AM: Message edited by: majdal ]

(in reply to eminent)
  Post #: 5
RE: Firewall Client and Intranet - 27.May2005 10:49:00 AM   
LLigetfa

 

Posts: 2187
Joined: 10.Aug.2004
From: fort frances.on.ca
Status: offline
Like I said... follow your nose. [Roll Eyes]
There is more than one place to set exclusions depending on how things are configured and depending on whether the WP or FWC is used.

YMMV

(in reply to eminent)
Post #: 6
RE: Firewall Client and Intranet - 27.May2005 1:23:00 PM   
Guest
haha [Smile] but still man even with direct access , its not working.

iam glad with the GPO , but the problem is that the isa fwc changes the settings the GPO has set before .

i have a portal and a wireless access port that has a web interface.

i need to execlude them from the isa proxy , i addedd their IPs in the direct access , i added a rule to acces them with all outbound and still nothing works !

so following the nose sometimes doesnt help [Smile]

a question :

can i restrict the fwc to change the GPO settings?

(in reply to eminent)
  Post #: 7
RE: Firewall Client and Intranet - 27.May2005 1:54:00 PM   
LLigetfa

 

Posts: 2187
Joined: 10.Aug.2004
From: fort frances.on.ca
Status: offline
I cannot help it if your nose is lost. Under the tabs that I mentioned, there are settings for both WP and FWC exclusions.

AFAIK, if you turn on the option of having the FWC set the WP and the exclusions, it will set it the same for all users. I chose not to have the FWC set WP and I use just GPOs to do it. That way I can have any number of GPOs with different settings.

(in reply to eminent)
Post #: 8
RE: Firewall Client and Intranet - 28.May2005 11:31:00 AM   
Guest
Thumb up for you man [Smile]

Thats the trick i want

i really was [Confused] with this , but now i understand it . thanks to you LLigetfa

(in reply to eminent)
  Post #: 9

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 Firewall] >> Firewall Client >> Firewall Client and Intranet Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts