Advertisement

05.21.2008 at 12:21PM PDT, ID: 23422156
[x]
Attachment Details

Question about ISA Server 2006 Outbound authentication

Asked by mankney1 in MS Internet Security & Accel

Tags: Microsoft, ISA Server, 2006

Hi, I need help clearing up some ISA Server 2006 issues.  It is a multi-homed setup. It is not set up for caching. We have an outbound access rule that allows All Authenticated Users to access the web and it works fine. I can access the web and the logs shows clearly this was the rule that allowed me through. Our clients are all Web proxyclients.

We also have an Active Directory group called Internet Deny All that is tied to another rule that blocks Http,Https,DNS and FTP oubound.  If I try to go out to the Ijnternet when I am logged in as a user that is in that group I do get blocked by the rule.  All is good so far.

The problem is when we use some specialty applications. For example we have some bank software that connects to the bank and sends confidential information by SSL.. The user is not in the Intenet Deny Group. The system does not allow them access. If I look at the logs it says the rule we created for Internet Deny All is blocking him and it looks like the bank software is trying to go through as an Anonymous User.  

Any ideas why that is the case? Why would this rule block access when the person is not in the AD group that denies Internet Access.

If anyone could help clear up why ISA behaves this way I would appreciate it.

Thanks,
MuchStart Free Trial
[+][-]05.21.2008 at 12:29PM PDT, ID: 21618238

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]05.21.2008 at 12:52PM PDT, ID: 21618435

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]05.21.2008 at 01:06PM PDT, ID: 21618561

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]05.22.2008 at 04:33AM PDT, ID: 21622779

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]05.22.2008 at 06:11AM PDT, ID: 21623447

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]05.22.2008 at 11:48AM PDT, ID: 21626483

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]05.22.2008 at 12:33PM PDT, ID: 21626878

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]05.23.2008 at 10:37AM PDT, ID: 21634101

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zone: MS Internet Security & Accel
Tags: Microsoft, ISA Server, 2006
Sign Up Now!
Solution Provided By: keith_alabaster
Participating Experts: 1
Solution Grade: A
 
 
[+][-]05.23.2008 at 01:43PM PDT, ID: 21635676

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628