Solved

ISA server 2004 and users in rules

Posted on 2006-07-11
14
3,685 Views
Last Modified: 2013-11-16
Hello. I have Isa server 2004 in an active directory environment. I have 1 simple rule, that all authenticated users have rights to port 80 and https. I want to add a rule for skype for certain users but when I add the rule it doesnt matter which users I select, all the users can use skype.
0
Comment
Question by:editperfil
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 5
  • 3
14 Comments
 
LVL 1

Expert Comment

by:cbeee
ID: 17082685
make sure the skype rule is above your 'simple' rule in the rulebase.
0
 

Author Comment

by:editperfil
ID: 17082739
Yes, is the first rule
0
 
LVL 1

Expert Comment

by:cbeee
ID: 17082819
so presumably nobody could access skype before you put the rule in ?

you have an AD group with the skype users in ?
0
How Do You Stack Up Against Your Peers?

With today’s modern enterprise so dependent on digital infrastructures, the impact of major incidents has increased dramatically. Grab the report now to gain insight into how your organization ranks against your peers and learn best-in-class strategies to resolve incidents.

 

Author Comment

by:editperfil
ID: 17082848
Yes. I define the users in Isa server. I create a group where I add the AD users
0
 
LVL 1

Expert Comment

by:cbeee
ID: 17082893
Best Practice and easier is to add the users to and AD group then use teh group for the rule.  The same goes for the simple rule.
0
 

Author Comment

by:editperfil
ID: 17082959
But it doesnt work!!!
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 17084135
I assume Skype is going out over port 80 also?
Open the gui,
select monitoring - logging - click on start query.
Make a Skype connection; are you seeing any additional traffic pass through the log?

Is the ISA in firewall mode or cache mode (one ot two nic's installed)?
Are you using the ISA client on your workstations?
Are you using SecureNAT?
0
 

Author Comment

by:editperfil
ID: 17084166
Is in firewall. In fact skype is an example. I tried other ports, for example radio and again if i put a rule all users can use it.
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 17084284
Can you answer the rest of the questions please?
0
 

Author Comment

by:editperfil
ID: 17084430
Is in firewall more
With isa client and without isa client
Yes securenat
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 17085613
How have you set the ISA Proxy?
open the GUI
Select configuration - networks
double-click internal and view the properties.
How are users authenticating for socks and web traffic? Over port 8080?

Open the gui,
select monitoring - logging - click on start query.
Make a Skype connection; are you seeing any additional traffic pass through the log?
0
 

Author Comment

by:editperfil
ID: 17098990
Over port 8080 with integrated security. I see traffic with skype.
0
 
LVL 51

Accepted Solution

by:
Keith Alabaster earned 250 total points
ID: 17125196
If Skype is using the same port as your standard web proxy traffic then you will not be able to block it in the normal way.

Right-click the outgoing rule and select configure http.
Select signatures.
See the attached link
http://forums.isaserver.org/Skype_Signature/m_2002004505/tm.htm

Regards
Keith
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 17131729
Thank you :)
0

Featured Post

Is Your DevOps Pipeline Leaking?

Is your CI/CD pipeline a hodge-podge of randomly connected tools? You’ve likely got a tool to fix one problem & then a different tool to fix another, resulting in a cluster of tools with overlapping functionality. Learn how to optimize your pipeline with Gartner's recommendations

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In Africa (and potentially where you live…), reliability of ISPs is questionable.  With the increased reliance on e-mail as one of the primary forms of communication, the costs to business are significant based on interuption of ISP Connectivity.  T…
Microsoft's ISA Server has been its pre-eminent security product for about a decade and is still regarded amongst the well-informed as one of the best software firewalls and application gateways ever released, by any manufacturer. ISA Server has bee…
Monitoring a network: how to monitor network services and why? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the philosophy behind service monitoring and why a handshake validation is critical in network monitoring. Software utilized …
If you’ve ever visited a web page and noticed a cool font that you really liked the look of, but couldn’t figure out which font it was so that you could use it for your own work, then this video is for you! In this Micro Tutorial, you'll learn yo…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question