Solved

ISA server 2004 and users in rules

Posted on 2006-07-11
14
3,643 Views
Last Modified: 2013-11-16
Hello. I have Isa server 2004 in an active directory environment. I have 1 simple rule, that all authenticated users have rights to port 80 and https. I want to add a rule for skype for certain users but when I add the rule it doesnt matter which users I select, all the users can use skype.
0
Comment
Question by:editperfil
  • 6
  • 5
  • 3
14 Comments
 
LVL 1

Expert Comment

by:cbeee
Comment Utility
make sure the skype rule is above your 'simple' rule in the rulebase.
0
 

Author Comment

by:editperfil
Comment Utility
Yes, is the first rule
0
 
LVL 1

Expert Comment

by:cbeee
Comment Utility
so presumably nobody could access skype before you put the rule in ?

you have an AD group with the skype users in ?
0
 

Author Comment

by:editperfil
Comment Utility
Yes. I define the users in Isa server. I create a group where I add the AD users
0
 
LVL 1

Expert Comment

by:cbeee
Comment Utility
Best Practice and easier is to add the users to and AD group then use teh group for the rule.  The same goes for the simple rule.
0
 

Author Comment

by:editperfil
Comment Utility
But it doesnt work!!!
0
 
LVL 51

Expert Comment

by:Keith Alabaster
Comment Utility
I assume Skype is going out over port 80 also?
Open the gui,
select monitoring - logging - click on start query.
Make a Skype connection; are you seeing any additional traffic pass through the log?

Is the ISA in firewall mode or cache mode (one ot two nic's installed)?
Are you using the ISA client on your workstations?
Are you using SecureNAT?
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Author Comment

by:editperfil
Comment Utility
Is in firewall. In fact skype is an example. I tried other ports, for example radio and again if i put a rule all users can use it.
0
 
LVL 51

Expert Comment

by:Keith Alabaster
Comment Utility
Can you answer the rest of the questions please?
0
 

Author Comment

by:editperfil
Comment Utility
Is in firewall more
With isa client and without isa client
Yes securenat
0
 
LVL 51

Expert Comment

by:Keith Alabaster
Comment Utility
How have you set the ISA Proxy?
open the GUI
Select configuration - networks
double-click internal and view the properties.
How are users authenticating for socks and web traffic? Over port 8080?

Open the gui,
select monitoring - logging - click on start query.
Make a Skype connection; are you seeing any additional traffic pass through the log?
0
 

Author Comment

by:editperfil
Comment Utility
Over port 8080 with integrated security. I see traffic with skype.
0
 
LVL 51

Accepted Solution

by:
Keith Alabaster earned 250 total points
Comment Utility
If Skype is using the same port as your standard web proxy traffic then you will not be able to block it in the normal way.

Right-click the outgoing rule and select configure http.
Select signatures.
See the attached link
http://forums.isaserver.org/Skype_Signature/m_2002004505/tm.htm

Regards
Keith
0
 
LVL 51

Expert Comment

by:Keith Alabaster
Comment Utility
Thank you :)
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Suggested Solutions

Forefront is the brand name for Microsoft's major security product. Forefront covers a number of specific security areas and has 'swallowed' a number of applications under this umbrella including Antigen, ISA Server, the Integrated Access Gateway (t…
Microsoft's ISA Server has been its pre-eminent security product for about a decade and is still regarded amongst the well-informed as one of the best software firewalls and application gateways ever released, by any manufacturer. ISA Server has bee…
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now