Solved

ISA server 2004 and users in rules

Posted on 2006-07-11
14
3,658 Views
Last Modified: 2013-11-16
Hello. I have Isa server 2004 in an active directory environment. I have 1 simple rule, that all authenticated users have rights to port 80 and https. I want to add a rule for skype for certain users but when I add the rule it doesnt matter which users I select, all the users can use skype.
0
Comment
Question by:editperfil
  • 6
  • 5
  • 3
14 Comments
 
LVL 1

Expert Comment

by:cbeee
ID: 17082685
make sure the skype rule is above your 'simple' rule in the rulebase.
0
 

Author Comment

by:editperfil
ID: 17082739
Yes, is the first rule
0
 
LVL 1

Expert Comment

by:cbeee
ID: 17082819
so presumably nobody could access skype before you put the rule in ?

you have an AD group with the skype users in ?
0
 

Author Comment

by:editperfil
ID: 17082848
Yes. I define the users in Isa server. I create a group where I add the AD users
0
 
LVL 1

Expert Comment

by:cbeee
ID: 17082893
Best Practice and easier is to add the users to and AD group then use teh group for the rule.  The same goes for the simple rule.
0
 

Author Comment

by:editperfil
ID: 17082959
But it doesnt work!!!
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 17084135
I assume Skype is going out over port 80 also?
Open the gui,
select monitoring - logging - click on start query.
Make a Skype connection; are you seeing any additional traffic pass through the log?

Is the ISA in firewall mode or cache mode (one ot two nic's installed)?
Are you using the ISA client on your workstations?
Are you using SecureNAT?
0
Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

 

Author Comment

by:editperfil
ID: 17084166
Is in firewall. In fact skype is an example. I tried other ports, for example radio and again if i put a rule all users can use it.
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 17084284
Can you answer the rest of the questions please?
0
 

Author Comment

by:editperfil
ID: 17084430
Is in firewall more
With isa client and without isa client
Yes securenat
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 17085613
How have you set the ISA Proxy?
open the GUI
Select configuration - networks
double-click internal and view the properties.
How are users authenticating for socks and web traffic? Over port 8080?

Open the gui,
select monitoring - logging - click on start query.
Make a Skype connection; are you seeing any additional traffic pass through the log?
0
 

Author Comment

by:editperfil
ID: 17098990
Over port 8080 with integrated security. I see traffic with skype.
0
 
LVL 51

Accepted Solution

by:
Keith Alabaster earned 250 total points
ID: 17125196
If Skype is using the same port as your standard web proxy traffic then you will not be able to block it in the normal way.

Right-click the outgoing rule and select configure http.
Select signatures.
See the attached link
http://forums.isaserver.org/Skype_Signature/m_2002004505/tm.htm

Regards
Keith
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 17131729
Thank you :)
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Need Advise - System / Network Security 4 53
Trojan blocked 11 85
suspending the anti virus 6 114
SQL Server Communications Audit 5 74
So the following errors occurs in 2 ways that I am aware of at this stage, and you receive one of the following error messages: ERROR 1. When trying to save a rule: No Web listener is specified for the Web publishing rule Autodiscovery Publishin…
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
Learn how to create flexible layouts using relative units in CSS.  New relative units added in CSS3 include vw(viewports width), vh(viewports height), vmin(minimum of viewports height and width), and vmax (maximum of viewports height and width).
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

867 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now