Solved

ISA server 2004 and users in rules

Posted on 2006-07-11
14
3,666 Views
Last Modified: 2013-11-16
Hello. I have Isa server 2004 in an active directory environment. I have 1 simple rule, that all authenticated users have rights to port 80 and https. I want to add a rule for skype for certain users but when I add the rule it doesnt matter which users I select, all the users can use skype.
0
Comment
Question by:editperfil
  • 6
  • 5
  • 3
14 Comments
 
LVL 1

Expert Comment

by:cbeee
ID: 17082685
make sure the skype rule is above your 'simple' rule in the rulebase.
0
 

Author Comment

by:editperfil
ID: 17082739
Yes, is the first rule
0
 
LVL 1

Expert Comment

by:cbeee
ID: 17082819
so presumably nobody could access skype before you put the rule in ?

you have an AD group with the skype users in ?
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Author Comment

by:editperfil
ID: 17082848
Yes. I define the users in Isa server. I create a group where I add the AD users
0
 
LVL 1

Expert Comment

by:cbeee
ID: 17082893
Best Practice and easier is to add the users to and AD group then use teh group for the rule.  The same goes for the simple rule.
0
 

Author Comment

by:editperfil
ID: 17082959
But it doesnt work!!!
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 17084135
I assume Skype is going out over port 80 also?
Open the gui,
select monitoring - logging - click on start query.
Make a Skype connection; are you seeing any additional traffic pass through the log?

Is the ISA in firewall mode or cache mode (one ot two nic's installed)?
Are you using the ISA client on your workstations?
Are you using SecureNAT?
0
 

Author Comment

by:editperfil
ID: 17084166
Is in firewall. In fact skype is an example. I tried other ports, for example radio and again if i put a rule all users can use it.
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 17084284
Can you answer the rest of the questions please?
0
 

Author Comment

by:editperfil
ID: 17084430
Is in firewall more
With isa client and without isa client
Yes securenat
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 17085613
How have you set the ISA Proxy?
open the GUI
Select configuration - networks
double-click internal and view the properties.
How are users authenticating for socks and web traffic? Over port 8080?

Open the gui,
select monitoring - logging - click on start query.
Make a Skype connection; are you seeing any additional traffic pass through the log?
0
 

Author Comment

by:editperfil
ID: 17098990
Over port 8080 with integrated security. I see traffic with skype.
0
 
LVL 51

Accepted Solution

by:
Keith Alabaster earned 250 total points
ID: 17125196
If Skype is using the same port as your standard web proxy traffic then you will not be able to block it in the normal way.

Right-click the outgoing rule and select configure http.
Select signatures.
See the attached link
http://forums.isaserver.org/Skype_Signature/m_2002004505/tm.htm

Regards
Keith
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 17131729
Thank you :)
0

Featured Post

Live: Real-Time Solutions, Start Here

Receive instant 1:1 support from technology experts, using our real-time conversation and whiteboard interface. Your first 5 minutes are always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you are like regular user of computer nowadays, a good bet that your home computer is on right now, all exposed to world of Internet to be exploited by somebody you do not know and you never will. Internet security issues has been getting worse d…
There are several problems reported according slow link speeds or poor performance in TMG 2010, UAG 2010 or ISA 2006. I want to collect here some of the common issues together to give a brief overview what can be the reason. Nevertheless, not all of…
Along with being a a promotional video for my three-day Annielytics Dashboard Seminor, this Micro Tutorial is an intro to Google Analytics API data.
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…

785 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question