[Webinar] Streamline your web hosting managementRegister Today



Posted on 2007-11-28
Medium Priority
Last Modified: 2012-06-21
I'm new to ISA Server,   we have experinced strange problem
our work environment is ( 1 Domain controller DC1 with windows server 2003 Sp2 & 50 Pcs with windwos XP professional sp2 all connected to DC1 & ISA server 2006 installed on a server with 2 NIC with Windows 2003 Sp2 and joined to Domain controller Dc1)
- Our business rule need to let some users Allow to Access ONLY 1 web site "our company web site" on the internet  and Deny all other web Sites
- I made the following Access Rules
Order            Name                                      Action        Protocols               From/Listner     |  To      |
3  |    AllowUsersToAcces1WebSite          | Allow       | DNS,HTTP,HTTPs  | Internal           | Co.WebSite*
4  | DenyUsersToAccesAnyotherWebSite | Deny        | DNS,HTTP,HTTPs  | Internal           | AnywebSoite*
1- Co.WebSite is URL Set i have created ( Name : Co.WebSite  & Added the URL http://www.mycompanyweb.com )
2- AnyWebSite is URL Set i have created ( Name : AnywebSite  & Added the URL http://*)
3- the clients are using NATSecure ( by setting the deafult gateway to refer to ISA IP)  

The problems:-
1- after i configured the access rule as above i tested from the clients it works good!!! BUT after sometimes the clients cant Access  our company site , Sure and any other sites
I dont know what's going on  , so i delete the rule and reacreate it again and try from clients the same problem come "works good but after sometimes cant access to the internet"

2- we have some pages use "https:// " in our company web site but when i apply the above rule the user couldnt access any pages use https:// even i added https://www.mycomanyweb.com/" and i read during creat the URL SET the following Note (  Urls Included in this set (applicable for HTTP traffic Only" )  , SO how can add https/www.ourcompanyweb.com" to the URL SET ?

am waintting your help

IF the DNS is not configured correctly, rules using URL Set may not be applied as expected  Urls Included in this set (applicable for HTTP traffic Only"
Question by:ali_alannah
  • 3
  • 2
LVL 19

Expert Comment

ID: 20365139
Are you using the web proxy or the firewall client?

If you are not, ISA does not see the URL only the IP address.  It then does a reverse lookup on the IP address, but may not get the DNS name you are expecting if the same IP address is used to host multiple web sites.

I recommend that you firstly use Domain Name Sets, unless you want to block/allow specific paths on a site.  Then, review the firewall logs to see the actual site name it is blocking.

You may also choose to use either the Firewall Client or Web Proxy, as it will provide more info to ISA Server.

Remember as well that DENY rules do exactly that.  If you want some authenticated users to have access then that rule will need to come before the DENY rule, but also remember that authenticated rules must come after all non-authenticated rules as they introduce an implicit DENY-ALL for non-authenticated connections.

Author Comment

ID: 20367105
Hello SteveH_UK,
Thanks for your help but please could you make it easy in steps because am newcomer to ISA server so do you mean

1- Using webProxy Or Firewalls client will solve this problem ? Because we are not use Proxy or Firewall clinent ONLY use SecuredNAT , So if this will solve our problem we can config the clients to use one of these (web Proxy or Firewall clients)

2- I dont understand what do u mean "I recommend that you firstly use Domain Name Sets"  , as i explain in my questions am using http://www.mycompanyweb.com  as URL SET to allow the client to acces it and using (http://*) as URl set to Deny accet to other all websites
LVL 51

Assisted Solution

by:Keith Alabaster
Keith Alabaster earned 300 total points
ID: 20367982
Add a rule above these two rules you have put in to allow http & https From Internal TO Internal - this assumes that you have your internal web server inside the local area network.

A domain set can be used instead of a url set - url sets follow the http://whatever/* format - domain sets use *.yourdomain.com style formats without http or https infront of them. this may help but the fact that your rules are working for a while suggests that you have done the job correctly.

Have you run the BPA on your ISA system? You need .net framework 1.1 for this to operate.

Upgrade your Question Security!

Your question, your audience. Choose who sees your identity—and your question—with question security.

LVL 19

Accepted Solution

SteveH_UK earned 1200 total points
ID: 20368160
URL Sets and Domain Name Sets are two different types of objects in ISA Server.  A URL Set can include, for example: "http://www.acompany.com/thispage"; but a domain name set only includes "www.acompany.com".  When you are configuring a rule and are choosing the "To" options, you can create a Domain Name Set the same way as an URL Set.

You do not need to use the firewall client or the web proxy (we didn't for a while), but they do help with diagnosing issues as ISA Server can provide more information, and it also enables user authentication so that you can create per-user rules.  As a general rule, it is a good idea to use the firewall client, but you will need to configure the Internal network to support it.  Have a look at the ISA Server Product Documentation, and then let me know if you need more help, that is if you decide to do either of these.

Make sure you've got the latest updates for ISA Server 2006, as they include a really helpful improvement in the log display.

Can you check that clients can find your company website, because I'm not sure that your DNS rules are ok.  If everyone uses external DNS servers, then you need to create an access rule that allows Internal to External for the DNS protocol.  If you have internal DNS servers, then you still need to do this for your internal DNS servers.  You can check client DNS lookup using:

nslookup www.google.com

If then, you are still having problems, try the following:

nslookup www.yourcompany.com

Then try:

ping -a

where is the IP address that nslookup returns.  What you need to know is whether a reverse DNS lookup on gives www.yourcompany.com.  I suspect that it does not, or at least does not consistently.  In these cases, you need to add the reported address to your URL Set or Domain Name Set in ISA Server.
LVL 19

Expert Comment

ID: 20368179
If you are taking on the responsibility for managing an ISA Server, or any firewall, you really must understand TCP/IP, DNS, DHCP and general firewall principles.  Can I recommend that you find a good book, perhaps by SAMS Publishing or Microsoft Press.  The exam kit books tend to be quite good.

Of course, we'll do our best to answer your current problems as quickly as we can!
LVL 51

Expert Comment

by:Keith Alabaster
ID: 20368253
Off topic - Steve - check out my profile at some point and drop me an email if you feel like it.


Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Forefront is the brand name for Microsoft's major security product. Forefront covers a number of specific security areas and has 'swallowed' a number of applications under this umbrella including Antigen, ISA Server, the Integrated Access Gateway (t…
Forefront Threat Management Gateway 2010 or FTMG comes with some very neat troubleshooting tools built-in when trying to identify what is actually happening behind the scenes within the product when traffic is passing through its interfaces. To the …
Hi, this video explains a free download that you can incorporate into your Access databases, or use stand-alone for contact management. Contacts -- Names, Addresses, Phone Numbers, eMail Addresses, Websites, Lists, Projects, Notes, Attachments…
The video will let you know the exact process to import OST/PST files to the cloud based Office 365 mailboxes. Using Kernel Import PST to Office 365 tool, one can quickly import numerous OST/PST files to Office 365. Besides this, the tool also comes…
Suggested Courses
Course of the Month9 days, 11 hours left to enroll

591 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question