Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17



Posted on 2007-11-28
Medium Priority
Last Modified: 2012-06-21
I'm new to ISA Server,   we have experinced strange problem
our work environment is ( 1 Domain controller DC1 with windows server 2003 Sp2 & 50 Pcs with windwos XP professional sp2 all connected to DC1 & ISA server 2006 installed on a server with 2 NIC with Windows 2003 Sp2 and joined to Domain controller Dc1)
- Our business rule need to let some users Allow to Access ONLY 1 web site "our company web site" on the internet  and Deny all other web Sites
- I made the following Access Rules
Order            Name                                      Action        Protocols               From/Listner     |  To      |
3  |    AllowUsersToAcces1WebSite          | Allow       | DNS,HTTP,HTTPs  | Internal           | Co.WebSite*
4  | DenyUsersToAccesAnyotherWebSite | Deny        | DNS,HTTP,HTTPs  | Internal           | AnywebSoite*
1- Co.WebSite is URL Set i have created ( Name : Co.WebSite  & Added the URL )
2- AnyWebSite is URL Set i have created ( Name : AnywebSite  & Added the URL http://*)
3- the clients are using NATSecure ( by setting the deafult gateway to refer to ISA IP)  

The problems:-
1- after i configured the access rule as above i tested from the clients it works good!!! BUT after sometimes the clients cant Access  our company site , Sure and any other sites
I dont know what's going on  , so i delete the rule and reacreate it again and try from clients the same problem come "works good but after sometimes cant access to the internet"

2- we have some pages use "https:// " in our company web site but when i apply the above rule the user couldnt access any pages use https:// even i added" and i read during creat the URL SET the following Note (  Urls Included in this set (applicable for HTTP traffic Only" )  , SO how can add https/" to the URL SET ?

am waintting your help

IF the DNS is not configured correctly, rules using URL Set may not be applied as expected  Urls Included in this set (applicable for HTTP traffic Only"
Question by:ali_alannah
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
LVL 19

Expert Comment

ID: 20365139
Are you using the web proxy or the firewall client?

If you are not, ISA does not see the URL only the IP address.  It then does a reverse lookup on the IP address, but may not get the DNS name you are expecting if the same IP address is used to host multiple web sites.

I recommend that you firstly use Domain Name Sets, unless you want to block/allow specific paths on a site.  Then, review the firewall logs to see the actual site name it is blocking.

You may also choose to use either the Firewall Client or Web Proxy, as it will provide more info to ISA Server.

Remember as well that DENY rules do exactly that.  If you want some authenticated users to have access then that rule will need to come before the DENY rule, but also remember that authenticated rules must come after all non-authenticated rules as they introduce an implicit DENY-ALL for non-authenticated connections.

Author Comment

ID: 20367105
Hello SteveH_UK,
Thanks for your help but please could you make it easy in steps because am newcomer to ISA server so do you mean

1- Using webProxy Or Firewalls client will solve this problem ? Because we are not use Proxy or Firewall clinent ONLY use SecuredNAT , So if this will solve our problem we can config the clients to use one of these (web Proxy or Firewall clients)

2- I dont understand what do u mean "I recommend that you firstly use Domain Name Sets"  , as i explain in my questions am using  as URL SET to allow the client to acces it and using (http://*) as URl set to Deny accet to other all websites
LVL 51

Assisted Solution

by:Keith Alabaster
Keith Alabaster earned 300 total points
ID: 20367982
Add a rule above these two rules you have put in to allow http & https From Internal TO Internal - this assumes that you have your internal web server inside the local area network.

A domain set can be used instead of a url set - url sets follow the http://whatever/* format - domain sets use * style formats without http or https infront of them. this may help but the fact that your rules are working for a while suggests that you have done the job correctly.

Have you run the BPA on your ISA system? You need .net framework 1.1 for this to operate.
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

LVL 19

Accepted Solution

SteveH_UK earned 1200 total points
ID: 20368160
URL Sets and Domain Name Sets are two different types of objects in ISA Server.  A URL Set can include, for example: ""; but a domain name set only includes "".  When you are configuring a rule and are choosing the "To" options, you can create a Domain Name Set the same way as an URL Set.

You do not need to use the firewall client or the web proxy (we didn't for a while), but they do help with diagnosing issues as ISA Server can provide more information, and it also enables user authentication so that you can create per-user rules.  As a general rule, it is a good idea to use the firewall client, but you will need to configure the Internal network to support it.  Have a look at the ISA Server Product Documentation, and then let me know if you need more help, that is if you decide to do either of these.

Make sure you've got the latest updates for ISA Server 2006, as they include a really helpful improvement in the log display.

Can you check that clients can find your company website, because I'm not sure that your DNS rules are ok.  If everyone uses external DNS servers, then you need to create an access rule that allows Internal to External for the DNS protocol.  If you have internal DNS servers, then you still need to do this for your internal DNS servers.  You can check client DNS lookup using:


If then, you are still having problems, try the following:


Then try:

ping -a

where is the IP address that nslookup returns.  What you need to know is whether a reverse DNS lookup on gives  I suspect that it does not, or at least does not consistently.  In these cases, you need to add the reported address to your URL Set or Domain Name Set in ISA Server.
LVL 19

Expert Comment

ID: 20368179
If you are taking on the responsibility for managing an ISA Server, or any firewall, you really must understand TCP/IP, DNS, DHCP and general firewall principles.  Can I recommend that you find a good book, perhaps by SAMS Publishing or Microsoft Press.  The exam kit books tend to be quite good.

Of course, we'll do our best to answer your current problems as quickly as we can!
LVL 51

Expert Comment

by:Keith Alabaster
ID: 20368253
Off topic - Steve - check out my profile at some point and drop me an email if you feel like it.


Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

ISA Server detected routes through the network adapter LAN that do not correlate with the network to which this network adapter belongs What does this mean and how can one go about correcting it? In simple terms, this error message indicates t…
Forefront Threat Management Gateway 2010 or FTMG comes with some very neat troubleshooting tools built-in when trying to identify what is actually happening behind the scenes within the product when traffic is passing through its interfaces. To the …
In this video, Percona Solution Engineer Dimitri Vanoverbeke discusses why you want to use at least three nodes in a database cluster. To discuss how Percona Consulting can help with your design and architecture needs for your database and infras…
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA:…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question