Solved

Some web site fail to load properly when anonymous access blocked

Posted on 2008-06-17
2
629 Views
Last Modified: 2011-10-19
Hello all -

I have an ISA 2004 implementation that has an issue.  All users use IE set to use the ISA server as a proxy.  This works well and we are getting usernames in the logs and are able to restrict browsing nicely.

Our setup is fairly basic - we have a simple rule ("Allow All Out") that allows all authenticated users out to all sites EXCEPT the domain names sets we specify.  These sets are things like porn sites, gambling sites, etc.  If a user goes to one of them, they "fall through" the "Allow All Out" rule and get blocked by the default rule.

However, there are some sites that fail to load properly because we do not allow anonymous connections.  For example (not a work related one) - www.sportsline.com.  When a user tries to go there we see the request from the user ok, but then there are several anonymous requests that get blocked and the page fails to load properly.  Here is a snipit of the ISA monitoring log -

Authenticated Client      Service      Server Name      Destination Host Name      Transport      HTTP Status Code      Destination IP      Destination Port      Protocol      Action      Rule      Client IP      Client Username      HTTP Method      URL                  
Yes      Proxy      ISA-HQ      www.sportsline.com      TCP      200 OK      64.30.236.34      80      http      Allowed Connection      Allow all out      192.168.0.8      xxx\Administrator      GET      http://www.sportsline.com/                  
No      Proxy      ISA-HQ      images.sportsline.com      TCP      12202 The ISA Server denied the specified Uniform Resource Locator (URL).       192.168.0.10      8080      http      Denied Connection      Default rule      192.168.0.8      anonymous      GET      http://images.sportsline.com/css/mccfavorites.css                  
Yes      Proxy      ISA-HQ      www.sportsline.com      TCP      200 OK      64.30.236.34      80      http      Allowed Connection      Allow all out      192.168.0.8      xxx\Administrator      GET      http://www.sportsline.com/data/community/remote-profile/mcc-top-members?as=json&callback=CBSi_renderMember                  
No      Proxy      ISA-HQ      images.sportsline.com      TCP      12202 The ISA Server denied the specified Uniform Resource Locator (URL).       192.168.0.10      8080      http      Denied Connection      Default rule      192.168.0.8      anonymous      GET      http://images.sportsline.com/images/cbss/ui2/h_btn.gif                  
No      Proxy      ISA-HQ      images.sportsline.com      TCP      12202 The ISA Server denied the specified Uniform Resource Locator (URL).       192.168.0.10      8080      http      Denied Connection      Default rule      192.168.0.8      anonymous      GET      http://images.sportsline.com/images/cbss/ui2/f_btn.gif
                  
(I know that is hard to read so I attached it as a file as well.)

What you see is the user (xxx\Administrator) going to www.sportline.com  and that is allowed by the "allow all out" rule.  This is so because the site is not one of our blocked sites and the user was able to authenticate.

Next, there is a request to images.sportsline.com that is denied as it is an anonymous request - hence the authentication rule fails and the default rule blocks it.

The only way I have been able to address this is to create a rule allowing *.sportsline.com for All Users before our authentication rules.  This allows the anonymous connection to work.  It is as if the page is making these anonymous requests and not the user, hence the lack of authentication and the failures.  Of course, we now lose the logging for users going to that site as they are hitting the rule which allows all users and we do not get authentication.

Hope this makes sense.  

If anyone could tell me why this is happening and how to correct it I would be most appreciative.

Thanks in advance!



isa-log.xls
0
Comment
Question by:dasmail2000
2 Comments
 
LVL 6

Accepted Solution

by:
Nyah247 earned 500 total points
ID: 21807011
Some websites will just not work with authentication turned on.  Poor coding usually...

You can add it to your bypass rule by going to Configuration > Networks > Internal > properties > web browser and add the *.domain.com to the "Directly access these servers or domains".  

Another option is as you mentioned...  Create an All Users rule.  I do have a rule in my configuration just for that.  I add common work related sites to this as well as a few of the liesure sites which have known issues.
0
 
LVL 1

Author Closing Comment

by:dasmail2000
ID: 31467920
That was what I thought the answer was...but it is good have a second opinon.

Thanks!
0

Featured Post

Free Tool: Postgres Monitoring System

A PHP and Perl based system to collect and display usage statistics from PostgreSQL databases.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Windows Updates / WSUS before joining domain with proxy 2 551
Issue with ISA 2006 Automatic Detection 5 646
Firewall Rule 1 280
IRM and Office 2016 5 394
I have been asked to explain on many, many occasions the correct way to setup network cards and DNS settings on ISA Server 2004, 2006 and forefront Threat management gateway (FTMG) and have willing done so. I have also promised my self everytime tha…
So the following errors occurs in 2 ways that I am aware of at this stage, and you receive one of the following error messages: ERROR 1. When trying to save a rule: No Web listener is specified for the Web publishing rule Autodiscovery Publishin…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question