Link to home
Start Free TrialLog in
Avatar of Ross-C
Ross-CFlag for United Kingdom of Great Britain and Northern Ireland

asked on

ISA Server Web Proxy Issue

We used to have an ISA Server Url filtering package which has now expired.  With funds being tight i have implemented an open source url filtering solution which runs on its own machine.  All i need to do is set the default gateway for the users to the new filtering machine for this to work.  My questions are i am having difficulty stopping the client stations from auto discovering the proxy service on ISA i have checked group police settings local machine settings etc.  It seems that even when i uncheck the auto detect web settings box periodically IE searches for a proxy then defaults to using ISA.  If possible i would also like some advice to write a logon script to change the default gateway.  Many Thanks in advance.
ASKER CERTIFIED SOLUTION
Avatar of Kieran_Burns
Kieran_Burns

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Ross-C

ASKER

I would prefer not to if possible as we have that many rules configured, also the new solution does not run as a proxy it runs as a gateway, If i set the proxy IP to the filtering server it doesn't work.  Just a note all our clients have static IP addresses.  I will have a look for a WPAD entry in the DNS.
Avatar of Kieran_Burns
Kieran_Burns

You could always proxy chain the ISA Server then. Just uplink the ISA Server to forward all trafiic to the filtering Server, that way you don't have to change anything on the network
Avatar of Ross-C

ASKER

sound like a good solution how would this affect inbound services.  
Avatar of Ross-C

ASKER

I don't think i can do this because the Untangle web filtering server does not act as a proxy it acts as a network gateway.  Normally the untangle server would sit between the external NIC of ISA and the router. It could also be used to replace the ISA Server.  I don't really want to set it up in this way because we have 4-5 external IPs listening on the ISA box for web, exchange, vpn rdp etc etc.  at the moment the untangle server has two internal IP addresses and does work if i manually set the gateway on the client computer.  The problem is that periodically IExplorer on the clients revert to using the proxy on isa therefore bypassing the URL filtering.
You can still achieve this by Web Proxy chaining, but if you don't want to, then look for the WPAD entry or configure the IE settings in Group Policy.
For reference, and to show how you can chain: http://www.isaserver.org/tutorials/Web-Proxy-Chaining-Form-Network-Routing.html
 
Avatar of Ross-C

ASKER

Thanks for your help, i cannot figure out how to do this i have read the guide at the link above and it asks to  specify the proxy port no. as it does not run as a proxy i am at a loss what to try next.  I know i could put the untangle server inbetween the isa server and the router.  I really don't want to have to reconfigure all of the inbound rules etc.