TMG web proxy

Posted on 2012-03-13
Last Modified: 2012-03-14
Hi all

When I'm putting TMG proxy settings like http://proxy:8080/wpad.dat in client IE no internet is available...

TMG log show that clients try to connect to http://"RRAS_IP":8080 ...

I have check NIC binding order and Internal is on top.. RRAS in bottom.

Any ideas on how to get the clients not to connect to TMG RRAS IP's ??

Question by:jakobmarkussen
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
  • 3

Author Comment

ID: 37713434
I found this in wpad:

DirectNames=new MakeNames();
function MakeProxies(){
this[0]=new Node("",1443312282,1.000000); should be ..

So I found this:

After doing a little digging, I've found that this is actually a known issue with TMG.  If changing the binding order of the Network Interfaces doesn't help...either of the following can help with this issue.

1. Change to a static range of addresses for the VPN client.


2. Run the script found at the following link.  The blog references ISA 2006, but the script does work on TMG as well.  This script will force TMG to use it's fully qualified domain name in the autoconfig script (instead of IP).

Some things to note before trying this script.
-It will restart the Firewall service, so you may want to try it afterhours.
-It may take a few minutes for the change to apply.
-Verify TMG's FQDN and make sure that internal clients will resolve this name to before running the script.

Richard Barker (MSFT)

Will it be "safe" to run this script on TMG?
LVL 51

Accepted Solution

Keith Alabaster earned 500 total points
ID: 37717006
Yes - it is safe to do so but I am not fully informed on your whole setup so implications on your environment cannot be assessed or qualified here. That said, Richard is one of the good guys at MS, However, I have not personally used it on TMG as I do not use wpad files anymore.


Author Closing Comment

ID: 37717068
Ok i will give it a go. Thanks. Could i ask why you don't use wpad?
NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

LVL 51

Expert Comment

by:Keith Alabaster
ID: 37717219
Sure - we use a .pac file which we use through GPO. Like a wpdat entry, it only operates when on the LAN and ignored when laptop users etc go off-site. The plus is that it is applied when VPN users connect.
LVL 29

Expert Comment

ID: 37717471
When I'm putting TMG proxy settings like http://proxy:8080/wpad.dat in client IE no internet is available...

Get rid of the "8080".
Change it to http://proxy/wpad.dat,...
In fact you should create a CNAME entry in DNS called "wpad" and point it at the A Record of the ISA Server.  So the url becomes:
Then create the Option 252 "WPAD" in DHCP using that same URL.
This way Autodetection will work with both DNS and DHCP instead of DHCP only.
The Browser will not require any settings at all except enabling the first Checkbox for Autodetection.

WPAD is not published on 8080, is published on 80.   Yes, there are Technet articlaes that say "8080",...yes, they are wrong,...yes, I have told MS about it multiple times, they haven't done anything about it, falls on deaf ears.

"8080" is used for Web Request from Web Proxy Clients,....not WPAD.
LVL 29

Expert Comment

ID: 37717475
LVL 51

Expert Comment

by:Keith Alabaster
ID: 37717491
Just for reference, I used to use 8080 for mine but no users were happy with the unfortunate delay that using the Auto detect option can introduce.

Author Comment

ID: 37717580
Thanks. I'll look at port 80 instead.
LVL 29

Expert Comment

ID: 37720055
Just for reference, I used to use 8080 for mine but no users were happy with the unfortunate delay that using the Auto detect option can introduce.

That left you with two things at once trying to listen on 8080.  Normal browser web requests are sent to ISA/TMG on 8080.  Maybe that was the cause of the delay.  My WPAD process happens in the "blink of an eye", keeping everything on the defaults.
LVL 29

Expert Comment

ID: 37720069
Oh, were using a PAC file?  So it was stored on a different "web server" instead of the ISA/TMG,...that should have been ok.

There was an IE patch out that was supposed to fix the unreasonable autodetect delay.  I had to apply it on a few machines in the past,..but haven't seen the problem now in over a year.

Author Comment

ID: 37720099

No it was keith_alabaster that used PAC file...
I use (or try to use) wpad.

I tried running the script by Richard Barker on a test TMG server, and it seems to work.
I will change to port 80 as you mention.

By the way - publishing by DNS wouldn't that be a problem on clients in branch offices behind another TMG?
LVL 29

Expert Comment

ID: 37720224
Only if they also are set to use WPAD too.   WPAD is global for everyone using the same AD/DNS structure.   If you have "exceptions" to that then you would continue to let the bulk of the Clienta use WPAD normally and then for the smaller groups of exceptions they would not use WPAD (disable the first auto detect checkbox in IE) but would still use proxy autodetection (enable only the second autodetect checkbox in IE,...the one that lets you give it a static URL to the script)

Remember that WPAD and Proxy Autodetection are two separate things.  WPAD autodetects the Script, not the Proxy, is the Script that then detects the proxy afterwards.

Featured Post

Simple, centralized multimedia control

Watch and learn to see how ATEN provided an easy and effective way for three jointly-owned pubs to control the 60 televisions located across their three venues utilizing the ATEN Control System, Modular Matrix Switch and HDBaseT extenders.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
In Which situation we need to add static routes 10 74
Powerline Adapter - Unidentified network 9 80
Low ampere 10 107
Cisco 3650 switch 1G port to 10G port 6 30
Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
Most of the applications these days are on Cloud. Cloud is ubiquitous with many service providers in the market. Since it has many benefits such as cost reduction, software updates, remote access, disaster recovery and much more.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor ( If you're looking for how to monitor bandwidth using netflow or packet s…

740 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question