Solved

ISA 2006

Posted on 2013-01-06
6
624 Views
Last Modified: 2013-07-10
Hi,


I am unable to open site behind my isa 2006 server.

https://crm.delta.com.tw:8020
0
Comment
Question by:Vshaily
6 Comments
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 38749879
Sorry to hear that.
0
 
LVL 10

Expert Comment

by:cpmcomputers
ID: 38749960
See if this helps


If you're running SBS Premium w/ ISA, then you'll need to add a protocol
definition for TCP 8020. The way ISA works, is that it uses protocol
definitions to define protocol (TCP/UDP/ICMP) and port combinations. It
then uses protocol rules that are based on these definitions as well as
other policy elements like schedules, users, etc. to determin who can go
where when. The effective 'allow all traffic' rule we have in ISA on SBS is
somewhat misleading as it only allows all of the protocols that are
currently defined. If a user tries to access a resource on the internet
using a protocol that is not currently defined in ISA (e.g. TCP 8020), then
ISA is going to deny the outbound request. Adding the new protocol
definition and restarting the Microsoft ISA Server Control service should solve the problem
0
 
LVL 23

Expert Comment

by:Suliman Abu Kharroub
ID: 38750715
create a rule to allow port 8020 from internal to that site.
0
Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

 
LVL 16

Accepted Solution

by:
PaciB earned 500 total points
ID: 38751498
No need to change anything in your rules. You should have an access rule that allow HTTPS to go outside and that's it for the rules...

The problem is that by default ISA/TMG do not allow SSL protocol on any other port than 443.

In your example the URL is https://blahblahblah:8020/... Meaning you want to access a SSL web site on a port that is not 443 !!

You can refer to this article that talks about the same problem : http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/d64b5887-9218-4387-bc95-11906e8bae82/
Even it is not the same port they want to use in the article it's the same cause.

As said in the article you'll have to download the script http://www.isatools.org/tools/isa_tpr.js and use it to allow your specific port 8020 to be used for SSL.
This change wil require a full restart of TMG services, stopping any current connections.


Have a good day.
0
 
LVL 10

Expert Comment

by:cpmcomputers
ID: 38751599
Good Point from PaciB - Missed it was Https:

I had to do the same for Plesk access - SSL on port 8443 - Was ages ago on an SBS2003 box with Isa2004
0
 

Author Comment

by:Vshaily
ID: 38753481
Dear All,

Now i got answer . and it's working fine. I dwonlad this script and run in command prompt of ISA server.

Cscript isa_tpr.js /add Ext8020 8020 . Now it's wprking.  Thanks/
0

Featured Post

Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

Join & Write a Comment

In all versions of ISA Server and the current version of FTMG, the default https protocol uses TCP port 443 and 563 only. This cannot be changed within the ISA or FTMG GUI and must be completed from a Windows cmd prompt on the ISA Server itself. …
Common practice undertaken by most system administrators is to document the configurations and final solutions of anything performed by them for their future use and reference. So here I am going to explain how to export ISA Server 2004 Firewall pol…
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now