Solved

ISA 2006

Posted on 2013-01-06
6
669 Views
Last Modified: 2013-07-10
Hi,


I am unable to open site behind my isa 2006 server.

https://crm.delta.com.tw:8020
0
Comment
Question by:Vshaily
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 38749879
Sorry to hear that.
0
 
LVL 10

Expert Comment

by:cpmcomputers
ID: 38749960
See if this helps


If you're running SBS Premium w/ ISA, then you'll need to add a protocol
definition for TCP 8020. The way ISA works, is that it uses protocol
definitions to define protocol (TCP/UDP/ICMP) and port combinations. It
then uses protocol rules that are based on these definitions as well as
other policy elements like schedules, users, etc. to determin who can go
where when. The effective 'allow all traffic' rule we have in ISA on SBS is
somewhat misleading as it only allows all of the protocols that are
currently defined. If a user tries to access a resource on the internet
using a protocol that is not currently defined in ISA (e.g. TCP 8020), then
ISA is going to deny the outbound request. Adding the new protocol
definition and restarting the Microsoft ISA Server Control service should solve the problem
0
 
LVL 23

Expert Comment

by:Suliman Abu Kharroub
ID: 38750715
create a rule to allow port 8020 from internal to that site.
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 16

Accepted Solution

by:
Bruno PACI earned 500 total points
ID: 38751498
No need to change anything in your rules. You should have an access rule that allow HTTPS to go outside and that's it for the rules...

The problem is that by default ISA/TMG do not allow SSL protocol on any other port than 443.

In your example the URL is https://blahblahblah:8020/... Meaning you want to access a SSL web site on a port that is not 443 !!

You can refer to this article that talks about the same problem : http://social.technet.microsoft.com/Forums/en-US/ForefrontedgeIA/thread/d64b5887-9218-4387-bc95-11906e8bae82/
Even it is not the same port they want to use in the article it's the same cause.

As said in the article you'll have to download the script http://www.isatools.org/tools/isa_tpr.js and use it to allow your specific port 8020 to be used for SSL.
This change wil require a full restart of TMG services, stopping any current connections.


Have a good day.
0
 
LVL 10

Expert Comment

by:cpmcomputers
ID: 38751599
Good Point from PaciB - Missed it was Https:

I had to do the same for Plesk access - SSL on port 8443 - Was ages ago on an SBS2003 box with Isa2004
0
 

Author Comment

by:Vshaily
ID: 38753481
Dear All,

Now i got answer . and it's working fine. I dwonlad this script and run in command prompt of ISA server.

Cscript isa_tpr.js /add Ext8020 8020 . Now it's wprking.  Thanks/
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

There are three types of ISA client that can be configured - these can be individual clients or multiples of a client on each PC or server SecureNAT. A SecureNAT client for ISA server is a client machine, work station or server, that has its defa…
There are several problems reported according slow link speeds or poor performance in TMG 2010, UAG 2010 or ISA 2006. I want to collect here some of the common issues together to give a brief overview what can be the reason. Nevertheless, not all of…
In an interesting question (https://www.experts-exchange.com/questions/29008360/) here at Experts Exchange, a member asked how to split a single image into multiple images. The primary usage for this is to place many photographs on a flatbed scanner…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question