ISA Clients >> SSL passthrough ISA

by RnJhZGEwMQ » Thu, 06 Apr 2006 18:52:01 GMT

I have a simple problem but can not seem to work it out.

I am using an application that uses SSL TCP 443 to compunicate with a remote
server. When it is passed through the ISA it is getting blocked. I can access
https no problem and if I move the client outside the ISA on a dmz the
application works fine. Even with the client behind the ISA I can telnet on
port 443 with no problems?????



ISA Clients >> SSL passthrough ISA

by Henk Steunenberg (Ms) » Thu, 06 Apr 2006 20:33:22 GMT


Hello,

You'll find several articles on www.isaserver.org about ssl:

http://www.isaserver.org/pages/search.asp?query=ssl

Henk

ISA Clients >> RE: SSL passthrough ISA

by U2hpamF6 » Sun, 09 Apr 2006 16:48:01 GMT

Hi,

I once had a client with a similar SSL problem... It finally turned out that
the Internal network range specified was incorrect (some internet IP
addresses were part of internal). Monitoring shows Source and Destination as
"Internal" - Failed Connection Attempt - and SSL simply doesnt work!

I'm sure this may not be your case, but just a thought!

Are you getting a "Denied Connection" in the ISA Monitoring/Logging tab?

Shijaz

ISA Clients >> SSL passthrough ISA

by RnJhZGEwMQ » Mon, 10 Apr 2006 16:40:02 GMT

I managed to resolve the issue. i had to add a rule to say allow non
authenticated trafic to the destination IP:443

Thanks

Similar Threads

1. Passthrough for ISA Proxy - passthrough

I was wondering if there was a way so users do NOT get a logon/password
when going through my ISA2k4.  The server is acting as a proxy only.

Here is the hard part.  I need to log their username. I know that I can
uncheck the "require all uses to authenticate" but will that still give
me the user information that I need? If not then how do I tie in the AD
so that I do not have the prompt?

Now,  This is NOT a firewall.  I am using it as a proxy server and it
is on the Domain with the users in question. This server has no outside
interface, and will be kept inside my domain.  I want to see who is
going where from this one segment. I will set this up as an internal
firewall once I get this part done so I can limit access to internal
resources.

If I am not making sence please let me know
Any Ideas?

2. ISA with full passthrough for use with GFI WebMonitor

3. ISA Passthrough to Internal FTP Server

I am running and SBS 2003 server including ISA 2004.  I want to set up 
another machine on the internal network that will host an FTP server (looking 
at Globalscape's SecureFTP Server but open to others).  Basically we have 
clients that we want to provide unique accounts to where they can put and get 
files specific to their account and everyone internally has access to each 
account's folders (root level for the FTP Server).

My SBS server is a dual-nic server (external WAN + internal LAN) so I am 
thinking I need to set up an access rule that will allow any FTP traffic 
(port 21) coming into to the server to be passed to this second machine 
running the FTP server.  Am I on the right track?  What is it/what are the 
steps I should follow to set this up?  Since the other internal XP clients 
can see the internal FTP server without having to go through the SBS I am 
thinking I don't have to make any changes for them.  Right?  I'm also open to 
suggestions

Thanks!

-Richard K

4. ISA passthrough to computer (IP address) - ISA Configuration

5. VPN/IPSEC-Passthrough with ISA 2k problem

Hi All

I am trying to set up the following vpn connection with IPSEC/NAT-T:
Client (1) in Lan -> ISA2000 (2) -> Firewall/Netscreen (3) -> DSL-Router -> 
Internet -> Remote Zywall Firewall/Server (4)

Just behind my firewall (3) I can establish a connection without any 
problem. Behind the ISA2000 (2) I am not able to connect. I followed the 
article of T. Shinder on www.isaserver.org "How to pass IPSec traffic 
through ISA Server" to open the ISA.I opened:
Port 500 UDP (send/receive)
Port 4500 UDP (send/receive)

Question 1: How can I test, if these ports 500/4500 UDP are really open on 
ISA2000 and traffic is passing?

(I tried the freeware-tool "Port QueryUI.exe" from Microsoft to verify that 
the ports on the ISA are really opened. But the result does not help a lot)

Question 2: Is there a way to do "diagnostic" logging on ISA 2000 to see, if 
traffic is passing these ports?

Question 3: Are there any other ports I do have to open for the Zyxel Remote 
Security Client (which is a SafeNet SoftRemoteLT Client)? I can't find any 
information on any other ports and Zyxel has not answered my demand yet.

Any help would be very much appreciated.

Best regards

Simon 


6. PPTP Passthrough from behind ISA 2004

7. PPTP Passthrough from behind ISA 2004 [RESOLVED]

"Jim in Arizona" < XXXX@XXXXX.COM > wrote in message 
news:% XXXX@XXXXX.COM ...
> Anyone know how to allow my internal users to connect to a VPN server out 
> on the internet from behind the ISA 2004 box?

I was able to fix it all of the sudden. I just created a new rule allowing 
outbound access for all the VPN protocols for all users. It's odd because 
the only other rule that was already there (besides the default deny all 
rule) was a rule to allow all traffic, all protocols for all users. I 
wouldn't think you'd have to create an additional rule specifiying the VPN 
protocols but I did and it then worked.