Proxy Server

Discussion in 'Internet, Connectivity and Communications' started by Nelix, Feb 9, 2004.

  1. Nelix
    Honorary Member

    Nelix Gigabyte Poster

    1,416
    3
    82
    Hi All,

    I am currently trying to configure an Proxy server, Before I go any further I will tell you now that the setup is not a setup that I would normally use as it allows the users to bypass the proxy if they want, but no one in the house has that kind of knowledge so until they do, the current setup will have to do.

    The machine that has the proxy software installed has got 2 NIC's each with static IP's. each of these cards is plugged into the switch (not ideal, but I did warn you), however I am having difficulty getting the clients to use the proxy, they just get a message similar to the Error 404 screen but this is issued from the proxy.

    Also virtually all the free IP address's that i have in my DHCP scope have been taken by the proxy and inthe Unique ID column of the DHCP MMC it says RAS.

    Any advice or ideas ?????? :?:
     
    Certifications: A+, 70-210, 70-290, 70-291, 74-409, 70-410, 70-411, 70-337, 70-347
    WIP: 70-346
  2. Nelix
    Honorary Member

    Nelix Gigabyte Poster

    1,416
    3
    82
    Ok, people, dont all rush at once :D

    I sorted it, just sat here for a few hours and used terminal services to change settings on ISA and then test it on the laptop. Still getting the following entry in event viewer on ISA Server though

    Date: 09/02/2004
    Time: 23:35
    Type: Error
    User: N/A
    Computer: Homeproxy

    Source: Microsoft Web Proxy
    Category: None
    Event ID: 14120

    Description:
    the ISA Server services cannot create a packet filter <IP Address>. This event occurs when there is a conflict between the Local Address Table (LAT) configuration and the windows 2000 routing table. Check the routing tale and the LAT to find the sourse of the conflict.


    How do I check the above????????? :?:
     
    Certifications: A+, 70-210, 70-290, 70-291, 74-409, 70-410, 70-411, 70-337, 70-347
    WIP: 70-346
  3. dreec

    dreec Nibble Poster

    59
    0
    19
    Must admit, not really used ISA much.
    To check Win2K rouitng table go to cmd prompt and type route print.
    If you want the display saved in text file try

    route print > c:\route.txt

    this will then output the table to a text file on C drive called...... route.

    If at latter date you wish to append data to text file type

    route print >> c:\route.txt

    This adds to end of previous file.

    Hope this helps
     
    Certifications: To many to list here, to few to matter
    WIP: None
  4. Phil
    Honorary Member

    Phil Gigabyte Poster

    1,680
    7
    87
    Just a thought Derek, have you cofigured the LAT on the ISA Server correctly? You need to tell it what address ranges are on it's prviate network.
     
    Certifications: MCSE:M & S MCSA:M CCNA CNA
    WIP: 2003 Upgrade, CCNA Upgrade
  5. Nelix
    Honorary Member

    Nelix Gigabyte Poster

    1,416
    3
    82
    Never Even seen ISA until i installed it, as far as I am aware I have told ISA the IP range in use on the internal network in the

    Network configuration > Local Address Table (LAT) Section.
     
    Certifications: A+, 70-210, 70-290, 70-291, 74-409, 70-410, 70-411, 70-337, 70-347
    WIP: 70-346
  6. Phil
    Honorary Member

    Phil Gigabyte Poster

    1,680
    7
    87
    Sounds like you configured it right, I did a search on the error you were getting and ms has this KB article
     
    Certifications: MCSE:M & S MCSA:M CCNA CNA
    WIP: 2003 Upgrade, CCNA Upgrade
  7. Nelix
    Honorary Member

    Nelix Gigabyte Poster

    1,416
    3
    82
    yeah, I found the same article when I did a search and although it says you can ignore the error I would rather resolve it but I dont fully understand the creation of the (A) file[/code]
     
    Certifications: A+, 70-210, 70-290, 70-291, 74-409, 70-410, 70-411, 70-337, 70-347
    WIP: 70-346
  8. Phil
    Honorary Member

    Phil Gigabyte Poster

    1,680
    7
    87
    I think what it is saying is that you have an internal web server which is being published by the ISA server and you have a client which is trying to access that web server and it can't cope with trying to loop the requests out then back in so you should create an entry on the internal DNS server to point the client to the internal IP address of the web server.
     
    Certifications: MCSE:M & S MCSA:M CCNA CNA
    WIP: 2003 Upgrade, CCNA Upgrade
  9. Nelix
    Honorary Member

    Nelix Gigabyte Poster

    1,416
    3
    82
    Well that just meant Blahhhhh la la la boo, to me at the moment

    Will have a look tomorrow.

    thanks Phil, will keep you informed.
     
    Certifications: A+, 70-210, 70-290, 70-291, 74-409, 70-410, 70-411, 70-337, 70-347
    WIP: 70-346
  10. Jakamoko
    Honorary Member

    Jakamoko On the move again ...

    9,924
    74
    229
    Gotta say, thats about as much as I understood of it too, Phil :eek: :lol:

    I'll stick to my own department, shall I ?
     
    Certifications: MCP, A+, Network+
    WIP: Clarity
  11. Nelix
    Honorary Member

    Nelix Gigabyte Poster

    1,416
    3
    82
    Just thought I would update you on this and say sorry to phil for disappearing the other night on MSN but as I have mentioned on another post, My server fell over. I have managed to salvage it, to an extent.

    I have set all the IP configuration back to the way it was before I had the ISA online for the time being, however we all seem to be browsing very very slow now ??????????????

    I will keep you updated

    Thanks for all your help phil, will give you a shout when I approach this project again.
     
    Certifications: A+, 70-210, 70-290, 70-291, 74-409, 70-410, 70-411, 70-337, 70-347
    WIP: 70-346
  12. Phil
    Honorary Member

    Phil Gigabyte Poster

    1,680
    7
    87
    No probs Derek, good luck sorting out the speed problems.
     
    Certifications: MCSE:M & S MCSA:M CCNA CNA
    WIP: 2003 Upgrade, CCNA Upgrade
  13. Nelix
    Honorary Member

    Nelix Gigabyte Poster

    1,416
    3
    82
    OK, this was just getting on my nerves all day so I came home and have not moved from the computer until it was sorted.

    Well it's sorted...........to a degree, the ISA server and the DC can conect to the internet through the proxy, when you click on internet explorer you blink and the homepage is there instantly, however when I try to connect to the internet from the main PC when I click on IE it takes approx 20 - 30 seconds to show the homepage, no matter what the homepage is (thats along time when your just staring at the screen waiting) in the bar at the bottom of the IE box it just says Connecting to site <IP address>, once connected I have NO speed problems at all, strange.

    Just going to try the laptop and see what happens when I connect using that

    BRB













    The laptop wont connect (Using Wireless will try cable tomorrow), I have even tried putting the IP address in the proxy address instead of the FQDN still no joy.

    Anyone got any ideas
     
    Certifications: A+, 70-210, 70-290, 70-291, 74-409, 70-410, 70-411, 70-337, 70-347
    WIP: 70-346
  14. Nelix
    Honorary Member

    Nelix Gigabyte Poster

    1,416
    3
    82
    I give up on this one, just seems to be too flakey.

    The laptop connects....sometimes, usually for around 3 web pages then nothing, other times it does not work at all.

    The main PC seems to work the best, however occasionally when you connect to certain sites, iy tou have to login, such as ebay, it just bombs you out with an error 400 page NOT even an error page from the ISA.

    Leaving this for now and going to start the search (again) for a script to log users off at a certain time.
     
    Certifications: A+, 70-210, 70-290, 70-291, 74-409, 70-410, 70-411, 70-337, 70-347
    WIP: 70-346
  15. Taz69

    Taz69 Byte Poster

    125
    0
    26
    If ISA seems oddd then try running the 'Secure Server' wizard which can be found on the ISA console by clicking 'Computer', right clicking your ISA server and selecting Secure. You should only need to select the lowest level of lockdown (Secure) but I did notice strange behaviour with my own ISA before running the wizard.


    On another note why not use ISA to limit when anyone can access the internet?
    First configure a schedule for when access is allowed (Policy Elements>Schedules)
    Then add a Protocol Rule to only allow access to the rest of the house within the schedule that you have created. You'll need to make sure that you don't have a second rule that allows internet access from anyone at anytime otherwise they will still be able to get internet access at other times of the day though.
    If you want to be crafty you could also set up a bandwidth rule to give you preferential access to the internet compared to everyone else :twisted:

    As to the event log message you are getting I hope that your Internal & External NICs on your ISA server are on different subnets. You will have to configure your LAT to include all your internal subnets and not the external subnet. What type of modem/router are you using and can you give a little more info on how it is set up ? How is your ISA set up ie Integrated mode or only as a pure proxy server ?
     
    Certifications: MCSE: S, MCSA:M, MCSA: S, Net+ & 70-284
    WIP: MCSA 2003 & MCSA:Messaging 2003
  16. Bluerinse
    Honorary Member

    Bluerinse Exabyte Poster

    8,878
    181
    256
    I see your ISA studies are coming on nicely Taz!

    I know this thread is old now and I am not sure if Nelix has sorted this problem out or not. Anyway, ISA is probably too complex and over the top for this situation, especially if you aren't too familiar with it. I still get frustrated with ISA and I have been studying/playing with it for months.

    Questions not covered in this thread...

    What type of clients are the computers running i.e. secure NAT/Firewall/Web Proxy?
    Have you enabled routing and IP packet filtering?
    Have you configured allow rules for common protocols?
    Have you configured the LDT (local domain table)
    Have you configured the browser/s proxy settings properly?
    Have you configured the ISA servers cache properly

    ISA is a brilliant product that is packed with features but you do need to know how to drive it.

    Pete
     
    Certifications: C&G Electronics - MCSA (W2K) MCSE (W2K)

Share This Page

Loading...
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.