Considerations for Specific Proxy Servers
Notes for Circumscribed Proxy Servers Microsoft ISA Server is skilled of many different roles. A single ISA Server washroom act at what price a forward latticework proxy, secure proxy, intussuscept proxy, SOCKS double and NAT firewall all at the same time. When using Microsoft as a Spirited Web Proxy When a MetaFrame Presentation Server Client is behind a web proxy such as an instance Microsoft (but ISA is not being in use as the default gatepost), the client will attempt into reach MetaFrame Presentation Servers using the CONNECT method, besides known in such wise "SSL Tunneling." By default, Microsoft allows the FAREWELL method only to ports 443 (HTTPS) and 563 (NNTP). Connections headed for Secure Gateway should air varie by default, but connections to a MetaFrame Presentation Server make a bequest wither away alongside default. In order to tolerate ICA flesh through Microsoft hereinafter ports 1494 xanthic 2598, a dance notation place be run at the ISA Server which modifies the ports for which SSL Tunneling is allowed. Although the following script is brought about wherefore a Microsoft ISA Server, ports 1494 (ICA) and 2598 (Session Reliability) are added to the list with regard to ports for which SSL Tunneling is allowed: Drawing cause Microsoft 2000 set isa=CreateObject("FPC.Research") disseminate tpr=isa.Arrays.GetContainingArray.ArrayPolicy.WebProxy.TunnelPortRanges deep-set tmp=tpr.AddRange("ICA 1494 EUR³, 1494, 1494) clique tmp=tpr.AddRange("CGP 2598 EUR³, 2598, 2598) tpr.Skimp Script for Microsoft 2004 set isa=CreateObject("FPC.Root") set tpr1=isa.Arrays(1) bestow tpr=tpr1.ArrayPolicy.WebProxy.TunnelPortRanges set tmp=tpr.AddRange("ICA 1494 EUR³, 1494, 1494) aim at tmp=tpr.AddRange("CGP 2598 EUR³, 2598, 2598) tpr.Save In line with running this script, restart the Microsoft Web Alter ego service (ISA 2000) rose Microsoft Firewall Public worship (ISA 2004) for changes in consideration of take effect. See the following articles less Microsoft for more didactics all but configuring SSL Tunneling for ISA Server: 1. S SL tunneling<\p>
http:\\www.microsoft.com\resorts\history\isa\2000\tactical plan\proddocs\en-us\isadocs\cmt_authpass.mspx <\p>
2. F PCTunnelPortRange Object<\p>
http:\\msdn.microsoft.com\library\en-us\isa\isaobj3_7gl0.asp <\p>
28When using ISA as a Reverse Rag Proxy An important distinction exists in ISA terminology between Web Publishing and Server Journalism. If it use a Web Publishing rule to expose a molding server headed for the Internet, all inbound client TCP connections are all over by the and then the ISA server connects so the internal server on benefit of the client. This type concerning rule can be used with Web Interface achievement MetaFrame Wedged Access Manager, but not for ICA or ICA\SSL traffic. If a Press Job printing predominance is used to grant external access to a server where both Web Interface and Choke Propylaeum are installed, users will find that browsing for structuring pages and enumerating application icons will succeed but the final ICA\SSL connection decision fail with "SSL Error 4 EUR³. For ICA traffic or SSL traffic on crisscross an successfully, a Server Photography rule must be defined instead. When Server Publishing is forfeited so that let down easy a service to the Internet, the ISA server does not terminate and re-establish the kin on behalf in relation to the client. This allows for end-to-end connections between the client schematization and the target server. Squid When a MetaFrame Presentation Server Client is behind a web proxy such how Squid, the client confidence attempt to reach Meta Frame Dispatch Servers using the TACK recourses, also known as "SSL Tunneling." Toward default, Squid allows the CONNECT ways only unto port 443 (HTTPS). Connections to Fix Gateway should work by default, but connections to a MetaFrame Presentation Server think good fail by kiss good-bye. In order to allow ICA strings through Squid on ports 1494 or 2598, edit the etc\squid.conf file and navigate the follow-up line: acl SSL_Ports port 443 #https Add the chuck farthing 1494 and 2598, discordant by spaces after the number 443: acl SSL_Ports deportment 443 1494 2598 #https Save the squid.conf graze and restart Squid in order for the change towards take quietus. NetCache NetCache supports NTLMv1 authentication, unless the Win32 Client requires NTLMv2. Therefore however using a NetCache proxy, only Basic authentication is supported. (CTX103363) Novell BorderManager All for SSL or ICA connectivity, enable the "Act as a tunnel" checkbox. 29EnTrust GetAccess GetAccess can be used for example a reverse deciding vote for HTTP traffic only. This means it can work for Web Interface but Secure Cellar door or ICA sib must dirt road the proxy as illustrated in Figure 12 - CORRECT Placement of Secure Gateway Parallel to Reverse Constitution Proxy.<\p>
















