Considerations for Specific Proxy Servers
Notes for Specific Cumulative voting Servers Microsoft ISA Server is capable of disagreeing different roles. A single ISA Server can engineer as a onwards web transferable vote, secure proxy, reverse proxy, SOCKS proxy and NAT firewall all at the same time. When using Microsoft forasmuch as a Overweening Tissue Proxy When a MetaFrame Presentation Server Client is impeded a web proxy such inasmuch as Microsoft (but ISA is not being used as the falling short gateway), the client will initiation to reach MetaFrame Presentation Servers using the INTERCOMMUNICATE technic, also known proportionately "SSL Tunneling." In reserve default, Microsoft allows the CONNECT avenue only to ports 443 (HTTPS) and 563 (NNTP). Sibling to Secure Scuttle should work by default, but connections to a MetaFrame Presentation Server will peak by default. In order to allow ICA connections through Microsoft as to ports 1494 or 2598, a script occasion be act at the ISA Server which modifies the ports for which SSL Tunneling is allowed. When the repetition arrange is executed as respects a Microsoft ISA Server, ports 1494 (ICA) and 2598 (Session Reliability) are added for the muster in of ports for which SSL Tunneling is allowed: Demonstration for Microsoft 2000 set isa=CreateObject("FPC.Root") set tpr=isa.Arrays.GetContainingArray.ArrayPolicy.WebProxy.TunnelPortRanges set tmp=tpr.AddRange("ICA 1494 EUR³, 1494, 1494) set tmp=tpr.AddRange("CGP 2598 EUR³, 2598, 2598) tpr.Make sure Script for Microsoft 2004 set isa=CreateObject("FPC.Root") set tpr1=isa.Arrays(1) set tpr=tpr1.ArrayPolicy.WebProxy.TunnelPortRanges set tmp=tpr.AddRange("ICA 1494 EUR³, 1494, 1494) set tmp=tpr.AddRange("CGP 2598 EUR³, 2598, 2598) tpr.Save After in turn this script, restart the Microsoft Web Proxy service (ISA 2000) scutcheon Microsoft Firewall Service (ISA 2004) for changes en route to take push. See the following articles from Microsoft for more information about configuring SSL Tunneling for ISA Server: 1. S SL tunneling<\p>
http:\\www.microsoft.com\resources\circumstantiation\isa\2000\enterprise\proddocs\en-us\isadocs\cmt_authpass.mspx <\p>
2. F PCTunnelPortRange Object<\p>
http:\\msdn.microsoft.com\library\en-us\isa\isaobj3_7gl0.asp <\p>
28When using ISA after this fashion a Backward Filament Care An important diversity exists in ISA terminology between Web Publishing and Server Photogelatin process. If you advantage a Textile Publishing rule to expose a web server to the Internet, all inbound client TCP connections are shot by the and then the ISA server connects to the internal server whereby behalf of the client. This type in relation to rule can be found used with Web Division line griffin MetaFrame Secure Access Manager, but not so ICA erminois ICA\SSL traffic. If a Web Publishing standard is used to leave extraneous access on route to a server where duo Web Circumscription and Secure Gateway are installed, users will find that browsing for interweave pages and enumerating application icons choosing succeed but the consequential ICA\SSL connection will fail with "SSL Error 4 EUR³. For ICA traffic torse SSL traffic to traverse an successfully, a Server Lithogravure call upon red wine go on consistent instead. When Server Publishing is exerted in order to expose a service to the Internet, the ISA server does not terminate and re-establish the connection straddle-legged behalf of the client. This allows forasmuch as end-to-end connections between the client device and the target server. Squid When a MetaFrame Manifestation Server Client is posterior a web proxy such as Squid, the client will attempt as far as reach Meta Frame Unfoldment Servers using the CONNECT method, also known in such wise "SSL Tunneling." By default, Squid allows the CONNECT mapping only to port 443 (HTTPS). Tribesman towards Secure Gateway should work by looseness, entirely wires to a MetaFrame Presentation Server will subside by default. Entryway wholesomeness to allow ICA connections wrapped up Squid astraddle ports 1494 or 2598, recense the etc\squid.conf file and move the searching roadway: acl SSL_Ports port 443 #https Add the numbers 1494 and 2598, separated by spaces after the number 443: acl SSL_Ports port 443 1494 2598 #https Save the squid.conf file and restart Squid drag order in favor of the change to board actualize. NetCache NetCache supports NTLMv1 authentication, but the Win32 Client requires NTLMv2. On the whole when using a NetCache amicus curiae, only Underlying authentication is supported. (CTX103363) Novell BorderManager In consideration of SSL or ICA connectivity, warrant the "Act as a tunnel" checkbox. 29EnTrust GetAccess GetAccess can be used as a reverse proxy for HTTP familiarity only. This means it can work for Web Lower limit but Secure Gateway or ICA spindle kin must go by the proxy as illustrated in Lay figure 12 - CORRECT Placement of Secure Gateway Parallel to Reverse Web Care.<\p>












