Quantcast
Channel: Forefront TMG and ISA Server forum
Viewing all articles
Browse latest Browse all 3822

DirectAccess force tunneling - Web proxy (TMG) needs authentication

$
0
0

Hello,

I have deployed a DirectAccess 2012 server using computer certificate authentication. The clients are connecting to corporate resources over the WAN usin DirectAccess. Forced tunneling is a requirement. The DirectAccess is only configured for IPHTTPS using a single NIC behind a firewall.

But there is a TMG web proxy in the corporate network that authenticates users. When these users connect over the Internet using devices that have DirectAccess enabled, they are not able to visit any sites as TMG blocks the connection. In the TMG logs, I see that the reason it is dropping these web connections are because the traffic is coming from an 'anonymous' user as per the logs.

The TMG proxy rule for Internet access requires user authentication. We are setting the proxy using GPO for all domain computers.

The issue is that when the Direct Access 2012 users are trying to access the Internet (as we are using force tunneling), the Direct Access server does not seem to be passing the user credentials to the reverse proxy. So the reverse proxy is blocking Internet access for these users.

I am seeking answer as to how can I configure Direct Access 2012 so that the domain users who are connected externally are able to browse Internet using the proxy.

Can someone please advise?


SinghP80


Viewing all articles
Browse latest Browse all 3822

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>