Quantcast
Channel: Forefront TMG and ISA Server forum
Viewing all articles
Browse latest Browse all 3822

Need to set up a custom HTTP protocol

$
0
0

I need to create a protocol definition for HTTP which doesn't include the Web Proxy Filter to workaround a problem as specified in this blog:

http://blogs.technet.com/b/isablog/archive/2006/09/25/why-do-i-need-a-deny-rule-to-make-an-allow-rule-for-a-custom-protocol-work-correctly.aspx

"To allow the nonstandard HTTP traffic, you need to create two access rules:

  • An access rule that uses the CustomHTTP protocol andallows traffic from <source>to the computer object representing the nonstandard HTTP server.
  • An access rule that uses the predefined HTTP protocol anddenies traffic from <source> to the computer object representing the nonstandard HTTP server.

The new allow rule must come before your original rule that allows HTTP traffic from <source> to the External network in the ordered list of policy rules, and the new deny rule should be placed immediately after the new allow rule."

I created a new protocol, choosing TCP port 80 outbound and made sure not to add the HTTP Proxy Filter. I must be doing something wrong because the access rule that I created (similar to the Allow rule above) using the custom protocol is skipped over when the source client tries to access the destination URL specified in the rules. It goes right to the Deny rule (similar to the one mentioned above).

The difference is that the Deny rule (which has the Web Proxy Filter) shows up under the Web Access Policy, whereas the Allow rule (with no Web Proxy Filter) only shows under the Firewall Policy. I believe this is a clue that I didn't create the protocol correctly, but I can't see any other way to do it.

Thanks in advance for any help on this. By the way, the reason I need to do this is because the Windows 10 1511 Update will not sync with a WSUS that is behind TMG. It seemed to work for another person affected. See my post for that issue:

https://social.technet.microsoft.com/Forums/windowsserver/en-US/94bc7f2c-03e7-4add-9b66-f541906d9ae0/one-esd-file-not-downloading?forum=winserverwsus


Viewing all articles
Browse latest Browse all 3822

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>