Networking Help
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationNetworking Help

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old June 1st, 2009, 04:43 PM
pheven's Avatar
pheven pheven is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2007
Location: the high seas
Posts: 123 pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 Day 20 h 52 m 6 sec
Reputation Power: 18
A veritable conundrum

Hello all,

I have a question which I am stumped on. I have a unix box which needs to access the internet through an ISA server.

The IP address of the unix machine falls within the local range set up on the ISA server, which appears to be correctly configured.

When you attempt to connect to any web page, the browser status bar says "website found, waiting for reply" and then the status bar shows "connecting to XXXX (ISA server name)".

TCP traffic is going out, because I am able to use a chat program and connect with external IP's. I am just not sure what would be blocking my HTTP, when everything looks good in the ISA server.

I am new to ISA servers, and any help like a checklist to go down or pointers in the right direction would be immensely appreciated.

Tech Info:
Unix machine running HP-UX 10.20
ISA Server version is 2004
Running on Windows Server 2003

Thanks for any help,
Phelan
__________________
theHobbes

Reply With Quote
  #2  
Old June 1st, 2009, 05:35 PM
Doug G Doug G is offline
Grumpier Old Moderator
Dev Shed God 15th Plane (12000 - 12499 posts)
 
Join Date: Jun 2003
Posts: 12,211 Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level) 
Time spent in forums: 1 Month 1 Week 3 Days 3 h 32 m 41 sec
Reputation Power: 1969
What is routing to the internet? ISA server is a firewall, not a router. Going 'through' ISA server kind of implies your unix machine is connected to a LAN network interface, and a 2nd interface is in the ISA server connected to the internet, and the ISA server machine is also doing the Internet sharing.
__________________
======
Doug G
======
I didn't attend the funeral, but I sent a nice letter saying I approved of it. --Mark Twain

Reply With Quote
  #3  
Old June 1st, 2009, 06:59 PM
pheven's Avatar
pheven pheven is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2007
Location: the high seas
Posts: 123 pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 Day 20 h 52 m 6 sec
Reputation Power: 18
Thanks for the quick reply Doug-

Yes, the unix machine is on the LAN and is set to connect out through the ISA server- can the ISA server also be a proxy server? In this case, would the traffic go something like this:

unix box > switch > ISA (Proxy) > gateway > internet?

Thanks for bearing with me, I am trying to get it all layed out in my head.

-Phelan

Reply With Quote
  #4  
Old June 1st, 2009, 09:24 PM
Doug G Doug G is offline
Grumpier Old Moderator
Dev Shed God 15th Plane (12000 - 12499 posts)
 
Join Date: Jun 2003
Posts: 12,211 Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level) 
Time spent in forums: 1 Month 1 Week 3 Days 3 h 32 m 41 sec
Reputation Power: 1969
Quote:
can the ISA server also be a proxy server? In this case, would the traffic go something like this:
I'm sorry, beyond what I already mentioned I don't have any idea what capabilities ISA server offers. It may also have proxy capabilites, ISA server showed up about the time Microsoft killed Proxy Server.

Nowdays I use either external hardware routers or linux machines for any networking stuff.

Reply With Quote
  #5  
Old June 2nd, 2009, 07:23 AM
sporky12 sporky12 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2004
Posts: 298 sporky12 User rank is First Lieutenant (10000 - 20000 Reputation Level)sporky12 User rank is First Lieutenant (10000 - 20000 Reputation Level)sporky12 User rank is First Lieutenant (10000 - 20000 Reputation Level)sporky12 User rank is First Lieutenant (10000 - 20000 Reputation Level)sporky12 User rank is First Lieutenant (10000 - 20000 Reputation Level)sporky12 User rank is First Lieutenant (10000 - 20000 Reputation Level)sporky12 User rank is First Lieutenant (10000 - 20000 Reputation Level)sporky12 User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 1 Day 17 h 38 m 56 sec
Reputation Power: 138
Quote:
Originally Posted by pheven
Hello all,

I have a question which I am stumped on. I have a unix box which needs to access the internet through an ISA server.

The IP address of the unix machine falls within the local range set up on the ISA server, which appears to be correctly configured.

When you attempt to connect to any web page, the browser status bar says "website found, waiting for reply" and then the status bar shows "connecting to XXXX (ISA server name)".

TCP traffic is going out, because I am able to use a chat program and connect with external IP's. I am just not sure what would be blocking my HTTP, when everything looks good in the ISA server.

I am new to ISA servers, and any help like a checklist to go down or pointers in the right direction would be immensely appreciated.

Tech Info:
Unix machine running HP-UX 10.20
ISA Server version is 2004
Running on Windows Server 2003

Thanks for any help,
Phelan

Make sure you have a network rule that allows trafic from internal network to the internet network (external)
Also if your nating and not routing

Check your firewall policy rules to make sure your not blocking port 80 traffic

Reply With Quote
  #6  
Old June 2nd, 2009, 04:56 PM
pheven's Avatar
pheven pheven is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2007
Location: the high seas
Posts: 123 pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 Day 20 h 52 m 6 sec
Reputation Power: 18
thanks for the replies-

yeah, I have no idea about the proxy server. I have a sneaking suspicion that there might be a layer I have yet to peel back in the ISA server.

Also, that rule is configured for the range the unix machine falls into. The traffic is going out to the proxy server (wherever that is, my current network admins are not entirely competent) and summarily internet via port 8080.

I went ahead and did a traffic capture while i attempted to connect to the internet on the unix box. I got an access denied packet pack, so I am assuming that I'm not providing the right credentials, which is kind of weird...

So my question now is, do I need to setup an account for the unix machine, or should I be able to provide my own network credentials to connect?

Yeesh! I may, of course, be on the completely wrong track...

Reply With Quote
  #7  
Old June 3rd, 2009, 08:40 AM
seack79 seack79 is offline
Contributing User
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: May 2004
Location: surfing the interwebz
Posts: 1,917 seack79 User rank is General 12nd Grade (Above 100000 Reputation Level)seack79 User rank is General 12nd Grade (Above 100000 Reputation Level)seack79 User rank is General 12nd Grade (Above 100000 Reputation Level)seack79 User rank is General 12nd Grade (Above 100000 Reputation Level)seack79 User rank is General 12nd Grade (Above 100000 Reputation Level)seack79 User rank is General 12nd Grade (Above 100000 Reputation Level)seack79 User rank is General 12nd Grade (Above 100000 Reputation Level)seack79 User rank is General 12nd Grade (Above 100000 Reputation Level)seack79 User rank is General 12nd Grade (Above 100000 Reputation Level)seack79 User rank is General 12nd Grade (Above 100000 Reputation Level)seack79 User rank is General 12nd Grade (Above 100000 Reputation Level)seack79 User rank is General 12nd Grade (Above 100000 Reputation Level)seack79 User rank is General 12nd Grade (Above 100000 Reputation Level)seack79 User rank is General 12nd Grade (Above 100000 Reputation Level)seack79 User rank is General 12nd Grade (Above 100000 Reputation Level)seack79 User rank is General 12nd Grade (Above 100000 Reputation Level) 
Time spent in forums: 1 Week 5 Days 12 h 42 m 59 sec
Reputation Power: 1760
Quote:
and summarily internet via port 8080


I could be wrong here, but most web browsing is done over port 80, this could be part of the problem if 80 is blocked or no rule is setup?

Reply With Quote
  #8  
Old June 3rd, 2009, 05:46 PM
pheven's Avatar
pheven pheven is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2007
Location: the high seas
Posts: 123 pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 Day 20 h 52 m 6 sec
Reputation Power: 18
You are certainly correct- http runs over port 80 generally. However I believe they have 8080 set up as a the port for the traffic requests to come into the Proxy Server, not the actual external internet.

Reply With Quote
  #9  
Old June 3rd, 2009, 07:25 PM
Doug G Doug G is offline
Grumpier Old Moderator
Dev Shed God 15th Plane (12000 - 12499 posts)
 
Join Date: Jun 2003
Posts: 12,211 Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level) 
Time spent in forums: 1 Month 1 Week 3 Days 3 h 32 m 41 sec
Reputation Power: 1969
Port 8080 is normally used as an alternate http port, in fact it's listed as such in the list of well known ports. For example, I use a linux web control panel ispconfig and it runs a 2nd webserver for it's own use on port 8080. So on that server I need to have both port 80 and 8080 open through the firewall and router.

Reply With Quote
  #10  
Old June 4th, 2009, 08:36 AM
sporky12 sporky12 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2004
Posts: 298 sporky12 User rank is First Lieutenant (10000 - 20000 Reputation Level)sporky12 User rank is First Lieutenant (10000 - 20000 Reputation Level)sporky12 User rank is First Lieutenant (10000 - 20000 Reputation Level)sporky12 User rank is First Lieutenant (10000 - 20000 Reputation Level)sporky12 User rank is First Lieutenant (10000 - 20000 Reputation Level)sporky12 User rank is First Lieutenant (10000 - 20000 Reputation Level)sporky12 User rank is First Lieutenant (10000 - 20000 Reputation Level)sporky12 User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 1 Day 17 h 38 m 56 sec
Reputation Power: 138
If I am not mistaken all traffic in the ISA is blocked by a firewall rule. So unless acted on by a Network rule or another firewall rule the port is blocked. If you need 8080 open you would need to create a new Firewall rule for that.

Reply With Quote
  #11  
Old June 5th, 2009, 07:06 PM
pheven's Avatar
pheven pheven is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2007
Location: the high seas
Posts: 123 pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 Day 20 h 52 m 6 sec
Reputation Power: 18
Cool, did not know that about port 8080 being an http alternate. However, I believe my port 8080 is open, as other machines in the network can browse traffic just fine.

Reply With Quote
  #12  
Old June 5th, 2009, 09:40 PM
Doug G Doug G is offline
Grumpier Old Moderator
Dev Shed God 15th Plane (12000 - 12499 posts)
 
Join Date: Jun 2003
Posts: 12,211 Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level)Doug G User rank is General 15th Grade (Above 100000 Reputation Level) 
Time spent in forums: 1 Month 1 Week 3 Days 3 h 32 m 41 sec
Reputation Power: 1969
Look here for the iana list of well-known ports http://www.iana.org/assignments/port-numbers, but keep in mind there are no hard and fast rules that force ports to be used by a particular service, developers can pretty much put any service on any port they want.

You can also find Microsoft's abridged wkp list in \windows\system32\drivers\etc\services, at least on my W2003 server.

Reply With Quote
  #13  
Old June 9th, 2009, 12:20 AM
Sepodati's Avatar
Sepodati Sepodati is online now
Banned
Dev Shed God 19th Plane (14000 - 14499 posts)
 
Join Date: Dec 1999
Location: Kentucky
Posts: 14,445 Sepodati User rank is General 31st Grade (Above 100000 Reputation Level)Sepodati User rank is General 31st Grade (Above 100000 Reputation Level)Sepodati User rank is General 31st Grade (Above 100000 Reputation Level)Sepodati User rank is General 31st Grade (Above 100000 Reputation Level)Sepodati User rank is General 31st Grade (Above 100000 Reputation Level)Sepodati User rank is General 31st Grade (Above 100000 Reputation Level)Sepodati User rank is General 31st Grade (Above 100000 Reputation Level)Sepodati User rank is General 31st Grade (Above 100000 Reputation Level)Sepodati User rank is General 31st Grade (Above 100000 Reputation Level)Sepodati User rank is General 31st Grade (Above 100000 Reputation Level)Sepodati User rank is General 31st Grade (Above 100000 Reputation Level)Sepodati User rank is General 31st Grade (Above 100000 Reputation Level)Sepodati User rank is General 31st Grade (Above 100000 Reputation Level)Sepodati User rank is General 31st Grade (Above 100000 Reputation Level)Sepodati User rank is General 31st Grade (Above 100000 Reputation Level)Sepodati User rank is General 31st Grade (Above 100000 Reputation Level)  Folding Points: 97169 Folding Title: Advanced FolderFolding Points: 97169 Folding Title: Advanced FolderFolding Points: 97169 Folding Title: Advanced FolderFolding Points: 97169 Folding Title: Advanced FolderFolding Points: 97169 Folding Title: Advanced Folder
Time spent in forums: 3 Months 2 Days 19 h 29 m 41 sec
Reputation Power: 3067
Send a message via ICQ to Sepodati Send a message via Yahoo to Sepodati
What are you using to access HTTP on the unix box? If it's a browser is it configured to use the ISA as a proxy and to send requests on port 8080? If it's not a browser, is it proxy aware? You generally have to tell the spplications manually to use a proxy & port.

Reply With Quote
  #14  
Old June 10th, 2009, 06:59 PM
pheven's Avatar
pheven pheven is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2007
Location: the high seas
Posts: 123 pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 Day 20 h 52 m 6 sec
Reputation Power: 18
Quote:
Originally Posted by Sepodati
What are you using to access HTTP on the unix box? If it's a browser is it configured to use the ISA as a proxy and to send requests on port 8080? If it's not a browser, is it proxy aware? You generally have to tell the spplications manually to use a proxy & port.


I am using netscape on the unix box- i have the ISA proxy and port 8080 specified in the settings. I even set up a new account and input the settings from scratch, but still no dice.

Reply With Quote
  #15  
Old June 30th, 2009, 06:52 PM
pheven's Avatar
pheven pheven is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2007
Location: the high seas
Posts: 123 pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level)pheven User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 Day 20 h 52 m 6 sec
Reputation Power: 18
Hi all,

Don't mean to resurrect this thread, but I though someone might be interested in the solution.

I had to go ahead and configure a rule in the ISA server firewall that allowed anonymous connections through the firewall from the unix box IP address to external and internal address (outside and inside the firewall). This bypassed the need for authentication (which, for whatever reason, I was unable to configure correctly). Now the box can browse through the proxy without problems.

Thanks for all the help and ideas, glad I got it licked finally!

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationNetworking Help > A veritable conundrum


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump




 Free IT White Papers!
 
How to Present Effectively Online
This white paper offers practical and actionable advice on the key steps that any presenter should consider as they plan and execute a Webinar or online meeting.

 
Open Source Security Myths
Open Source Software (OSS) is computer software whose source code is available to the general public with relaxed or non-existent intellectual property restrictions (or arrangement such as the public domain), and is usually developed with the input of many contributors.

 
Power and Cooling Capacity Management for Data Centers
This paper describes the principles for achieving power and cooling capacity management.

 
Scalable, Fault-Tolerant NAS for Oracle - The Next Generation
For several years NAS has been evolving as a storage alternative for Oracle databases, and for good reason: NAS is quite often the simplest, most cost-effective storage approach for Oracle. Learn about the benefits that HP's approach to scalable NAS brings to Oracle environments in this comprehensive white paper.

 
Understanding Web Application Security Challenges
This white paper discusses many common threats and preventive measures for Web application security, and explains what you can do to help protect your organization.

 

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 




© 2003-2009 by Developer Shed. All rights reserved. DS Cluster 6 Hosted by Hostway
Stay green...Green IT