After my problem with ISA having to be reinstalled. I am trying something different.
We have a requirement to install or utilise a Web URL screening facility. To this end we originally installed a Client Site Proxy plugin for ISA. This worked initially then it all went wrong.
Anyway I thought I would try a less invasive alternative; Install the Non-ISA version of the Client Site Proxy service on a standalone PC on the internal network. This service uses [a] SQUID (port 3128)
Its all installed and configured, however ISA is stopping it in the (default) SBS Internet Access Rule, with Denied connection for port 3128.
I looked at the failure and created a Firewall Policy that 'Allowed' Outbound Traffic for Port 3128 from Internal to External for All Users, I placed this rule immediatly above the Default Internet Access Rule and called it 'CSP Access Rule'.
ISA is apparently ignoring this rule entirely still and presists in SBS Internet Access rule denying connections.
Am I missing something obvious here?
Thanks
Paul
|