Registered users    
MembershipMembership:
Latest New UserLatest:Chris Naylor
New TodayNew Today:12
New YesterdayNew Yesterday:10
User CountOverall:23325

Private messaging    
You must be logged in to use this module.
Top 10 posters    
NamePosts
Mariette Knap12894
Marina Roos12507
Eriq Neale2114
Stan Guinn1913
Michael Patrick1912
Robert Pearman1771
Nick Pieters1425
Stewart Brown616
william warren600
Kevin D.579
Welcome unauthorized visitor    
If you want to join us in the discussions on this forum you need to register first. Registration is free! If you are already a registered user please login to join the forum.
Small Business Server Support Forum    
Subject: ISA Policy blocking Mapquest/Google maps
Prev Next
You are not authorized to post a reply.

Author Messages
Chester Hull User is Offline
United States
Member since
4/28/2005

Registered Users
Posts: 30

9/26/2008 07:36 PM  
We've implemented a locked down internet for our client. They want most users to only be able to access a certain whitelist of urls.

So we've created the rule in ISA, and it's working well. Except when they try to access Mapquest or Google Maps. They can browse those websites, and enter the addresses and directions they want, and that part of the site works. But the map images won't load.
 
Everything on the page loads except the images.
 
What am I missing? The URLs for the map searches don't show it using any other domain, but apparently it is pulling those map images from another domain, or IP address. Any help?

Thanks!

Chester
Simon Aub User is Offline
United States
Member since
4/29/2007

Registered Users
Posts: 46

9/27/2008 02:01 AM  
Great thing about ISA is that you can see in real time what is happening; monitor in the ISA console while someone tries to access the webpage. Then adjust or add a Access Rule. Having said that, how "locked down" is "locked down"?
What Ports are blocked?
Chester Hull User is Offline
United States
Member since
4/28/2005

Registered Users
Posts: 30

9/29/2008 03:58 PM  
The way we've locked it down is this:
We've created a rule that allows access to a given list of URL's. We've assigned most of the users to that rule.
Then we've removed those users from the default SBS Internet Access Rule.

This means that those specific users can only access that specific set of URLs that we've put in the list.

I will check the ISA monitor, and see if that will help identify the reason they are being blocked.

Chester
Chester Hull User is Offline
United States
Member since
4/28/2005

Registered Users
Posts: 30

10/02/2008 06:46 PM  
ok, we're having some success! By using the Monitoring tool, I was able to see what URLs were being blocked, and add those to the "whitelist".
 
However, because the rule is using specific Windows Users, whenever a request goes to an allowed URL from "anonymous", that request is blocked. So some controls, images, and things like that are still being blocked.
 
Here is an example of the block from the Monitoring console:
The ISA Server requires authorization to fulfill the request. Access to the Web Proxy service is denied.  0x0 0x800 Web Proxy Filter 10/2/2008 12:38:10 PM 192.168.16.2 8080 http Denied Connection SBS Restricted Internet Access 192.168.16.106 anonymous Internal External GET http://audible.edgeboss.net/download/audible/content/bk/sadl/000023/bk_sadl_000023_sample.mp3
 
So, how should I make this work? Should I allow access for Anonymous through a different rule. (like the default rule, or the Protected Networks rule), or is there a better way?

Chester
Simon Aub User is Offline
United States
Member since
4/29/2007

Registered Users
Posts: 46

10/04/2008 01:28 AM  
Without knowing what rules you have specifically....you might want to check the order of your rules. ISA processes the rules in order, so sometimes moving a rule can solve the problem.
You are not authorized to post a reply.
Forums > Microsoft Small Business Server 2003 & 2000 > ISA Server 2004 > ISA Policy blocking Mapquest/Google maps



ActiveForums 3.7
Forum policy    
These Discussion Forums are dedicated to the discussion of the Small Business Server and related server and client software. For the benefit of the community please observe the following posting guidelines:
  1. No Advertising. This includes promotion of commercial products and non-commercial products which are not directly related to Small Business Server and related server and client software.
  2. No Flaming or Trolling.
  3. No Profanity, Racism, or Prejudice.
  4. Site Moderators have the final word on approving/removing a thread or post or comment.