CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Web Security > SSL Network Extender
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-06-06
rubber_chicken rubber_chicken is offline
Member
 
Join Date: 2006-03-08
Location: New Zealand
Posts: 82
Rep Power: 3
rubber_chicken has an average reputation (10+)
Default Unable to connect through MS ISA2004 server

Hi,

I'm trying to connect to an external suppliers SSL VPN connection. I sit behind a MS ISA 2004 server. I get to the Checkpoint authentication page, enter my credentials and then whilst it sets up the connection I get another request for credentials.

The pop-up is "Realm proxy-caching web server "

No credentials I have found work.

My ISA server allows anonymous connections. This connection works when I try it over my home DSL connection so I know the remote credentials are correct and not locked out.

So, it looks like an ISA problem, but I thought this was supposed to go through all proxies.

Any ideas?

All help is appreciated.
Reply With Quote
  #2 (permalink)  
Old 2006-06-08
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 873
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Unable to connect through MS ISA2004 server

Oddly, I spent today from behind an ISA 2004 server (which is behind FW-1) to connect to a test Connectra NGX R61 box that's on a cable modem on the Internet (my R60 to R61 upgrade test box).

When I did this same thing to Connectra NGX R60, I got the same proxy prompt and could enter my credentials as "domain\user" and get through ISA (I do require authentication through ISA). I haven't gotten it once connecting to Connectra NGX R61 with its version of the SSL Network Extender.

One of the fixes in Connectra NGX R61 is improved authentication through proxy servers, yet you say ISA does not require authentication. Do you know what version of Connectra they're using?

Ray
Reply With Quote
  #3 (permalink)  
Old 2006-06-13
rubber_chicken rubber_chicken is offline
Member
 
Join Date: 2006-03-08
Location: New Zealand
Posts: 82
Rep Power: 3
rubber_chicken has an average reputation (10+)
Default Re: Unable to connect through MS ISA2004 server

Hi,

Sorry for the delay in responding. Not too sure what version they are running. I'll go away and see if I can find out. I don't suppose the connection website gives me any clues?

Cheers
Reply With Quote
  #4 (permalink)  
Old 2006-06-13
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 873
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Unable to connect through MS ISA2004 server

If they have it set up so you have to select "current browser" or the "Integrity Secure Browser", it's not R61. The Integrity Secure Browser was removed in R61 in favor of a "Secure Workspace" or whatever it's called.

They may not give you the ISB selection, so if it's not there, it's not definitive. I don't know if the ISB was there before Connectra NGX.

Both the login screen and the SSL Network Extender in R61 have a 2004-2006 copyright date on its screen while the R60 one has a 2004-2005 date.

I looked at the release notes and confirmed that R61 will work through ISA with either NTLM (Integrated) authentication or Basic authentication. R60 only worked through ISA with Basic authentication.

If your ISA server in fact has authentication required and Basic was not enabled and they are pre-R61, that could cause what you're seeing.

Ray
Reply With Quote
  #5 (permalink)  
Old 2006-06-22
stextor stextor is offline
Junior Member
 
Join Date: 2006-05-10
Location: South Florida
Posts: 2
Rep Power: 0
stextor has an average reputation (10+)
Default Re: Unable to connect through MS ISA2004 server

I have this same issue with R60. I vpn in, try to connect to an http site and then login and get redirected to an https site. When I do this I get a "page not found". What I have found as a workaround is to set the "protocol type" to http_non_standard. Go to the properties of your http protocol.. click advanced.. use the drop down list to change it from http to http_non_standard. The only caveate is when you close the browser (or even logoff) the IE browser locks up.

In the meantime we upgraded to SP2 on our ISA servers. Still didn't help unless http_non_standard is selected.

Anyone know the difference between http and http_non_standard?
Reply With Quote
  #6 (permalink)  
Old 2006-06-22
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 873
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Unable to connect through MS ISA2004 server

Sorry, I don't know the difference. Is this the topology?

You behind ISA 2004 -> Internet -> Connect to Connectra behind some kind of firewall -> connect to internal HTTP server -> redirect to HTTPS server

However if you installed ISA 2004 SP2, make sure you also installed the post-SP2 hotfix or you will have other headaches: http://support.microsoft.com/kb/916106/en-us

Are you traversing ISA 2004 as a SecureNAT client, a firewall client and/or a web proxy client?

Ray
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 09:13.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0