Networking Forums

Networking Forums > Computer Networking > Windows Networking > IPSec Question

Reply
Thread Tools Display Modes

IPSec Question

 
 
Niki Blowfield
Guest
Posts: n/a

 
      05-17-2005, 01:10 PM
Hi

We have 2 proxy servers in use on our network, the first is running ISA
Server 2000 and a URL Filtering plugin. All clients point at this server.
This server uses NT Authentication to ensure only valid users can access the
internet

Upstream from this proxy, we have a virus scanning proxy server, which in
turn forwards requests to the internet

This upstream proxy is the only IP address which is granted HTTP access to
the internet

We need to ensure this upstream proxy is secured against people entering the
server name and port number into their IE6 Proxy settings, thus bypassing our
secure filtering proxy server and its controls/logging

The software that is running on the upstream proxy is a basic virus scanner,
and cannot control who accesses it. Up until now we have been changing the
port number periodically so its tough to guess

We would like to use IPSec to secure comms so that only the downstream proxy
has permissions to access the upstream proxy

When I configure IPSec to secure comms in this fashion (deny All IP, permit
IP from downstream proxy), at the Windows level, all looks fine, however,
internet browsing immediately fails

It appears that the downstream proxy does not strip the IP address of the
client that was requesting HTTP

The upstream proxy therefore appears to see the HTTP requests coming from
the original client, rather than the downstream proxy that is actually making
the requests

Is there a way of IPSec allowing this kind of pass-through HTTP traffic, but
not accepting direct connections from any IP other than the downstram proxy?

Thanks,
Mr. Niki Blowfield
 
Reply With Quote
 
 
 
 
Phillip Windell
Guest
Posts: n/a

 
      05-17-2005, 03:52 PM
Forget IPSec. Just put the upstream proxy in another subnet that is
physically separated by the ISA Server (aka a Back-to-Back DMZ). Users
won't be able to get to the thing without going through the ISA.

[users] --> [ISA] --> [other proxy] --><internet>

--

Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com


"Niki Blowfield" <Niki (E-Mail Removed)> wrote in message
news:B6217DFA-CB8B-4662-B9BE-(E-Mail Removed)...
> Hi
>
> We have 2 proxy servers in use on our network, the first is running ISA
> Server 2000 and a URL Filtering plugin. All clients point at this server.
> This server uses NT Authentication to ensure only valid users can access

the
> internet
>
> Upstream from this proxy, we have a virus scanning proxy server, which in
> turn forwards requests to the internet
>
> This upstream proxy is the only IP address which is granted HTTP access to
> the internet
>
> We need to ensure this upstream proxy is secured against people entering

the
> server name and port number into their IE6 Proxy settings, thus bypassing

our
> secure filtering proxy server and its controls/logging
>
> The software that is running on the upstream proxy is a basic virus

scanner,
> and cannot control who accesses it. Up until now we have been changing the
> port number periodically so its tough to guess
>
> We would like to use IPSec to secure comms so that only the downstream

proxy
> has permissions to access the upstream proxy
>
> When I configure IPSec to secure comms in this fashion (deny All IP,

permit
> IP from downstream proxy), at the Windows level, all looks fine, however,
> internet browsing immediately fails
>
> It appears that the downstream proxy does not strip the IP address of the
> client that was requesting HTTP
>
> The upstream proxy therefore appears to see the HTTP requests coming from
> the original client, rather than the downstream proxy that is actually

making
> the requests
>
> Is there a way of IPSec allowing this kind of pass-through HTTP traffic,

but
> not accepting direct connections from any IP other than the downstram

proxy?
>
> Thanks,
> Mr. Niki Blowfield



 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
IPSec Filter Question Chupacabra Windows Networking 2 07-24-2006 01:19 PM
Another IPSec tunneling question, this time with NAT! Jordan Mills Windows Networking 0 05-23-2006 11:29 PM
ISAKMP and IPSec Rookie question Fredly Windows Networking 2 01-27-2005 06:15 AM
IPSec & VPN question hongbing zhu Windows Networking 4 01-12-2005 08:06 AM
IPSec question Alex Windows Networking 2 12-24-2003 09:08 AM



1 2 3 4 5 6 7 8 9 10 11