ISA 2006 VPN Clients are not able to access https (443) websites

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • abdoelmasry
    New Member
    • Oct 2006
    • 104

    ISA 2006 VPN Clients are not able to access https (443) websites

    Hi Profs

    I have ISA server 2006 installed on Windows server 2003 enterprise Edition,

    i configured isa server as remote access server, to support remote users access using VPN to my Local network and also access internet through ISA.

    remote users are not able to access https websites,

    i mean, i can access http://www.yahoo.com but cannot access https://login.yahoo.com

    i have created access rule says (Allow All Traffic From VPN clients to All networks and local host) and also (allow all networks to access VPN Clients)

    i checked logging to check dropped packets, no dropped packets.

    local computers can access internet with no problems.

    this problem happens with vpn clients only.

    Any one have idea ?

    Thank you
  • sicarie
    Recognized Expert Specialist
    • Nov 2006
    • 4677

    #2
    Is the 'allow any any' rule the only one in your ISA config?

    Comment

    • sicarie
      Recognized Expert Specialist
      • Nov 2006
      • 4677

      #3
      Are you sure certificates are being handled correctly?

      Comment

      • abdoelmasry
        New Member
        • Oct 2006
        • 104

        #4
        No, I have many other rules but i set the rule (allow any any) at first to override other rules.

        what do you mean by (certificates)?
        this is outgoing connection from vpn client to login.yahoo.com
        i don't think that i will need certificate to connect to yahoo

        it's very strange problem,
        i know that ppp encrypts and compress data and also SSL encrypts data,
        may ppp encryption conflict with SSL Encryption ??

        Thank you

        Comment

        • sicarie
          Recognized Expert Specialist
          • Nov 2006
          • 4677

          #5
          I would recommend backing up your ruleset and then removing all the others - sometimes programs use the top as the highest priority, sometimes they use the last.

          If you want to make sure that no other rules are interfering, I'd recommend removing all the others.

          Comment

          • abdoelmasry
            New Member
            • Oct 2006
            • 104

            #6
            Hi sicarie

            Problem Solved

            the problem was CRL,

            ISA server was unable to download Certificate Revocation List(CRL) to secure connection to SSL.

            i set (CRL Download) in isa system policy(enabled) to All Networks and localhost.

            Thank You Bro :)

            Comment

            • sicarie
              Recognized Expert Specialist
              • Nov 2006
              • 4677

              #7
              Awesome, thanks for posting the fix too!

              Comment

              Working...