Configuring ISA Server Client Settings

Configuring Web Browser Properties

To configure Web browser properties, access the Web Browser Properties dialog box in the Client Configuration node of the ISA Server management console. The different settings that you can configure on the Web Browser Properties dialog box are explained here.

On the General tab, you can configure the following settings:

On the Direct Access tab; you can select which computers should bypass the ISA server. The available options are:

On the Backup Route tab, you can specify backup routes that should be used when the ISA server cannot be accessed:

On the Application Settings tab, you can configure how ISA Server interacts with applications.

Configuring Firewall Client Properties

To configure Firewall client properties, access the Firewall Client Properties dialog box in the Client Configuration node of the ISA Server management console. The different settings that you can configure on the Firewall Client Properties dialog box are explained here.

On the General tab, you can configure the following settings:

Configuring SecureNAT Clients

With a SecureNAT client, you have to configure the client so that Internet requests are passed to the ISA server’s internal network interface. SecureNAT clients also require ISA Server application filters to access the Internet. SecureNAT clients are supported on operating systems that support Transmission Control Protocol/Internet Protocol (TCP/ IP).

You have to ensure that the default gateway for SecureNAT clients is configured correctly. When configuring the default gateway for the SecureNAT clients, you have to take into account the network topology. In a simple network topology, routers are not configured between the SecureNAT client and the ISA Server computer. A complex network however has one or multiple routers that connect multiple subnets configured between SecureNAT clients and the ISA Server computer.

To configure a SecureNAT client:

How to modify the default settings for Web browser clients

  1. Open the ISA Management console.
  2. Navigate to the Client Configuration node in the console tree.
  3. Double-click the Web Browser object.
  4. The Web Browser Properties dialog box opens.
  5. If you do not want the Firewall client software to configure the Web browser of the client, uncheck the Configure Web Browser During Firewall Client Setup checkbox. The current Web proxy settings of the client will remain unchanged.
  6. If you want clients to access the ISA server through its IP address, then enter the IP address of the internal network adapter of the ISA server in the DNS Name box. The DNS name will no longer be used.
  7. If you want clients to automatically discover the closest ISA server, enable the Automatically Discover Settings checkbox. This is usually done when you have to support roaming clients. Here, you configure DHCP servers and DNS servers to support the Web Proxy Auto Discover (WPAD) feature.
  8. If you want Web browsers to use an automatic configuration script created by ISA Server, to obtain Web proxy settings, then enable the Set Web Browsers To Use Automatic Configuration Script checkbox.
  9. If you want to use a different configuration script, select the Use Custom URL option and enter the URL for the script.
  10. Click the Direct Access tab.
  11. If you have client computers that should bypass the ISA server, then specify these client computers here.
  12. Click the Backup Route tab.
  13. Specify any backup route(s) which should be used when the ISA server cannot be accessed. A backup route can be a connection to:
    • Another ISA computer
    • Internet
  1. Click OK.

How to modify the default settings for Firewall clients

  1. Open the ISA Management console.
  2. Navigate to the Client Configuration node in the console tree.
  3. Double-click the Firewall Client object.
  4. The Firewall Client Properties dialog box opens.
  5. If you want clients to access the ISA server through its DNS name, enter the information in the DNS Name box.
  6. If you want clients to access the ISA server through its IP address, then enter the IP address of the internal network adapter of the ISA server in the IP Address box. The DNS name will no longer be used.
  7. If you want clients to automatically discover the closest ISA server, select the Enable ISA Firewall Automatic Discovery In Firewall Client checkbox. This is usually done when you have to support roaming clients. Here, you configure DHCP servers and DNS servers to support the WinSock Proxy Auto Discover (WSPAD) feature. Once a client has obtained a DHCP lease agreement, the client will automatically discover the closest ISA server.
  8. Click the Application Settings tab.
  9. This is where you can modify how ISA Server interacts with applications.
  10. Click OK.

How to publish automatic discovery

  1. Open the ISA Management console.
  2. Navigate to the ISA server.
  3. Expand the ISA server and select Properties from the shortcut menu.
  4. Click the Auto Discovery tab.
  5. Select the Publish Automatic Discovery Information checkbox.
  6. In the Use This Port for Automatic Discovery Requests, enter the appropriate port number.
  7. Click OK.
  8. When a warning message box appears, then select the Save the Changes And Restart The Services option.
  9. Click OK.

How to manually configure Internet Explorer to use the Web Proxy Service

  1. Open Internet Explorer.
  2. Click the Tools menu and then select Internet Options.
  3. The Internet Options dialog box opens.
  4. Click the Connections tab.
  5. Click LAN Settings.
  6. Enable the Use A Proxy Server checkbox.
  7. In the Address textbox, enter the ISA Server computer name of ISA Server array name.
  8. In the Port textbox, enter the appropriate port number.
  9. Click OK.

How to enable SecureNAT clients to route Internet requests through an active dial-up entry

To create the dial-up entry:

  1. Open the ISA Management console.
  2. Navigate to the Policy Elements node.
  3. Expand the Policy Elements node.
  4. Right-click Dial-up Entries and then select New Dial-Up Entry from the shortcut menu.
  5. The New Dial-Up Entry dialog box opens.
  6. In the Name box, enter a name for the new dial-up entry.
  7. In the Description box, provide a description for the dial-up entry.
  8. In the Use The Following Network Dial-Up Connection box, enter the name of the network dial-up connection that you created.
  9. Click Set Account.
  10. The Set Account dialog box opens.
  11. In the User box, enter the name of the user account provided by the ISP.
  12. In the Password box and Confirm Password box, enter and verify the password of the user, and then click OK.
  13. Click OK in the New Dial-Up Entry dialog box.

To set the active dial-up entry:

  1. Open the ISA Management console.
  2. Click the View menu and select Advanced.
  3. Expand the Policy Elements node.
  4. Select the Dial-up Entries folder.
  5. The details pane shows all existing dial-up entries.
  6. Select the dial-up entry that you want as the active dial-up entry, and then select Set As Active Entry from the shortcut menu.

To set enable SecureNAT clients to use the active dial-up entry

  1. Open the ISA Management console.
  2. Navigate to the Network Configuration node.
  3. Right-click the Network Configuration node and then select Properties from the shortcut menu.
  4. The Network Configuration Properties dialog box opens.
  5. Click the Firewall Chaining tab.
  6. Select the Use Primary Connection option.
  7. Select the Use Dial-up Entry checkbox.
  8. Click OK.

To restart the restart the ISA Firewall service

  1. Open the ISA Management console.
  2. Expand the Monitoring node.
  3. Select the Services node.
  4. Right-click the Firewall service and select Stop.
  5. Right-click the Firewall service once more and then select Start.

How to install the Firewall Client

A Firewall client is a client computer on which Firewall Client software is installed and enabled. Firewall Clients software is usually installed from a network installation share.

After the Firewall Client software is installed, the following components are installed on the client computer:

To install the Firewall Client software:

  1. Browse to the network share for servername\mspclnt share, the shared ISA Server client installation files.
  2. Double-click the Setup file (setup.exe ) in the directory to install the Firewall Client software on the client.
  3. The Microsoft Firewall Client Installation wizard launches.
  4. Click Next on the Welcome page.
  5. On the Destination page, specify the folder in which the Firewall Client software should be installed. Click Next.
  6. The Ready To Install The Program page opens.
  7. Click Install.
  8. The firewall client is installed next.
  9. Click Finish.

How to enable automatic discovery for firewall clients

  1. Open Control Panel on the client computer.
  2. Double-click Firewall Client.
  3. Enable the Automatically Detect ISA Server checkbox.
  4. Click OK.

How to configure DNS for automatic discovery of ISA Server

  1. Click Start, Administrative Tools, and then click DNS to open the DNS management console.
  2. Expand the Forward Lookup Zones node.
  3. Right-click the domain which hosts the ISA Server array, and then select New Host from the shortcut menu.
  4. The New Host dialog box opens.
  5. Enter the DNS computer name for the ISA Server computer or array in the Name textbox.
  6. Enter the internal IP address of the ISA Server computer in the IP Address textbox.
  7. Click the Add Host button.
  8. The new host record is added to the zone.
  9. Right-click the forward lookup zone in the console tree, and then select New Alias from the shortcut menu.
  10. The New Resource Record dialog box opens.
  11. Enter WPAD in the Alias Name textbox.
  12. Enter the fully qualified domain name of the ISA server.
  13. Click OK.
  1. Open the ISA Management console.
  2. Right-click the ISA server and select Properties from the shortcut menu.
  3. Click the Auto Discovery tab.
  4. Enable the Publish Automatic Discovery Information checkbox.
  5. Click OK.

How to configure DHCP for automatic discovery of ISA Server

  1. Click Start, Administrative Tools, and then click DHCP to open the DHCP management console.
  2. In the console tree, locate the DHCP server that you want to configure.
  3. Right-click the DHCP server and then select Set Predefined Options from the shortcut menu.
  4. The Predefined Options and Values dialog box opens.
  5. Click the Add button.
  6. The Option Type dialog box opens.
  7. In the Name box, enter WPAD.
  8. In the Data Type drop-down list box, select the String data type option.
  9. In the Code box, enter the appropriate value.
  10. In the Description box, enter a description.
  11. Click OK in the Option Type dialog box.
  12. The Predefined Options and Values dialog box should now display the WPAD entry in the Option Name drop-down list box.
  13. In the String textbox, enter either of the following:
    • http://isaserver/wpad.dat
    • http://WPAD/wpad.dat
  1. Click OK in the Predefined Options and Values dialog box.
  2. In the console tree of the DHCP management console, select the DHCP server.
  3. Right-click Server Options and select Configure Options from the shortcut menu.
  4. In the Available Options box, select the WPAD option.
  5. Click OK.
  1. Open the ISA Management console.
  2. Right-click the ISA server and select Properties from the shortcut menu.
  3. Click the Auto Discovery tab.
  4. Enable the Publish Automatic Discovery Information checkbox.
  5. Click OK.

Troubleshooting ISA Server Client Connections

ISA Server client connectivity issues occur when you make configuration changes for ISA Server but do you do not restart the Firewall service, Web Proxy service, or H.323 Gatekeeper service. If you have a client connectivity issue where connectivity stops after it has been previously established, then you can also try restarting the appropriate service to resolve the issue.

When you make the ISA Server configuration changes listed below, you need to restart the necessary services:

How to stop an ISA service

  1. Open the ISA Management console.
  2. Click the View menu and select Advanced.
  3. Select the Services node.
  4. Right-click the service that you want to start, and then select Stop from the shortcut menu.

How to start an ISA service

  1. Open the ISA Management console.
  2. Click the View menu and select Advanced.
  3. Select the Services node.
  4. Right-click the service that you want to start, and then select Start from the shortcut menu.

To troubleshoot the different ISA Server client types, you need to understand the installation and configuration requirements for each client type:

A few ISA client configuration problems and the strategies for troubleshooting these issues are summarized here:

A few dial-up connections problems and the strategies for troubleshooting these issues are summarized here:

When troubleshooting client access authentication problems, consider the following important factors:

When troubleshooting automatic discovery problems, consider the following important factors:



Top 5 Free Networking Tools

Bookmark Configuring ISA Server Client Settings

Latest Blog Posts


English English GermanGerman SpanishSpanish FrenchFrench ItalianItalian PortuguesePortuguese RussianRussian DutchDutch
GreekGreek HindiHindi JapaneseJapanese KoreanKorean ChineseChinese Chinese (Simplified)Chinese (Simplified) ArabicArabic

Copyright 2009 Tech-FAQ. All rights reserved. Privacy Policy.