Wednesday, January 10, 2007

ISA Proxy & Firewall Get Rid of them !!

Bypassing ISA Proxy & Firewall

Hi Folks,

Are you tired of your Web Proxy / Firewall which denies access to some sites,
Here it is if your company is using ISA Server for Proxy / Firewall, you can bypass it.

Let’s get started.

When you have the ISA 2004 Firewall client software running on the client machine, all external-bound traffic will be sent to the ISA Server.


If you are going through the ISA, you will have a ISA Firewall client installed on your machine.
Just check at this location
C:\Documents and Settings\All Users\Application Data\Microsoft\Firewall Client 200x

Under this folder you will find common & management INI files here you have to create a new text file in Notepad and name it as LocalLAT.txt.

let’s allow all traffic to the network orkut.com to bypass the ISA Server.
For that we will need the IP address for orkut.com
Same can be applied for the rest of the sites, which are restricted.

Enter the IP range as follows:
Save the file and close it.
See here:


Now, Open the Computer Management or Services MMC and restart the Firewall Client Agent.
See here:



configure ISA to allow traffic to certain domains/IP addresses to totally bypass the ISA server.

There is also a server side component for firewall client installed machines to bypass ISA Server when trying to access a particular domain name. The following section will explain the procedure of enabling this:
1. Open ISA firewall console.
2. On the right pane, select Toolbox and expand Networks.
3. Right click on the Internal network and go to Properties.
4. Select the Domain tab and click Add.
5. Enter the name of the domain in the Enter a domain name to include: box and click OK.

See here:




6. Click OK on the Internal Properties page to close the window.

The above configuration will enable the Firewall client configured machine to not use ISA Server when contacting the Domain name listed in the Domain Names box.

Even if you added your IP address to the LocalLAT.txt file,
it won’t bypass the ISA firewall when you are using Internet Explorer and the Automatically Detect Settings is enabled.
There are a few settings on the ISA firewall to enable Direct Access and bypass proxy when accessing the intranet sites and servers,

See here:


You can enable direct access to a set of IP addresses or to a Domain using the following method:
1. Open the ISA firewall Console.
2. On the right pane, select Toolbox and expand Networks.
3. Right click on the Internal network and go to Properties.
4. Select the Web Browser tab.
5. Select Bypass proxy for the servers in this network option.
This will tell the client machine to bypass the ISA server
when accessing the local server.
6. Select Directly access computers specified in the Domain tab option.
7. Click Add button.

See here:


Enter the IP address range or the Domain name. Click OK.

See here:



8. Click OK on the Internal Properties page to close the window.

Congrats ! You are done now.

Try accessing the orkut.com ! and the other sites you may want 2 surf!!

Nitin Kushwaha
CHFI.CEH.NSA.SCSCA.CIW-SA.ITIL.MCSE.MCSA

1 comment:

Andrew Dsouza said...

Hey Dude !

Heads up !

It really works w0w:-)

why MS left it

Crazy man.!