Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

Users are repeatedly prompted for their credentials when they try to access the Internet after a firewall chain is configured between ISA Server, Microsoft Forefront Threat Management Gateway, Medium Business Edition, or Windows Essential Business Server


View products that this article applies to.

Symptoms

After you configure a firewall chain between two or more computers that are running Microsoft Internet Security and Acceleration (ISA) Server 2000, ISA Server 2004, Microsoft Forefront Threat Management Gateway, Medium Business Edition, or Windows Essential Business Server 2008, users who try to access the Internet are repeatedly prompted for their credentials.

↑ Back to the top


Cause

This issue may occur after you configure an upstream ISA Server, Microsoft Forefront Threat Management Gateway, Medium Business Edition, or Windows Essential Business Server computer and a downstream ISA Server, Microsoft Forefront Threat Management Gateway, Medium Business Edition, or Windows Essential Business Server computer to require authentication. Web browsers, such as Microsoft Internet Explorer, may not keep track of which proxy servers they have authenticated against. In this case, the browser authenticates the first ISA Server, Microsoft Forefront Threat Management Gateway, Medium Business Edition, or Windows Essential Business Server computer in the firewall chain. If the browser does not retain the proxy authentication information, the browser may have to authenticate with additional ISA Server, Microsoft Forefront Threat Management Gateway, Medium Business Edition, or Windows Essential Business Server computers in the firewall chain.

↑ Back to the top


Resolution

To resolve this issue, allow anonymous access on either the downstream ISA Server, Microsoft Forefront Threat Management Gateway, Medium Business Edition, or Windows Essential Business Server computers or the upstream ISA Server, Microsoft Forefront Threat Management Gateway, Medium Business Edition, or Windows Essential Business Server computers. Additionally, you can configure the last proxy server in the chain to use NTLM authentication, and then you can configure, in the relevant access rule, the downstream ISA Server, Microsoft Forefront Threat Management Gateway, Medium Business Edition, or Windows Essential Business Server computers in the chain to pass credentials to the upstream ISA Server, Microsoft Forefront Threat Management Gateway, Medium Business Edition, or Windows Essential Business Server computers. After you change this configuration, the upstream computers will see all requests as coming from the single user account that you configured in the access rule of the downstream computers. Only one computer that is running ISA Server, Microsoft Forefront Threat Management Gateway, Medium Business Edition, or Windows Essential Business Server in the firewall chain requires authentication.

↑ Back to the top


Status

This behavior is by design.

↑ Back to the top


References

For additional information, click the following article numbers to view the articles in the Microsoft Knowledge Base:
297080 � Incomplete HTML pages and random authentication prompts if ISA Server is chained to upstream proxy
810561� RemoveAllProxyAuthorization not applied to SSL tunneling (CONNECT) requests

↑ Back to the top


Keywords: KB883285, kbprb, kbtshoot, kbfirewall, kbenv

↑ Back to the top

Article Info
Article ID : 883285
Revision : 3
Created on : 9/7/2004
Published on : 9/7/2004
Exists online : False
Views : 312