To create a new policy in ISA Server or in Microsoft Forefront Threat Management Gateway, Medium Business Edition that blocks transparent HTTP clients without requiring authentication, you must create a new protocol in ISA Server, create a new access rule, and then remove the HTTP protocol from the Web Proxy Filter. To do this, follow these steps:
- Create a new protocol that is named Transparent HTTP. To do this, follow these steps:
- Start the ISA Server Management tool or Microsoft Forefront Threat Management Gateway, Medium Business Edition.
- Expand the name of your ISA Server computer or the Microsoft Forefront Threat Management Gateway, Medium Business Edition computer name, click Firewall Policy, and then click the Toolbox tab in the right-pane.
Note For ISA Server Enterprise Edition, expand Arrays, expand Array_Name, and then click Firewall Policy. - In the right-pane, right-click Protocol, and then click New Protocol.
- Type a name for the new protocol. Use a descriptive name, such as Transparent HTTP Protocol, and then click Next.
- Click New on the Primary Connection Information page.
- Under Protocol type, click TCP, and then click Outbound under Direction.
- Under Port Range, type 80 in the From box, type 80 in To box, and then click OK.
- Click Next, click No on the Secondary Connections page, and then click Next.
- Click Finish.
- Create a new access rule that denies transparent HTTP traffic from the internal network to the external network. To do this, follow these steps:
- In the ISA Server Management Tool, right-click Firewall Policy, point to New, and then click Access Rule.
- Type a name for the new access rule. Use a descriptive name, such as Transparent HTTP rule, and then click Next.
- Click Deny, and then click Next.
- In the This rule applies to list, click Selected Protocols, and then click Add.
- Expand User-Defined, click Transparent HTTP Protocol, click Add, and then click Close.
- Click Next.
- On the Access Rule Sources page, click Add.
- Expand Networks, click Internal, click Add, and then click Close.
- Click Next.
- On the Access Rule Destinations page, click Add.
- Expand Networks, click External, click Add, and then click Close.
- Click Next.
- On the User Sets page, click All Users, and then click Next.
- Click Finish.
Note Put the new access rule before any other rules that permit HTTP traffic.
- Remove the HTTP protocol from the Web Proxy filter. To do this, follow these steps:
- In the ISA Server Management Tool, click Firewall Policy, and then click the Toolbox tab in the right-pane.
- In the right-pane, expand Common Protocols, right-click HTTP, and then click Properties.
- Click the Parameters tab.
- Under Application Filters, click to clear the Web Proxy Filter check box, and then click OK.