Use the following procedure to create a new Web publishing rule for ISA Server 2006 or ISA Server 2006 Service Pack 1 (SP1).
-
On the ISA Server, open ISA Server Management. To open ISA Server Management, click Start, point to All Programs, point to Microsoft ISA Server, and then click ISA Server Management.
-
In the console tree, expand the ISA Server name. (If you are using ISA Server 2006 SP1 Enterprise Edition, expand Arrays, and then expand the ISA Server name.)
-
Click Firewall Policy.
-
On the Tasks tab, click Publish Web Sites.
-
On the Welcome to the New Web Publishing Rule Wizard page, in the Web publishing rule name box, type a name for the new publishing rule, and then click Next.
-
On the Select Rule Action page, click Allow, and then click Next.
-
On the Publishing Type page, ensure that Publish a single Web site or load balancer is selected, and then click Next.
-
On the Server Connection Security page, select Use SSL to connect to the published Web server or server farm, and then click Next.
-
On the Internal Publishing details page, in the Internal site name box, type the name of the TS Gateway server, and then click Next.
If the ISA Server cannot resolve the name of the TS Gateway server, type the IP address of the TS Gateway server. Alternatively you can include this information in the Hosts file.
-
On the second instance of the Internal Publishing Details page, do the following:
- Ensure that the Path box is empty.
- Ensure that the Forward the original host header instead of the actual one specified in the Internal site name field on the previous page check box is cleared.
- Click Next.
-
On the Public Name Details page, do the following:
- In Accept requests for, ensure that This domain name (type below) is selected.
- In the Public name box, type the name of the TS Gateway server. The specified name must match the name of the TS Gateway server through which users will connect in this scenario. This name must also match the certificate name (CN) or the Subject Alternative Name (SAN) in the certificate that is installed on the TS Gateway server.
Note |
|---|
| If you are using the Subject Alternative Name (SAN) attributes of certificates, clients that connect to the TS Gateway server must be running RDC 6.1. RDC 6.1 is available with Windows Server 2008, Windows Vista with SP1, and Windows XP with SP3. The RDC 6.1 (6.0.6001) client supports Remote Desktop Protocol 6.1. |
- Ensure that the Path box is empty.
- Click Next.
-
If required, create a new SSL Web listener. If you have a pre-existing listener with a certificate that matches the public name, you do not need to create a new SSL Web listener. In this case, select the appropriate Web listener, click Next, and then proceed to Step 13.
If you do need to create a new SSL Web listener, do the following:
- On the Select Web Listener page, click New.
- On the Welcome to the New Web Listener Wizard page, in the Web Listener Name box, type a name for the Web listener, and then click Next.
- On the Client Connection Security page, click Require SSL secured connections with clients, and then click Next.
- On the Web Listener IP Addresses page, do the following:
- Under Listen for incoming Web requests from these networks, select the External check box.
- Ensure that The ISA Server will compress content sent to clients through this Web Listener if the clients requesting the content support compression check box is selected.
- Click Select IP Addresses.
- On the External Listener IP Selection page, do the following:
- Click Specified IP addresses on the ISA Server in the selected Network. Under Available IP addresses, select the appropriate IP address, click Add, and then click OK.
- Click Next.
- On the Listener SSL Certificates page, click Assign a certificate for each IP address, click the appropriate IP address, and then click Select Certificate.
- On the Select Certificate page, under Select certificate, click the TS Gateway server certificate, click Select, and then click Next.
Note |
|---|
ISA Server 2006 is able to use either the Subject or the first Subject Alternative Name (SAN) entry. For example, if ISA Server is expecting the certificate to read “contoso.com,” the name should be in one of the following formats: - The certificate “Subject” (AKA “common name”)
Or
- The first entry in the Subject Alternative Name (SAN) list (ISA Server 2006 only)
These restrictions do not impact ISA Server 2006 SP1. |
- On the Authentication Settings page, click No Authentication, and then click Next.
- If ISA Server is a member of a domain and:
- Client authenticates by using only a password:
- On the Authentication Settings page, click No Authentication, and then click Next.
- On the Single Sign On Settings page, click Next.
- Client authenticates by using only a smart card:
- On the Authentication Settings page, click SSL Client Certificate Authentication or No Authentication, and then click Next.
- On the Single Sign On Settings page, click Next.
Note |
|---|
| If both password and smart card authentication are allowed on the TS Gateway server, Authentication setting SSL Client Certificate Authentication must be set to No Authentication. |
- If ISA Server is in a workgroup and the client authenticates by using either a password or smart card or both:
- On the Authentication Settings page, click No Authentication, and then click Next.
- On the Single Sign On Settings page, click Next.
- On the Completing the New Web Listener Wizard page, click Finish.
- On the second instance of the Completing the NewWeb Listener Wizard page, confirm that the correct Web listener properties appear, and then click Finish.
-
On the Select Web Listener page, confirm that the appropriate Web listener is selected, and then click Next.
-
On the Authentication Delegation page, click No delegation, but client may authenticate directly, and then click Next.
Important |
| Selecting the incorrect Authentication Delegation option will cause clients to be unable to connect to the TS Gateway server. Clients will receive a continuous credential prompt indicating that the logon failed. |
-
On the User Sets page:
- If Authentication Settings in SSL Web listener is set to No Authentication, verify that All Users is selected, and then click Next.
- If Authentication Settings in SSL Web listener is set to SSL Client Certificate Authentication, verify that All Authenticated Users is selected, and then click Next.
-
On the Completing the New Web Site Publishing Rule Wizard page, click Finish.
-
To save the changes and update the ISA Server firewall policy, in the details pane of the ISA Server Management console, click Apply.
-
In the Apply New Configuration dialog box, click OK after the changes are applied (a progress bar appears while the changes are being applied).