Народ! Кто подскажет как правильно настроить правило в ISA 2004 чтобы компьютеры внутри локалки могли активировать лицензионный Win XP?
Все что я нашел:
http://support.microsoft.com/kb/291983
Windows Product Activation uses the following ports:
80 - HTTP
443 - HTTPS
MORE INFORMATION
For Windows Product Activation to succeed, configure firewalls or other devices that are between the client and the Internet to allow traffic to pass over ports 80, and 443.
You can use Microsoft Internet Explorer or other Internet browsers to test connectivity through these ports.
To test whether port 80 is open: 1. Open Internet Explorer.Type http://www.microsoft.com:80 in the Address bar, and then press ENTER.
2. Type http://www.microsoft.com:80 in the Address bar, and then press ENTER.
To test whether port 443 is open: 1. Open Internet Explorer.Type https://www.microsoft.com:443 in the Address bar, and then press ENTER.
2. Type https://www.microsoft.com:443 in the Address bar, and then press ENTER.
If you can access the Microsoft Web site each time, ports 80 and 443 are accessible.
If your browser displays an error message such as "connection timed out," the corresponding port may be blocked.
Эти порты открыти и работают.
в логах иса пишет:
Original Client IP Client Agent Authenticated Client Service Referring Server Destination Host Name Transport HTTP Method MIME Type Object Source Source Proxy Destination Proxy Bidirectional Client Host Name Filter Information Network Interface Raw IP Header Raw Payload GMT Log Time Source Port Processing Time Bytes Sent Bytes Received Cache Information Error Information Log Time Client IP Destination IP Destination Port Protocol Action Rule Result Code HTTP Status Code Client Username Source Network Destination Network URL Server Name Log Record Type
0.0.0.0 Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.1) No Proxy wpa.one.microsoft.com TCP GET - - - - - - 22.10.2007 8:46:00 0 500 4513 158 0x4 0x0 22.10.2007 12:46:00 192.168.0.2 192.168.0.1 3128 http Denied Connection internet 12209 The ISA Server requires authorization to fulfill the request. Access to the Web Proxy filter is denied. anonymous Internal External http://wpa.one.microsoft.com/ EST-S-PX1 Web Proxy Filter
Вероятно что то в способе авторизации.
Нашел еще один линк
http://technet.microsoft.com/en-us/library/bb490216.aspx
Вообщем я в правиле в distanetion прописал
http://go.microsoft.com/*
https://sls.microsoft.com/*
https://sls.microsoft.com:443
http://crl.microsoft.com/pki/crl/products/MicrosoftRootAuthority.crl
http://crl.microsoft.com/pki/crl/products/MicrosoftProductSecureCommunications.crl
http://www.microsoft.com/pki/crl/products/MicrosoftProductSecureCommunications.crl
http://crl.microsoft.com/pki/crl/products/MicrosoftProductSecureServer.crl
http://www.microsoft.com/pki/crl/products/MicrosoftProductSecureServer.crl
Может дело в типе аутентификации? почему то пишет что не firewall filter а web proxy.
Как можно настроить чтобы иса пропускала активацию XP? кто как делал?
Все что я нашел:
http://support.microsoft.com/kb/291983
Windows Product Activation uses the following ports:
80 - HTTP
443 - HTTPS
MORE INFORMATION
For Windows Product Activation to succeed, configure firewalls or other devices that are between the client and the Internet to allow traffic to pass over ports 80, and 443.
You can use Microsoft Internet Explorer or other Internet browsers to test connectivity through these ports.
To test whether port 80 is open: 1. Open Internet Explorer.Type http://www.microsoft.com:80 in the Address bar, and then press ENTER.
2. Type http://www.microsoft.com:80 in the Address bar, and then press ENTER.
To test whether port 443 is open: 1. Open Internet Explorer.Type https://www.microsoft.com:443 in the Address bar, and then press ENTER.
2. Type https://www.microsoft.com:443 in the Address bar, and then press ENTER.
If you can access the Microsoft Web site each time, ports 80 and 443 are accessible.
If your browser displays an error message such as "connection timed out," the corresponding port may be blocked.
Эти порты открыти и работают.
в логах иса пишет:
Original Client IP Client Agent Authenticated Client Service Referring Server Destination Host Name Transport HTTP Method MIME Type Object Source Source Proxy Destination Proxy Bidirectional Client Host Name Filter Information Network Interface Raw IP Header Raw Payload GMT Log Time Source Port Processing Time Bytes Sent Bytes Received Cache Information Error Information Log Time Client IP Destination IP Destination Port Protocol Action Rule Result Code HTTP Status Code Client Username Source Network Destination Network URL Server Name Log Record Type
0.0.0.0 Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.1) No Proxy wpa.one.microsoft.com TCP GET - - - - - - 22.10.2007 8:46:00 0 500 4513 158 0x4 0x0 22.10.2007 12:46:00 192.168.0.2 192.168.0.1 3128 http Denied Connection internet 12209 The ISA Server requires authorization to fulfill the request. Access to the Web Proxy filter is denied. anonymous Internal External http://wpa.one.microsoft.com/ EST-S-PX1 Web Proxy Filter
Вероятно что то в способе авторизации.
Нашел еще один линк
http://technet.microsoft.com/en-us/library/bb490216.aspx
Вообщем я в правиле в distanetion прописал
http://go.microsoft.com/*
https://sls.microsoft.com/*
https://sls.microsoft.com:443
http://crl.microsoft.com/pki/crl/products/MicrosoftRootAuthority.crl
http://crl.microsoft.com/pki/crl/products/MicrosoftProductSecureCommunications.crl
http://www.microsoft.com/pki/crl/products/MicrosoftProductSecureCommunications.crl
http://crl.microsoft.com/pki/crl/products/MicrosoftProductSecureServer.crl
http://www.microsoft.com/pki/crl/products/MicrosoftProductSecureServer.crl
Может дело в типе аутентификации? почему то пишет что не firewall filter а web proxy.
Как можно настроить чтобы иса пропускала активацию XP? кто как делал?