<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/MU" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Solving the &#34;Directly access these servers or domains&#34; issue in ISA Server 2004 SP2</title>
	<link>http://blogs.isaserver.org/pouseele/2006/07/21/solving-the-directly-access-these-servers-or-domains-issue-in-isa-server-2004-sp2/</link>
	<description>Stefaan Pouseele, an ISA Server MVP, discusses issues brought up within various ISA articles and Microsoft publications. Updates to the ISA Firewall, protocol support, discussions on the different ISA clients, ISA features, how to clean up network traffic and links to new ISA server literature are all be included within the blog. Get help on troubleshooting the ISA network firewall and learn how to create good security policies. Coverage on ISA Server 2006 also appears.</description>
	<pubDate>Wed,  7 Jan 2009 09:05:24 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>

	<item>
		<title>by: Stefaan Pouseele</title>
		<link>http://blogs.isaserver.org/pouseele/2006/07/21/solving-the-directly-access-these-servers-or-domains-issue-in-isa-server-2004-sp2/#comment-23745</link>
		<pubDate>Sat, 24 May 2008 12:34:30 +0000</pubDate>
		<guid>http://blogs.isaserver.org/pouseele/2006/07/21/solving-the-directly-access-these-servers-or-domains-issue-in-isa-server-2004-sp2/#comment-23745</guid>
					<description>Hi Gary, 

I haven't redone the tests on ISA 2004 SP3 but I assume that the SP2 behavior still applies. In fact, did you already compare the SP2 version of the wpad.dat file or the routing script with the SP3 version? That should give you the answer.  

HTH, 
Stefaan</description>
		<content:encoded><![CDATA[<p>Hi Gary, </p>
<p>I haven&#8217;t redone the tests on ISA 2004 SP3 but I assume that the SP2 behavior still applies. In fact, did you already compare the SP2 version of the wpad.dat file or the routing script with the SP3 version? That should give you the answer.  </p>
<p>HTH,<br />
Stefaan
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Gary Moon</title>
		<link>http://blogs.isaserver.org/pouseele/2006/07/21/solving-the-directly-access-these-servers-or-domains-issue-in-isa-server-2004-sp2/#comment-23691</link>
		<pubDate>Fri, 23 May 2008 17:29:09 +0000</pubDate>
		<guid>http://blogs.isaserver.org/pouseele/2006/07/21/solving-the-directly-access-these-servers-or-domains-issue-in-isa-server-2004-sp2/#comment-23691</guid>
					<description>Hi, Stefaan -
I was wondering if this is still true after ISA 2004 SP3? I'm having a devil of a time getting ISA to recognize domain names on the &quot;directly access&quot; list, and I previously changed it to all IP addresses based on a post from Tom Schinder a while back. Should I remove the IP's and go back to URL's?
Thanks
Gary</description>
		<content:encoded><![CDATA[<p>Hi, Stefaan -<br />
I was wondering if this is still true after ISA 2004 SP3? I&#8217;m having a devil of a time getting ISA to recognize domain names on the &#8220;directly access&#8221; list, and I previously changed it to all IP addresses based on a post from Tom Schinder a while back. Should I remove the IP&#8217;s and go back to URL&#8217;s?<br />
Thanks<br />
Gary
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Stefaan Pouseele</title>
		<link>http://blogs.isaserver.org/pouseele/2006/07/21/solving-the-directly-access-these-servers-or-domains-issue-in-isa-server-2004-sp2/#comment-171</link>
		<pubDate>Wed, 09 Aug 2006 09:51:47 +0000</pubDate>
		<guid>http://blogs.isaserver.org/pouseele/2006/07/21/solving-the-directly-access-these-servers-or-domains-issue-in-isa-server-2004-sp2/#comment-171</guid>
					<description>Hi Will, 

I never investigated the use of &quot;plainhostnames&quot;, at least assuming you mean with &quot;plainhostnames&quot; the unqualified name or a single-label name. 

As far as I can tell nothing has changed between ISA SP2 and the fix KB920716 for &quot;plainhostnames&quot;. So, if it was already a problem with ISA SP2 it will still be a problem. However, I can't confirm if ISA SP2 broke the &quot;plainhostnames&quot; feature because I have no pre-SP2 wpad.dat example file.

I suggest you contact Microsoft PSS if this issue is important in your environment and if it worked before ISA SP2. 

HTH, 
Stefaan</description>
		<content:encoded><![CDATA[<p>Hi Will, </p>
<p>I never investigated the use of &#8220;plainhostnames&#8221;, at least assuming you mean with &#8220;plainhostnames&#8221; the unqualified name or a single-label name. </p>
<p>As far as I can tell nothing has changed between ISA SP2 and the fix KB920716 for &#8220;plainhostnames&#8221;. So, if it was already a problem with ISA SP2 it will still be a problem. However, I can&#8217;t confirm if ISA SP2 broke the &#8220;plainhostnames&#8221; feature because I have no pre-SP2 wpad.dat example file.</p>
<p>I suggest you contact Microsoft PSS if this issue is important in your environment and if it worked before ISA SP2. </p>
<p>HTH,<br />
Stefaan
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Will</title>
		<link>http://blogs.isaserver.org/pouseele/2006/07/21/solving-the-directly-access-these-servers-or-domains-issue-in-isa-server-2004-sp2/#comment-168</link>
		<pubDate>Mon, 31 Jul 2006 05:51:32 +0000</pubDate>
		<guid>http://blogs.isaserver.org/pouseele/2006/07/21/solving-the-directly-access-these-servers-or-domains-issue-in-isa-server-2004-sp2/#comment-168</guid>
					<description>Hi Stefaan.
You have explained this really well however I still have issues with &quot;plainhostnames&quot;. I have applied the fix (KB920716) so I can add both names (URLs) and IPs in my &quot;direct&quot; list however now plainhostnames are no longer sent direct by default. If I only have names in the list then plainhostnames are sent direct by default - as soon as the 1st IP is added this feature is broken. This is probably a minor issue for most people however in our environment its a bit of a pain as I don't want to have to list all the plainhostname webservers we have internally (usually accessed directly for testing). I also don't want to bypass my entire 10.0.0.0/8 subnet. Anyway thanks for this blog!</description>
		<content:encoded><![CDATA[<p>Hi Stefaan.<br />
You have explained this really well however I still have issues with &#8220;plainhostnames&#8221;. I have applied the fix (KB920716) so I can add both names (URLs) and IPs in my &#8220;direct&#8221; list however now plainhostnames are no longer sent direct by default. If I only have names in the list then plainhostnames are sent direct by default - as soon as the 1st IP is added this feature is broken. This is probably a minor issue for most people however in our environment its a bit of a pain as I don&#8217;t want to have to list all the plainhostname webservers we have internally (usually accessed directly for testing). I also don&#8217;t want to bypass my entire 10.0.0.0/8 subnet. Anyway thanks for this blog!
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Stefaan Pouseele</title>
		<link>http://blogs.isaserver.org/pouseele/2006/07/21/solving-the-directly-access-these-servers-or-domains-issue-in-isa-server-2004-sp2/#comment-158</link>
		<pubDate>Tue, 25 Jul 2006 19:34:56 +0000</pubDate>
		<guid>http://blogs.isaserver.org/pouseele/2006/07/21/solving-the-directly-access-these-servers-or-domains-issue-in-isa-server-2004-sp2/#comment-158</guid>
					<description>Hi Scott, 

thanks! ;-)

Stefaan</description>
		<content:encoded><![CDATA[<p>Hi Scott, </p>
<p>thanks! <img src='http://blogs.isaserver.org/pouseele/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>Stefaan
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Scott</title>
		<link>http://blogs.isaserver.org/pouseele/2006/07/21/solving-the-directly-access-these-servers-or-domains-issue-in-isa-server-2004-sp2/#comment-157</link>
		<pubDate>Tue, 25 Jul 2006 12:00:48 +0000</pubDate>
		<guid>http://blogs.isaserver.org/pouseele/2006/07/21/solving-the-directly-access-these-servers-or-domains-issue-in-isa-server-2004-sp2/#comment-157</guid>
					<description>WOOT!
That was it! This is the only place I have seen it spelled out like that. I have an open case with MS and they have not been able to figure it out. Thanks!!!!

Scott</description>
		<content:encoded><![CDATA[<p>WOOT!<br />
That was it! This is the only place I have seen it spelled out like that. I have an open case with MS and they have not been able to figure it out. Thanks!!!!</p>
<p>Scott
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Stefaan Pouseele</title>
		<link>http://blogs.isaserver.org/pouseele/2006/07/21/solving-the-directly-access-these-servers-or-domains-issue-in-isa-server-2004-sp2/#comment-152</link>
		<pubDate>Sat, 22 Jul 2006 09:18:42 +0000</pubDate>
		<guid>http://blogs.isaserver.org/pouseele/2006/07/21/solving-the-directly-access-these-servers-or-domains-issue-in-isa-server-2004-sp2/#comment-152</guid>
					<description>Hi Scott, 

remember that you have to specify the destinations as URL! So try one of the following: 
- http://host.domain.tld/* -&amp;#62; only http requests to only this host
- */host.domain.tld/*      -&amp;#62; anything to only this host
- *host.domain.tld/*       -&amp;#62; anything to all destinations containing this host

HTH, 
Stefaan</description>
		<content:encoded><![CDATA[<p>Hi Scott, </p>
<p>remember that you have to specify the destinations as URL! So try one of the following:<br />
- <a href='http://host.domain.tld/*' rel='nofollow'>http://host.domain.tld/*</a> -&gt; only http requests to only this host<br />
- */host.domain.tld/*      -&gt; anything to only this host<br />
- *host.domain.tld/*       -&gt; anything to all destinations containing this host</p>
<p>HTH,<br />
Stefaan
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Scott</title>
		<link>http://blogs.isaserver.org/pouseele/2006/07/21/solving-the-directly-access-these-servers-or-domains-issue-in-isa-server-2004-sp2/#comment-149</link>
		<pubDate>Sat, 22 Jul 2006 00:05:57 +0000</pubDate>
		<guid>http://blogs.isaserver.org/pouseele/2006/07/21/solving-the-directly-access-these-servers-or-domains-issue-in-isa-server-2004-sp2/#comment-149</guid>
					<description>This fix still does not work for servername.domain.com/*.
I have some servers that are inside the firewall and some that are outside the firewall with the same domain name, so I want to exclude certian names. This fix only allows me to use *.domain.com/*. Do you see the same in your tests?</description>
		<content:encoded><![CDATA[<p>This fix still does not work for servername.domain.com/*.<br />
I have some servers that are inside the firewall and some that are outside the firewall with the same domain name, so I want to exclude certian names. This fix only allows me to use *.domain.com/*. Do you see the same in your tests?
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Tom Shinder</title>
		<link>http://blogs.isaserver.org/pouseele/2006/07/21/solving-the-directly-access-these-servers-or-domains-issue-in-isa-server-2004-sp2/#comment-148</link>
		<pubDate>Fri, 21 Jul 2006 18:31:34 +0000</pubDate>
		<guid>http://blogs.isaserver.org/pouseele/2006/07/21/solving-the-directly-access-these-servers-or-domains-issue-in-isa-server-2004-sp2/#comment-148</guid>
					<description>Hi Stefaan,

Excellent post!!!
Thanks!
Tom</description>
		<content:encoded><![CDATA[<p>Hi Stefaan,</p>
<p>Excellent post!!!<br />
Thanks!<br />
Tom
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
