Cannot access server in HQ through proxy server

Hi Experts,

We have a TMG 2010 installed and clients are accessing Internet through it.

And now there is an access problem to the destinatined server in HQ in another country, and it was fine to reach the destinated server before the servere changed its IP.

When trying to accesss the destinated server with new IP, the TMG log and report shows the connection status with

12030: The connection with the server was terminated abnoramlly.

While there is another guest segment that allows Internet access without proxy server, and they are able to access the server with no problem at all.

When I captured packets using Wireshark from the pc and found that the connection was actually from the pc to proxy server with the following result:

from PC to Proxy server

CONNECT xxx.xxx.com:443 HTTP/1.0

from Proxy server to PC

HTTP/1.1 502 Proxy Error (The connection with the server was terminated abnormally) (text/html)

Would there be a configuration problem inside TMG?

When i include the domain in https inspection exemption list, is that means client would be able to reach ther destination without being inspected?

Then how about the incoming connection? Is there any rules which will restrict HTTPS inbound?

Apart from above problem, clients also not able access some of https website such as banking with CA's, and no problem using guest segment (not through proxy server).

Thanks in advance

Ben

April 26th, 2015 3:06am

Hi,

>>And now there is an access problem to the destinatined server in HQ in another country, and it was fine to reach the destinated server before the servere changed its IP.

Have you tried to re-create the rule to access the destinatined server after it changed the IP?

>>When i include the domain in https inspection exemption list, is that means client would be able to reach ther destination without being inspected?

When a site is added to the HTTPS inspection exclusion list, Forefront TMG does not check the sites certificate for expiration or revocation. However, name mismatch and trust are always checked, unless the No Validation mark is set.

Reference:Troubleshooting HTTPS inspection

Best Regards,

Joyce

Free Windows Admin Tool Kit Click here and download it now
April 27th, 2015 4:49am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics