Platinum Edition Using Windows NT Server 4

Previous chapterNext chapterContents


Chapter 59

Using Proxy Server

Some of the main topics in this chapter are

This chapter discusses in detail the Microsoft Proxy Server component of the BackOffice family of products. Proxy Server is a higher level server component that sits on top of Internet Information Server (IIS) to provide a particular piece of the I-net connectivity puzzle.

The main purpose of Proxy Server is to act as an access control gateway for providing clients connectivity to the Internet. Proxy Server enables secure, two-way communications between clients on a local network and the Internet by passing requests between the local network and the Internet. The Proxy Server services client requests and server responses but masks the identities of the client and server from each other. In addition, Proxy Server uses access control lists to limit outgoing access by clients and access from the Internet by unauthorized users.


NOTE: To the Proxy Server, a client is a computer, software, or service that makes a request for information from a server machine on a network. A server is a computer, software, or service that responds to the request.

Resource Requirements

Careful planning in implementing an effective solution is important to the success of an organization's Internet connectivity. The setup of a Proxy Server requires special attention to the requirements for hardware and software.

Proxy Server not only requires special hardware considerations but also requires certain software components for proper installation and operation. Each of these requirements is discussed in detail in the following sections.

Hardware

The hardware requirements for running a Proxy Server machine are identical to the requirements for Windows NT Server 4.0 and IIS.

In addition to the machine running Proxy Server, however, other hardware components play an important role in setting up an effective Proxy Server implementation.

One of the most important considerations is the storage subsystem. The Proxy Server caches frequently accessed Web sites and documents on its local hard disks. The use of a fast and high throughput subsystem can substantially increase system performance and server response time.

In addition, you should get as much memory as possible in your Proxy Server machine. A typical installation with 64M of RAM is not unreasonable. The memory requirements will be greatly influenced by the number of users being supported and the number of simultaneous connections being handled.


TIP: The use of NTFS file system for the hard disk subsystem is a good idea, due to its high throughput, fault tolerance, and security features.


TIP: It is a good idea to spread the Proxy Server storage requirements across multiple physical disks to improve system performance.

The speed of the Internet connection is also important. Currently, the choices most commonly available include:

Software

The Proxy Server is a component of the Microsoft BackOffice suite of server components. Because Proxy Server is a higher level component, however, it requires certain BackOffice components for its operation.The following software components are required for successful installation of Proxy Server:


CAUTION: You must upgrade the Windows NT Server installation by installing the Windows NT Server 4.0 Service Pack 1 maintenance update to your Proxy Server machine. The service pack is included on your Proxy Server CD.

Make sure that the appropriate drivers are installed for the network cards, modems, or ISDN adapters being used.


TIP: The machine running the Proxy Server can be a Primary Domain Controller, Backup Domain Controller, or a stand-alone server. It is recommended, however, that you configure the Proxy Server machine as a stand-alone server to improve performance and security.

Proxy Server Features

Microsoft Proxy Server provides a rich and powerful combination of functionality and ease of use for establishing corporate-wide secure Internet connectivity. It acts as a gateway between the local network and the external Internet. It leverages the Microsoft BackOffice suite of server products to provide advanced security, high performance, reliability, and ease-of-use features. Some of the features supported by Proxy Server include:

Proxy Server provides its functionality through two Windows NT services that run on a server machine: Web Proxy service and WinSock Proxy service. The following sections detail some of the features these services support.

Web Proxy Service

The Web Proxy service provides some of the basic functionality needed to implement the Proxy Server. It is a standards-based service that supports the common Internet protocols, such as HTTP, FTP, and Gopher.


NOTE: The Web Proxy service is CERN-proxy compatible, which is the standard used by most popular proxy implementations.

Some of the features supported by Web Proxy include the following:

WinSock Proxy Service

The WinSock Proxy service provides services for Windows applications that comply with the Windows Sockets version 1.1. Some of the features supported by the WinSock Proxy Service include the following:

Having learned about the features of the Proxy Server, the following sections discuss its installation, setup, and administration functions.

Setting Up Your Proxy Server

Proxy Server installs the Web Proxy and WinSock Proxy services to control Internet access and network security. Before you can install Proxy Server, you need to complete the following steps:

1. Set up a computer with Windows NT Server version 4.0 or higher. Make sure that the TCP/IP services are installed during Windows NT Server installation.

2. Install the Windows NT Server 4.0 Service Pack 1.


NOTE: Service Pack 1 is included on the Proxy Server CD.
3. Install IIS version 3.0.


TIP: IIS can be installed during the installation of Windows NT Server 4.0 or at a later time by using the IIS Setup program. During the installation process, you get the option of installing IIS. You can install IIS at that point or use the Setup program later to install IIS. The two procedures are identical, and this chapter outlines the procedure for installing IIS on a preconfigured Windows NT Server 4.0 machine. See Chapter 52, "Setting Up Internet Information Server," for more details.
4. Make sure that you have an administrator logon ID and password that you can use to install Proxy Server.

Make sure that these steps are completed before you attempt to install the Proxy Server software.

Installing Proxy Server

To start the installation, execute Setup.exe on the Proxer Server CD. After you have started the Setup program for Proxy Server:

1. Read the Welcome screen, and click Continue. The Proxy Server Setup dialog box appears (see Figure 59.1).

Fig. 59.1

The Proxy Server Setup dialog box enables you to change the default installation directory for Proxy Server.

2. If needed, change the folder where Proxy Server will be installed by clicking Change Folder; otherwise click Installation Options.

3. The Installation Options dialog box appears (see Figure 59.2).

4. By default, all options are selected. Make the appropriate selections for your needs, and click Continue. (For a first-time installation, you should install Proxy Server and the Administration tool. Documentation files can be installed at a later time if you want.)

5. The Proxy Server Cache Drives dialog box appears (see Figure 59.3). Assign appropriate disk space for caching by selecting a drive, entering a value for Maximum Size, and clicking Set. When finished, click OK.

Fig. 59.2

The Installation Options dialog box enables you to select the various services that will be installed during Proxy Server installation.

Fig. 59.3

Proxy Server uses cache drives to store frequently accessed data files.


NOTE: You must assign at least one drive and 5M of disk space for caching. The minimum recommended caching space for Proxy Server is 100M plus 0.5M for each client being serviced by the Proxy Server.


TIP: It's a good idea to use NTFS drives for caching. They provide better performance and security.


CAUTION: Do not use removable media or CD-ROM drives as caching drives.
6. The Local Address Table Configuration dialog box appears (see Figure 59.4). Define IP addresses being used by your internal network here. You can define multiple ranges from the pool of your IP addresses; however, each range must be a contiguous block of IP addresses. Click OK.

Fig. 59.4

Local Address Tables (LATs) enable you to define the IP address ranges that constitute your internal network.

7. You can also create a LAT by using the Construct Table button. When you click Construct Table, the Construct Local Address Table dialog box appears (see Figure 59.5). This dialog box enables you to include some predefined private internal network IP ranges as part of your LAT. It also enables you to obtain IP address ranges from your network adapter cards and from internal routing tables.

Fig. 59.5

The Construct Local Address Table dialog box enables you to include some predefined IP ranges as part of your internal network.


TIP: It's a good idea to use the Construct Local Address Table dialog box to include the predefined ranges and then add any other internal network ranges to the list.
8. When finished, click OK to return to the Local Address Table Configuration dialog box.

9. If you need to add any other IP address to the LAT table, use the From and To boxes and the Add button to add the ranges to the LAT table list.

10. When finished, click OK. The Client Installation/Configuration dialog box appears (see Figure 59.6).

Fig. 59.6

The Client Installation/Configuration dialog box enables you to set up the options for installation of WinSock and Web Proxy Clients.

11. Use the WinSock Proxy Client combo box to set up the options for installing WinSock clients from this server. Choose the method clients will use to connect to the Proxy Server. Clients can connect to the server by using its name or IP address.


CAUTION: If using a DNS name, make sure that the name displayed in the text box is correct and ensure that the DNS server has an appropriate entry for the Proxy Server name.
The Enable Access Control check box enables Proxy Server security and ensures that only clients with appropriate permissions can use the WinSock Proxy service. If disabled, all clients will have access to the WinSock Proxy service.

12. Use the Web Proxy Client combo box to set up the options for installing Web Proxy Clients from this server. If you select the Set Client Setup to Configure Browser Proxy Settings check box, the Client Setup program automatically configures the Web browser software to use the appropriate Proxy Server.


NOTE: The Set Client Setup to Configure Browser Proxy Settings feature works only with the Netscape Navigator and Microsoft Internet Explorer browsers.
Make sure that the correct Proxy Server name is listed in the text box.


NOTE: You cannot configure the Connect Clients to Proxy via Port setting here. The setting is preset for IIS. You must use the Internet Service Manager to change this value. Configuration of this option is covered later in this chapter.
The Enable Access Control check box enables Proxy Server security and ensures that only clients with appropriate permissions can use the WinSock Proxy service. If disabled, all clients will have access to the WinSock Proxy service.
13. When finished, click OK. The Setup program installs the necessary files and completes the Proxy Server setup.


TIP: To uninstall Proxy Server, use Uninstall from the Proxy Server program group.

At this point, Proxy Server installation is complete. You can use the Proxy Server program group to start the Internet Service Manager and administer Proxy Server services.

Administering Proxy Server

A powerful combination of tools and services are provided in the BackOffice suite for administering Proxy Server. The central administrative tool for Proxy Server is the Internet Service Manager provided with IIS. The Proxy Server Setup program modifies the Internet Service Manager so that it can also manage the Web proxy and WinSock Proxy services. In addition, tools included with Windows NT Server, such as the Performance Monitor and User Manager, can be used to administer various facets of the Proxy Server.

Using the Internet Service Manager

The Internet Service Manager is the focal point for most Proxy Server administration tasks. In particular, the Internet Service Manager administers the two services provided by the Proxy Server: Web Proxy and WinSock Proxy.

To administer Proxy Server services through Internet Service Manager:

1. Start the Internet Service Manager (see Figure 59.7). All services running on the currently selected server are listed.

2. If managing a different server, connect to that server by choosing Properties, Connect. Optionally, you can also list all servers running Internet services on the network by choosing Properties, Find All Servers.

Fig. 59.7

The Internet Service Manager can be used to administer Proxy Server services.


NOTE: Internet Service Manager can be used to administer local, as well as remote Proxy Servers.
3. As soon as you connect to the desired server, you can administer the particular Proxy Server service by double-clicking the computer name next to the service.

The following sections describe in detail the configuration options for the two Proxy Server services. The Internet Service Manager uses property sheets to configure and manage services running on the server.

Administering the Web Proxy Service. To configure the Web Proxy service, from the Internet Service Manager screen, double-click the computer name next to the Web Proxy service. The Web Proxy Service Properties dialog box appears with the Service tab selected (see Figure 59.8).

Fig. 59.8

The Service tab enables you to configure basic service options for the Proxy Server.

The Web Proxy Service Properties dialog box displays tabs for each category that can be configured:

Services. The Service tab sets basic options for the Web Proxy service (refer to Figure 59.9). To set these options, click the Service tab, and follow these steps:

1. The system uses the Product ID number and Comment text box to identify the Proxy Server. Enter a comment that can be used to identify the Web Proxy service.

2. The Enable Internet Publishing check box determines whether or not the Proxy Server will enable outside Internet users to gain access to Web servers on the local network. By default, this box is unchecked.


CAUTION: Be careful about enabling the Enable Internet Publishing check box. Make sure that you understand the security risks and take appropriate measures to counteract unauthorized access to your Web sites and corporate network.
3. Clicking the Current Sessions button displays the Web Proxy Service User Sessions dialog box (see Figure 59.9). This enables administrators to view the user connections currently using the Proxy Server service.

Fig. 59.9

The Web Proxy Service User Sessions dialog box can be used to dynamically monitor user activity across the Proxy Server.

4. The Edit Local Address Table (LAT) button on the Service tab enables administrators to make changes to the LAT table, as discussed earlier.

5. When finished, click Apply to commit changes, or click OK to close the Properties dialog box.


See "Securing Internet TCP/IP Services," p. 993

Permissions. The Permissions tab is used to configure access control permissions for the Web Proxy service (see Figure 59.10).

Fig. 59.10

The Permissions tab enables administrators to control client access to the Web Proxy service.

The Permissions tab can be used to control access for the following Internet services:

Permissions are granted on a per-service basis. You need to set up access lists for each service individually by selecting the appropriate service in the Protocol drop-down list. To grant users and groups permissions to the various Internet protocols, use the Add button to reach the Add Users and Groups dialog box (see Figure 59.11).

Fig. 59.11

The Add Users and Groups dialog box is used to grant Internet access permissions.

When finished, click Apply or OK to commit changes.

Caching. The Caching tab is used to configure caching information for the Web Proxy service (see Figure 59.12).

Fig. 59.12

The Caching parameters are critical for optimal Web Proxy service performance.


TIP: Once enabled, caching stores the most frequently accessed locations and documents on the local storage subsystem. The main purpose of caching is to optimize system performance.

To set caching options:

1. Set appropriate values for the Cache Expiration Policy and Enable Active Caching options.


NOTE: It's best to experiment with these values and monitor the results to determine what the best setting is for your network needs.
2. The Change Cache Size button enables administrators to expand or contract the size of the allocated cache disk space. Typical cache sizes are about 2-4M for each concurrent user connected through the Proxy Server.

3. The Reset Defaults button restores the original caching values.

4. The Advanced button displays the Advanced Cache Policy dialog box, as shown in Figure 59.13. This dialog box can be used to set a maximum size limit for cached objects and to reuse expired objects from cache when the Web site is unavailable.

Fig. 59.13

Advanced caching options enable fine-tuning of caching performance.

5. The Cache Filters combo box options enable administrators to specify sites that should be especially cached or not. Clicking Add brings up the Cache Filter Properties dialog box, which enables you to add specific URL locations for the cache filters (see Figure 59.14).

Fig. 59.14

By caching frequently visited site URLs, performance can be greatly improved.

6. When finished, click Apply or OK to commit changes.

See "An Introduction to Performance Monitoring," p. 661

Logging. The Logging tab is used to configure event logging options for the Web Proxy service (see Figure 59.15).

Fig. 59.15

You can use the Logging tab to set up elaborate reporting for troubleshooting purposes.

Logging information can be stored in log files, or you can use an ODBC-compatible database, such as Microsoft SQL Server, to store logging information.


TIP: You can use a single log file or a single ODBC database to store logging information from multiple servers.

To configure logging information, click the Logging tab and follow these steps:

1. Click the Enable Logging check box to start logging for the Web Proxy service.

2. Select the Regular Logging or Verbose Logging option. The Verbose option provides more detailed textual descriptions of log entries, whereas the Regular option provides logging codes.

3. Select Log to File or Log to SQL/ODBC Database.

4. If you've selected Log to File, you have the following choices:


NOTE: If you do not use the Automatically Open New Log File option, the same log file will be used indefinitely. You must select an existing directory or manually create a new directory for log files by using File Manager or the MKDIR command.
5. If you've selected Log to SQL/ODBC Database, you must configure the following options:


NOTE: You must use the ODBC Applet in Control Panel to create the specified system ODBC data source.
6. Click OK to continue, or click Apply to immediately implement the changes.


CAUTION: Logging to an ODBC data source is slower than logging to a file. Sites with heavy traffic should consider logging to a file for performance reasons or adding processing power to the server (such as adding a processor and higher performance disk subsystem) to support the additional load.

Filters. The Web Proxy Service Properties Filters tab is used to specify access limits and to control the network traffic on your Proxy Server (see Figure 59.16). You can choose a default access option that either will grant access to all users or deny access to all users. Then you can specify individual computers or groups that are the exceptions to the default. This section describes the option of granting access by default and entering exceptions that will be denied access.

To configure Filters options, select the Filters tab on the Web Proxy Service Properties dialog box, and follow these steps:

1. Select the Enable Filtering option for access control.

2. To exclude computers from having access, you can specify computers that will be granted access by using the Add button. This displays the Grant Access To dialog box (see Figure 59.17).

Fig. 59.16

Use the Web Proxy Service Filters tab to specify access control properties and network usage limits.

Fig. 59.17

The Grant Access To dialog box is used to grant access to selected computers when a default policy that denies access to everyone has been chosen.

3. In the Grant Access To dialog box, specify the computer or the group of computers that will be granted access, using the IP addresses for those computers. For a group of computers, you must also specify a subnet mask used by the group of computers. You can also specify a domain name.

4. Click OK to return to the Filters tab.

5. The specified computer or group of computers shows up in the included list. You can specify more computers to exclude or remove computers from the list by selecting them and clicking Remove. Use the Edit button to change the Grant Access To properties for a computer from the list.

6. When finished, click OK to continue or click Apply to immediately enforce the changes.

Administering WinSock Proxy Service. To configure the WinSock Proxy service running on a Proxy Server, double-click the computer name running the service to bring up the WinSock Proxy service properties dialog box. There are tabs for each category that can be configured:

The Services, Logging, and Filters tabs are identical to those used for the Web Proxy service. Refer to the previous section for the Web Proxy service for more information on setting these options.

The Protocols tab is used to define or reconfigure existing Internet protocols that clients can use to access resources on the Internet (see Figure 59.18).

Fig. 59.18

The Protocols tab defines parameters for the various Web access technologies.

The Proxy Server comes equipped with a large number of protocol definitions, such as RealAudio, VDOLive, SMTP, POP3, and NNTP. By defining protocols for the common Internet protocols, access can be granted or denied to clients by using the Permissions tab. To add a protocol definition from the Protocols tab:

1. Select the protocol in the Protocol Definitions drop-down list, and click Add. The Protocol Definition dialog box appears (see Figure 59.19).

2. Provide a Protocol Name in the text box.


CAUTION: The protocol name and port number must be unique for each new protocol.
3. In the Initial Connection box, provide a Port number.

Fig. 59.19

The Protocol Definition dialog box can be used to add support for additional Internet protocols.


TIP: Most common protocol port numbers are defined in the PROTOCOL file located in the <systemroot\system32\drivers\etc> directory. You can print that file to have a list of protocol and port numbers handy.
4. Select the protocol type.

5. In the Direction box, specify whether the protocol will be used for inbound or outbound traffic initially.

6. Use the Port Ranges for Subsequent Connections combo box to specify additional port ranges for protocols that facilitate both inbound and outbound traffic. The FTP protocol and the Telnet service are examples of two-way traffic protocols.

7. Click OK to save the new protocol definition.

Proxy Server Auto Dial Configuration

The Proxy Server Auto Dial feature is provided for scenarios when your organization's Internet connection is not permanent. A permanent, or dedicated, connection maintains constant connectivity to the Internet. A nondedicated connection establishes itself as needed. Usually, nondedicated connections terminate when there has been no traffic for a certain period of time and reestablish when Internet traffic is generated.

The Proxy Server Auto Dial feature provides dynamic connection of nondedicated Internet connections. When a client machine generates an Internet request, the Proxy Server recognizes it, reestablishes the Internet connection, and services the client request.

To configure Auto Dial:

1. From the Start menu, choose Programs, Microsoft Proxy Server, Auto Dial Configuration. This displays the Microsoft Proxy Auto Dial dialog box (see Figure 59.20).

Fig. 59.20

Use the Dialing Hours tab to set valid times for Dial on Demand connectivity.

2. Click the Dialing Hours tab.

3. Select the Enable Dial on Demand check box.

4. Select time slots when Proxy Server can dynamically establish a connection to the Internet. If time slots are set up, users can only connect to the Internet during those times. All requests during invalid times are denied by the Proxy Server.

5. Select the Credentials tab (see Figure 59.21). It's used to provide logon authentication information for establishing Auto Dial connections.

Fig. 59.21

Use the Credentials tab to provide logon authentication information for establishing an Auto Dial Internet connection.

6. Select the appropriate entry from the RAS phonebook entries list.

7. Provide a User Name and Password that can be used to connect to the Internet.

8. Optionally, provide a Domain name if required for connectivity.

9. Click Apply or OK to commit changes. Auto Dial configuration is complete.

Monitoring Proxy Server Performance

You can monitor Proxy Server performance in many ways. Proxy Server uses the Performance Monitor, Windows NT's built-in monitoring tool, to provide administrators with a means to gauge system performance and diagnose problems.

In addition to the Performance Monitor, the Windows NT logging system records events for Proxy Server. You can also use the built-in Proxy Server logging mechanism to gain insight into the server operation and performance.

Proxy Server also provides SNMP-based monitoring capabilities. If you're using SNMP-based monitoring tools, Proxy Server provides MIB files that can be used to enable SNMP monitoring.

However, Performance Monitor provides the most well-integrated and easy to use means of monitoring system performance for Proxy Server. When Proxy Server is first installed, three Performance Monitor objects are created to monitor Proxy Server activity:

To monitor Proxy Server performance, follow these steps:

1. From the Start menu, choose Programs, Microsoft Proxy Server, Monitor Microsoft Proxy Server Performance. The Performance Monitor screen appears (see Figure 59.22).

Fig. 59.22

Performance Monitor can monitor Proxy Server activity and diagnose performance bottlenecks.

2. To view additional counters, choose File, New Chart.

3. Choose Edit, Add to Chart. The Add to Chart dialog box appears.

4. Select an object to monitor, such as the WinSock Proxy Server service.

5. Select a counter from the counters list.

6. Click Add and then click Done.


See "An Introduction to Performance Monitoring," p. 661

Implementing Server Security

Installing and operating a Proxy Server involves paying special attention to the security issues involved. If you're running a server being accessed by thousands of users internally, security of your server and other computers on your enterprise network becomes an important issue. Microsoft accomplishes the security needs of administrators by integrating security for Proxy Server with the security model built into Windows NT Server.

Windows NT provides powerful security features for user authentication, access control, and auditing. Proxy Server leverages these capabilities of the Windows NT operating system to provide security for its Internet-based services.

Windows NT uses a security model that handles security for all services by using a single logon authentication mechanism. By creating user accounts and setting access permissions for those accounts, administrators can control what resources and services are available to users.

You can minimize the chance of security problems by adopting these standards:


Previous chapterNext chapterContents


Macmillan Computer Publishing USA

© Copyright, Macmillan Computer Publishing. All rights reserved.