
Some of the main topics in this chapter are
This chapter discusses in detail the Microsoft Proxy Server component of the BackOffice family of products. Proxy Server is a higher level server component that sits on top of Internet Information Server (IIS) to provide a particular piece of the I-net connectivity puzzle.
The main purpose of Proxy Server is to act as an access control gateway for providing clients connectivity to the Internet. Proxy Server enables secure, two-way communications between clients on a local network and the Internet by passing requests between the local network and the Internet. The Proxy Server services client requests and server responses but masks the identities of the client and server from each other. In addition, Proxy Server uses access control lists to limit outgoing access by clients and access from the Internet by unauthorized users.
NOTE: To the Proxy Server, a client is a computer, software, or service that makes a request for information from a server machine on a network. A server is a computer, software, or service that responds to the request.
Careful planning in implementing an effective solution is important to the success of an organization's Internet connectivity. The setup of a Proxy Server requires special attention to the requirements for hardware and software.
Proxy Server not only requires special hardware considerations but also requires certain software components for proper installation and operation. Each of these requirements is discussed in detail in the following sections.
The hardware requirements for running a Proxy Server machine are identical to the requirements for Windows NT Server 4.0 and IIS.
In addition to the machine running Proxy Server, however, other hardware components play an important role in setting up an effective Proxy Server implementation.
One of the most important considerations is the storage subsystem. The Proxy Server caches frequently accessed Web sites and documents on its local hard disks. The use of a fast and high throughput subsystem can substantially increase system performance and server response time.
In addition, you should get as much memory as possible in your Proxy Server machine. A typical installation with 64M of RAM is not unreasonable. The memory requirements will be greatly influenced by the number of users being supported and the number of simultaneous connections being handled.
TIP: The use of NTFS file system for the hard disk subsystem is a good idea, due to its high throughput, fault tolerance, and security features.
TIP: It is a good idea to spread the Proxy Server storage requirements across multiple physical disks to improve system performance.
The speed of the Internet connection is also important. Currently, the choices most commonly available include:
The Proxy Server is a component of the Microsoft BackOffice suite of server components. Because Proxy Server is a higher level component, however, it requires certain BackOffice components for its operation.The following software components are required for successful installation of Proxy Server:
CAUTION: You must upgrade the Windows NT Server installation by installing the Windows NT Server 4.0 Service Pack 1 maintenance update to your Proxy Server machine. The service pack is included on your Proxy Server CD.
Make sure that the appropriate drivers are installed for the network cards, modems, or ISDN adapters being used.
TIP: The machine running the Proxy Server can be a Primary Domain Controller, Backup Domain Controller, or a stand-alone server. It is recommended, however, that you configure the Proxy Server machine as a stand-alone server to improve performance and security.
Microsoft Proxy Server provides a rich and powerful combination of functionality and ease of use for establishing corporate-wide secure Internet connectivity. It acts as a gateway between the local network and the external Internet. It leverages the Microsoft BackOffice suite of server products to provide advanced security, high performance, reliability, and ease-of-use features. Some of the features supported by Proxy Server include:
Proxy Server provides its functionality through two Windows NT services that run on a server machine: Web Proxy service and WinSock Proxy service. The following sections detail some of the features these services support.
The Web Proxy service provides some of the basic functionality needed to implement the Proxy Server. It is a standards-based service that supports the common Internet protocols, such as HTTP, FTP, and Gopher.
NOTE: The Web Proxy service is CERN-proxy compatible, which is the standard used by most popular proxy implementations.
Some of the features supported by Web Proxy include the following:
The WinSock Proxy service provides services for Windows applications that comply with the Windows Sockets version 1.1. Some of the features supported by the WinSock Proxy Service include the following:
Having learned about the features of the Proxy Server, the following sections discuss its installation, setup, and administration functions.
Proxy Server installs the Web Proxy and WinSock Proxy services to control Internet access and network security. Before you can install Proxy Server, you need to complete the following steps:
NOTE: Service Pack 1 is included on the Proxy Server CD.
TIP: IIS can be installed during the installation of Windows NT Server 4.0 or at a later time by using the IIS Setup program. During the installation process, you get the option of installing IIS. You can install IIS at that point or use the Setup program later to install IIS. The two procedures are identical, and this chapter outlines the procedure for installing IIS on a preconfigured Windows NT Server 4.0 machine. See Chapter 52, "Setting Up Internet Information Server," for more details.
Make sure that these steps are completed before you attempt to install the Proxy Server software.
To start the installation, execute Setup.exe on the Proxer Server CD. After you have started the Setup program for Proxy Server:
The Proxy Server Setup dialog box enables you to change the default installation directory for Proxy Server.
The Installation Options dialog box enables you to select the various services that will be installed during Proxy Server installation.
Proxy Server uses cache drives to store frequently accessed data files.
NOTE: You must assign at least one drive and 5M of disk space for caching. The minimum recommended caching space for Proxy Server is 100M plus 0.5M for each client being serviced by the Proxy Server.
TIP: It's a good idea to use NTFS drives for caching. They provide better performance and security.
CAUTION: Do not use removable media or CD-ROM drives as caching drives.
Local Address Tables (LATs) enable you to define the IP address ranges that constitute your internal network.
The Construct Local Address Table dialog box enables you to include some predefined IP ranges as part of your internal network.
TIP: It's a good idea to use the Construct Local Address Table dialog box to include the predefined ranges and then add any other internal network ranges to the list.
The Client Installation/Configuration dialog box enables you to set up the options for installation of WinSock and Web Proxy Clients.
CAUTION: If using a DNS name, make sure that the name displayed in the text box is correct and ensure that the DNS server has an appropriate entry for the Proxy Server name.
NOTE: The Set Client Setup to Configure Browser Proxy Settings feature works only with the Netscape Navigator and Microsoft Internet Explorer browsers.
NOTE: You cannot configure the Connect Clients to Proxy via Port setting here. The setting is preset for IIS. You must use the Internet Service Manager to change this value. Configuration of this option is covered later in this chapter.
TIP: To uninstall Proxy Server, use Uninstall from the Proxy Server program group.
At this point, Proxy Server installation is complete. You can use the Proxy Server program group to start the Internet Service Manager and administer Proxy Server services.
A powerful combination of tools and services are provided in the BackOffice suite for administering Proxy Server. The central administrative tool for Proxy Server is the Internet Service Manager provided with IIS. The Proxy Server Setup program modifies the Internet Service Manager so that it can also manage the Web proxy and WinSock Proxy services. In addition, tools included with Windows NT Server, such as the Performance Monitor and User Manager, can be used to administer various facets of the Proxy Server.
The Internet Service Manager is the focal point for most Proxy Server administration tasks. In particular, the Internet Service Manager administers the two services provided by the Proxy Server: Web Proxy and WinSock Proxy.
To administer Proxy Server services through Internet Service Manager:
The Internet Service Manager can be used to administer Proxy Server services.
NOTE: Internet Service Manager can be used to administer local, as well as remote Proxy Servers.
The following sections describe in detail the configuration options for the two Proxy Server services. The Internet Service Manager uses property sheets to configure and manage services running on the server.
Administering the Web Proxy Service. To configure the Web Proxy service, from the Internet Service Manager screen, double-click the computer name next to the Web Proxy service. The Web Proxy Service Properties dialog box appears with the Service tab selected (see Figure 59.8).
The Service tab enables you to configure basic service options for the Proxy Server.
The Web Proxy Service Properties dialog box displays tabs for each category that can be configured:
Services. The Service tab sets basic options for the Web Proxy service (refer to Figure 59.9). To set these options, click the Service tab, and follow these steps:
CAUTION: Be careful about enabling the Enable Internet Publishing check box. Make sure that you understand the security risks and take appropriate measures to counteract unauthorized access to your Web sites and corporate network.
The Web Proxy Service User Sessions dialog box can be used to dynamically monitor user activity across the Proxy Server.
See "Securing Internet TCP/IP Services," p. 993
Permissions. The Permissions tab is used to configure access control permissions
for the Web Proxy service (see Figure 59.10).
Fig. 59.10
The Permissions tab enables administrators to control client access to the Web Proxy service.
The Permissions tab can be used to control access for the following Internet services:
Permissions are granted on a per-service basis. You need to set up access lists for each service individually by selecting the appropriate service in the Protocol drop-down list. To grant users and groups permissions to the various Internet protocols, use the Add button to reach the Add Users and Groups dialog box (see Figure 59.11).
The Add Users and Groups dialog box is used to grant Internet access permissions.
When finished, click Apply or OK to commit changes.
Caching. The Caching tab is used to configure caching information for the
Web Proxy service (see Figure 59.12).
Fig. 59.12
The Caching parameters are critical for optimal Web Proxy service performance.
TIP: Once enabled, caching stores the most frequently accessed locations and documents on the local storage subsystem. The main purpose of caching is to optimize system performance.
To set caching options:
NOTE: It's best to experiment with these values and monitor the results to determine what the best setting is for your network needs.
Advanced caching options enable fine-tuning of caching performance.
By caching frequently visited site URLs, performance can be greatly improved.
See "An Introduction to Performance Monitoring," p. 661
Logging. The Logging tab is used to configure event logging options for
the Web Proxy service (see Figure 59.15).
Fig. 59.15
You can use the Logging tab to set up elaborate reporting for troubleshooting purposes.
Logging information can be stored in log files, or you can use an ODBC-compatible database, such as Microsoft SQL Server, to store logging information.
TIP: You can use a single log file or a single ODBC database to store logging information from multiple servers.
To configure logging information, click the Logging tab and follow these steps:
NOTE: If you do not use the Automatically Open New Log File option, the same log file will be used indefinitely. You must select an existing directory or manually create a new directory for log files by using File Manager or the MKDIR command.
NOTE: You must use the ODBC Applet in Control Panel to create the specified system ODBC data source.
CAUTION: Logging to an ODBC data source is slower than logging to a file. Sites with heavy traffic should consider logging to a file for performance reasons or adding processing power to the server (such as adding a processor and higher performance disk subsystem) to support the additional load.
Filters. The Web Proxy Service Properties Filters tab is used to specify access limits and to control the network traffic on your Proxy Server (see Figure 59.16). You can choose a default access option that either will grant access to all users or deny access to all users. Then you can specify individual computers or groups that are the exceptions to the default. This section describes the option of granting access by default and entering exceptions that will be denied access.
To configure Filters options, select the Filters tab on the Web Proxy Service Properties dialog box, and follow these steps:
Use the Web Proxy Service Filters tab to specify access control properties and network usage limits.
The Grant Access To dialog box is used to grant access to selected computers when a default policy that denies access to everyone has been chosen.
Administering WinSock Proxy Service. To configure the WinSock Proxy service running on a Proxy Server, double-click the computer name running the service to bring up the WinSock Proxy service properties dialog box. There are tabs for each category that can be configured:
The Services, Logging, and Filters tabs are identical to those used for the Web Proxy service. Refer to the previous section for the Web Proxy service for more information on setting these options.
The Protocols tab is used to define or reconfigure existing Internet protocols that clients can use to access resources on the Internet (see Figure 59.18).
The Protocols tab defines parameters for the various Web access technologies.
The Proxy Server comes equipped with a large number of protocol definitions, such as RealAudio, VDOLive, SMTP, POP3, and NNTP. By defining protocols for the common Internet protocols, access can be granted or denied to clients by using the Permissions tab. To add a protocol definition from the Protocols tab:
CAUTION: The protocol name and port number must be unique for each new protocol.
The Protocol Definition dialog box can be used to add support for additional Internet protocols.
TIP: Most common protocol port numbers are defined in the PROTOCOL file located in the <systemroot\system32\drivers\etc> directory. You can print that file to have a list of protocol and port numbers handy.
The Proxy Server Auto Dial feature is provided for scenarios when your organization's Internet connection is not permanent. A permanent, or dedicated, connection maintains constant connectivity to the Internet. A nondedicated connection establishes itself as needed. Usually, nondedicated connections terminate when there has been no traffic for a certain period of time and reestablish when Internet traffic is generated.
The Proxy Server Auto Dial feature provides dynamic connection of nondedicated Internet connections. When a client machine generates an Internet request, the Proxy Server recognizes it, reestablishes the Internet connection, and services the client request.
To configure Auto Dial:
Use the Dialing Hours tab to set valid times for Dial on Demand connectivity.
Use the Credentials tab to provide logon authentication information for establishing an Auto Dial Internet connection.
You can monitor Proxy Server performance in many ways. Proxy Server uses the Performance Monitor, Windows NT's built-in monitoring tool, to provide administrators with a means to gauge system performance and diagnose problems.
In addition to the Performance Monitor, the Windows NT logging system records events for Proxy Server. You can also use the built-in Proxy Server logging mechanism to gain insight into the server operation and performance.
Proxy Server also provides SNMP-based monitoring capabilities. If you're using SNMP-based monitoring tools, Proxy Server provides MIB files that can be used to enable SNMP monitoring.
However, Performance Monitor provides the most well-integrated and easy to use means of monitoring system performance for Proxy Server. When Proxy Server is first installed, three Performance Monitor objects are created to monitor Proxy Server activity:
To monitor Proxy Server performance, follow these steps:
Performance Monitor can monitor Proxy Server activity and diagnose performance bottlenecks.
See "An Introduction to Performance Monitoring," p. 661
Installing and operating a Proxy Server involves paying special attention to the security issues involved. If you're running a server being accessed by thousands of users internally, security of your server and other computers on your enterprise network becomes an important issue. Microsoft accomplishes the security needs of administrators by integrating security for Proxy Server with the security model built into Windows NT Server.
Windows NT provides powerful security features for user authentication, access control, and auditing. Proxy Server leverages these capabilities of the Windows NT operating system to provide security for its Internet-based services.
Windows NT uses a security model that handles security for all services by using a single logon authentication mechanism. By creating user accounts and setting access permissions for those accounts, administrators can control what resources and services are available to users.
You can minimize the chance of security problems by adopting these standards:
© Copyright, Macmillan Computer Publishing. All rights reserved.