<?xml version="1.0" encoding="utf-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: ISA Server and slow SSL</title>
	<link>http://www.mrchuckles.net/2005/04/21/isa-server-and-slow-ssl/</link>
	<description>So much tech, so little time...</description>
	<pubDate>Tue, 06 Jan 2009 01:45:28 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>By: Steven</title>
		<link>http://www.mrchuckles.net/2005/04/21/isa-server-and-slow-ssl/#comment-1918</link>
		<dc:creator>Steven</dc:creator>
		<pubDate>Thu, 14 Jul 2005 20:36:14 +0000</pubDate>
		<guid>http://www.mrchuckles.net/2005/04/21/isa-server-and-slow-ssl/#comment-1918</guid>
		<description>Jacks, in your ISA console, under Server Name -&#62; Configuration -&#62; General, there should be an icon for "Define Connection Limits".  Click there to configuration your connection limits and timeouts.</description>
		<content:encoded><![CDATA[<p>Jacks, in your ISA console, under Server Name -&gt; Configuration -&gt; General, there should be an icon for &#8220;Define Connection Limits&#8221;.  Click there to configuration your connection limits and timeouts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jacks</title>
		<link>http://www.mrchuckles.net/2005/04/21/isa-server-and-slow-ssl/#comment-1917</link>
		<dc:creator>Jacks</dc:creator>
		<pubDate>Thu, 14 Jul 2005 18:47:06 +0000</pubDate>
		<guid>http://www.mrchuckles.net/2005/04/21/isa-server-and-slow-ssl/#comment-1917</guid>
		<description>Where do you change the timeout setting?</description>
		<content:encoded><![CDATA[<p>Where do you change the timeout setting?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Edwin</title>
		<link>http://www.mrchuckles.net/2005/04/21/isa-server-and-slow-ssl/#comment-1912</link>
		<dc:creator>Edwin</dc:creator>
		<pubDate>Fri, 01 Jul 2005 15:07:50 +0000</pubDate>
		<guid>http://www.mrchuckles.net/2005/04/21/isa-server-and-slow-ssl/#comment-1912</guid>
		<description>I'm running MS Proxy 2.0 having the same slow SSL connections. Some sites however after a while are running much faster, without a single change in the configuration. In the netherlands two sites to try are: https://secure.postplaza.nl/tracktrace/ and https://www.p3.postbank.nl/sesam/SesamLoginServlet.

I acuse the webhosting side of the connection of having some settings not in order.
I suppose on some SSL servers there are settings for redirected SSL traffic.
</description>
		<content:encoded><![CDATA[<p>I&#8217;m running MS Proxy 2.0 having the same slow SSL connections. Some sites however after a while are running much faster, without a single change in the configuration. In the netherlands two sites to try are: <a href="https://secure.postplaza.nl/tracktrace/" rel="nofollow">https://secure.postplaza.nl/tracktrace/</a> and <a href="https://www.p3.postbank.nl/sesam/SesamLoginServlet." rel="nofollow">https://www.p3.postbank.nl/sesam/SesamLoginServlet.</a></p>
<p>I acuse the webhosting side of the connection of having some settings not in order.<br />
I suppose on some SSL servers there are settings for redirected SSL traffic.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: snow white</title>
		<link>http://www.mrchuckles.net/2005/04/21/isa-server-and-slow-ssl/#comment-1910</link>
		<dc:creator>snow white</dc:creator>
		<pubDate>Tue, 28 Jun 2005 14:37:29 +0000</pubDate>
		<guid>http://www.mrchuckles.net/2005/04/21/isa-server-and-slow-ssl/#comment-1910</guid>
		<description>Darn its seems to be a client (ie) issue as well, my XP workstation (sp2) works almost fine. But all client workstations (2k sp4, ie 6sp1) still give problems. Wtf has M$ done, Again!</description>
		<content:encoded><![CDATA[<p>Darn its seems to be a client (ie) issue as well, my XP workstation (sp2) works almost fine. But all client workstations (2k sp4, ie 6sp1) still give problems. Wtf has M$ done, Again!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: snow white</title>
		<link>http://www.mrchuckles.net/2005/04/21/isa-server-and-slow-ssl/#comment-1909</link>
		<dc:creator>snow white</dc:creator>
		<pubDate>Tue, 28 Jun 2005 09:58:38 +0000</pubDate>
		<guid>http://www.mrchuckles.net/2005/04/21/isa-server-and-slow-ssl/#comment-1909</guid>
		<description>Cool finally i have more to go on, it partly solved my problems as well requarding one website that was soooo sloooow. 

I use the word partly because the website is now browse able, but still slow. Using a direct connection gives a good comparisons in what ISA 2004 is doing whit my speed. Im rather disappointed of some bad "features" of the product and the low flexibility of the configuration options rules ed. 

Are there more tricks to boost the speed up as u know of?
</description>
		<content:encoded><![CDATA[<p>Cool finally i have more to go on, it partly solved my problems as well requarding one website that was soooo sloooow. </p>
<p>I use the word partly because the website is now browse able, but still slow. Using a direct connection gives a good comparisons in what ISA 2004 is doing whit my speed. Im rather disappointed of some bad &#8220;features&#8221; of the product and the low flexibility of the configuration options rules ed. </p>
<p>Are there more tricks to boost the speed up as u know of?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Proxy4NT</title>
		<link>http://www.mrchuckles.net/2005/04/21/isa-server-and-slow-ssl/#comment-1908</link>
		<dc:creator>Proxy4NT</dc:creator>
		<pubDate>Mon, 27 Jun 2005 07:10:57 +0000</pubDate>
		<guid>http://www.mrchuckles.net/2005/04/21/isa-server-and-slow-ssl/#comment-1908</guid>
		<description>Hm.. we did not have a limitation for connections and the time is 120 seconds, so I am not sure if this what we see is the same like yours.
You will see open connections from clients because HTTP/1.1 is used
and it will have keep alive the connection for a faster re-usage for the next.
You will find informations about this at http://www.faqs.org/rfcs/rfc2616.html section 8.1.3 Proxy Servers.
</description>
		<content:encoded><![CDATA[<p>Hm.. we did not have a limitation for connections and the time is 120 seconds, so I am not sure if this what we see is the same like yours.<br />
You will see open connections from clients because HTTP/1.1 is used<br />
and it will have keep alive the connection for a faster re-usage for the next.<br />
You will find informations about this at <a href="http://www.faqs.org/rfcs/rfc2616.html" rel="nofollow">http://www.faqs.org/rfcs/rfc2616.html</a> section 8.1.3 Proxy Servers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steven</title>
		<link>http://www.mrchuckles.net/2005/04/21/isa-server-and-slow-ssl/#comment-1907</link>
		<dc:creator>Steven</dc:creator>
		<pubDate>Wed, 22 Jun 2005 10:51:21 +0000</pubDate>
		<guid>http://www.mrchuckles.net/2005/04/21/isa-server-and-slow-ssl/#comment-1907</guid>
		<description>No, we didn't need to chnage the retransmit value in the registry, because our connections weren't timing out, they were being deined by the ISA Server.  ISA Server is significantly different from Proxy Server, and I believe ISA Server controls TCP/IP retransmits on its own.</description>
		<content:encoded><![CDATA[<p>No, we didn&#8217;t need to chnage the retransmit value in the registry, because our connections weren&#8217;t timing out, they were being deined by the ISA Server.  ISA Server is significantly different from Proxy Server, and I believe ISA Server controls TCP/IP retransmits on its own.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Proxy4NT</title>
		<link>http://www.mrchuckles.net/2005/04/21/isa-server-and-slow-ssl/#comment-1906</link>
		<dc:creator>Proxy4NT</dc:creator>
		<pubDate>Tue, 21 Jun 2005 10:34:18 +0000</pubDate>
		<guid>http://www.mrchuckles.net/2005/04/21/isa-server-and-slow-ssl/#comment-1906</guid>
		<description>Did you deal with the TcpMaxDataRetransmissions TCP/IP Value?
At my box the connection limit is set to unlimited and the time out is set to 120 in the internal networks object web proxy tab under advanced.
There was an article http://support.microsoft.com/default.aspx?scid=kb;en-us;191143 for the older Proxy Servers but the problem is
still the same. We use only plain web proxy feature without having the firewall client installed.

See you...
</description>
		<content:encoded><![CDATA[<p>Did you deal with the TcpMaxDataRetransmissions TCP/IP Value?<br />
At my box the connection limit is set to unlimited and the time out is set to 120 in the internal networks object web proxy tab under advanced.<br />
There was an article <a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;191143" rel="nofollow">http://support.microsoft.com/default.aspx?scid=kb;en-us;191143</a> for the older Proxy Servers but the problem is<br />
still the same. We use only plain web proxy feature without having the firewall client installed.</p>
<p>See you&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steven</title>
		<link>http://www.mrchuckles.net/2005/04/21/isa-server-and-slow-ssl/#comment-1905</link>
		<dc:creator>Steven</dc:creator>
		<pubDate>Mon, 20 Jun 2005 14:11:02 +0000</pubDate>
		<guid>http://www.mrchuckles.net/2005/04/21/isa-server-and-slow-ssl/#comment-1905</guid>
		<description>The above solution is for ISA Server 2004, which doesn't have an Outgoing Web Request listener.  I assume you're talking about ISA Server 2000.  I haven't run ISA Server 2000 for about a year, and I hadn't solved this problem when I was running ISA 2000, so I'm not certain where you would find the client connection limits.  Note that this problem on ISA 2004 stemmed from ALL client connections to the server being limited, not just outgoing web requests.  I don't know if ISA 2000 even has such a feature.</description>
		<content:encoded><![CDATA[<p>The above solution is for ISA Server 2004, which doesn&#8217;t have an Outgoing Web Request listener.  I assume you&#8217;re talking about ISA Server 2000.  I haven&#8217;t run ISA Server 2000 for about a year, and I hadn&#8217;t solved this problem when I was running ISA 2000, so I&#8217;m not certain where you would find the client connection limits.  Note that this problem on ISA 2004 stemmed from ALL client connections to the server being limited, not just outgoing web requests.  I don&#8217;t know if ISA 2000 even has such a feature.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jazman</title>
		<link>http://www.mrchuckles.net/2005/04/21/isa-server-and-slow-ssl/#comment-1904</link>
		<dc:creator>Jazman</dc:creator>
		<pubDate>Fri, 17 Jun 2005 05:53:20 +0000</pubDate>
		<guid>http://www.mrchuckles.net/2005/04/21/isa-server-and-slow-ssl/#comment-1904</guid>
		<description>Sorry to be dumb.But are you talking about the settings under outgoing web requests?</description>
		<content:encoded><![CDATA[<p>Sorry to be dumb.But are you talking about the settings under outgoing web requests?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
