Article ID: 312176 - View products that this article applies to.
This article was previously published under Q312176
If you use NTLM authentication with a proxy, Internet Explorer may send extraneous NTLM authorization requests. This causes "407 Proxy authentication required" HTTP responses from the proxy. This problem can occur with either Microsoft Internet Security and Acceleration (ISA) Server 2000 or with Microsoft Proxy Server 2.0.
If this problem occurs, you may experience any of the following symptoms:
This problem may occur when Wininet recycles a keep-alive connection into the keep-alive connection pool so that the connection can be used to process other requests. If NTLM authentication has not completed on a connection yet, and if that connection is recycled, a new anonymous request is sent on that connection. This behavior produces a "407" response again.
This problem may or may not be visible, depending on the page that is requested. HTML pages that include many images (by using <IMG SRC=xxx> tags) typically produce the problem.
Internet Explorer 6To resolve this problem, obtain the latest service pack for Internet Explorer 6 . For additional information, click the following article number to view the article in the Microsoft Knowledge Base:
(http://support.microsoft.com/kb/328548/EN-US/ )How to Obtain the Latest Internet Explorer 6 Service Pack
Internet Explorer 6 SP1 with Q331906Use the procedure that is described in this section to resolve this problem if you have installed the hotfix that is described in the following Microsoft Knowledge Base article:
331906Follow these steps, and then quit Registry Editor:
(http://support.microsoft.com/kb/331906/EN-US/ )You Cannot Connect to the Internet After You Install Microsoft Updates
Internet Explorer 5.5 Service Pack 2A supported fix is now available from Microsoft, but it is only intended to correct the problem described in this article. Only apply it to systems that are experiencing this specific problem. This fix may receive additional testing to further ensure product quality. Therefore, if you are not severely affected by this problem, Microsoft recommends that you wait for the next Internet Explorer 5.5 service pack that contains this hotfix.
To resolve this problem immediately, contact Microsoft Product Support Services to obtain the fix. For a complete list of Microsoft Product Support Services phone numbers and information about support costs, visit the following Microsoft Web site:
http://support.microsoft.com/default.aspx?scid=fh;EN-US;CNTACTMSNote In special cases, charges that are ordinarily incurred for support calls may be canceled if a Microsoft Support Professional determines that a specific update will resolve your problem. The usual support costs will apply to additional support questions and issues that do not qualify for the specific update in question.
The English version of this fix has the file attributes (or later) that are listed in the following table. The dates and times for these files are listed in coordinated universal time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time tool in Control Panel.
Date Time Version Size File name ------------------------------------------------------- 17-Jun-2002 14:33 5.50.4918.1800 481 040 Wininet.dll
To work around this problem, set the MaxConnectionsPerServer value to 1. This limits the number of simultaneous HTTP connection to one. The default value is to use two connections. For additional information, click the article number below to view the article in the Microsoft Knowledge Base:
(http://support.microsoft.com/kb/282402/EN-US/ )How to Configure Internet Explorer to Have More Than Two Download Sessions
Microsoft has confirmed that this is a problem in the Microsoft products that are listed at the beginning of this article. This problem was first corrected in Internet Explorer 6 Service Pack 1.
Note that if you use the NTLM pass-through that is provided by ISA Server the pass-through always causes heavy NTLM traffic. In this scenario, Microsoft Internet Information Services (IIS) uses request-based authentication instead of the default session-based authentication. Therefore, every request (such as GET and POST requests) must be authenticated by using the three-way NTLM handshake.
Article ID: 312176 - Last Review: January 31, 2007 - Revision: 4.13
Contact us for more help
Connect with Answer Desk for expert help.