Knowledge Base

Error 12201: "proxy-to-proxy authentication"

Article ID: 177063

Article Last Modified on 1/16/2007


APPLIES TO


This article was previously published under Q177063

SYMPTOMS

When you chain or array the Microsoft Proxy Server version 2.0 servers, you may receive the following error message:
Error 12201 A chained proxy server or array member requires proxy-to-proxy authentication. Please contact your server administrator.

CAUSE

This error occurs when Encrypted (Microsoft Windows NT Challenge/Response) authentication is used to send credentials to the upstream proxy server or array when anonymous access is allowed on the proxy servers.

Note This authentication option is set in the Web Proxy Service properties. To set the option, select Routing, select Upstream Routing, and then select Use Credentials to Communicate with Upstream Proxy Array.

RESOLUTION

To resolve this problem, disable anonymous authentication in the Microsoft Internet Information Server (IIS) WWW Service properties on the proxy servers that participate in the chain or array. To do this, select Windows NT Challenge/Response authentication (enabled).

If you are concerned about security on your intranet, you can use Basic authentication together with Secure Sockets Layer (SSL) encryption. However, when you do this, all transmissions are encrypted. Therefore, this method has a significant effect on the performance of the server.

Keywords: kbfaq KB177063