Microsoft has released official recommendations on how to configure your ISA Server firewall to beat down Sobig worm traffic. Check this out, read the info, and get the fixes.
Here's the awaited for part 2 in our series on how to get the calling ISA Server firewall/VPN gateway to use EAP/TLS certificate-based authentication when connecting to the answering ISA Server firewall/VPN gateway. Get it while its hot! (and our servers are online)
If you're using your ISA Server firewall as a VPN gateway, you're probably using MS-CHAPv2 authentication and the PPTP VPN protocol. While that provides decent security for your gateway to gateway link, how about moving to the next level? That's right, use EAP/TLS certificate authentication and L2TP/IPSec. Sounds hard? Its easier than you think. Check out part 1 today!
Check out this list of key KB articles compiled by top-notch PSS escalation engineer Scott Jiles. One of them might just solve a tough ISA Server 2000 problem you're having today!
Do you need to know what fixes were available before SP1? How about after SP1? Do you need to know what fixes were included in SP1 or what ISA fixes were released after Feature Pack 1? Scott Jiles has put together a comprehensive list of fixes and shares his compilation with the ISAServer.org community.
One of the most frequent pieces of advice I give is to disable anonymous access. What exactly do I mean? I'm sure many of you have asked that question! Check out this article an get an explanation of my request to "disable anonymous access"
Road warriors depend on VPN access to the corporate network. Just one file, one presentation, can make the difference between happy holidays for everyone and standing in line at a soup kitchen. Windows Server 2003 supports PPTP, L2TP/IPSec, and the new RFC IPSec NAT Traversal VPN protocol. IPSec NAT-T allows your road warriors to use IPSec to connect from anywhere. Check this article to find out how.
If you want to publish services co-located on the ISA Server itself, you have to be sure that socket pooling is disabled. We've described how to disable socket pooling in IIS 5.0 here at ISAServer.org. IIS 6.0 is a completely different story. Raymond Comvalius shows you how to disable socket pooling for IIS and Exchange Services running on the firewall itself.
Have you wanted to log to a database, but you didn't have a Microsoft SQL Server sitting around? Then Brian Bailey has some good news for you! Brian shows you in this article how to get ISA Server 2000 to log to a MySQL database. Enjoy!
One of the more problematic situations businesses running ISA Server firewalls run into is name resolution support for SecureNAT clients. Unlike the situation with Firewall and Web Proxy clients, where the ISA Server firewall resolves Internet host names on their behalf, the SecureNAT client must be able to resolve Internet host names themselves. If the SecureNAT client can’t resolve the name, the connection fails. Check out this article for a great, low maintenance solution to this problem.
Featured Links*
Receive all the latest articles by email!
Receive Real-Time & Monthly ISAserver.org article updates in your mailbox. Enter your email below! Click for Real-Time sample & Monthly sample
Become an ISAserver.org member!
Discuss your ISA Server issues with thousands of other ISA Server experts. Click here to join!