I’ve noticed a recent burst of posts from ISA 2004 firewall administrators stating that they can’t get Outlook 2003 to work through the ISA firewall. With further questioning, I’ve discovered that these ISA firewall administrators are using the Firewall client. It’s great to hear they’ve had the good judgment to use the Firewall client! The Firewall client gives them strong user/group based access control for outbound connections for all Winsock TCP and UDP protocols. The Firewall client is one of the key pieces of the ISA firewall that enables it to provide a high level of security that your typical hardware firewall could never provide. This article solves the problem and explains away the Outlook/Firewall client misconceptions.
I decided to take the DIY approach for setting ISA firewall to securely publish Exchange 2003 Outlook Web Access using forms-based authentication and SSL bridging to provide a higher level of security in web mail access. I believe this step-by-step article will take out some of the guess work that I went through when checking the configuration.
Network and Firewall Administrators have been facing a battle to uphold the integrity and productivity of their networks. Some of the major issues they have found with these potentially dangerous applications (P2P, IM’s) are the potential to disclose corporate information (source code etc) in a non mediated forum, the misuse of company resources, legal issues, possible virus incursion and simply the fact that it is another (flavor of the month) type point of attack, potentially jeopardizing the entire network.
This article will describe how in simple terms we can leverage a new feature of ISA Server 2004 to prevent these types of applications clogging our internet pipe and exposing our company/network to the above issues.
One of the more unusual configuration options for the ISA firewall is what I call the "ISP co-location" configuration. I wrote about this configuration for the ISA Server 2000 firewall in an article Configuring an ISP Co-located Web/SMTP/ISA Server. I called this an ISP co-location configuration because in an ISP co-lo environment you typically don’t have the option to install a server with multiple interfaces. So, if you want to run your ISP co-located Web, FTP and SMTP server, you need to do it with a single NIC. Check out this article for how to create the single NIC colo config with your ISA 2004 firewall.
The release this week of Microsoft Internet and Security Acceleration (ISA) Server 2004 marks the availability of an important new solution in the quest for better corporate network security. ISA Server 2004 is an advanced application layer firewall, VPN and Web cache solution that helps enable customers to easily maximize existing IT investments by improving network security and performance.
Strong user/group based inbound and outbound access control is one of the key security features seen in true stateful application layer inspection firewalls. Unlike simple stateful filtering firewalls, the stateful application layer inspection firewall can make allow or deny decisions based on application layer information, such as the name of the user or the user's group membership, when evaluating an inbound or outbound request. This article discusses how to use the ISA 2004 firewall's Domain Name Sets feature to control outbound access and block forbidden sites.
Need a way to view in real time what users are accessing on the Web? How about an easy way to disconnect users who are downloading giant sized files? If so, then you need GFI's WebMonitor 2. This is a *must have* FREEWARE utility for all ISA firewall admins. Check out this article for details on what GFI WebMonitor 2 can do for you.
Use your ISA 2004 firewall to whack the MyDoom virus! Check out this article for full step by step details and a link to Jim Harrison's *free* script that does it all for you.
Use your ISA 2004 firewall to whack the Bagle virus! Check out this article for full step by step details and a link to Jim Harrison's click-o-matic script that does it all for you.
One of the key security features ISA Server 2004 firewalls bring to the plate is their ability to block a wide variety of viruses and worms. The ISA 2004 firewall can block external users from infecting your network and the prevent infected hosts on the corporate network from infecting machines on external networks. This page will be updated on an ongoing basis with links to articles on how to configure your ISA 2004 to block widespread virus and worm attacks.
Use your ISA 2004 firewall to whack the Ject virus! Check out this article for full step by step details and a link to Jim Harrison's one of a kind, best of breed Block Ject script for ISA firewalls.
Use your ISA 2004 firewall to whack the Sasser virus! Check out this article for full step by step details and a link to Jim Harrison's out of this world Block Sasser script for ISA firewalls.
Featured Links*
Receive all the latest articles by email!
Receive Real-Time & Monthly ISAserver.org article updates in your mailbox. Enter your email below! Click for Real-Time sample & Monthly sample
Become an ISAserver.org member!
Discuss your ISA Server issues with thousands of other ISA Server experts. Click here to join!