I am sure we have all either encountered or heard of this "problem" one time or another if the ISA Server is part of the Active Directory Domain. Is it a problem? No, it is by design. To block all unnecessary traffic is the job of the firewall. I know Domain Controller traffic is not unnecessary unreachable traffic, but we have to "explain" to the ISA Server that DC traffic is reachable.
The ISA firewall can be configured to use strong, two-factor authentication to allow VPN clients access to selected network resources. When two-factor authentication with smart cards and the ISA firewall's stateful packet and application layer inspection engines kick in, you know you've got the best Firewall/VPN device you can get. Idan Plotnik shows you how to make it happen.
As good as the ISA firewall’s built-in Web site access control features are, you can always do better. To squeeze out the last ounce of stateful application layer inspection protection for Web connections, you’ll need a comprehensive and smart add-on. We tested SurfControl Web Filter for ISA Server 2004 and found it a stalwart partner in pumping up the ISA firewall security to the next level.
Many of you have read the article I did on how to enable NLB bidirectional affinity in ISA Server 2004 Standard Edition at http://isaserver.org/articles/2004bidirnlb.html. In that article I tried to make it clear that NLB BDA is not officially supported on ISA Server 2004 Standard Edition. However, it is fully supported in ISA Server 2004 Enterprise Edition and I highly recommend that if you require full NLB functionality for your ISA firewall deployments, then you should use the Enterprise Edition of the product.
A very nice feature of the ISA Server 2004 is the ability to verify the connectivity by regularly monitoring connections from the ISA Server computer to any specific computer or URL on any network. To accomplish that you have to configure connectivity verifiers. However, did you ever wonder how they exactly work, which access rules are involved and how this activity is logged? If you are interested in that kind of stuff, this article might give you some more background information.
In this two part article I will cover the default settings of the ISA 2004 System policy and how these can be manipulated to enable ISA to interact differently with other networked resources. The ISA system policy editor is one way of configuring ISA in a secure way and in also making changes that can un-secure ISA. This is why the security professional must understand the permutations of the system policy tool.
For those of you new to stateful application layer inspection of SSL tunneled data, the procedures involved might not immediately make sense. To get you up and running with your secure OWA and Web site publishing through the ISA firewall, we’ll present a two part series on how the ISA firewall handles remote access to Web sites using Web Publishing Rules. In this, part 1, we'll looking at some of the details of HTTP to HTTP bridging to prepare you for the complexities of SSL to SSL bridging in part 2.
ISAserver.org still has a few more signed copies of Tom & Deb Shinder’s Configuring ISA Server 2004 to offer. That's why we have decided to extend the free book giveaway for one more week to make sure all the copies are given away. In this document we will provide you with more information about how to win a free copy by adding our RSS Feed to your Tech website, linking to us, or submitting a comment about third party ISA Server software.
Service Pack 1 for the new ISA firewall's Standard Edition was released this week. Check out this article for some details on what its got and my installation experience.
Featured Links*
Receive all the latest articles by email!
Receive Real-Time & Monthly ISAserver.org article updates in your mailbox. Enter your email below! Click for Real-Time sample & Monthly sample
Become an ISAserver.org member!
Discuss your ISA Server issues with thousands of other ISA Server experts. Click here to join!