ISAserver.org Newsletter of July 2009

ISAserver.org Monthly Newsletter of October 2010 Sponsored by: Collective Software

Welcome to the ISAserver.org newsletter by Debra Littlejohn Shinder, MVP. Each month we will bring you interesting and helpful information on ISA Server. We want to know what all *you* are interested in hearing about. Please send your suggestions for future newsletter content to dshinder@isaserver.org

Easy Two-factor Logon for TMG/ISA VPN and Extranet

Question: I want to increase extranet and VPN security, but all the multi-factor systems I've looked at are too costly, or a hassle to deploy.  Shouldn't there be an easier way?
Answer: Take a look at the AuthLite OTP system.  Integration with ISA/TMG and AD is a snap.  Users carry a small, inexpensive USB key on their keychain and log in securely from anywhere, no client software 
required! Licensed per-user, any size organization can easily afford AuthLite.

You can evaluate AuthLite today with no obligation from Collective Software.

1. Certificates and UAG DirectAccess

One of the more common questions regarding the UAG DirectAccess server relates to certificate requirements. The reason for this is that PKI is an important component of a DirectAccess solution. There are basically three places where you need to plan for certificate deployment in your UAG DirectAccess solution.

These three general areas include:

  • Computer certificates
  • Network Location Server certificates
  • IP-HTTPS listener certificates

Computer Certificates

Computer certificates are used for client and server authentication on the UAG DirectAccess server and the DirectAccess clients. These certificates are usually generated by your private PKI using your Microsoft Certificate Server and deployed using autoenrollment. The computer certificates allow the clients to prove their identity to the UAG DirectAccess server and allow the UAG DirectAccess server to prove its identity to the DirectAccess clients. The certificates are required for authenticating both the intranet and infrastructure tunnels.

Network Location Server Web Site Certificates

A Network Location Server (NLS) is used by the DirectAccess client to determine if the DirectAccess client is on the intranet. If the DirectAccess client can create an SSL session with a Network Location Server on the intranet, then it knows that it's on the intranet and the DirectAccess turns off the Name Resolution Policy Table and uses the DNS server configured on the network interface, which is typically assigned to the client over DHCP. In order for the Network Location Server to enable SSL connects to itself, it needs a web site certificate bound to the web site hosted by the Network Location Server. There are no special requirements for the Network Location Server - it can be any SSL site - there is no specific or special content required.

IP-HTTPS Certificates

IP-HTTPS is an IPv6 transition protocol that allows the DirectAccess client to connect to the UAG DirectAccess server over the IPv4 Internet. IP-HTTPS encapsulates the IPv6 messages in an IPv4 header and then wraps that up in an HTTP header and then encrypts it with SSL. As you can imagine, there's a lot of overhead in the protocol, but it does allow the DirectAccess client to connect to the UAG DirectAccess server even when the client is located behind a port restricted firewall or even when the DirectAccess client is located behind a web proxy server. In order to create an IP-HTTPS listener on the UAG DirectAccess server, you need to acquire a certificate for the listener. In general, you should use a commercial certificate for this, since the DirectAccess client needs to be able to check the CRL for the IP-HTTPS certificate and commercial certificate providers have already built out a highly available CRL access infrastructure.

That's about it. The certificate requirements for UAG DirectAccess are not onerous or complex. There are no "special" certificates required, no special SAN entries, or any other "off-label" requirements. Most organizations will generate their own computer certificates and use autoenrollment, and most firms are going to create their own certificates for the Network Location Server. You could even use private certificates for the IP-HTTPS listener if you want, but you would then need to publish your private CRL. That's not too difficult, but you can make life easier using a commercial certificate, if for no other reason than that you don't need to create your own high availability solution for the CRL.

I hope you found this useful and that you'll find that PKI for UAG DirectAccess is pretty easy. If you have any questions on how to get your UAG DirectAccess PKI up and running, just let me know. Send me a note at dshinder@isaserver.org and I'll see what I can do to help you.

See you next month! - Deb.
dshinder@isaserver.org

======================
Quote of the Month - ?Most of what we call management consists of making it difficult for people to get their work done?. - Peter Drucker
======================

2. ISA Server 2006 Migration Guide - Order Today!

Dr. Tom Shinder's best selling books on ISA Server 2000 and 2004 were the "ISA Firewall Bibles" for thousands of ISA Firewall administrators. Dr. Tom and his illustrious team of ISA Firewall experts now present to you , ISA Server 2006 Migration Guide. This book leverages the over two years of experience Tom and his team of ISA Firewall experts have had with ISA 2006, from beta to RTM and all the versions and builds in between. They've logged literally 1000's of flight hours with ISA 2006 and they have shared the Good, the Great, the Bad and the Ugly of ISA 2006 with their no holds barred coverage of Microsoft's state of the art stateful packet and application layer inspection firewall..

Order your copy of ISA Server 2006 Migration Guide. You'll be glad you did.


   Click here to Order
   your copy today

Easy Two-factor Logon for TMG/ISA VPN and Extranet

Question: I want to increase extranet and VPN security, but all the multi-factor systems I've looked at are too costly, or a hassle to deploy.  Shouldn't there be an easier way?
Answer: Take a look at the AuthLite OTP system.  Integration with ISA/TMG and AD is a snap.  Users carry a small, inexpensive USB key on their keychain and log in securely from anywhere, no client software 
required! Licensed per-user, any size organization can easily afford AuthLite.

You can evaluate AuthLite today with no obligation from Collective Software.

3. ISAserver.org Learning Zone Articles of Interest

4. ISA/TMG/UAG Content of the Month

Interesting collection of twitter posts on how to configure the TMG firewall in an SBS/ESB environment. While I didn?t go through every rule or recommendation to make sure they were valid, it does look like a useful list overall.

Check it out here.

5. Tip of the Month

Often there are performance issues with the ISA firewall. These can be due to DNS issues. For a good review of how to fix DNS issues related see this WindowsNetworking.com article

Easy Two-factor Logon for TMG/ISA VPN and Extranet

Question: I want to increase extranet and VPN security, but all the multi-factor systems I've looked at are too costly, or a hassle to deploy.  Shouldn't there be an easier way?
Answer: Take a look at the AuthLite OTP system.  Integration with ISA/TMG and AD is a snap.  Users carry a small, inexpensive USB key on their keychain and log in securely from anywhere, no client software 
required! Licensed per-user, any size organization can easily afford AuthLite.

You can evaluate AuthLite today with no obligation from Collective Software.

6. ISA/TMG/IAG/UAG Link of the Month

  • Download TMG 2010 120-day trial here

7. Blog Posts 

8. Ask Sgt Deb

QUESTION:

I've read that when you install UAG there is also TMG installed on the same computer. Can I use both the UAG and the TMG components? That is to say, can I configure the TMG like I would if the TMG were on a standalone box?

ANSWER:

While that might sound like a good idea - in general you should stay away from the TMG console. There are a limited number of supported scenarios where you should go into the TMG console. For a list of scenarios where TMG configuration is support on the UAG server, check out the UAG support boundaries document here.

Do you have any questions or ideas for content? Email me on dshinder@isaserver.org.

Easy Two-factor Logon for TMG/ISA VPN and Extranet

Question: I want to increase extranet and VPN security, but all the multi-factor systems I've looked at are too costly, or a hassle to deploy.  Shouldn't there be an easier way?
Answer: Take a look at the AuthLite OTP system.  Integration with ISA/TMG and AD is a snap.  Users carry a small, inexpensive USB key on their keychain and log in securely from anywhere, no client software 
required! Licensed per-user, any size organization can easily afford AuthLite.

You can evaluate AuthLite today with no obligation from Collective Software.