Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Config ISA Server 2006 for Security

Reply
Thread Tools Display Modes

Config ISA Server 2006 for Security

 
 
Salvador
Guest
Posts: n/a

 
      08-08-2009
I'm thinking of installing an ISA Server 2006 EE, for redundancy in case of
a fall from a server. I have several questions:

1 .- I can configure the ISA within the AD to authenticate users without a
security risk?.
The infrastructure would be: Internet (ISP optical fibre) - LAN: external
IP: 215.25.xx - Internal IP: 192.16.xx

I dont have DMZ.

Internet - ISA EE - LAN
|
AD (domain Internal)

2 .- To have redundancy, they are 2 + 1 ISA Server servers not CSS?

What worries me most is the first part, I recommend it?. Thank you

 
Reply With Quote
 
 
 
 
Jens Baier
Guest
Posts: n/a

 
      08-08-2009
Hi,

> 1 .- I can configure the ISA within the AD to authenticate users without a
> security risk?.


yes, via AD integrated ISA or RADIUS or LDAP (for publishing rules only)

> The infrastructure would be: Internet (ISP optical fibre) - LAN:
> external IP: 215.25.xx - Internal IP: 192.16.xx


> 2 .- To have redundancy, they are 2 + 1 ISA Server servers not CSS?


2 ISA + 2 CSS for redundancy would be the best!

--
Gruss Jens
www.it-training-grote.de
www.forefront-tmg.de
https://mvp.support.microsoft.com/profile/Marc.Grote
http://blog.it-training-grote.de

 
Reply With Quote
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      08-09-2009
Hello Salvador,

For ISA server i suggest you use also following NG/Forums:
microsoft.public.isaserver

http://www.microsoft.com/communities...blic.isaserver

or

http://social.technet.microsoft.com/...ntedgesecurity

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> I'm thinking of installing an ISA Server 2006 EE, for redundancy in
> case of a fall from a server. I have several questions:
>
> 1 .- I can configure the ISA within the AD to authenticate users
> without a
> security risk?.
> The infrastructure would be: Internet (ISP optical fibre) - LAN:
> external
> IP: 215.25.xx - Internal IP: 192.16.xx
> I dont have DMZ.
>
> Internet - ISA EE - LAN
> |
> AD (domain Internal)
> 2 .- To have redundancy, they are 2 + 1 ISA Server servers not CSS?
>
> What worries me most is the first part, I recommend it?. Thank you
>



 
Reply With Quote
 
Salvador
Guest
Posts: n/a

 
      08-09-2009
there may be security problems with that configuration?.
I have read do not recommend that ISA as web / proxy integrated with the AD,
right?.

"Jens Baier" <> wrote in message
news:...
> Hi,
>
>> 1 .- I can configure the ISA within the AD to authenticate users without
>> a security risk?.

>
> yes, via AD integrated ISA or RADIUS or LDAP (for publishing rules only)
>
>> The infrastructure would be: Internet (ISP optical fibre) - LAN:
>> external IP: 215.25.xx - Internal IP: 192.16.xx

>
>> 2 .- To have redundancy, they are 2 + 1 ISA Server servers not CSS?

>
> 2 ISA + 2 CSS for redundancy would be the best!
>
> --
> Gruss Jens
> www.it-training-grote.de
> www.forefront-tmg.de
> https://mvp.support.microsoft.com/profile/Marc.Grote
> http://blog.it-training-grote.de
>


 
Reply With Quote
 
Phillip Windell
Guest
Posts: n/a

 
      08-10-2009

"Salvador" <> wrote in message
news:...
> there may be security problems with that configuration?.
> I have read do not recommend that ISA as web / proxy integrated with the
> AD, right?.
>
> "Jens Baier" <> wrote in message
> news:...
>> Hi,
>>
>>> 1 .- I can configure the ISA within the AD to authenticate users without
>>> a security risk?.

>>
>> yes, via AD integrated ISA or RADIUS or LDAP (for publishing rules only)
>>
>>> The infrastructure would be: Internet (ISP optical fibre) - LAN:
>>> external IP: 215.25.xx - Internal IP: 192.16.xx

>>
>>> 2 .- To have redundancy, they are 2 + 1 ISA Server servers not CSS?

>>
>> 2 ISA + 2 CSS for redundancy would be the best!
>>
>> --
>> Gruss Jens
>> www.it-training-grote.de
>> www.forefront-tmg.de
>> https://mvp.support.microsoft.com/profile/Marc.Grote
>> http://blog.it-training-grote.de
>>

>



 
Reply With Quote
 
Phillip Windell
Guest
Posts: n/a

 
      08-10-2009

"Salvador" <> wrote in message
news:...
> there may be security problems with that configuration?.
> I have read do not recommend that ISA as web / proxy integrated with the
> AD, right?.


Not correct.

Debunking the Myth that the ISA Firewall Should Not be a Domain Member
http://www.isaserver.org/tutorials/D...in-Member.html


--
Phillip Windell

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------


 
Reply With Quote
 
Salvador
Guest
Posts: n/a

 
      08-10-2009
Then there can be no security problems, "I explained, this will have an ISA
server IP on the internet, if you set up an ad, if I jump the firewall,
enter the network?

"Phillip Windell" <> wrote in message
news:...
>
> "Salvador" <> wrote in message
> news:...
>> there may be security problems with that configuration?.
>> I have read do not recommend that ISA as web / proxy integrated with the
>> AD, right?.

>
> Not correct.
>
> Debunking the Myth that the ISA Firewall Should Not be a Domain Member
> http://www.isaserver.org/tutorials/D...in-Member.html
>
>
> --
> Phillip Windell
>
> The views expressed, are my own and not those of my employer, or
> Microsoft,
> or anyone else associated with me, including my cats.
> -----------------------------------------------------
>
>


 
Reply With Quote
 
Phillip Windell
Guest
Posts: n/a

 
      08-10-2009


"Salvador" <> wrote in message
news:...
> Then there can be no security problems, "I explained, this will have an
> ISA server IP on the internet, if you set up an ad, if I jump the
> firewall, enter the network?


Well,...hmm,...how do I approach this?

1. If you ever "jumped" the ISA you would be the first in the history of
mankind. ISA in its entire product history has never been busted through.
Admins have left it open in ways that they shouldn't,...but that is their
fault,...not the ISA's.

2. If you got past the ISA you would be on the network no matter if there
was an AD structure or not (a Domain and a Network are two different
things). It could be a 100% Linux network with no "Domain" at all and
you'd still be "on the network". Also ISA as a domain member does not
mean you have access to AD using it any more than being on a workstation
gives you access to AD because the workstation is a domain member,...ISA is
not a Domain Controller (except for SBS deployment,...and facilities with
high security requirements don't use SBS).

3. ISA being a Domain member increases its security,..not decreases it,...
because of all the abilities it gains with AD. How are you going to "jump"
ISA if you are forced to authenticate with it when you don't have such
credentials to authenticate with it? The whole purpose for Active Directory
Domains to even exist is to create a solid robust "security environment".
If creating Domain means creating risks instead of reducing them,...then
lets just stop creating domains.

--
Phillip Windell

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Server config and security fixes listings archie Scripting 0 06-25-2007 06:28 AM
security updates 2006-07-12 pemei Windows Update 0 07-14-2006 03:59 PM
security presentations at Tech-Ed 2006 Brad Dinerman [MVP - Windows Server Networking] Windows Server 0 06-06-2006 02:51 AM
security presentations at Tech-Ed 2006 Brad Dinerman [MVP - Windows Server Networking] Server Networking 0 06-06-2006 02:51 AM
Norton Internet Security 2006 & Norton SystemWorks 2006 Incompatia Dipu : The Genesis Of The Nemesis Internet Explorer 5 03-31-2006 10:05 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59