<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title>THE OFFICIAL BLOG OF THE SBS "DIVA" : ISA Server</title><link>http://msmvps.com/blogs/bradley/archive/tags/ISA+Server/default.aspx</link><description>Tags: ISA Server</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>So you want to ensure that you have full access to ISA before, during and after patching for 09-016?</title><link>http://msmvps.com/blogs/bradley/archive/2009/04/20/so-you-want-to-ensure-that-you-have-full-access-to-isa-before-during-and-after-patching-for-09-016.aspx</link><pubDate>Tue, 21 Apr 2009 02:45:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1689294</guid><dc:creator>bradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1689294</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1689294</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2009/04/20/so-you-want-to-ensure-that-you-have-full-access-to-isa-before-during-and-after-patching-for-09-016.aspx#comments</comments><description>&lt;p&gt;So you want to ensure that you have full access to ISA before, during and after patching for 09-016 (assuming you don&amp;#39;t have a box with more than 4 procs) &lt;a href="http://blogs.technet.com/sbs/archive/2009/04/20/ms09-012-and-isa-server-standard-edition-14109-failures.aspx"&gt;http://blogs.technet.com/sbs/archive/2009/04/20/ms09-012-and-isa-server-standard-edition-14109-failures.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS09-016.mspx"&gt;http://www.microsoft.com/technet/security/Bulletin/MS09-016.mspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Listen to this for the reason you want to add a policy for remote management:&lt;/p&gt;
&lt;p&gt;Inside SBS Episode #12 - The ISA Server Meltdown | Odeo: Search, Discover and Share Digital Media from Millions of Audio and Video Clips: &lt;br /&gt;&lt;a href="http://odeo.com/episodes/538067-Inside-SBS-Episode-12-The-ISA-Server-Meltdown" class="moz-txt-link-freetext"&gt;http://odeo.com/episodes/538067-Inside-SBS-Episode-12-The-ISA-Server-Meltdown&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;Mark, Damian, Justin, Chris on ISA. &lt;br /&gt;&lt;br /&gt;8:53 minutes in Justin talks about it. &lt;br /&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-family:Arial;font-size:x-small;"&gt;Launch the ISA console&lt;/span&gt; &lt;/li&gt;
&lt;li&gt;&lt;span style="font-family:Arial;font-size:x-small;"&gt;Click on Firewall Policy&lt;/span&gt; &lt;/li&gt;
&lt;li&gt;&lt;span style="font-family:Arial;font-size:x-small;"&gt;Click on Edit system policy&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-family:Arial;font-size:x-small;"&gt;Okay see that setting that says &amp;quot;Remote Management&amp;quot;?&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:Arial;font-size:x-small;"&gt;&lt;img src="http://www.sbslinks.com/images/image.36.gif" alt="" /&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:Arial;font-size:x-small;"&gt;See where you build a rule to add your external [static] IP address to remotely manage the box via TS no matter what?&amp;nbsp; See where you can even add the ability to ping from your remote server?&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:Arial;font-size:x-small;"&gt;&lt;img src="http://www.sbslinks.com/images/image.37.gif" alt="" /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:Arial;font-size:x-small;"&gt;Click edit, then add your static IP to that category of &amp;quot;remote management computers&amp;quot;.&amp;nbsp;&amp;nbsp;Adding that rule there means you won&amp;#39;t hit a &amp;quot;lockout&amp;quot; when you remotely manage ISA....like...installing a security patch.&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1689294" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>SBS premium and Quad Core</title><link>http://msmvps.com/blogs/bradley/archive/2008/02/20/sbs-premium-and-quad-core.aspx</link><pubDate>Wed, 20 Feb 2008 08:13:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1519909</guid><dc:creator>bradley</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1519909</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1519909</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2008/02/20/sbs-premium-and-quad-core.aspx#comments</comments><description>&lt;h4 id="subjcns!1ABA4CA6583AB317!155" style="MARGIN-BOTTOM:0px;"&gt;&lt;em&gt;SBS Premium with ISA Server 2004 on Quad Core CPUs&lt;/em&gt;&lt;/h4&gt;
&lt;div class="bvMsg" id="msgcns!1ABA4CA6583AB317!155"&gt;
&lt;p&gt;I hope Darren doesn&amp;#39;t mind me stealing his entire REALLY good blog post about how he got stuck installing Windows 2003 sp2 and ISA on a quad core CPU server and how he needed to get up to ISA 2004 sp2 or sp3 to fix this&lt;em&gt;&amp;nbsp;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Recently a customer of mine purchased a Dual Quad Core server to act as their SBS Premium server.&amp;nbsp; They planned to run SQL Server and ISA Server on this machine, and wanted the machine to last 5 to 7 years, so a dual Quad core configuration isn&amp;#39;t out of line, and price wise, it wasn&amp;#39;t much more expensive than two dual core processors. &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;When they went to install the ISA Server component however, they found that ISA Server wouldn&amp;#39;t start.&amp;nbsp; Complaining about there being too many processors.&amp;nbsp; &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;SBS supports two PHYSICAL CPUs as counted by the number of CPU Sockets on the main board, not by the number of processor cores reported to the operating system.&amp;nbsp; So ISA not working isn&amp;#39;t a licensing issue, but rather a bug in ISA&amp;#39;s detection of the number of CPUs. &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Fortunately, there is a fix: &lt;font color="#ff0000"&gt;Install ISA Server 2004 SP2&lt;/font&gt;.&amp;nbsp; &amp;lt;edit now install ISA 2004 sp3 instead -- Download details: ISA Server 2004 Standard Edition Service Pack 3: &lt;br /&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=A05A074A-5033-4792-AF8B-58B90D841436&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyId=A05A074A-5033-4792-AF8B-58B90D841436&amp;amp;displaylang=en&lt;/a&gt;&amp;gt;&lt;br /&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;To figure out the fastest / least error prone way of doing this, I contacted Microsoft&amp;#39;s Pre-Sales Tech support, and here&amp;#39;s the exact order in which they recommend doing the installation: &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Now, there are few different things you need to do before going ahead with installing SP2 on ISA 2004.&lt;br /&gt;1.) Make sure you download SP2 for ISA 2004 and two following roll outs first: &lt;/em&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;Update for HTTP issues in Internet Security and Acceleration Server 2004 Service Pack 2&lt;br /&gt;&lt;/em&gt;&lt;a href="http://support.microsoft.com/kb/916106"&gt;&lt;em&gt;http://support.microsoft.com/kb/916106&lt;/em&gt;&lt;/a&gt;&lt;em&gt; &lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Update for HTTP issues in Internet Security and Acceleration Server 2004 Service Pack 2&lt;br /&gt;&lt;/em&gt;&lt;a href="http://support.microsoft.com/kb/917902"&gt;&lt;em&gt;http://support.microsoft.com/kb/917902&lt;/em&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;2.) Go ahead and install everything in the following order; SP2, KB 916106 then KB 917902. &amp;lt;instead install ISA 2004 sp3&amp;gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Once that is done with, you’ll probably want to install SP2 for Windows, apparently this is a potential problem with ISA; please view the following blog posting for information on the issue, before actually going ahead and installing it. &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;VPN, SecureNat/Nat and Outlook clients not working after installing Windows Service Pack 2 in SBS 2003 Premium &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/sbs/archive/2007/03/19/vpn-securenat-nat-and-outlook-clients-not-working-after-installing-windows-service-pack-2-in-sbs-2003-premium.aspx"&gt;&lt;em&gt;http://blogs.technet.com/sbs/archive/2007/03/19/vpn-securenat-nat-and-outlook-clients-not-working-after-installing-windows-service-pack-2-in-sbs-2003-premium.aspx&lt;/em&gt;&lt;/a&gt;&lt;em&gt; &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;After all that is done, there is a chance that you might experience a performance issue with the workload spiking on one of the CPUs, the support team hasn’t had any calls on it, but just in case, here’s the KB on how to fix it. &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Throughput for an ISA Server that is running on a Windows Server 2003 Service Pack 2 (SP2)-based multiprocessor computer may be greatly reduced or completely blocked &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://support.microsoft.com/kb/934809"&gt;&lt;em&gt;http://support.microsoft.com/kb/934809&lt;/em&gt;&lt;/a&gt;&lt;br /&gt;&lt;em&gt;Darren&amp;#39;s Space: SBS Premium with ISA Server 2004 on Quad Core CPUs: &lt;br /&gt;http://darrenmyher.spaces.live.com/blog/cns!1ABA4CA6583AB317!155.entry&lt;br /&gt;&lt;/em&gt;&lt;br /&gt;&lt;/p&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1519909" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>A rule for ISA</title><link>http://msmvps.com/blogs/bradley/archive/2007/12/31/a-rule-for-isa.aspx</link><pubDate>Mon, 31 Dec 2007 18:38:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1429507</guid><dc:creator>bradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1429507</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1429507</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2007/12/31/a-rule-for-isa.aspx#comments</comments><description>&lt;p&gt;&lt;font face="arial,helvetica,sans-serif" size="2"&gt;&lt;a class="" href="http://www.amazon.com/Windows-Server-Administrators-Companion-PRO-Administrators/dp/0735625050/ref=sr_1_2?ie=UTF8&amp;amp;s=books&amp;amp;qid=1199126731&amp;amp;sr=1-2"&gt;Charlie&lt;/a&gt; needed to connect to Gmail&amp;#39;s nntp folders inside of Outlook.&amp;nbsp; He had ISA&amp;#39;s rules to not be all open and realized it was impacting Gmail.&amp;nbsp; &lt;/font&gt;&lt;/p&gt;&lt;pre&gt;&lt;font face="arial,helvetica,sans-serif" size="2"&gt;(Necessary if you&amp;#39;re going to use Outlook rule processing, since SBS
doesn&amp;#39;t include a default rule for this.) You&amp;#39;ll need to add an ISA Rule
to make it work on some machines. I could post the XML file, but it&amp;#39;s
easy enough to set up:

1.) Open ISA Mgmt console. 
2.) Scroll down to near the bottom, just about the SBS Internet Access
Rule
3.) Click Tasks tab on right, click Create a New Access Rule
4.) Give it a name - &amp;quot;Gmail SSL Allow&amp;quot; (or whatever). Click Next
5.) Select Allow, click Next.
6.) Select This Rule Applies to Selected Protocols from the drop down
list. 
7.) Click Add. Expand Mail. Select IMAPS (and IMAP4 if you also use
non-secure IMAP servers somewhere.) Click Add. Click Close.
8.) Click Next to move to the Access Rule Sources page. Click Add
9.) Expand Network Sets, select All Protected Networks. Click Add. Click
Close.
10.) Click Next to move to the Access Rule Destinations. Click Add.
11.) Expand Networks, select External, click Add. Click Close.
12.) Click Next to move to the User Sets. I leave this at All Users. 
13.) Click Next to move to the Completing New Access Rule page. 
14.) Click Finish. Then Click Apply to make the rule actually active. 

You&amp;#39;re in business. 

Charlie.&lt;/font&gt; &lt;/pre&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1429507" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>What happened to my DHCP after ISA sp2?</title><link>http://msmvps.com/blogs/bradley/archive/2007/10/13/what-happened-to-my-dhcp-after-isa-sp2.aspx</link><pubDate>Sun, 14 Oct 2007 04:17:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1247338</guid><dc:creator>bradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1247338</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1247338</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2007/10/13/what-happened-to-my-dhcp-after-isa-sp2.aspx#comments</comments><description>&lt;span style="FONT-SIZE:12pt;FONT-FAMILY:&amp;#39;Times New Roman&amp;#39;,&amp;#39;serif&amp;#39;;mso-fareast-font-family:Calibri;mso-fareast-theme-font:minor-latin;mso-ansi-language:EN-US;mso-fareast-language:EN-US;mso-bidi-language:AR-SA;"&gt;&lt;font face="Arial" size="2"&gt;MPECS Inc. Blog: SBS Premium - SBS Post Install ISA Rule Must Do for DHCP: &lt;br /&gt;&lt;a href="http://blog.mpecsinc.ca/2007/10/sbs-premium-sbs-post-install-isa-rule.html"&gt;http://blog.mpecsinc.ca/2007/10/sbs-premium-sbs-post-install-isa-rule.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blog.mpecsinc.ca/2007/10/windows-xp-ie7-in-microsoftwindows.html"&gt;&lt;/a&gt;&lt;br /&gt;&lt;/font&gt;&lt;a href="http://feeds.feedburner.com/~r/MpecsIncBlog/~3/168142162/windows-xp-ie7-in-microsoftwindows.html"&gt;&lt;/a&gt;&lt;/span&gt;
&lt;p&gt;Philip&amp;#39;s blog talks about the case of the missing DHCP&lt;/p&gt;
&lt;p&gt;Amy talks about why this happens:&lt;/p&gt;
&lt;p&gt;Why DHCP Stops Working After You Add a Custom Access Rule - SecureSMB: &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/securesmb/archive/2007/10/13/why-dhcp-stops-working-after-you-add-a-custom-access-rule.aspx"&gt;http://msmvps.com/blogs/securesmb/archive/2007/10/13/why-dhcp-stops-working-after-you-add-a-custom-access-rule.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;One of the unusual-ness of SBS is the behavior of rule making on the box it&amp;#39;s protecting.&amp;nbsp; This is one side effect we see, and in particular I&amp;#39;ve seen it pop up post sp2.&amp;nbsp; ISA is very RFC aware and my guess is that with the application of sp2 it&amp;#39;s gotten a bit more RFC aware than it already was.&amp;nbsp; But that&amp;#39;s pure speculation and probably what is going on is the mere &amp;#39;change&amp;#39; that a service pack application brings and perhaps teh consultant has changed rule order post sp2 and is not equating that with the action.&amp;nbsp; But bottom line, watch your rules.&amp;nbsp; I don&amp;#39;t have a special DHCP rule here and my server works just fine.&lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1247338" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>ISA hot topics</title><link>http://msmvps.com/blogs/bradley/archive/2007/10/12/isa-hot-topics.aspx</link><pubDate>Sat, 13 Oct 2007 01:22:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1245824</guid><dc:creator>bradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1245824</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1245824</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2007/10/12/isa-hot-topics.aspx#comments</comments><description>&lt;p&gt;&lt;font face="arial,helvetica,sans-serif"&gt;&amp;gt;&amp;gt;&amp;gt; HOT TOPICS for OCTOBER 2007 &amp;lt;&amp;lt;&amp;lt;&lt;br /&gt;&lt;br /&gt;The following &amp;quot;hot topics&amp;quot; were posted and resolved during the month of &lt;br /&gt;September:&lt;br /&gt;&lt;br /&gt;ISSUE&lt;br /&gt;=====&lt;br /&gt;When you try to access external FTP sites in an ISA environment, you may &lt;br /&gt;experience ISA error message:&lt;br /&gt;&lt;br /&gt;ISA Server: extended error message :&lt;br /&gt;200 Type set to I.&lt;br /&gt;200 PORT command successful.&lt;br /&gt;550 Permission denied on server.&amp;nbsp; You are restricted to your account.&lt;br /&gt;&lt;br /&gt;This mostly occurs when you visit some FTP sites which needs authentication &lt;br /&gt;in IE7 using the URL form &lt;/font&gt;&lt;a&gt;&lt;font face="arial,helvetica,sans-serif"&gt;ftp://username:password@ftp.site.com&lt;/font&gt;&lt;/a&gt;&lt;font face="arial,helvetica,sans-serif"&gt;.&lt;br /&gt;&lt;br /&gt;In IE6&lt;br /&gt;-------&lt;br /&gt;You can also access the FTP site using the URL &lt;/font&gt;&lt;a&gt;&lt;font face="arial,helvetica,sans-serif"&gt;ftp://ftp.site.com&lt;/font&gt;&lt;/a&gt;&lt;font face="arial,helvetica,sans-serif"&gt;. It will &lt;br /&gt;prompts you to input username and password. After inputting username and &lt;br /&gt;password, you can access the ftp site.&lt;br /&gt;&lt;br /&gt;In IE7&lt;br /&gt;-------&lt;br /&gt;No matter what types of clients you are using (SecureNAT, web-proxy(BTW, it &lt;br /&gt;will not work with folder view enabled) or firewall client). You just cannot &lt;br /&gt;access it successfully.&lt;br /&gt;&lt;br /&gt;CAUSE&lt;br /&gt;======&lt;br /&gt;This is because folder view is disabled in IE7, this is by design. This is &lt;br /&gt;controlled by windows shell. Internet Explorer 6 and the Windows shell were &lt;br /&gt;basically the same program but used different user interface (UI) entry &lt;br /&gt;points. However, IE7 install new component of its own, it is not the same &lt;br /&gt;program of Windows shell.&lt;br /&gt;&lt;br /&gt;RESOLUTION&lt;br /&gt;===========&lt;br /&gt;To workaround the issue, you must access the website in Windows Explorer.&lt;br /&gt;&lt;br /&gt;MORE INFORMATION&lt;br /&gt;=================&lt;br /&gt;Separation of Internet Explorer 7 from the Windows shell&lt;br /&gt;&lt;/font&gt;&lt;a href="http://support.microsoft.com/?id=928675"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;http://support.microsoft.com/?id=928675&lt;/font&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;font face="arial,helvetica,sans-serif"&gt;ISSUE&lt;br /&gt;=====&lt;br /&gt;ISA firewall service failed to start after you installed ISA 2004 Server on &lt;br /&gt;the SBS. When we manually start firewall service, it retuned &amp;quot;Windows could &lt;br /&gt;not start the Microsoft firewall on local computer. For more info review the &lt;br /&gt;Event Log.&amp;nbsp; If this is a non-Microsoft service, contact the vendor and refer &lt;br /&gt;to service specific error code -2147221005&amp;quot;.&lt;br /&gt;&lt;br /&gt;In application log, you got Firewall error 14001: &amp;quot;The description for Event &lt;br /&gt;ID ( 14001 ) in Source ( Microsoft Firewall ) cannot be found. The local &lt;br /&gt;computer may not have the necessary registry information or message&lt;br /&gt;DLL files to display messages from a remote computer. You may be able to use &lt;br /&gt;the /AUXSOURCE= flag to retrieve this description; see Help and Support for &lt;br /&gt;details.&lt;br /&gt;&lt;br /&gt;Reinstalled ISA Server, however this issue persists.&lt;br /&gt;&lt;br /&gt;CAUSE&lt;br /&gt;======&lt;br /&gt;Corrupted registry or components.&lt;br /&gt;&lt;br /&gt;RESOLUTION&lt;br /&gt;===========&lt;br /&gt;Check the permission on following registry keys:&lt;br /&gt;&lt;br /&gt;HEKY_CLASSES_ROOT/Fpc.FPCFilterExpressions&lt;br /&gt;HEKY_CLASSES_ROOT /Fpc.FPCFilterExpressions.1 HEKY_CLASSES_ROOT /FPC.Root &lt;br /&gt;HEKY_CLASSES_ROOT /FPC.Root.1 HEKY_CLASSES_ROOT /FPCSTG HEKY_CLASSES_ROOT &lt;br /&gt;/FPCSTG.1 HEKY_CLASSES_ROOT /FPCSTG.FPCStorageEnvironment HEKY_CLASSES_ROOT &lt;br /&gt;/FPCSTG.FPCStorageEnvironment.1 HEKY_CLASSES_ROOT /FPCSTG.FPCStorageFactory &lt;br /&gt;HEKY_CLASSES_ROOT /FPCSTG.FPCStorageFactory.1&lt;br /&gt;&lt;br /&gt;Set the above registry keys with following permission:&lt;br /&gt;&lt;br /&gt;Administrator - Full Control&lt;br /&gt;System - Full Control&lt;br /&gt;Network Service - Full control&lt;br /&gt;Authenticated Users - Full Control&lt;br /&gt;Creator Owner - Full Control&lt;br /&gt;Server Operators - Full Control&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;ISSUE&lt;br /&gt;=====&lt;br /&gt;OWA access problem via ISA 2006.&amp;nbsp; Error Code: 500 Internal Server Error. The &lt;br /&gt;number of HTTP requests per minute exceeded the configured limit. Contact &lt;br /&gt;the server administrator. (12219).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;CAUSE&lt;br /&gt;======&lt;br /&gt;Incorrect authentication method, FBA was enabled on both ISA and Exchange.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;RESOLUTION&lt;br /&gt;===========&lt;br /&gt;Disabled FBA on Exchange server and enabled it on the ISA web listener.&lt;br /&gt;&lt;br /&gt;MORE INFORMATION&lt;br /&gt;=================&lt;br /&gt;Publishing Exchange Server 2003 with ISA Server 2006&lt;br /&gt;&lt;/font&gt;&lt;a href="http://www.microsoft.com/technet/isa/2006/deployment/exchange2003.mspx"&gt;&lt;font face="arial,helvetica,sans-serif"&gt;http://www.microsoft.com/technet/isa/2006/deployment/exchange2003.mspx&lt;/font&gt;&lt;/a&gt; &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1245824" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>After upgrading nic drivers - reboot your box.</title><link>http://msmvps.com/blogs/bradley/archive/2007/05/04/after-upgrading-nic-drivers-reboot-your-box.aspx</link><pubDate>Sat, 05 May 2007 01:27:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:890805</guid><dc:creator>bradley</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=890805</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=890805</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2007/05/04/after-upgrading-nic-drivers-reboot-your-box.aspx#comments</comments><description>&lt;p&gt;&lt;img src="http://www.sbslinks.com/images/imag5.13.gif" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;After doing a firmware upgrade and a driver upgrade to 10.24.0... reboot your server.&lt;/p&gt;
&lt;p&gt;ISA will will block the traffic and not let it out.&amp;nbsp; I had a feeling it would freak out just a smidge with that firmware/nic driver upgrade...and it did.&lt;/p&gt;
&lt;p&gt;Now on to see if that helps with getting SP2 on the box.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=890805" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>ISA rules in the wrong place</title><link>http://msmvps.com/blogs/bradley/archive/2007/01/16/isa-rules-in-the-wrong-place.aspx</link><pubDate>Wed, 17 Jan 2007 07:15:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:499644</guid><dc:creator>bradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=499644</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=499644</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2007/01/16/isa-rules-in-the-wrong-place.aspx#comments</comments><description>&lt;P&gt;&lt;A href="http://simultaneouspancakes.com/Lessons/2007/01/15/isa-and-dhcp/"&gt;http://simultaneouspancakes.com/Lessons/2007/01/15/isa-and-dhcp/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;When you start using ISA to restrict things... be careful about restricting too much.....&lt;/P&gt;
&lt;P&gt;Depending on where you put that ISA rule set you&amp;nbsp;could end up shutting off DHCP services as a result.....&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;-------- Original Message --------&lt;BR&gt;Subject: Sharing info.. ISA Rules&lt;BR&gt;Date: Sat, 13 Jan 2007 22:25:44 -0000&lt;BR&gt;From: Pop &amp;lt;&lt;A href="mailto:Iknowyouwantit@lol.com"&gt;Iknowyouwantit@lol.com&lt;/A&gt;&amp;gt;&lt;BR&gt;Newsgroups: microsoft.public.windows.server.sbs&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;If you already all knew it then sorry... ;-)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Set up a denied access rule for 'banned sites' a few days later noticed pcs &lt;BR&gt;were not getting an IP address from server DHCP (oh yes, router DHCP &lt;BR&gt;switched off...lol)&lt;BR&gt;Noticed the above rule was before the SBS Protected network rule, moved it &lt;BR&gt;below and DHCP working again...&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Interesting...&lt;/EM&gt;&lt;BR&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=499644" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>So I'm looking in my ISA log files...</title><link>http://msmvps.com/blogs/bradley/archive/2007/01/03/so-i-m-looking-in-my-isa-log-files.aspx</link><pubDate>Thu, 04 Jan 2007 04:15:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:468527</guid><dc:creator>bradley</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=468527</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=468527</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2007/01/03/so-i-m-looking-in-my-isa-log-files.aspx#comments</comments><description>&lt;P&gt;So I'm looking in my ISA log files because for the last couple of days my &lt;A class="" href="http://www.scorpionsoft.com/products/"&gt;Scorpion Software Firewall da&lt;/A&gt;shboard has indicated I've been getting ntp attacks from two IP addresses:&amp;nbsp;192.168.116.1 and 192.168.142.1 and it's now&amp;nbsp;where I have some time on my&amp;nbsp;hands to&amp;nbsp;figure out what's going on.... they aren't getting out ...but what are they there?&amp;nbsp; My internal IP address&amp;nbsp;on this network is based on the&amp;nbsp;old SBS 4.x numbering of 10.0.0.x,&amp;nbsp;my home IP&amp;nbsp;range is 192.168.16.x... the 192.168.1.254 is my external nic attached to the router...so WHY do&amp;nbsp;I have two IP addresses attempting to&amp;nbsp;get a time sync&amp;nbsp;and being denied?&amp;nbsp;&amp;nbsp;When I ping them they are unavailable, and an arp -a brings back nothing.&amp;nbsp; Well in&amp;nbsp;chatting with Amy she indicated that the logging I was seeing "0xc0040014 FWX_E_FWE_SPOOFING_PACKET_DROPPED" was not hitting a "rule" but rather at the kernel mode.&amp;nbsp; It was labelling them as spoofed as it didn't see these addresses in my domain.&lt;/P&gt;
&lt;P&gt;&lt;IMG src="http://www.sbslinks.com/images/blogim8.jpg"&gt; &lt;/P&gt;
&lt;P&gt;No kidding.... neither did I... so what are they?&amp;nbsp; So Amy Googled and found that one might be a Vmware network connection and the other Cisco.... Vmware?&amp;nbsp; Hang on .. I have vmware on this workstation but it's not loaded up... and at the time I had the two nics enabled (I've since disabled them)&lt;/P&gt;
&lt;P&gt;&lt;IMG src="http://www.sbslinks.com/images/blogim7.jpg"&gt; &lt;/P&gt;
&lt;P&gt;And sure enough...that was the IP addresses that the nics were assigned in the interface and ISA was just doing was it was supposed to be doing on my internal network and saying "yo, I don't recognize these, they aren't on my approved internal IP addresses so I'm blocking them".&amp;nbsp; Okay so not exactly like that, but you get my meaning.&lt;/P&gt;
&lt;P&gt;Sure 'nuff, disabled the nics as I'm not running a vmware on this machine at this time and that was indeed it. Once again, the firewall dashboard stuck something in my face that I don't think I would have noticed otherwise.&lt;/P&gt;
&lt;P&gt;And by the way.... to Amy ... Ditto!&amp;nbsp; THANK YOU! for all that you do for the SBS and ISA Community!&amp;nbsp; &lt;U&gt;&lt;FONT color=#810081&gt;&lt;A href="http://isainsbs.blogspot.com/2007/01/thank-you.html"&gt;http://isainsbs.blogspot.com/2007/01/thank-you.html&lt;/A&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;A href="http://isainsbs.blogspot.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=468527" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>Using ISA to protect the SBS mail server just a smidge more....</title><link>http://msmvps.com/blogs/bradley/archive/2006/12/29/using-isa-to-protect-the-sbs-mail-server-just-a-smidge-more.aspx</link><pubDate>Fri, 29 Dec 2006 21:14:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:458765</guid><dc:creator>bradley</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=458765</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=458765</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2006/12/29/using-isa-to-protect-the-sbs-mail-server-just-a-smidge-more.aspx#comments</comments><description>&lt;FONT face=arial,helvetica,sans-serif&gt;The recent closure of the Open Relay Database as reported by &lt;/FONT&gt;&lt;/FONT&gt;&lt;A href="http://www.incidents.org/diary.php?storyid=1950&amp;amp;isc=48d23068262df70edf8d9a39e913814a"&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt;incidents.org&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt; points out how email and spam have changed over the years.&amp;nbsp; Once upon a time Open Relays abounded and was the main way that spam attacks were launched. Now spam comes and attacks us from various ways from spam bots to NDR attacks.&amp;nbsp; No longer is Open Relay our main SMTP security issue these days.&amp;nbsp; In fact Exchange 2003 is not a mail relayer by default.&amp;nbsp; Nevertheless, while our servers have gotten more secure, the spam impact is rising. As they've changed the playing field, we're using different tools to fight back.&amp;nbsp; While the built in IMF spam filter in Exchange 2003 sp2 is an excellent spam filtering, there are new hosted solutions that place the burden of filtering on the backs of specialized vendors that can better see the Spam trends.&amp;nbsp; From vendors such as Postini, Microsoft's &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/exchange/services/services.mspx"&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt;Frontbridge&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2&gt;&lt;FONT face=arial,helvetica,sans-serif&gt;, to the vendor that I personally use, &lt;/FONT&gt;&lt;A class="" href="http://www.exchangedefender.com/"&gt;&lt;FONT face=arial,helvetica,sans-serif&gt;ExchangeDefender.com&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=arial,helvetica,sans-serif&gt; it provides additional filtering in front of your Exchange server.&lt;BR&gt;&lt;BR&gt;Hosted Exchange filtering provides several benefits.&amp;nbsp; The first being that these vendors specialize in seeing the trends of viruses and spam and thus can act on these trends much faster than I can.&amp;nbsp; Secondly they house the spam on their servers and not mine.&amp;nbsp; And last but certainly not least, one of the reasons that I chose this was to provide a more secure connectivity to my mail server.&amp;nbsp; I was able to do this by utilizing my ISA server 2004 to provide a bit more protection for my Small Business Server network.&amp;nbsp; &lt;/FONT&gt;&lt;/FONT&gt;
&lt;P class=style6&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt;Before the change, I could literally see pings from various countries entering my network via the open port 25 that I used to accept inbound email connections.&amp;nbsp; Using an add on tool to ISA Server 2004, the Firewall Dashboard from &lt;/FONT&gt;&lt;A href="http://www.scorpionsoft.com/"&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt;Scorpion Software&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt;, you could see the various countries and IP addresses:&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=style9&gt;&lt;FONT face=arial,helvetica,sans-serif&gt;Figure 1 - Scorpion Software's Firewall Dashboard showing various SMTP connections&lt;FONT size=2&gt;&lt;SPAN class=style6&gt;&lt;IMG src="http://www.sbslinks.com/images/img2.gif"&gt;&lt;/SPAN&gt; &lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN class=style6&gt;&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt;While attempts to guess a username and password on a mail connection on a network that has passphrases or a password policy that ensures that they are long, strong and not easily crackable at all, should not be a concern to the savvy network administrator, the reality is for many firms is that they would prefer to reduce an exposed attack surface if it's reasonable to do so.&amp;nbsp; There have been cases where firms have been subjected to dictionary attacks and have had a password cracked merely to use the mail server and authenticate it to be used in more spam attacks.&amp;nbsp; These attacks called &lt;/FONT&gt;&lt;A href="http://www.vamsoft.com/authattack.asp"&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt;SMTP auth attacks&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt; have increased over the years.&amp;nbsp; In addition, the concern that I have with my firm located in California with data of California residents, is that should an attacker use a SMTP auth attack and through my own stupidity or misconfiguration, a password is cracked, that event would warrant a event under a law in California called &lt;/FONT&gt;&lt;A href="http://info.sen.ca.gov/pub/01-02/bill/sen/sb_1351-1400/sb_1386_bill_20020926_chaptered.html"&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt;SB1386&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt; whereby I would need to notify clients of my firm's that their sensitive data may have been breached.&lt;BR&gt;&lt;BR&gt;In our case, it is extremely reasonable and extremely easy to limit the connections to our mail server ports with a bit of judicious editing to our ISA server policy that allows connections to our mail server.&amp;nbsp; The service that I use, &lt;/FONT&gt;&lt;A href="http://www.exchangedefender.com/"&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt;ExchangeDefender&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt; only connects to my server from a specific set of IP addresses.&amp;nbsp; Therefore, to ensure that we only accept inbound port 25 connections from those servers, we will set up rules in ISA Server 2004 to better protect the server and limit SMTP connections to only those 5 IP ranges.&amp;nbsp; This will then in turn, close down the potential for SMTP auth attacks and other misdirected connections to the port 25 in my server, thus reducing even more of an already limited attack surface via the server.&lt;BR&gt;&lt;BR&gt;Our first step in the process is to determine the IP addresses that we need to restrict port 25 to.&amp;nbsp; The IP addresses are all Class C addresses.&amp;nbsp; We begin by launching the ISA management console as shown below:&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN class=style9&gt;&lt;FONT face=arial,helvetica,sans-serif&gt;Figure 2 - Default rules as provided by the SBS 2003 "Connect to Email and Internet Wizard"&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN class=style6&gt;&lt;BR&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt;&lt;IMG src="http://www.sbslinks.com/images/img15.jpg"&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT face=arial,helvetica,sans-serif&gt; &lt;/FONT&gt;&lt;SPAN class=style2&gt;&lt;SPAN class=style5&gt;&lt;BR&gt;&lt;BR&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt;In my case, my version of ISA server 2004 is installed on the SBS 2003 network server and has a rule wizard that has pre-built the access to the server for email.&amp;nbsp; I will edit that rule to provide the additional restrictions I need, but I need to remember that should I need to rerun the Connect to Internet and Email Wizard, or &lt;/FONT&gt;&lt;A href="http://support.microsoft.com/kb/825763"&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt;CEICW&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt; as it's commonly called, that is inside the Small Business Server network, it will reset these email rules to default.&amp;nbsp; So at the end of this process, I'll make sure that I backup the ISA configurations I've customized to ensure they are retained.&lt;BR&gt;&lt;BR&gt;So we begin by editing the policy and providing the additional IP restrictions so that only the IP addresses from the ExchangeDefender servers can connect to the SMTP connection on my server.&amp;nbsp; In my example using SBS 2003's ISA server configuration, it has built for me a SMTP access rule that I will edit.&amp;nbsp; Double check on the Smtp Server Access Rule and browse to the "From" tab.&amp;nbsp; From here you can see that the current allowed connections are from the entire Internet.&amp;nbsp; This is what we will be editing.&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN class=style8&gt;&lt;FONT face=arial,helvetica,sans-serif&gt;Figure 3 - Editing the SMTP server access rule&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN class=style5&gt;&lt;BR&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt;&amp;nbsp;&lt;IMG src="http://www.sbslinks.com/images/imgB1.gif"&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=arial,helvetica,sans-serif&gt; &lt;/FONT&gt;&lt;SPAN class=style2&gt;&lt;SPAN class=style5&gt;&lt;BR&gt;&lt;BR&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt;We will first begin by adding the necessary Address ranges that we need to limit connections.&amp;nbsp; After clicking on "Add" we are presented with a Network Entities screen.&amp;nbsp; We now need to click on "New" to add a new category of addresses that we will limit inbound port 25 connections from.&amp;nbsp; As you can see, you are presented with various ways that you can add different rules sets for access.&amp;nbsp; Ranging from "Networks" to sets, to various computers, to address ranges and so on.&amp;nbsp; This makes it easy to add a rule with a specific need in mind.&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN class=style8&gt;&lt;FONT face=arial,helvetica,sans-serif&gt;Figure 4: Defining the Network Entities&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN class=style5&gt;&lt;BR&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt;&lt;IMG src="http://www.sbslinks.com/images/img10.gif"&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=arial,helvetica,sans-serif&gt; &lt;/FONT&gt;&lt;SPAN class=style2&gt;&lt;SPAN class=style5&gt;&lt;BR&gt;&lt;BR&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt;We will build a series of Address ranges based on the information given to us by the Hosted Antivirus and AntiSpam provider that we will use to limit the connections.&amp;nbsp; While we can use several categories of network entities to build the rule, including Address ranges for each range, Subnets for each one, the easiest way is to use the Computer Set rule and include in one set the five ranges that we have been given by the vendor to limit the connections to.&amp;nbsp; This allows for the best organized rule as all of the vendors IP ranges that he has given us to limit connections to will be included in one spot.&amp;nbsp; Be sure to add enough descriptive information to the rule set to ensure that you will remember the intent and to document it in your Firewall change log or whatever process you use to document firewall changes.&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN class=style8&gt;&lt;FONT face=arial,helvetica,sans-serif&gt;Figure 5: Using New Computer&amp;nbsp; Rule Element&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN class=style5&gt;&lt;BR&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt;&lt;IMG src="http://www.sbslinks.com/images/img1A.gif"&gt;&lt;BR&gt;&lt;BR&gt;When everything is all done, the rules we have built will be included as one set.&amp;nbsp; We can now easily remove the existing rule of "External" which allows all connections from all locations, with the more restrictive rule that only allows the 5 address ranges that have been specified.&amp;nbsp; And like all other edits to Firewall rules in ISA, it's as easy as clicking on the "Apply" button to easily change the rule to our new edited one.&lt;BR&gt;&amp;nbsp;&lt;BR&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN class=style8&gt;&lt;FONT face=arial,helvetica,sans-serif&gt;Figure 6:&amp;nbsp; Applying the new configuration&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN class=style5&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=2&gt;&lt;FONT face=arial,helvetica,sans-serif&gt;&lt;SPAN class=style6&gt;&lt;IMG src="http://www.sbslinks.com/images/img25.jpg"&gt;&lt;/SPAN&gt; &lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN class=style2&gt;&lt;SPAN class=style5&gt;&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt;Last but not least, we need to remember that in the Small Business Server 2003 environment we need to remember that should we re-run the firewall wizard for any reason, any SBS wizard specific rule that we customized before will be reset back to the original once you rerun that wizard.&amp;nbsp; Therefore documentation of the changes you make, and ensuring that at the end of the process of customization you click on properties of the rule and you export the rule to allow for easy import will ensure that you can easily and quickly get the Firewall settings back as you need them to be.&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN class=style8&gt;&lt;FONT face=arial,helvetica,sans-serif&gt;Figure 7:&amp;nbsp; Exporting out the changed configuration&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN class=style5&gt;&lt;BR&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt;&lt;IMG src="http://www.sbslinks.com/images/img2B.jpg"&gt;&lt;BR&gt;&lt;BR&gt;In reality for many of us that use the power of ISA 2004 to better protect and report on the Internet connectivity on our SBS 2003 networks, we typically only run the Connect to Email and Internet wizard once when initially setting up the ISA 2004 configuration.&amp;nbsp; After that first configuration, we tend to edit the rules as we need them and there is typically no need to rerun the setup wizard.&amp;nbsp; &lt;BR&gt;&lt;BR&gt;You can now use or go to any number of port probing web sites and tools ranging from Steve Gibson's veritable Shields Up on his &lt;/FONT&gt;&lt;A href="http://www.grc.com/"&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt;www.grc.com&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt; web site to Microsoft's&lt;/FONT&gt;&lt;A href="http://support.microsoft.com/kb/832919"&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt; portquery&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=arial,helvetica,sans-serif size=2&gt; tool and see that no longer is your port 25 seen open to the Internet and ready for drive by port 25 password attempts. While you are still fully able to get all of your cleaned and de-spammed email, you are no longer the fully exposed connection you once were.&lt;BR&gt;&lt;BR&gt;Before you limit the connections, a port query response comes back with the following:&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;FONT size=2&gt;&lt;FONT face=arial,helvetica,sans-serif&gt;&lt;EM&gt;Data returned from port:&lt;BR&gt;220 domain.com Microsoft ESMTP MAIL Service, Version: 6.0.3790.1830 ready at Mon, 25 Dec 2006 03:06:17 -0800 &lt;BR&gt;portqry.exe -n xx.xx.xx.xx -e 25 -p TCP exits with return code 0x00000000.&lt;/EM&gt;&lt;BR&gt;&lt;BR&gt;After you limit the connection, the response comes back as follows:&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=2&gt;&lt;FONT face=arial,helvetica,sans-serif&gt;&lt;EM&gt;TCP port 25 (smtp service): FILTERED&lt;BR&gt;portqry.exe -n xx.xx.xx.xx -e 25 -p TCP exits with return code 0x00000002.&lt;/EM&gt;&lt;BR&gt;&lt;BR&gt;Thus providing a bit more protection from drive by SMTP auth attackers.&lt;BR&gt;&lt;BR&gt;While I would never say that a firewall should be a "set it up and then forget about it", typically the ISA 2004 configuration is straightforward enough that typically my only needs for adjusting are when my business needs change or a security stance changes have dictated a change in the firewall.&amp;nbsp; The rest of the time,&amp;nbsp; it just keeps doing what it does very well, being a great protection and reporting access tool for my business' network.&lt;BR&gt;&lt;BR&gt;And now, it gave me just a little bit more help in the war against SPAM.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=style9&gt;&lt;SPAN class=style2&gt;&lt;SPAN class=style5&gt;&lt;FONT size=2&gt;&lt;EM&gt;&lt;FONT face=arial,helvetica,sans-serif&gt;(Now blogged from this location on my blog site, was formerly blogged at &lt;/FONT&gt;&lt;A class="" href="http://msmvps.com/blogs/bradley/archive/2006/12/28/using-isa-to-protect-exposed-ports.aspx"&gt;&lt;FONT face=arial,helvetica,sans-serif&gt;another location&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=arial,helvetica,sans-serif&gt;)&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=style9&gt;&lt;SPAN class=style2&gt;&lt;SPAN class=style5&gt;&lt;EM&gt;P.S.&amp;nbsp; as I've joked with folks.. the worse thing about all these external hosted spam filtering services is that they make your email boring.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=458765" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>Using ISA to protect Exposed ports</title><link>http://msmvps.com/blogs/bradley/archive/2006/12/28/using-isa-to-protect-exposed-ports.aspx</link><pubDate>Thu, 28 Dec 2006 15:14:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:455532</guid><dc:creator>bradley</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=455532</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=455532</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2006/12/28/using-isa-to-protect-exposed-ports.aspx#comments</comments><description>&lt;P&gt;&lt;STRIKE&gt;As a FYI a blog post I did on how to use ISA 2004 to better close your SMTP connection to the outside world ... especially when you are connnected to ExchangeDefender.com is up on the ISA server blog&lt;/STRIKE&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/isablog/archive/2006/12/28/exchange-spam-filtering-and-isa-server.aspx"&gt;&lt;STRIKE&gt;http://blogs.technet.com/isablog/archive/2006/12/28/exchange-spam-filtering-and-isa-server.aspx&lt;/STRIKE&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="" href="http://www.vladville.com/2006/12/get-some-exchangedefender-love.html"&gt;Exchangedefender.com&lt;/A&gt; is the service that I use that prefilters, cleans and despams my firm's email....&lt;/P&gt;
&lt;P&gt;Bottom line it makes my email boring these days.&amp;nbsp; And I'm serious about that... it's quite dull these days.&amp;nbsp; Only business email.&amp;nbsp; :-)&lt;/P&gt;
&lt;P&gt;P.S.&amp;nbsp; The post is off the blog site.. sorry if you are looking for it.&amp;nbsp; No, I really won't go into why it was removed (not for reasons some folks might be thinking of anyway).&amp;nbsp; &lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=455532" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>New ISA news</title><link>http://msmvps.com/blogs/bradley/archive/2006/12/12/new-isa-news.aspx</link><pubDate>Wed, 13 Dec 2006 01:26:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:416414</guid><dc:creator>bradley</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=416414</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=416414</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2006/12/12/new-isa-news.aspx#comments</comments><description>&lt;P&gt;WSUS Product Team Blog : New Product Category for ISA Firewall client: &lt;BR&gt;&lt;A class=moz-txt-link-freetext href="http://blogs.technet.com/wsus/archive/2006/12/12/new-product-category-for-isa-firewall-client.aspx"&gt;http://blogs.technet.com/wsus/archive/2006/12/12/new-product-category-for-isa-firewall-client.aspx&lt;/A&gt; &lt;BR&gt;&lt;BR&gt;How to obtain the version of Firewall Client for ISA Server (December &lt;BR&gt;2006) that includes Windows Vista support: &lt;BR&gt;&lt;A class=moz-txt-link-freetext href="http://support.microsoft.com/kb/929556"&gt;http://support.microsoft.com/kb/929556&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;Finally the ISA firewall client that will support Vista is out today and there's a new WSUS category to boot!&lt;/P&gt;
&lt;P&gt;This is a tad confusing because the page on the download site says "Public beta" but&amp;nbsp;the KB article doesn't say beta, nor does SeanDaniel.com....in the public ISA newsgroup it was posted that these are indeed final parts.&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=416414" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>Issues installing ISA 2004</title><link>http://msmvps.com/blogs/bradley/archive/2006/10/27/Issues-installing-ISA-2004.aspx</link><pubDate>Fri, 27 Oct 2006 19:58:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:214575</guid><dc:creator>bradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=214575</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=214575</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2006/10/27/Issues-installing-ISA-2004.aspx#comments</comments><description>Question&lt;br /&gt;&lt;br /&gt;Several days ago when i install ISA 2004 in SBS 2003 R2 i get the following &lt;br /&gt;error in the &lt;br /&gt;ISAWRAP_*.log file... and installation setup stops&amp;quot;Installer activated, &lt;br /&gt;command-line=&amp;#39;/v&amp;quot;/qn FULLPATHANSWERFILE=\&amp;quot;C:\Program &lt;br /&gt;Files\Microsoft Windows Small Business &lt;br /&gt;Server\Support\Premium\ISA2k4und2006_10_10_02_47_26.ini\&amp;quot;&amp;quot;&amp;#39; &lt;br /&gt;Running setup wrapper in quiet mode. &lt;br /&gt;Activating firewall installation program &lt;br /&gt;Setup failed. Error returned: 0x643 &lt;br /&gt;Firewall installation failed, hr=80070643 &lt;br /&gt;Installation completed successfully &lt;br /&gt;ShowSecurePage: Not showing on unattended&amp;quot;&lt;br /&gt;&lt;br /&gt;------------&lt;br /&gt;&lt;em&gt;Solution:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Setup failed. Error returned: 0x643&lt;br /&gt;Firewall installation failed, hr=80070643&lt;br /&gt;&lt;br /&gt;Regarding the error 0x643, we have experienced several similar issues &lt;br /&gt;before, on the root of C drive there was a hidden config.msi folder. That &lt;br /&gt;folder was created by a MSI installer for a previous failed installation of &lt;br /&gt;another application. After renaming that folder to config.msi.old, the &lt;br /&gt;installation of ISA was successful. To view hidden folder, please click &lt;br /&gt;Tools-&amp;gt;Folder Options, go to the View tab, and then change the option &lt;br /&gt;&amp;quot;Hidden files and folders&amp;quot; to &amp;quot;Show hidden files and folders&amp;quot;.&lt;br /&gt;&lt;br /&gt;Detailed steps:&lt;br /&gt;&lt;br /&gt;1.&amp;nbsp; Open explorer and navigate to the location of your config.msi folder &lt;br /&gt;(this is a hidden system folder created by the MSI installation, located on &lt;br /&gt;the root of the C: drive by default)&lt;br /&gt;&lt;br /&gt;2.&amp;nbsp; Remove the read-only and system flags from the folder&lt;br /&gt;&lt;br /&gt;3.&amp;nbsp; Rename the folder to config.msi.old&lt;br /&gt;&lt;br /&gt;4.&amp;nbsp; Restart the installation&lt;br /&gt;&lt;br /&gt;Meanwhile, please open the Regedit and check the following registry key:&lt;br /&gt;1. Go to the following registry directory&lt;br /&gt;HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RemoteAccess&lt;br /&gt;&lt;br /&gt;2. On the menu bar, go to Edit, Permissions.&lt;br /&gt;&lt;br /&gt;3. Check the existing users to make sure they have Full Control Permission.&lt;br /&gt;&lt;br /&gt;4. Add Everyone group and grant Full Control &lt;br /&gt;&lt;br /&gt;5. Click Advanced button and check the two check boxes:&lt;br /&gt;&lt;br /&gt;&amp;quot;Allow inheritable permission from the parent&amp;quot;. &lt;br /&gt;&amp;quot;Replace permission entries on all child objects&amp;quot;.&lt;/em&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=214575" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>How to block MSN Messenger traffic and Windows Live Messenger traffic by using ISA Server</title><link>http://msmvps.com/blogs/bradley/archive/2006/10/08/How-to-block-MSN-Messenger-traffic-and-Windows-Live-Messenger-traffic-by-using-ISA-Server.aspx</link><pubDate>Mon, 09 Oct 2006 05:46:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:163743</guid><dc:creator>bradley</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=163743</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=163743</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2006/10/08/How-to-block-MSN-Messenger-traffic-and-Windows-Live-Messenger-traffic-by-using-ISA-Server.aspx#comments</comments><description>&lt;p&gt;I don&amp;#39;t allow everyone in my office to have external IM in the office.&amp;nbsp; I happened to catch Exchange 2000/SBS 2000 on software assurance and caught Live Communication for internal only instant messenging.&amp;nbsp; If you do allow your firm to have external IM and you want to do a bit of control, here&amp;#39;s a KB to add a bit of control...&lt;/p&gt;&lt;p&gt;&lt;a href="http://support.microsoft.com/?kbid=925120"&gt;http://support.microsoft.com/?kbid=925120&lt;/a&gt;&lt;/p&gt;&lt;h1 class="title"&gt;&lt;font size="2"&gt;How to block MSN Messenger traffic and Windows Live Messenger traffic by using ISA Server&lt;/font&gt;&lt;/h1&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=163743" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>ISA firewall won't start</title><link>http://msmvps.com/blogs/bradley/archive/2006/08/10/107308.aspx</link><pubDate>Fri, 11 Aug 2006 04:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:107308</guid><dc:creator>bradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=107308</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=107308</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2006/08/10/107308.aspx#comments</comments><description>&lt;P&gt;&lt;FONT face=Arial size=2&gt;So there are times when you get a weird answer to a weird problem....&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;We've seen before that ISA/RRAS/MSfirewall won't start with a event id 7001, 7024 and 7.....&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;..and believe it or not the KB article that does the trick is this one:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;You cannot use the Fax service on a Windows Server 2003-based domain controller or you receive a "Permissions could not be properly configured for Fax Operators" error message when you run the Windows Small Business Server 2003 Setup program: &lt;BR&gt;&lt;/FONT&gt;&lt;A href="http://support.microsoft.com/kb/842207/en-us"&gt;&lt;FONT face=Arial color=#ff1493 size=2&gt;http://support.microsoft.com/kb/842207/en-us&lt;/FONT&gt;&lt;/A&gt;&lt;BR&gt;&lt;FONT face=Arial size=2&gt;&lt;BR&gt;All of this is documented in Jeff Middleton's Swing Migration method at&lt;FONT color=#ff1493&gt; &lt;/FONT&gt;&lt;A href="http://www.sbsmigration.com"&gt;&lt;FONT color=#ff1493&gt;www.sbsmigration.com&lt;/FONT&gt;&lt;/A&gt; as he's seen the issue before.... &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;The Microsoft Firewall service terminated with &lt;BR&gt;service-specific error 212994 (0x34002).&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;You can see more of it &lt;/FONT&gt;&lt;A href="http://groups.google.com/group/microsoft.public.windows.server.sbs/msg/c44cb27aec8453bd?hl=en&amp;amp;"&gt;&lt;FONT face=Arial color=#ff1493 size=2&gt;here in this post&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Arial size=2&gt;.&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=107308" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>ISA and IIS on the same box</title><link>http://msmvps.com/blogs/bradley/archive/2006/08/06/106919.aspx</link><pubDate>Sun, 06 Aug 2006 23:59:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:106919</guid><dc:creator>bradley</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=106919</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=106919</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2006/08/06/106919.aspx#comments</comments><description>&lt;P&gt;&lt;FONT face=Arial size=2&gt;On the&lt;A href="http://www.microsoft.com/downloads/details.aspx?familyid=0ccded0c-7730-4506-b2c3-f6d32355d36c&amp;amp;displaylang=en"&gt; &lt;FONT color=#ff1493&gt;download site&lt;/FONT&gt; &lt;/A&gt;is a program that allows you to do ISA and IIS on the same box.. there's just one problem... while it's a cool tool for SBS.. the fact is that you cannot install ISA 2006 on a SBS box.&amp;nbsp; For one we're not licensed for it... and for two it breaks the CEICW.&amp;nbsp; So while this is a cool download for our ISA 2004 boxes.. co-locating 2006 on a SBS box breaks things.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class=downloadInfo&gt;&lt;A name=Description&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=2&gt;&lt;EM&gt;'When Internet Information Services (IIS) and Microsoft® Internet Security and Acceleration (ISA) Server 2006 are co-located, as in a Microsoft Small Business Server (SBS) installation, and a Dynamic Host Configuration Protocol (DHCP) or Domain Name System (DNS) server has a Web Proxy Automatic Discovery (WPAD) entry that points to the computer running IIS and ISA Server, the server applications use the same port. This prevents requests from Web Proxy clients for a Wpad.dat file and prevents Winsock Proxy Autodetect (WSPAD) requests from Firewall clients for a Wspad.dat file from reaching the server.&lt;BR&gt;&lt;BR&gt;The files in this package can be used to configure IIS to direct client requests for proxy automatic configuration data to ISA Server using server-side Active Server Pages (ASP) code.'&lt;/EM&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=106919" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>ISA 2004 needed sp2 to properly load</title><link>http://msmvps.com/blogs/bradley/archive/2006/08/04/106751.aspx</link><pubDate>Sat, 05 Aug 2006 04:06:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:106751</guid><dc:creator>bradley</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=106751</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=106751</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2006/08/04/106751.aspx#comments</comments><description>&lt;P&gt;&lt;FONT face=Arial size=2&gt;Phil had installed SBS 2003 on a 2 processor, Dual core Xeon so = 8 logical processors... he then installed ISA 2004 and got the message:&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;EM&gt;The ISA Server Standard Edition cannot run. Either the server is using more &lt;/EM&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;EM&gt;than 4 processors, or it is configured to use the Active Directory service.&amp;nbsp; &lt;/EM&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;EM&gt;Use the source location 100.371.4.0.2163.213 to report the failure. Contact &lt;/EM&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;EM&gt;Microsoft (R) Corporation for more&amp;nbsp; information.&lt;o:p&gt;&lt;/o:p&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;..and after reboot the ISA services would not restart.&amp;nbsp; Ended up he had to install ISA 2004 sp2 to get ISA to function on this spec of a machine.&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=106751" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>ISA 2006 RTM's (but remember it doesn't work on SBS)</title><link>http://msmvps.com/blogs/bradley/archive/2006/08/01/106463.aspx</link><pubDate>Wed, 02 Aug 2006 03:57:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:106463</guid><dc:creator>bradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=106463</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=106463</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2006/08/01/106463.aspx#comments</comments><description>&lt;P&gt;&lt;FONT face=Arial size=2&gt;Just a reminder that while ISA 2006 has recently RTM'd... the CEICW doesn't work with it and we're not licensed for it...So play with it for testing purposes for standalone installs....but don't try to install it on SBS.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Check out &lt;/FONT&gt;&lt;A href="http://blogs.technet.com/tristank/archive/2006/08/02/444450.aspx"&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;FONT color=#ff1493&gt;Tristan's blog&lt;/FONT&gt; &lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Arial size=2&gt;for more.&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=106463" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>ISA 2004 sp2 update for issues with Delta/iTunes, etc.</title><link>http://msmvps.com/blogs/bradley/archive/2006/04/24/92392.aspx</link><pubDate>Mon, 24 Apr 2006 19:15:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:92392</guid><dc:creator>bradley</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=92392</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=92392</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2006/04/24/92392.aspx#comments</comments><description>&lt;P class=MsoNormal&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;Heads up ..this 'may' need to reboot your server, so you'd probably need to install this after hours just in case...&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;EM&gt;(and if you have WSUS set for "publically available patches" ... or whatever that one category is....you should see this in your WSUS console as well....)&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;Download details: ISA Server 2004 Standard Edition Update:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?familyid=2aa53ee6-527c-4398-ab7c-fcf8e8dde8ce&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?familyid=2aa53ee6-527c-4398-ab7c-fcf8e8dde8ce&amp;amp;displaylang=en&lt;/A&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Arial size=2&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Arial size=2&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Overview&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Arial size=2&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;This update addresses the following HTTP issues for ISA Server 2004 Standard and Enterprise Editions with Service Pack 2 (SP2):&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Arial size=2&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;• KB 915045: Error 502 "The HTTP request includes a non-supported Header" when accessing certain web servers. This occurs when accessing certain Web servers that return headers that are incompatible with each other.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Arial size=2&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;• KB 915421: Errors 11001 or 400 when accessing certain web servers. This is caused by a misinterpretation of spaces in headers provided by ISA Server, and results in a corrupted URL and failure to load the Web page.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Arial size=2&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;• KB 915422: Event ID 23004 when accessing web sites that respond with compressed content. Some Web servers always return compressed content, which is denied by ISA Server when it did not request compressed content.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Arial size=2&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;• KB 916573: Error 500 (Internal Server Error. Not implemented (-2147467263)) when trying to download zip attachments from an Outlook Web Access server. The header returned by Outlook Web Access causes ISA Server to deny the response.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Arial size=2&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;• KB 917134: Grayed out checkbox “Enable caching of content received through the BITS service”&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=92392" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/bradley/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>ISA 2004 sp2 hotfix and a reboot</title><link>http://msmvps.com/blogs/bradley/archive/2006/04/12/90787.aspx</link><pubDate>Thu, 13 Apr 2006 04:20:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:90787</guid><dc:creator>bradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=90787</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=90787</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2006/04/12/90787.aspx#comments</comments><description>&lt;P class=MsoNormal&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;Just in case you install the hotfix to fix the iTunes, Delta.com, Sun.com issues with ISA2004 and you DON'T get prompted for a reboot... reboot... just in case.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;Besides sometimes I 'bounce the box' just to put a detailed info in that Shutdown logging screen.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;Now I'm sure someone will tell me there's a way to do this without rebooting... but ...&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;EM&gt;From the newsgroup --&lt;/EM&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;EM&gt;I wanted to post this for anyone out there thinking about getting the patch from PSS that fixed the way ISA 2004 SP2 breaks access to the ITunes music store. Here is the link &lt;/EM&gt;&lt;A href="http://support.microsoft.com/?kbid=916106"&gt;&lt;EM&gt;http://support.microsoft.com/?kbid=916106&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; . I loaded the version of this patch for ISA 2004 Standard on my SBS box yesterday and everything appeared to go well. I didn't realize until this morning that it completely hammered IIS and all of the websites were stopped. ISA server's log was reporting an error trying to access the published page, publishing.&amp;lt;server domain&amp;gt;. I restarted IIS and mail began flowing, but OWA was still down and I could not start the default website because it was "in use by another process." I rebooted the server and all was well again, but I sat with mail and the websites down for about 20 hours. So just as a warning for anyone installing this patch, reboot the server afterwards. You are not prompted to do so by the installer.&lt;o:p&gt;&lt;/o:p&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Arial size=2&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;EM&gt;Peace&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=90787" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>Patch for issues with ISA 2004 sp2</title><link>http://msmvps.com/blogs/bradley/archive/2006/04/10/90371.aspx</link><pubDate>Tue, 11 Apr 2006 06:17:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:90371</guid><dc:creator>bradley</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=90371</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=90371</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2006/04/10/90371.aspx#comments</comments><description>&lt;P&gt;&lt;FONT face=Arial size=2&gt;Update for HTTP issues in Internet Security and Acceleration Server 2004 Service Pack 2: &lt;BR&gt;&lt;/FONT&gt;&lt;A href="http://support.microsoft.com/?kbid=916106"&gt;&lt;FONT face=Arial size=2&gt;http://support.microsoft.com/?kbid=916106&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;The hotfix for issues with ISA 2004 sp2 is now out....&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;For those of you who remember..that's Sun.com and Delta.com web site issues and iTunes and the biggies.&lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=90371" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/ISA+Server/default.aspx">ISA Server</category></item></channel></rss>