<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Dr. Tom's ISA Server 2004 Firewall Blog : ISA Server</title><link>http://msmvps.com/blogs/shinder/archive/tags/ISA+Server/default.aspx</link><description>Tags: ISA Server</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>ISA 2004 HTTP Security Filter - Will It Meet Its Potential?</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/29/5625.aspx</link><pubDate>Thu, 29 Apr 2004 07:51:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:5625</guid><dc:creator>shinder</dc:creator><slash:comments>8</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/shinder/rsscomments.aspx?PostID=5625</wfw:commentRss><comments>http://msmvps.com/blogs/shinder/archive/2004/04/29/5625.aspx#comments</comments><description>&lt;p&gt;&lt;font face="Verdana" size="1"&gt;ISA 2004 firewalls include a very powerful HTTP Security Filter. This filter allows you to block virtually any HTTP connection attempt, based on the settings you configure in the filter. The HTTP Security filter allows you to configure the ISA 2004 firewall to perform detailed searches of the HTTP header and body, and block connections that match your criteria. When used properly, this has the potential to be the ISA 2004 firewall's “killer app”.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;However, most firewall admins have to do double, triple, quadruple and quintiple duties. They don't have time to make the ISA 2004 firewall their avocation. They need to handle WinXP/Win9x/Win2000 clients, WinNT4/Win2003/Win2003 servers, SQL Servers, Exchange Servers, SharePoint Servers, Certificate Servers, RRAS Servers, IIS Servers, and lots more. There are only so many hours in a day, and the attraction to a firewall like ISA 2004 is that it appears easy to configure. And, on the whole, they would be right.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;However, while the HTTP Security filter has a powerful and easy to use interface, the documentation of the feature is abysmal. What do I mean by “abysmal“? Search your dictionary for “tautology“ and then read the Help file and any other MS docs on this subject you might find.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Most firewall admins who opt for ISA 2004 firewalls do so because they want to take advantage of the unique protection provided by ISA 2004, especially for the ISA 2004 firewall's one of a kind VPN and Exchange security features. This level of protection can be made even better if MS would actually &lt;em&gt;explain&lt;/em&gt; and &lt;em&gt;define&lt;/em&gt; the various components of this filter and how it works. Otherwise, the HTTP Security Fitler's power and utility will end up in the dustbin of history like the H.323 Gatekeeper and possibly the VPN-Q feature (I'll moan about VPN-Q in a future posting).&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;So the celebrity challange for MS is to come up with clear (not concise! concise usually means “I don't have the time or inclination to fully explain the subject and explore implications), complete and &lt;em&gt;useful&lt;/em&gt; documentation on the HTTP filter. This is how ISA 2004 firewalls can displace Checkpoint and PIX, and prevent users from adopting a Linux based solutution. After all, if I'm going to have to spend hours, days or weeks figuring out how to configure a key piece of a firewall, I don't have to pay for it, I'll just use Linux! :-)&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;So, MS docs team -- belly up to the bar and give the ISA 2004 firewall community what it needs, not what you think they need.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Thanks!&lt;br /&gt;Tom&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=5625" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/shinder/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>Disabling Spoof Detection in ISA 2004 Firewalls</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/29/5624.aspx</link><pubDate>Thu, 29 Apr 2004 07:31:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:5624</guid><dc:creator>shinder</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/shinder/rsscomments.aspx?PostID=5624</wfw:commentRss><comments>http://msmvps.com/blogs/shinder/archive/2004/04/29/5624.aspx#comments</comments><description>&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Spoof detection in ISA 2004 firewalls is a handy feature that helps protect the firewall from spoof attacks. However, there are some circumstances that generate spurious spoofs , such as when implementing NLB. No problem! Here's the fix, courtesy of our good friend, Barclay Neira:&lt;/font&gt;&lt;/p&gt;&lt;b&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;284811 HOW TO: Disable the IP Spoofing Detection Feature in Internet Security and Acceleration Server&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font size="1"&gt;&lt;/font&gt;&lt;/p&gt;&lt;/b&gt;&lt;a href="http://support.microsoft.com/?id=284811"&gt;&lt;b&gt;&lt;u&gt;&lt;font color="#0000ff"&gt;&lt;font face="Verdana" size="1"&gt;http://support.microsoft.com/?id=284811&lt;/font&gt;&lt;/font&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;font size="1"&gt; &lt;/font&gt;
&lt;p&gt;&lt;strong&gt;&lt;font face="Verdana" size="1"&gt;Here is the location you would need to update. All other information is the same:&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;font face="Verdana" size="1"&gt;HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/Services/FwEng/Parameters&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Thanks Barclay!&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=5624" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/shinder/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>Fixes for Instant Messenger Related Problems</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/27/5554.aspx</link><pubDate>Tue, 27 Apr 2004 06:12:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:5554</guid><dc:creator>shinder</dc:creator><slash:comments>20</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/shinder/rsscomments.aspx?PostID=5554</wfw:commentRss><comments>http://msmvps.com/blogs/shinder/archive/2004/04/27/5554.aspx#comments</comments><description>&lt;p&gt;&lt;font face="Verdana" size="1"&gt;One of the most common problems seen on the Web boards and mailing lists are Instant Messenger related issues. How do you get them to work? How do you make them stop working? My solution is to remove the dreaded IM'ers from the users machines :-)&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;However, if you want more information on how to get these things to work, check out:&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Microsoft ISA Server Message Boards: Tips for msn,yahoo,kazaa: &lt;/font&gt;&lt;a href="http://forums.isaserver.org/ultimatebb.cgi?ubb=get_topic;f=14;t=000096"&gt;&lt;font face="Verdana" size="1"&gt;http://forums.isaserver.org/ultimatebb.cgi?ubb=get_topic;f=14;t=000096&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Lots of very useful tips and tricks there.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;HTH,&lt;br /&gt;Tom&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=5554" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/shinder/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>Cool Script for Auto Failover and Failback for Windows 2003 ISA Firewalls</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/26/5518.aspx</link><pubDate>Mon, 26 Apr 2004 10:52:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:5518</guid><dc:creator>shinder</dc:creator><slash:comments>6</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/shinder/rsscomments.aspx?PostID=5518</wfw:commentRss><comments>http://msmvps.com/blogs/shinder/archive/2004/04/26/5518.aspx#comments</comments><description>&lt;p&gt;&lt;font face="Verdana" size="1"&gt;A frequent request on the ISA boards is a script or other &lt;strong&gt;free&lt;/strong&gt; method that you can use to fail over and fail back if you have multiple external interfaces. &lt;strong&gt;Custler&lt;/strong&gt;, a frequently posted on the &lt;strong&gt;&lt;a href="http://forums.isaserver.org"&gt;http://forums.isaserver.org&lt;/a&gt;&lt;/strong&gt; message boards has posted a very nice script to get you started. Jim Harrison may jump in with a fix that will help it work in Windows 2000.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Check it out here:&lt;br /&gt;&lt;/font&gt;&lt;a href="http://forums.isaserver.org/ultimatebb.cgi?ubb=get_topic;f=26;t=000012#000011"&gt;&lt;font face="Verdana" size="1"&gt;http://forums.isaserver.org/ultimatebb.cgi?ubb=get_topic;f=26;t=000012#000011&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Thanks guys!&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Tom&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=5518" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/shinder/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>The Mystery of the ISA 2004 Beta Newsgroups</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/26/5516.aspx</link><pubDate>Mon, 26 Apr 2004 08:53:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:5516</guid><dc:creator>shinder</dc:creator><slash:comments>5</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/shinder/rsscomments.aspx?PostID=5516</wfw:commentRss><comments>http://msmvps.com/blogs/shinder/archive/2004/04/26/5516.aspx#comments</comments><description>&lt;p&gt;&lt;font face="Verdana" size="1"&gt;I wrote to Jerry Bryant about putting some beta newsgroups for ISA 2004 on the msnews.microsoft.com Web site. Silly me, there were already ISA 2004 beta 2 newsgroups. The problem is that they're very effectively hidden from public view! This explains why the level of activity in the “public” newsgroups for ISA 2004 is so much less than what I saw during the ISA 2000 beta.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Anyhow, if you're interested in getting invovled with the public ISA 2004 Beta 2 newsgroups, here's the secret sauce:&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;font face="Verdana" size="1"&gt;Viewing these Newsgroups with an NNTP Newsreader&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Since these are private newsgroups, your server will require you to logon using the following information:&lt;/font&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;font face="Verdana" size="1"&gt;Server: privatenews.microsoft.com &lt;/font&gt;
&lt;/li&gt;&lt;li&gt;&lt;font face="Verdana" size="1"&gt;Account name: privatenews\ISA2004 &lt;/font&gt;
&lt;/li&gt;&lt;li&gt;&lt;font face="Verdana" size="1"&gt;Password: BetaPassword &lt;/font&gt;
&lt;/li&gt;&lt;li&gt;&lt;font face="Verdana" size="1"&gt;Note that the password is case-sensitive. &lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;&lt;font face="Verdana" size="1"&gt;Viewing these Newsgroups through Outlook Express&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;font face="Verdana" size="1"&gt;Launch Outlook Express &lt;/font&gt;
&lt;/li&gt;&lt;li&gt;&lt;font face="Verdana" size="1"&gt;Select Tools - Accounts &lt;/font&gt;
&lt;/li&gt;&lt;li&gt;&lt;font face="Verdana" size="1"&gt;Select Add &amp;amp; click News &lt;/font&gt;
&lt;/li&gt;&lt;li&gt;&lt;font face="Verdana" size="1"&gt;Enter Your Name &lt;/font&gt;
&lt;/li&gt;&lt;li&gt;&lt;font face="Verdana" size="1"&gt;Enter an alias (you may want to consider avoiding posting with your real e-mail alias, as these newsgroups are exposed publicly through the web interface. &lt;/font&gt;&lt;a href="http://www.microsoft.com/communities/conduct/default.mspx#XSLTsection122121120120"&gt;&lt;font face="Verdana" size="1"&gt;More about e-mail aliases and privacy&lt;/font&gt;&lt;/a&gt;&lt;font face="Verdana" size="1"&gt;.) &lt;/font&gt;
&lt;/li&gt;&lt;li&gt;&lt;font face="Verdana" size="1"&gt;Internet News Server Name Page - enter privatenews.microsoft.com and check "My news server requires me to log on". Click "Next". &lt;/font&gt;
&lt;/li&gt;&lt;li&gt;&lt;font face="Verdana" size="1"&gt;Enter Account name - privatenews\ISA2004 &lt;/font&gt;
&lt;/li&gt;&lt;li&gt;&lt;font face="Verdana" size="1"&gt;Enter password (case-sensitive): BetaPassword &lt;/font&gt;
&lt;/li&gt;&lt;li&gt;&lt;font face="Verdana" size="1"&gt;Click Next &amp;amp; Finish &lt;/font&gt;
&lt;/li&gt;&lt;li&gt;&lt;font face="Verdana" size="1"&gt;Close and download the newsgroups. &lt;/font&gt;&lt;/li&gt;&lt;/ol&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Of course, you can go to &lt;/font&gt;&lt;a href="http://forums.isaserver.org"&gt;&lt;font face="Verdana" size="1"&gt;http://forums.isaserver.org&lt;/font&gt;&lt;/a&gt;&lt;font face="Verdana" size="1"&gt; and we have a &lt;em&gt;very&lt;/em&gt; active discussion going on regarding ISA 2004 firewalls.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;HTH,&lt;br /&gt;Tom&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=5516" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/shinder/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>Download New ISA 2000 Video Presentations</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/26/5515.aspx</link><pubDate>Mon, 26 Apr 2004 08:45:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:5515</guid><dc:creator>shinder</dc:creator><slash:comments>18</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/shinder/rsscomments.aspx?PostID=5515</wfw:commentRss><comments>http://msmvps.com/blogs/shinder/archive/2004/04/26/5515.aspx#comments</comments><description>&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Microsoft has posted some video presentations that you can download and view at your leisure. Do what I do -- burn these guys to a DVD and play them while flying from one gig to another. You can watch Martin Sargent reruns only so many times :-)&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;With ISA Server 2004 now not that far away, Microsoft have released a bunch of ISA 2000 Presentations.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="http://www.microsoft.com/downloads/details.aspx?FamilyID=d82f5566-75bc-41ec-95e5-cb168e6e30b2&amp;amp;amp;DisplayLang=en" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=d82f5566-75bc-41ec-95e5-cb168e6e30b2&amp;amp;DisplayLang=en" target="_blank"&gt;&lt;b title="http://www.microsoft.com/downloads/details.aspx?FamilyID=d82f5566-75bc-41ec-95e5-cb168e6e30b2&amp;amp;amp;DisplayLang=en"&gt;&lt;font face="Verdana" size="1"&gt;Internet Security and Acceleration Server Network Design for Microsoft .NET Applications&lt;/font&gt;&lt;/b&gt;&lt;/a&gt;&lt;br /&gt;&lt;font face="Verdana" size="1"&gt;In this presentation you will learn how to design a network for multi-tiered Microsoft .NET applications. The session introduces each element of the architecture and explains how to use ISA Server in different places throughout the network. &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="http://www.microsoft.com/downloads/details.aspx?FamilyID=ebe657ca-e2bc-461b-9385-fe8e28d51c7a&amp;amp;amp;DisplayLang=en" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=ebe657ca-e2bc-461b-9385-fe8e28d51c7a&amp;amp;DisplayLang=en" target="_blank"&gt;&lt;b title="http://www.microsoft.com/downloads/details.aspx?FamilyID=ebe657ca-e2bc-461b-9385-fe8e28d51c7a&amp;amp;amp;DisplayLang=en"&gt;&lt;font face="Verdana" size="1"&gt;Microsoft® Internet Security and Acceleration Server Best Practices and Troubleshooting&lt;/font&gt;&lt;/b&gt;&lt;/a&gt;&lt;br /&gt;&lt;font face="Verdana" size="1"&gt;In this presentation you will get the best practices for installing and administering Microsoft Internet Security and Acceleration Server. &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="http://www.microsoft.com/downloads/details.aspx?FamilyID=31dde91d-4792-45fe-a743-752549780105&amp;amp;amp;DisplayLang=en" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=31dde91d-4792-45fe-a743-752549780105&amp;amp;DisplayLang=en" target="_blank"&gt;&lt;b title="http://www.microsoft.com/downloads/details.aspx?FamilyID=31dde91d-4792-45fe-a743-752549780105&amp;amp;amp;DisplayLang=en"&gt;&lt;font face="Verdana" size="1"&gt;Microsoft® Internet Security and Acceleration Server Deployment Techniques&lt;/font&gt;&lt;/b&gt;&lt;/a&gt;&lt;br /&gt;&lt;font face="Verdana" size="1"&gt;In this presentation see how to deploy Microsoft Internet Security and Acceleration Server to provide caching and firewall functions. Learn about planning issues, guidance on client types, and the design of ISA Server policies. &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="http://www.microsoft.com/downloads/details.aspx?FamilyID=a2a9b998-377d-4679-9fad-838968d40b76&amp;amp;amp;DisplayLang=en" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=a2a9b998-377d-4679-9fad-838968d40b76&amp;amp;DisplayLang=en" target="_blank"&gt;&lt;b title="http://www.microsoft.com/downloads/details.aspx?FamilyID=a2a9b998-377d-4679-9fad-838968d40b76&amp;amp;amp;DisplayLang=en"&gt;&lt;font face="Verdana" size="1"&gt;How to Protect Your Network Using Microsoft® Internet Security and Acceleration Server 2000 &lt;/font&gt;&lt;/b&gt;&lt;/a&gt;&lt;br /&gt;&lt;font face="Verdana" size="1"&gt;In this presentation see how Microsoft Internet Security and Acceleration Server 2000 can be used to provide both proxy, caching and firewall security for your network, and more. &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font size="1"&gt;&lt;font face="Verdana"&gt;HTH,&lt;br /&gt;&lt;/font&gt;&lt;font face="Verdana"&gt;Tom&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=5515" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/shinder/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>Another TechEd ISA 2004 Session</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/26/5512.aspx</link><pubDate>Mon, 26 Apr 2004 07:43:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:5512</guid><dc:creator>shinder</dc:creator><slash:comments>7</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/shinder/rsscomments.aspx?PostID=5512</wfw:commentRss><comments>http://msmvps.com/blogs/shinder/archive/2004/04/26/5512.aspx#comments</comments><description>&lt;p&gt;&lt;font face="Verdana" size="1"&gt;If you're planning on attending TechEd this year in San Diego, then you might be interested in another session that I'm doing. Here's the info:&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana"&gt;&lt;font size="1"&gt;&lt;strong&gt;Date:&lt;/strong&gt; May 25&lt;br /&gt;&lt;strong&gt;Time: &lt;/strong&gt;5:00PM -- 6:15PM&lt;br /&gt;&lt;strong&gt;Code: &lt;/strong&gt;SECC04&lt;br /&gt;&lt;strong&gt;Description:&lt;/strong&gt; ISA Server 2004 Enhanced Microsoft Exchange and VPN Services Support: How ISA Server Provides Enhanced Security for MS Exchange and VPN&lt;br /&gt;&lt;strong&gt;Speaker Name:&lt;/strong&gt; Tom Shinder -- ISAServer.org&lt;br /&gt;&lt;strong&gt;Code:&lt;/strong&gt; Canbana4&lt;br /&gt;&lt;strong&gt;Reg Type:&lt;/strong&gt; COMM&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;I'll talk about what's new, what cool, and what's unique about ISA 2004's VPN and Exchange Server protection features.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Hope to see you there!&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Thanks!&lt;br /&gt;Tom&lt;/font&gt;&lt;/p&gt;
&lt;p align="center"&gt;&lt;a class="link1" href="http://www.microsoft.com/seminar/teched2004/regtravel.mspx" name=""&gt;&lt;font size="1"&gt;&lt;img alt="Microsoft Tech·Ed 2004" src="http://www.microsoft.com/seminar/teched2004/images/teched_logo.jpg" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=5512" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/shinder/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>Birds of a Feather Session for ISA Fans at TechEd in San Diego</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/25/5475.aspx</link><pubDate>Sun, 25 Apr 2004 15:45:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:5475</guid><dc:creator>shinder</dc:creator><slash:comments>5</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/shinder/rsscomments.aspx?PostID=5475</wfw:commentRss><comments>http://msmvps.com/blogs/shinder/archive/2004/04/25/5475.aspx#comments</comments><description>&lt;p&gt;&lt;font face="Verdana" size="1"&gt;If you're an ISA firewall fan, and want to get together with other ISA afficianados, then check out the Birds of a Feather (BOF) session we're putting together for TechEd. A number of ISA gurus (and me too) will be there! Here's the run down so far:&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" color="#0000ff" size="1"&gt;Application layer firewalls are the present and future of secure network computing, and ISA firewalls set the standard. ISAserver.org gurus and MVPs Tom Shinder, Chris Gregory, Jason Ballard and Jim Harrison crack open the case on ISA Server firewall placement and config. Bring your config and design questions to this interactive and info-packed session.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;If you're going to TechEd and haven't voted on this session yet, then do! Head on over to &lt;/font&gt;&lt;a href="http://www.ineta.org/bof/Default.aspx"&gt;&lt;font face="Verdana" size="1"&gt;http://www.ineta.org/bof/Default.aspx&lt;/font&gt;&lt;/a&gt;&lt;font face="Verdana" size="1"&gt; and vote for our session. Only sessions that get enough votes will be given space.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Thanks!&lt;br /&gt;Tom&lt;/font&gt;&lt;/p&gt;
&lt;p align="center"&gt;&lt;a class="link1" href="http://www.microsoft.com/seminar/teched2004/regtravel.mspx" name=""&gt;&lt;font face="Verdana" size="1"&gt;&lt;img alt="Microsoft Tech·Ed 2004" src="http://www.microsoft.com/seminar/teched2004/images/teched_logo.jpg" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=5475" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/shinder/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>Protecting Microsoft Exchange with ISA Server 2004 Firewalls: Integrating the ISA Firewall into an Established Network Infrastructure</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/25/5469.aspx</link><pubDate>Sun, 25 Apr 2004 12:38:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:5469</guid><dc:creator>shinder</dc:creator><slash:comments>6</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/shinder/rsscomments.aspx?PostID=5469</wfw:commentRss><comments>http://msmvps.com/blogs/shinder/archive/2004/04/25/5469.aspx#comments</comments><description>&lt;p&gt;&lt;font face="Verdana" size="1"&gt;If you didn't already know, ISA firewall's are &lt;em&gt;the firewalls&lt;/em&gt; for protecting Microsoft Exchange Servers. One of the things the hampers adoption is the belief by many firewall and network admins that they need to change up their current network topologies in a big way to support a new ISA firewall. Not true! Check out this article I posted today to see how easy it is to get ISA firewall protection without having to re-jigger your entire network infrastructure to support it.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.msexchange.org/articles/2004protectexch.html"&gt;&lt;font face="Verdana" size="1"&gt;http://www.msexchange.org/articles/2004protectexch.html&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Thanks!&lt;br /&gt;Tom&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=5469" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/shinder/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>DCOM Error Related to SMTP Message Screener</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/25/5468.aspx</link><pubDate>Sun, 25 Apr 2004 11:34:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:5468</guid><dc:creator>shinder</dc:creator><slash:comments>4</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/shinder/rsscomments.aspx?PostID=5468</wfw:commentRss><comments>http://msmvps.com/blogs/shinder/archive/2004/04/25/5468.aspx#comments</comments><description>&lt;p&gt;&lt;font face="Verdana" size="1"&gt;The ISA firewall's SMTP Message Screener is pretty cool. Its not a full-fleged spam whacker, but it provides a nice first line of defense against unwanted email. One thing that was a bit problematic with the ISA 2000 firewall's SMTP Message Screener was that it depended on DCOM messages being passed between the SMTP relay with the SMTP Message Screener installed and the ISA firewall machine. You don't see this problem if the SMTP Message Screener is on the ISA firewall itself, but you do see it if it's on another machine.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;If you see an error that looks some like this:&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;font face="Verdana" color="#ff0000" size="1"&gt;DCOM got error "General access denied error " from the computer proxy&lt;br /&gt;when attempting to activate the server:&lt;br /&gt;{0820D243-0B18-4B0A-88F0-D857F0C91E62}&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Then you'll benefit from this cool fix from Jim Harrison:&lt;/font&gt;&lt;/p&gt;&lt;b&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;That GUID represents the VendorParametersSet processing DLL in ISA.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" color="#0000ff"&gt;&lt;font size="1"&gt;Try this:&lt;br /&gt;1 - open a cmd window and navigate to your ISA installation folder.&lt;br /&gt;2. type (no quotes): "regsvr32 vps2.dll" &lt;enter&gt;&lt;br /&gt;3. say "OK" to the next to popups&lt;br /&gt;4. type (no quotes): "net stop isactrl /y" &lt;enter&gt;&lt;br /&gt;5. wait until all the services are stopped&lt;br /&gt;6. type (no quotes): "net start w3proxy" &lt;enter&gt;&lt;br /&gt;7. wait until the web proxy service starts&lt;br /&gt;8. If you'e running Integrated or Firewall mode, type (no quotes): "net start fwsrv" &lt;enter&gt;&lt;br /&gt;9. If you're running RRAS on the ISA, type (no quotes): "net start remoteaccess" &lt;enter&gt;&lt;br /&gt;10. if you're running Cache or Integrated mode, type (no quotes): "net start w3schdwn" &lt;enter&gt;&lt;/enter&gt;&lt;/enter&gt;&lt;/enter&gt;&lt;/enter&gt;&lt;/enter&gt;&lt;/enter&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;/b&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;As always, Jim dredges up the best fixes in the biz!&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Thanks!&lt;br /&gt;Tom&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font size="1"&gt;&lt;img height="91" src="http://isaserver.org/img/logo.gif" width="248" usemap="#logo_home" border="0" /&gt;&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=5468" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/shinder/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>ISA 2004 Firewall Client Weirdness</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/23/5387.aspx</link><pubDate>Fri, 23 Apr 2004 07:35:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:5387</guid><dc:creator>shinder</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/shinder/rsscomments.aspx?PostID=5387</wfw:commentRss><comments>http://msmvps.com/blogs/shinder/archive/2004/04/23/5387.aspx#comments</comments><description>&lt;p&gt;&lt;font face="Verdana" size="1"&gt;The ISA firewall's Firewall Client app is really the killer app of the ISA 2000 and ISA 2004 firewall. It's a real shame that so many people shy away from it, because its a key component to a strong outbound access control scheme. Without strong outbound access control, you might as well run a dumb packet filter router like a PIX!&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Anyhow, the Firewall client from ISA 2004 can get a bit flakey. The reason for this is that it uses an encrypted connection between the Firewall client machine and the ISA 2004 firewall. The ISA 2004 firewall client can whack out when trying to connect to ISA 2000 and Proxy 2.0 machines because it uses only the TCP channel (TCP 1745) when connecting to the firewall. Proxy 2.0 expects to be able to use the UDP control channel, and at times ISA 2000 will want to use one too. You can fix this problem by adding the following Registry key on the Firewall client machines:&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="FONT-SIZE: 10pt; COLOR: fuchsia; FONT-FAMILY: Verdana; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: HE"&gt;&lt;strong&gt;&lt;font size="1"&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\Firewall Client 2004\EnableUdpControlChannel = 1&lt;/font&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;That's your fact for the day. Now on to documenting for the ISA 2004/Exchange Kit the procedures required for putting together a unihomed ISA 2004 box to support reverse proxy for OWA and RPC/HTTP connections.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Laterz,&lt;br /&gt;Tom&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=5387" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/shinder/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>The Pain of Putting the Front-end Exchange in the DMZ</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/22/5343.aspx</link><pubDate>Thu, 22 Apr 2004 09:23:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:5343</guid><dc:creator>shinder</dc:creator><slash:comments>6</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/shinder/rsscomments.aspx?PostID=5343</wfw:commentRss><comments>http://msmvps.com/blogs/shinder/archive/2004/04/22/5343.aspx#comments</comments><description>&lt;p&gt;&lt;font face="Verdana" size="1"&gt;I finally finished the ISA 2004/Exchange Deployment Kit doc on the FE/BE Exchange config where the front-end is in a trihomed DMZ segment. What a pain! Actually, the ISA config is easy, but there are so many steps in configuring the Exchange Servers, Exchange Services, Email clients and certificate management, its easy to miss a step. On top of that, add in the vargaries of spazzing out virtual machines. Not sleeping for over 24 probably doesn't help either :-)&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;However, the final doc is a real work of art. I know that everyone has been wanting support for the FE in the DMZ, and now with ISA 2004 is works.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;I hope I'll be able to demo the config for you at TechEd. Maybe if I get really motivated, I'll do some .avi movies of the config and put them on CD for you to take home. If only I could buy more hours in day. I'm getting up before going to bed these days!&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Thanks!&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Tom&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=5343" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/shinder/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>ISA 2004 RPC Filter Breaks Certificates Snap-in</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/21/5303.aspx</link><pubDate>Wed, 21 Apr 2004 16:05:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:5303</guid><dc:creator>shinder</dc:creator><slash:comments>11</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/shinder/rsscomments.aspx?PostID=5303</wfw:commentRss><comments>http://msmvps.com/blogs/shinder/archive/2004/04/21/5303.aspx#comments</comments><description>&lt;p&gt;&lt;font face="Verdana" size="1"&gt;I really like using the Certificates MMC snap-in because it greatly simplifies issuing certificates to domain members when using an enterprise CA. Sadly enough, the ISA 2004 RPC filter kills the Certificates snap-in, and also the Certificate Request Wizard used to issue certificates to IIS and Exchange Services. Bummer.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;The solution is to disable the RPC filter in the &lt;strong&gt;Add-ins&lt;/strong&gt; node and then create an Access Rule that allows all IP traffic between the communicating hosts. Just make sure to remember to disable this rule and re-enable the RPC filter after you've issued the certificates!&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;If you don't want to go through that hassle, you can always use the Web enrollment site, or create a file for an offline request.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;HTH,&lt;br /&gt;Tom&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=5303" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/shinder/archive/tags/ISA+Server/default.aspx">ISA Server</category></item><item><title>First Post</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/21/5302.aspx</link><pubDate>Wed, 21 Apr 2004 16:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:5302</guid><dc:creator>shinder</dc:creator><slash:comments>7</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/shinder/rsscomments.aspx?PostID=5302</wfw:commentRss><comments>http://msmvps.com/blogs/shinder/archive/2004/04/21/5302.aspx#comments</comments><description>&lt;p&gt;&lt;font face="Verdana" size="1"&gt;This is the first post for ISA Server. I'll talk about 2000 and 2004.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Thanks!&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Verdana" size="1"&gt;Tom&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=5302" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/shinder/archive/tags/ISA+Server/default.aspx">ISA Server</category></item></channel></rss>