<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>ISA 2004 HTTP Security Filter - Will It Meet Its Potential?</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/29/5625.aspx</link><description>ISA 2004 firewalls include a very powerful HTTP Security Filter. This filter allows you to block virtually any HTTP connection attempt, based on the settings you configure in the filter. The HTTP Security filter allows you to configure the ISA 2004 firewall</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>re:ISA 2004 HTTP Security Filter - Will It Meet Its Potential?</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/29/5625.aspx#58962</link><pubDate>Fri, 22 Jul 2005 15:13:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:58962</guid><dc:creator>TrackBack</dc:creator><description>ISA 2004 HTTP Security Filter - Will It Meet Its Potential?ooeess&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=58962" width="1" height="1"&gt;</description></item><item><title>re:ISA 2004 HTTP Security Filter - Will It Meet Its Potential?</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/29/5625.aspx#48024</link><pubDate>Fri, 20 May 2005 00:41:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:48024</guid><dc:creator>TrackBack</dc:creator><description>^_~,pretty good!csharpsseeoo&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=48024" width="1" height="1"&gt;</description></item><item><title>re:ISA 2004 HTTP Security Filter - Will It Meet Its Potential?</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/29/5625.aspx#41859</link><pubDate>Wed, 13 Apr 2005 04:32:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:41859</guid><dc:creator>TrackBack</dc:creator><description>^_^,Pretty Good!&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=41859" width="1" height="1"&gt;</description></item><item><title>re: ISA 2004 HTTP Security Filter - Will It Meet Its Potential?</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/29/5625.aspx#19716</link><pubDate>Fri, 19 Nov 2004 10:21:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:19716</guid><dc:creator>shinder</dc:creator><description>is there any books arround on how to configure the web filtering ?&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=19716" width="1" height="1"&gt;</description></item><item><title>re: ISA 2004 HTTP Security Filter - Will It Meet Its Potential?</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/29/5625.aspx#18887</link><pubDate>Fri, 12 Nov 2004 16:30:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:18887</guid><dc:creator>shinder</dc:creator><description>ISA 2004 proxy breaks connection from remote clients (they connect to ISA via external NIC). Is it by design to prohibit external connections? How to avoid this?&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=18887" width="1" height="1"&gt;</description></item><item><title>re: ISA 2004 HTTP Security Filter - Will It Meet Its Potential?</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/29/5625.aspx#12184</link><pubDate>Sun, 22 Aug 2004 21:20:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:12184</guid><dc:creator>shinder</dc:creator><description>HELLO ALL IN THERE,..&lt;br&gt;FIRST OF ALL I TELL U ABOUT ME SOMETHING,..&lt;br&gt;I'SHANI FROM PAKISTAN,..I HAVE A NET CAFE,..&amp;amp; I USE WINDOWS 2000 SERVER WITH ISA SERVER 2000,...&lt;br&gt;MY SERVICES R FINE BUT ITS NOT MUCH TO ME I KNOW ISA SERVER PROVIDE THE BEST SERVICE AFTER ALL MY SERVICES COZ I SE MY NEIGHBOUR SERVICE THAT HAVE TOO ISA SERVER 2000&lt;br&gt;BUT HIS SERVICE IS BETER THEN ME COZ HE KNOW TO CONFIGURE HIS ISA SERVER FOR BEST SERVICE BUT I DONT,..I LEARN NOT SO MUCH ABOUT IT SO I WANA KNOW THAT HOW I CAN CONFIGURE MY ISA SERVER 2000 FOR BEST,..IS ANY BUDY THERE THAT CAN HELP ME,..&lt;br&gt;THANKS&lt;br&gt;SHAANI&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=12184" width="1" height="1"&gt;</description></item><item><title>re: ISA 2004 HTTP Security Filter - Will It Meet Its Potential?</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/29/5625.aspx#6255</link><pubDate>Tue, 11 May 2004 15:56:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:6255</guid><dc:creator>shinder</dc:creator><description>I absolutely agree.&lt;br&gt;&lt;br&gt;HTTP filters could be a killer use for ISA2k4. Think along the lines of true application firewalls which protect against sql injection and XSS attacks and not just web server misconfiguration. These app firewalls definately fit a gap in the market, but they are enormously expensive in comparision to ISA. $20K $1k is a no brainer! In addition other f/w vendors such as checkpoint offer &amp;quot;app layer&amp;quot; stuff these days, but the perimeter isn't always the right place for app layer protection - you need that stuff inside and as a reverse proxy. &lt;br&gt;&lt;br&gt;Given ISAs sales positioning as a app layer f/w and all the hype around web server misconfig vulnerabilities and app liabilities this is too good an opportunity to waste - I know for a fact there are many orgs who would deploy ISA if it did true app layer protection - behind 'traditional' permiter devices.&lt;br&gt;&lt;br&gt;Microsoft must either develop some decent sample filters or engage a partner to develop them - its just not that difficult to write a sql injection definition in C++, but the sysadmin aint gonna do it.&lt;br&gt;&lt;br&gt;At the very least they need to get the documentation up to scratch - not just leave us with a dead basic SMTP sample!&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=6255" width="1" height="1"&gt;</description></item><item><title>re: ISA 2004 HTTP Security Filter - Will It Meet Its Potential?</title><link>http://msmvps.com/blogs/shinder/archive/2004/04/29/5625.aspx#5865</link><pubDate>Mon, 03 May 2004 23:51:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:5865</guid><dc:creator>shinder</dc:creator><description>Tom&lt;br&gt;&lt;br&gt;Couldnt agree more!!!!&lt;br&gt;&lt;br&gt;Greg&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=5865" width="1" height="1"&gt;</description></item></channel></rss>