<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Search results for 'app:weblogs' matching tag 'ISA'</title><link>http://msmvps.com/search/SearchResults.aspx?q=app:weblogs&amp;tag=ISA&amp;orTags=0&amp;o=DateDescending</link><description>Search results for 'app:weblogs' matching tag 'ISA'</description><dc:language>en-US</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>EBS - SharePoint - TMG and ISA - Postback and Read-Only fix</title><link>http://msmvps.com/blogs/jeffloucks/archive/2009/11/17/ebs-sharepoint-tmg-and-isa-postback-and-read-only-fix.aspx</link><pubDate>Tue, 17 Nov 2009 06:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740213</guid><dc:creator>jeffl</dc:creator><description>&lt;p&gt;This is an early report of a fix to a problem which showed up in EBS at a client site. &lt;/p&gt;
&lt;p&gt;First, I would like to say if you are facing this problem the fix will not be instantaneous because of a number of technologies at play.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The Problem&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;1) When a user goes to save a new SharePoint item such as an announcement, the page returns an error. As a result of the error, the item is not created. The page reports a Postback Error.&lt;/p&gt;
&lt;p&gt;2) When a user uploads a document to SharePoint there is no problem. When the user then opens the document for editing &amp;nbsp;it is only available for read only. Changes to the document cannot be saved.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The Fix&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;From the TMG console:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;em&gt;Select&lt;/em&gt; Firewall Policy&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Right Click &amp;#39;&lt;/em&gt;Allow Authenticated Users to access SharePoint services&amp;#39; &lt;em&gt;and select &lt;/em&gt;Properties&lt;/li&gt;
&lt;li&gt;The &amp;#39;Allow Authenticated Users to access SharePoint services&amp;#39; Properties dialog will appear. &lt;em&gt;Select the &lt;/em&gt;Paths tab&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Click the &lt;/em&gt;Add Button&lt;/li&gt;
&lt;li&gt;Using the default settings add a path for&amp;nbsp;&amp;nbsp;/webresource.axd*&lt;/li&gt;
&lt;li&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/jeffloucks/1777.TMG_5F00_WebResource.axd.png"&gt;&lt;img src="http://msmvps.com/resized-image.ashx/__size/550x0/__key/CommunityServer.Blogs.Components.WeblogFiles/jeffloucks/1777.TMG_5F00_WebResource.axd.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Click Apply and then OK to exit.&lt;/li&gt;
&lt;li&gt;I suggest you run IISreset on the Management server where SharePoint is located by default..&lt;/li&gt;
&lt;li&gt;Additionally you should wait fifteen minutes for TMG to update and start applying the path.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Since this is an early fix if I have updates over time I will report back. If you have different experience please touch base and leave a comment.&lt;/p&gt;
&lt;p&gt;&lt;span class="style1"&gt;Jeff &lt;/span&gt;&lt;span class="style2"&gt;Loucks&lt;br /&gt;&lt;/span&gt;&lt;span class="style2"&gt;Available Technology&lt;/span&gt;&lt;br /&gt;&lt;a target="_blank" href="http://www.availabletech.net" title="Available Technology"&gt;&lt;img height="70" width="250" src="http://www.availabletech.net/images/AvailableTechnologylogo2009.png" alt="Available Technology" /&gt;&lt;/a&gt;&lt;br /&gt;&amp;nbsp;&lt;a rel="alternate" type="application/rss+xml" href="http://feeds.feedburner.com/AvailableTechnology" title="Subscribe to my feed"&gt;&lt;img src="http://www.feedburner.com/fb/images/pub/feed-icon32x32.png" style="border-width:0px;" alt="" /&gt;&lt;/a&gt;&amp;nbsp;&lt;a rel="alternate" type="application/rss+xml" href="http://feeds.feedburner.com/AvailableTechnology" title="Subscribe to my feed"&gt;&lt;span style="color:#ff9900;"&gt;Subscribe in a reader&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Killing off ISA</title><link>http://msmvps.com/blogs/cgross/archive/2009/10/11/killing-off-isa.aspx</link><pubDate>Sun, 11 Oct 2009 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1731820</guid><dc:creator>cgross</dc:creator><description>&lt;p&gt;Earlier today &lt;a href="http://msmvps.com/blogs/bradley" target="_blank"&gt;Susan&lt;/a&gt; blogged about upgrade season in her office, and getting ready to migrate from SBS 2003 to 2008.&amp;#160; In that &lt;a href="http://msmvps.com/blogs/bradley/archive/2009/10/10/planning-for-upgrade-season.aspx" target="_blank"&gt;post&lt;/a&gt;, she talked about uninstalling ISA and mentioned a &lt;a href="http://msmvps.com/blogs/kwsupport/archive/2008/09/07/uninstalling-isa-2004.aspx" target="_blank"&gt;post&lt;/a&gt; that Kevin has on that subject.&amp;#160; I thought I’d take a moment to expand a little bit on Kevin’s post and add a few thoughts from my own battle scars with removing ISA.&lt;/p&gt;  &lt;p&gt;First and foremost – Kevin mentions removing the ISA firewall client from all of your PCs before you remove ISA from the server.&amp;#160; I cannot overstate how crucial this step is.&amp;#160; The ISA 2004 firewall client uninstaller wants access to the original installation MSI, which lives in a share on your SBS box.&amp;#160; This share is actually the &lt;em&gt;Clients&lt;/em&gt; folder in the ISA installation directory.&amp;#160; So what happens when you remove ISA from your SBS?&amp;#160; You guessed it – the mspclnt share with the firewall client installation files is removed, which means any firewall clients still installed on PCs are not going to be happy when you try to remove them and they can’t find the MSI.&lt;/p&gt;  &lt;p&gt;Since the &lt;em&gt;Clients&lt;/em&gt; folder under the ISA installation folder is typically only about 5MB, I copy this folder to a safe spot on the server – usually my Tech directory where we keep various utilities and scripts.&amp;#160; Here’s why – more and more, customers are backing up their workstations whether via Acronis / StorageCraft / Windows Home Server.&amp;#160; We may find ourselves at a point in the not so distant future after removing ISA that we need to restore a PC from an image taken before ISA was removed, and need to remove the firewall client again.&amp;#160; Or we may discover a forgotten PC / laptop that we missed removing the firewall client from.&amp;#160; There’s all sorts of scenarios – but by keeping the &lt;em&gt;Clients &lt;/em&gt;folder in-tact, we can share that out with the original mspclnt share name at any time and be able to uninstall the firewall client just like ISA was still installed on the server.&amp;#160; Without the mspclnt share, you have a very VERY ugly path in front of you, and it is safe to say that you may end up facing the decision of living with the firewall client still on the machines, or wiping &amp;amp; re-installing the OS . . .&lt;/p&gt;  &lt;p&gt;Second – Kevin also makes a brief mention about proxy settings.&amp;#160; When you uninstall the firewall client from a PC, it will automatically disable proxy settings for the user account that is running the uninstall, but not for any other users on the machine.&amp;#160; So if you have a PC that multiple users log in to, or if you are running a terminal server, be prepared for some proxy pain.&amp;#160; I actually have a little VBScript that disables proxy settings for the current user by changing the value of the HKCU\Software\Microsoft\Windows\CurrentVersion\InternetSettings\ProxyEnable key from 1 to 0.&amp;#160; I modify my login script to call the VBScript, in effect ensuring proxy gets disabled for each user when they log in to each machine.&amp;#160;&amp;#160; &lt;/p&gt;  &lt;p&gt;The other aspect with proxy settings to keep in mind are your server-side applications.&amp;#160; Unless you modified your ISA firewall policy to allow unauthenticated outbound http access from the server itself, you most likely specified proxy information for apps like Trend Micro’s Worry-Free Business Security or even WSUS – so that they can download their updates automatically.&amp;#160; After removing ISA, you no longer have a proxy server, which means apps configured to use a proxy aren’t going to be able to get out to the internet.&amp;#160; As a result, you stop getting automatic updates for things like A/V.&amp;#160; So you will need to manually update the connection settings in these apps to remove the proxy settings previously defined.&lt;/p&gt;  &lt;p&gt;So – here’s my quick checklist for removing ISA from your network &amp;amp; installing a hardware firewall:&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Prep your hardware firewall in a lab setting.&amp;#160; Enter in all public IP info, disable DHCP, and create all of our inbound rules.&amp;#160; It’s best to do this while ISA is still installed &amp;amp; working, so you can refer to the rules in ISA to make sure you don’t miss any necessary inbound rules for your environment.&lt;/li&gt;    &lt;li&gt;Backup your ISA configuration.&amp;#160; While we’re moving away from ISA permanently, if we do encounter an issue with the new hardware solution where something isn’t working that was working with ISA, the ISA backup is an XML file that is relatively easy to read to see what rules you had and what they did without having to reinstall &amp;amp; restore ISA on your SBS.&lt;/li&gt;    &lt;li&gt;Open up your outbound access in ISA by creating the proverbial ALL/ALL/ALL rule.&amp;#160; In other words, create a new access rule in ISA allowing All outbound traffic via all protocols for all users/computers.&amp;#160; Much of the internet access in ISA on SBS is dependent on users being members of the Internet Users security group.&amp;#160; The firewall client on the PCs is what actually passes user info to the ISA server so it can check group membership.&amp;#160; Once we remove the firewall client from PCs, ISA isn’t going to be getting user info and some stuff that worked before isn’t going to work now.&amp;#160; If you only have 5 PCs and are moving from ISA to your hardware firewall on a Sunday when no one is working, you might be able to skip this step.&amp;#160; But if you have a larger number of PCs, etc. this helps to insure you don’t disrupt users’ internet access &lt;em&gt;too&lt;/em&gt; much while removing the firewall client . . . &lt;/li&gt;    &lt;li&gt;In my case, I update my domain login script to call my DisableProxy.vbs script at this point.&lt;/li&gt;    &lt;li&gt;Uninstall the firewall client from ALL PCs.&amp;#160; Again – see my notes above.&amp;#160; Your life will be MUCH simpler if you insure the firewall client is completely removed from all PCs before removing ISA from your server.&lt;/li&gt;    &lt;li&gt;Copy the contents of the mspclnt share (%programfiles%\Microsoft ISA Server\Clients by default) to a safe location on the server, and plan to keep this folder safe for some time&amp;#160; &lt;img src="http://msmvps.com/emoticons/emotion-1.gif" alt="Smile" /&gt;&lt;/li&gt;    &lt;li&gt;Follow Kevin’s steps 3-9 to remove ISA from the server.&lt;/li&gt;    &lt;li&gt;When you re-run the CEICW, it should automatically update the DHCP scope option on the server to use the internal IP of the new hardware firewall as the default gateway setting.&amp;#160; If you have any devices that are using static IP addresses, you will need to manually update those with the new gateway.&amp;#160; (HINT:&amp;#160; Take a few extra minutes to create DHCP reservations for each device using a static IP, and change those devices to DHCP – so if you have another network reconfiguration in the future, all you have to do is reboot those devices instead of reconfigure &lt;img src="http://msmvps.com/emoticons/emotion-1.gif" alt="Smile" /&gt;.&amp;#160;&amp;#160;&amp;#160; For all of your other DHCP devices, you will want to run an ipconfig /release followed by an ipconfig /renew to update their IP settings so they pull the new gateway, or you can reboot them as well.&amp;#160; HINT 2 – PSTools are your friend.&amp;#160; Create a batch file with the two ipconfig commands, and use PSExec to push &amp;amp; execute the batch file on all machines in the domain from the server.&amp;#160; 5 minutes tops to update the IPConfig on all domain machines (that are online) instead of sneakernetting . . .&lt;/li&gt;    &lt;li&gt;ALSO – if you followed Jim Harrison’s steps to configure auto-detection of proxy settings on your SBS LAN, you want to remove the wpad A record from your internal AD domain forward lookup zone in DNS – otherwise you may have devices pulling proxy settings for pointing to your non-existent proxy server via auto-detect.&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;So that’s my addendum to &lt;a href="http://msmvps.com/blogs/kwsupport/archive/2008/09/07/uninstalling-isa-2004.aspx" target="_blank"&gt;Kevin’s excellent post&lt;/a&gt;.&amp;#160; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;P.S. . . .&amp;#160;&amp;#160; and if you haven’t decided on a hardware firewall yet, I highly recommend &lt;a href="http://www.calyptix.com" target="_blank"&gt;Calyptix&lt;/a&gt; devices.&amp;#160; These are the standard devices we are implementing when migrating customers to SBS 2008.&lt;/p&gt;</description></item><item><title>GFI Webmonitor</title><link>http://msmvps.com/blogs/securesmb/archive/2009/06/16/gfi-webmonitor.aspx</link><pubDate>Tue, 16 Jun 2009 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1709945</guid><dc:creator>Anonymous</dc:creator><description>For the ISA fans out there. 
GFI Webmonitor has a public beta available for Webmonitor 2009 SR2.
http://forums.gfi.com/m_900777363/mpage_1/key_/tm.htm#900777363
</description></item><item><title>Two Important new White Papers</title><link>http://msmvps.com/blogs/securesmb/archive/2009/04/09/two-important-new-white-papers.aspx</link><pubDate>Thu, 09 Apr 2009 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1686394</guid><dc:creator>Anonymous</dc:creator><description>1. Step-by-Step Configuring ISA 2006 in front of SBS 2008. See http://www.thirdtier.net/blog for more details. Those of you that got ISA 2006 as part of the make-good in SA have been waiting for this. It’s a nice step-by-step paper, easy to follow to get your rules setup correctly.
2. Security Features in Microsoft Online Services. http://www.microsoft.com/downloads/details.aspx?FamilyID=5736aaac-994c-4410-b7ce-bdea505a3413&amp;#38;DisplayLang=en&amp;#160; [...]</description></item><item><title>ISA or Calyptix?</title><link>http://msmvps.com/blogs/securesmb/archive/2009/02/11/isa-or-calyptix.aspx</link><pubDate>Wed, 11 Feb 2009 06:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1671375</guid><dc:creator>Anonymous</dc:creator><description>As migrations to SBS 2008 start to pick up steam, consultants that were using ISA as part of SBS 2003 Premium are wondering how the Calyptix Access Enforcer compares. Let’s make one thing clear right off the bat; nothing compares to ISA except ISA. ISA has a rating of 4+. That’s as good as it [...]</description></item><item><title>Secure IMAP in SBS 2003 with ISA 2004</title><link>http://msmvps.com/blogs/steveb/archive/2009/01/21/secure-imap-in-sbs-2003-with-isa-2004.aspx</link><pubDate>Wed, 21 Jan 2009 06:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1664410</guid><dc:creator>steveb</dc:creator><description>&lt;p&gt;Eriq Neale wrote this &lt;a target="_blank" href="http://simultaneouspancakes.com/Lessons/2007/09/14/configuring-imap-over-ssl-on-sbs-2003-premium-with-isa-2004/" title="Q&amp;#39;s great post on configuring IMAP SSL behind ISA 2004 on SBS 2003"&gt;post&lt;/a&gt; in September, 2007.&amp;nbsp; Given that I referenced it yet again today while configuring a customer&amp;#39;s SBS 2003 R2 Premium with ISA 2004 to get IMAPS running for an employee&amp;#39;s Mac at their house so they could use Apple Mail and IMAP, I figured I would drop a quick note of thanks here to Eriq and link to it for my own quick reference to dig it up again later.&amp;nbsp; ;-)&lt;/p&gt;
&lt;p&gt;Thanks Eriq!&amp;nbsp; Thanks to Tim too for encouraging you to write it up!&lt;/p&gt;
&lt;p&gt;Steve&lt;/p&gt;</description></item><item><title>Teaching at Baker College</title><link>http://msmvps.com/blogs/securesmb/archive/2009/01/05/teaching-at-baker-college.aspx</link><pubDate>Mon, 05 Jan 2009 06:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1658564</guid><dc:creator>Anonymous</dc:creator><description>I will be teaching a course a Baker College in Auburn Hills this winter in ISA. In addition to the prescribed curriculum I intend to bring real world experience into the classroom. So students will learn not just the what, but also why and when to apply a particular security solution. ISA is an very [...]</description></item><item><title>EBS-MVP Awardee</title><link>http://msmvps.com/blogs/securesmb/archive/2009/01/01/ebs-mvp-awardee.aspx</link><pubDate>Thu, 01 Jan 2009 06:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1658296</guid><dc:creator>Anonymous</dc:creator><description>Today I was awarded by Microsoft with the Essential Business Server - Most Valuable Professional. I am especially pleased to be the first person in the USA, to get this award. 
Microsoft has awarded me an MVP in previous years but I&amp;#8217;ve never been the first. Gotta say it feels really good to the only [...]</description></item><item><title>EBS: Introduction to TMG Q&amp;amp;A</title><link>http://msmvps.com/blogs/securesmb/archive/2008/12/06/ebs-introduction-to-tmg-q-amp-a.aspx</link><pubDate>Sat, 06 Dec 2008 06:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1655995</guid><dc:creator>Anonymous</dc:creator><description>Thanks everyone for attending the session on Thursday. Below is the Q&amp;#38;A content from the session. It is also available for offline viewing at the 5w/50 partner training site.
As part of our continuing series of free educational seminars at ThirdTier, I am planning to hold additional seminars on more advanced topics in TMG and EBS [...]</description></item><item><title>Migration from SBS 2003 to EBS 2008</title><link>http://msmvps.com/blogs/steveb/archive/2008/10/08/migration-from-sbs-2003-premium-w-isa-to-ebs-2008.aspx</link><pubDate>Wed, 08 Oct 2008 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1650141</guid><dc:creator>steveb</dc:creator><description>&lt;p&gt;&amp;nbsp;&lt;img width="343" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/steveb/EBS2008.JPG" alt="EBS 2008" height="74" style="vertical-align:top;" /&gt;&lt;/p&gt;
&lt;p&gt;When migrating over to EBS from SBS 2003 there are couple pre-migration steps that will save you a lot of trouble.&lt;/p&gt;
&lt;p&gt;First:&lt;/p&gt;
&lt;p&gt;Change the IP address of your SBS LAN IP.&amp;nbsp; This will allow you to point mail to it during the installation process.&amp;nbsp; If you do not change it, then you will not be able to have mail hit it if one of your EBS servers (in our deployments, we&amp;#39;ve standardized on .1 for SEC, .2 for MGT, and .3 for MSG) are going to use x.x.x.2 (default SBS 2003 IP address fourth octet).&lt;/p&gt;
&lt;p&gt;Second:&lt;/p&gt;
&lt;p&gt;If running SBS 2003 Premium and using ISA or dual-NIC&amp;#39;d with RRAS firewall?&amp;nbsp; Do yourself a big,&amp;nbsp;big&amp;nbsp;favor and separate out the firewall role (ISA or RRAS) from the SBS box.&amp;nbsp; Using an inexpensive hardware device make it the default gateway BEFORE you start the EBS setup.&amp;nbsp; The key here is to separate out your default gateway from the rest of the server roles on SBS that EBS is looking to so they are not all on the same IP address.&lt;/p&gt;</description></item></channel></rss>