Notices
Non Scooby Related Anything Non-Scooby related

Microsoft ISA - Knowledge/Experience?

Thread Tools
 
Search this Thread
 
Old Sep 26, 2001 | 04:07 PM
  #1  
Puff The Magic Wagon!'s Avatar
Puff The Magic Wagon!
Thread Starter
Moderator
25 Year Member
iTrader: (2)
 
Joined: May 2000
Posts: 16,980
Likes: 15
From: From far, far away...
Question

After last week's debacle (thanks for help folks ) have decided that

a) Split IIS & Web Proxy away from Exchange Server

b) U/grade to ISA

Therefore just about to order a W2K Server (PIII 1Ghz 1Gb RAM etc) to run IIS 5.0 & ISA. Before I do - any comments? Pitfalls? etc...

Reason we want ISA is software firewall features (some) & ability to apply policies of what can/can't access to users/groups/machines ( )

Thanks

Reply
Old Sep 26, 2001 | 05:02 PM
  #2  
ChrisB's Avatar
ChrisB
Moderator
 
Joined: Dec 1998
Posts: 23,573
Likes: 0
From: Staffs
Post

I've had my first exposure to ISA recently.

Probably 10 times as complex as Proxy IMHO!

I certainly wouldn't trust my network security to ISA. Two Security Bullentins on ISA already.

I would go for a combination of good firewall (probably an appliance ie SonicWall [1] or Nokia) and possibly some additional software.

Just my $0.02.

Chris.

[1] The SonicWall can do content filtering & is a damn sight easier to look after than ISA -
Reply
Old Sep 26, 2001 | 05:38 PM
  #3  
LanCat's Avatar
LanCat
Scooby Regular
 
Joined: Jul 2000
Posts: 536
Likes: 0
From: cloud cuckoo land
Post

Yes ISA is more complex than Proxy Server was but the extra flexibility is well worth it imho.

I use it to allow specific NT groups access to sets of approved internet sites and deny everything else. Works a treat. A little fiddly to set up to start with but once you are done it works just fine.

I haven't used the firewall side just the cache so I can't comment on that. I'd be wary of using it as my main internet firewall but many do and if that's as far as your budget goes; you could do worse. Don't worry about the security bulletins too much, there isn't a firewall out there that hasn't had them at some time. Getting the OS secure for the firewall is the trick. However if you need a cheap firewall check out the Gnatbox maybe?

Oh and it's well worth you moving iis and proxy away from Exchange, you'll gain so much from that because they are currently spinning their wheels fighting over memory.

Before I forget check
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
ptholt
Computer & Technology Related
3
Dec 2, 2002 02:02 PM
paulmon
Non Scooby Related
1
Dec 7, 2001 02:29 PM
sgould
Non Scooby Related
6
Dec 15, 2000 04:00 PM




All times are GMT +1. The time now is 10:56 PM.