Welcome to ISAserver.org
Forums |
Register |
Login |
My Profile |
Inbox |
RSS
|
My Subscription |
My Forums |
Address Book |
Member List |
Search |
FAQ |
Ticket List |
Log Out
Discussion about article on making the ISA firewall a domain member
|
Users viewing this topic:
none
|
Logged in as: Guest
|
Login | |
|
RE: Discussion about article on making the ISA firewall... - 20.Jun.2006 10:22:19 PM
|
|
|
adidell
Posts: 7
Joined: 5.Aug.2003
Status: offline
|
So, What were Steve's arguments against domain membership? To be fair, let's hear the other side :). Thanks, ~Andrew
|
|
|
|
RE: Discussion about article on making the ISA firewall... - 21.Jun.2006 2:44:02 AM
|
|
|
tshinder
Posts: 49202
Joined: 10.Jan.2001
From: Texas
Status: offline
|
Hi Steve, Thanks! Tom
_____________________________
Thomas W Shinder, M.D.
|
|
|
|
RE: Discussion about article on making the ISA firewall... - 21.Jun.2006 6:46:01 AM
|
|
|
drixie
Posts: 21
Joined: 15.Mar.2006
Status: offline
|
How about one-way trusts? Would'nt that work well, but still avoiding full domain membership for the ISA machine?
|
|
|
|
RE: Discussion about article on making the ISA firewall... - 21.Jun.2006 9:35:38 AM
|
|
|
wbplomp
Posts: 138
Joined: 18.Nov.2004
From: Netherlands, The
Status: offline
|
Hi Tom, This is a very good article. I was also very surprised (and a bit disappointed) of Steve's argument. I thought that we finally left the basics of a resource domain in Windows NT 4.0 with Proxy Server 2.0. I always say ISA Server should be a member of the domain to have full function. But you do have to harden your ISA Server to take percuasion. On this moment I even use a third-party front-end firewall, I trust ISA do, but to be sure. I thereby hope Microsoft will comment on this article... Boudewijn
< Message edited by wbplomp -- 21.Jun.2006 9:40:01 AM >
|
|
|
|
RE: Discussion about article on making the ISA firewall... - 21.Jun.2006 3:37:01 PM
|
|
|
amm1270
Posts: 8
Joined: 6.Nov.2002
Status: offline
|
Hi Tom. I agree with the article and have had my ISA firewall a domain member since ISA 2000. I need the granular access control for both inbound and outbound traffic and having ISA in the domain makes that possible. Also I enjoyed your talk at Tech Ed.
|
|
|
|
RE: Discussion about article on making the ISA firewall... - 21.Jun.2006 3:41:17 PM
|
|
|
tshinder
Posts: 49202
Joined: 10.Jan.2001
From: Texas
Status: offline
|
quote:
ORIGINAL: drixie How about one-way trusts? Would'nt that work well, but still avoiding full domain membership for the ISA machine? Hi Drixie, Read the article! One-way trusts are a psychiatric salve! They problem no real security and only add complexity, while reducing your overall security posture. Thanks! Tom
_____________________________
Thomas W Shinder, M.D.
|
|
|
|
RE: Discussion about article on making the ISA firewall... - 21.Jun.2006 3:46:52 PM
|
|
|
tshinder
Posts: 49202
Joined: 10.Jan.2001
From: Texas
Status: offline
|
quote:
ORIGINAL: amm1270 Hi Tom. I agree with the article and have had my ISA firewall a domain member since ISA 2000. I need the granular access control for both inbound and outbound traffic and having ISA in the domain makes that possible. Also I enjoyed your talk at Tech Ed. Hi Ammm, Thanks for the kind words about my talk :) You get it! That's great! Thanks! Tom
_____________________________
Thomas W Shinder, M.D.
|
|
|
|
RE: Discussion about article on making the ISA firewall... - 21.Jun.2006 7:39:59 PM
|
|
|
drixie
Posts: 21
Joined: 15.Mar.2006
Status: offline
|
OK, OK, almost converted... we've been having issues with FW client authentication, could it be because our ISA is in a one-way trust relationship with the main domain? Also, if we're planning to use Radius OTP authentication, wouldn't a one-way trust be "enough"? Why would we need client certificates? PS: Many thanks for the site and the book - it has saved us a lot of work!
|
|
|
|
RE: Discussion about article on making the ISA firewall... - 21.Jun.2006 9:45:12 PM
|
|
|
drixie
Posts: 21
Joined: 15.Mar.2006
Status: offline
|
OK, I'm convinced... we'd like some people to have VPN access beyond web publishing, so I guess we really have no choice. Thanks again!
|
|
|
|
RE: Discussion about article on making the ISA firewall... - 22.Jun.2006 12:28:35 AM
|
|
|
tshinder
Posts: 49202
Joined: 10.Jan.2001
From: Texas
Status: offline
|
quote:
ORIGINAL: drixie OK, I'm convinced... we'd like some people to have VPN access beyond web publishing, so I guess we really have no choice. Thanks again! Hi Drixie, You bet! Thanks!!! Tom
_____________________________
Thomas W Shinder, M.D.
|
|
|
|
RE: Discussion about article on making the ISA firewall... - 22.Jun.2006 3:01:18 AM
|
|
|
SteveRiley
Posts: 2
Joined: 7.Apr.2006
From: Seattle, WA, USA
Status: offline
|
Friends! Either I misstated my point at TechEd (more likely) or Tom misunderstood (less likely), but that doesn't really matter. Fact is, Tom and I are in violent agreement about domain membership; I'm simply approaching a particular intractable problem from my experience dealing with certain customers. There's no debate here, because Tom is correct: domain membership is better. I wrote a bit more in my blog: http://blogs.technet.com/steriley/archive/2006/06/21/438111.aspx Steve Riley steve.riley@microsoft.com
|
|
|
|
RE: Discussion about article on making the ISA firewall... - 23.Jun.2006 9:02:55 PM
|
|
|
ChrisP
Posts: 7
Joined: 23.Jun.2006
Status: offline
|
Just wanted to say great article on this. I get this question sometimes and now have a resource to send to people for review. :) -cp
|
|
|
|
New Messages |
No New Messages |
Hot Topic w/ New Messages |
Hot Topic w/o New Messages |
Locked w/ New Messages |
Locked w/o New Messages |
|
Post New Thread
Reply to Message
Post New Poll
Submit Vote
Delete My Own Post
Delete My Own Thread
Rate Posts |
|