Posts: 96
Joined: 8.Dec.2004
From: London
Status: offline
Hello All,
Correct me in I'm wrong, but isn't the whole point of SSL Bridging that the ISA Server can perform stateful inspection of packets that are bridged?
I have tried to get MacAfee SecurityShield to inspect SSL Bridged packets, but it seems that it is only doing HTTP (as well as SMTP and FTP). Is this correct? If not, what do I need to do to correct it?
Surely at the point that they hit the HTTP filter, if they are being bridged, then they are HTTP packets, and so should be examined. Can anyone help with this?
Otherwise, I have to say that MacAfee SecurityShield does seem like a good product.
Posts: 96
Joined: 8.Dec.2004
From: London
Status: offline
I've managed to solve this!
The version that you download off the McAfee website is not the latest version. You need the patch, which is not that easy to come by. This upgrades the ISA2K4FILTER.DLL to version 1.0.550. I don't know yet whether there is a more recent version.
The latest patch is from February 25, 2005. It is a re-release of Patch 1 which the site recommends reinstalling over the old version of the patch.
The file name from the McAfee site is SSH10Patch1. My overall experience with this product is very good. In installed very quickly and went to work right away.