I've seen the following happening twice at different companies: Firewall Service gets stopped for reasons documented at KB923767 and then ISA Server acts like any other server connected to a network.
From Internet, I could remotely connect to the ISA Server using RDP, even there is no access rule to allow such thing, except through VPN connection. From LAN I could connect to Isa's C$ share and, again, no access rule will ever allow that!
So, how come?
All ISA Security Feature are only relied on a single service, and when something (or someone) blows up this service, goodbye security?
Wouldn't the server be all locked down when Firewall Service gets stopped?