<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-10396525</id><updated>2011-12-14T21:47:51.586-05:00</updated><category term='Logging'/><title type='text'>ISA in SBS - yes, it's secure</title><subtitle type='html'>A central location for SBS ISA specific configuration information relevant to small consulting practices and others smart enough to use the best technology in the world.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default?start-index=101&amp;max-results=100'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>133</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-10396525.post-8963839381187820655</id><published>2007-09-26T09:31:00.001-04:00</published><updated>2009-01-22T09:48:15.735-05:00</updated><title type='text'>This Is The Last Post</title><content type='html'>This is the last post for this particular blog.&lt;br /&gt;&lt;br /&gt;Don't panic! I've created a new blog. The new blog will have a much broader focus and cover not only ISA but the full range of security challenges encountered by small businesses every day. It will include technical how to, as well as opinion, commentary and product reviews.&lt;br /&gt;&lt;br /&gt;The new blog location is &lt;a href="http://securesmb.harborcomputerservices.net/"&gt;http://securesmb.harborcomputerservices.net/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I will keep this blog online for some period as an archive.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-8963839381187820655?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/8963839381187820655/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=8963839381187820655&amp;isPopup=true' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/8963839381187820655'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/8963839381187820655'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/09/this-is-last-post.html' title='This Is The Last Post'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-5214737827586218377</id><published>2007-08-27T15:31:00.000-04:00</published><updated>2007-08-27T15:33:36.495-04:00</updated><title type='text'>ISA SP3 Logging Improvements</title><content type='html'>I've been so busy lately that I haven't had a chance to blog much. Thank goodness that the official ISA blog has picked up the slack. :)  They've put out some great posts lately including todays: Logging Diasgnostic Improvements in SP3. You definately need to check it out.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://blogs.technet.com/isablog/archive/2007/08/26/diagnostic-improvements-in-isa-server-2004-service-pack-3.aspx"&gt;http://blogs.technet.com/isablog/archive/2007/08/26/diagnostic-improvements-in-isa-server-2004-service-pack-3.aspx&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-5214737827586218377?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='ISA SP3 Logging Improvements'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/5214737827586218377/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=5214737827586218377&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/5214737827586218377'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/5214737827586218377'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/08/isa-sp3-logging-improvements.html' title='ISA SP3 Logging Improvements'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-7436522964035006736</id><published>2007-08-27T11:47:00.000-04:00</published><updated>2007-08-27T11:55:03.904-04:00</updated><title type='text'>ISA @ SMBNation</title><content type='html'>ISA will be featured in the technical track at SMB Nation this year. My presentation back in March at SMBTN was well received. I'll be building on that presentation. I will demonstrate several configurations that are in demand for SMB consultants:&lt;br /&gt;&lt;br /&gt;Spam and Flood protection&lt;br /&gt;Limiting Internet Access: Integration with AD and Group Policy&lt;br /&gt;Logging and Reporting&lt;br /&gt;Backup and Recovery&lt;br /&gt;&lt;br /&gt;So be there. Dana Epp, Security MVP has organized top drawer technical content for this conference. It's September 29 - October 1. &lt;a href="http://www.smbnation.com/"&gt;http://www.smbnation.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Also, a heads up. I'll be presenting at SMB Focus in Sydney Australia in November as well. Plan now and I'll see you there.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-7436522964035006736?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='ISA @ SMBNation'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/7436522964035006736/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=7436522964035006736&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/7436522964035006736'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/7436522964035006736'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/08/isa-smbnation.html' title='ISA @ SMBNation'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-1271787922572785773</id><published>2007-07-17T14:55:00.000-04:00</published><updated>2007-07-17T15:19:31.650-04:00</updated><title type='text'>Thoughts on what it means to not have an edge SBS</title><content type='html'>Situating SBS on the edge of the small business network has always been a controversial topic. A network in a box for small companies has to include some kind of firewall doesn't it? So through the years it was RRAS, Proxy 2.0, ISA 2000 and ISA 2004. With word out that SBS will no longer be supported on the edge that means that ISA on that box and RRAS are both out of the picture. Considering that most SBS servers are currently protected by RRAS that's significant.&lt;br /&gt;&lt;br /&gt;Having worked in the small business market for a number of years I can tell you with certainty that this will leave the vast majority of SBS customers with networks protected by their DSL router. A DSL router just isn't sufficient to protect against today's application targeted attacks. Neither is it sophisticated enough to serve the publishing needs of Exchange 2007 without leaving gaping holes to exploit.&lt;br /&gt;&lt;br /&gt;Microsoft knows best how to protect Microsoft software. SBS is jammed packed with Microsoft software as are most small business desktops. What then will be the official "best practice" recommended by Microsoft to protect their software that these customers are so dependant upon?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-1271787922572785773?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Thoughts on what it means to not have an edge SBS'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/1271787922572785773/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=1271787922572785773&amp;isPopup=true' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/1271787922572785773'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/1271787922572785773'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/07/thoughts-on-what-it-means-to-not-have.html' title='Thoughts on what it means to not have an edge SBS'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-7046812981081223095</id><published>2007-07-17T14:48:00.000-04:00</published><updated>2007-07-17T14:55:23.368-04:00</updated><title type='text'>The Skinny on ISA in SBS 2008</title><content type='html'>The official word:&lt;br /&gt;&lt;br /&gt;"With respect to ISA, here's what we're public on:&lt;br /&gt;&lt;br /&gt;- SBS no longer will support being the edge box.  You'll need SBS to be behind a network firewall of some sort -- could be a hardware firewall, could be a software firewall, such as ISA.&lt;br /&gt;&lt;br /&gt;- ISA, itself, will no longer support running on the SBS server itself -- this is really related to #1.  We're building the SBS tools in the next rev assuming that the network firewall is elsewhere."&lt;br /&gt;&lt;br /&gt;I wish I was allowed to say more about what's going on in the next version of SBS but I'm not. So from the official statement above it doesn't take a rocket scientist to notice that you're going to have to place your ISA server in front of SBS next time around on a seperate server. Unfortunately there's no public statement about what this means the product list is for SBS Premium because obviously we're going to need another license of Windows for that second server. We'll have to wait and see.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-7046812981081223095?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='The Skinny on ISA in SBS 2008'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/7046812981081223095/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=7046812981081223095&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/7046812981081223095'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/7046812981081223095'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/07/skinny-on-isa-in-sbs-2008.html' title='The Skinny on ISA in SBS 2008'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-43406531059314555</id><published>2007-06-06T10:17:00.000-04:00</published><updated>2007-06-06T10:20:13.004-04:00</updated><title type='text'>News: Microsoft soft unveils Stirling</title><content type='html'>Microsoft unveiled a new product, code name Stirling, yesterday at Tech-Ed. For those wondering where ISA is going in the future. Here's a hint. There is also another product under development under a different code name that non-enterprise businesses will also be interested in.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.infoworld.com/article/07/06/04/Microsoft-unveils-integrated-security_1.html"&gt;See the full article here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-43406531059314555?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='News: Microsoft soft unveils Stirling'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/43406531059314555/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=43406531059314555&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/43406531059314555'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/43406531059314555'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/06/news-microsoft-soft-unveils-stirling.html' title='News: Microsoft soft unveils Stirling'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-1960288299141411480</id><published>2007-05-02T09:32:00.000-04:00</published><updated>2007-05-02T09:49:20.643-04:00</updated><title type='text'>ISA 2004 SP3 Released</title><content type='html'>&lt;a href="http://www.microsoft.com/technet/isa/2004/sp3.mspx"&gt;ISA 2004 SP3 is here. &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;ISA Server 2004 SP3 includes the following new features and improved functionality:&lt;br /&gt;•&lt;br /&gt;Improvements to the ISA Server Management console with the addition of a new Troubleshooting node&lt;br /&gt;•&lt;br /&gt;Enhanced log viewing functionality&lt;br /&gt;•&lt;br /&gt;Additional log filtering functionality&lt;br /&gt;•&lt;br /&gt;Diagnostic logging, including over 200 new diagnostic logging events&lt;br /&gt;•&lt;br /&gt;Integration with the Microsoft ISA Server Best Practices Analyzer Tool&lt;br /&gt;•&lt;br /&gt;Support for publishing Microsoft Exchange Server 2007 with ISA Server 2004&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-1960288299141411480?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='ISA 2004 SP3 Released'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/1960288299141411480/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=1960288299141411480&amp;isPopup=true' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/1960288299141411480'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/1960288299141411480'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/05/isa-2004-sp3-released.html' title='ISA 2004 SP3 Released'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-2575121706270100388</id><published>2007-05-02T09:24:00.000-04:00</published><updated>2007-05-02T09:32:29.530-04:00</updated><title type='text'>Vista might not connect immediately</title><content type='html'>&lt;a href="http://http://technet2.microsoft.com/WindowsVista/en/library/3e2d2dc5-c802-411e-9be4-dd29ec86c9351033.mspx?mfr=true"&gt;Network Connectivity Status Indicator and Resulting Internet Communication in Windows Vista&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Read all about it in TechNet. Vista contains a feature which uses DNS to locate and connect to a pre-defined website. This is part of the new network identification feature. So when Vista detects a new network and pops up the box for you to select how much you trust this newly connected network, this article explains what has happened in the background.&lt;br /&gt;&lt;br /&gt;The key issues are:&lt;br /&gt;&lt;br /&gt;1.       Vista clients behind ISA may not immediately recognize that they are connected to the Internet via a firewall&lt;br /&gt;2.       ISA logs will contain denied DNS traffic destined for 131.107.255.255 (yes, this is a valid IP address)&lt;br /&gt;&lt;br /&gt;And don't panic.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-2575121706270100388?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Vista might not connect immediately'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/2575121706270100388/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=2575121706270100388&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/2575121706270100388'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/2575121706270100388'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/05/vista-might-not-connect-immediately.html' title='Vista might not connect immediately'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-4299071079788603312</id><published>2007-04-25T10:38:00.000-04:00</published><updated>2007-04-25T11:04:47.046-04:00</updated><title type='text'>Publishing AuthAnvil Self Service Token Enrollment</title><content type='html'>In using AuthAnvil to create a secure two-factor remote access for the SBS servers we manage it was decided that we'd like to allow users to Enroll the Cryptocard token we've provided themselve. AuthAnvil allows this through a self service token enroll website located on IIS. We'll use SSL to publish this site.&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Click Publish a Web Server. Call it AuthAnvil Token Enroll.&lt;/li&gt;&lt;li&gt;Click Next, Choose Allow, Click Next.&lt;/li&gt;&lt;li&gt;The server name will be publishing.yourinternaldomain.local. Check Forward the orginal host header. The path will be /AuthEnroll/*  The public name is the DNS name of your server, for example: mail.domain.com. Click Next.&lt;/li&gt;&lt;li&gt;Choose the SBS Web Listener. Click Next.&lt;/li&gt;&lt;li&gt;Leave All Users. Click Next.&lt;/li&gt;&lt;li&gt;Click Next, until done. Then Click Finish.&lt;/li&gt;&lt;li&gt;Make sure your rule is at the bottom of the other publishing rules in your server. This will make it rule 6 or so. &lt;/li&gt;&lt;li&gt;Right click on it and select Properties&lt;/li&gt;&lt;li&gt;On the Bridging tab make sure SSL is checked &lt;/li&gt;&lt;li&gt;On the To tab check to make sure your server name is correct, the check box is checked and the radio button for requests appear to come from the ISA server is selected.&lt;/li&gt;&lt;li&gt;On the Public Name tab make sure the public DNS name of your server is listed and is correct.&lt;/li&gt;&lt;li&gt;Click OK.&lt;/li&gt;&lt;li&gt;Press the Apply button for this rule to take effect.&lt;/li&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-4299071079788603312?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Publishing AuthAnvil Self Service Token Enrollment'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/4299071079788603312/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=4299071079788603312&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/4299071079788603312'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/4299071079788603312'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/04/publishing-authanvil-self-service-token.html' title='Publishing AuthAnvil Self Service Token Enrollment'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-6990759568776250001</id><published>2007-04-17T12:15:00.000-04:00</published><updated>2007-04-17T12:23:33.112-04:00</updated><title type='text'>Multi-Core Processors: Another reason for SP2</title><content type='html'>While loading an ISA2004 onto new hardware I ran into a problem where the firewall service would not run. When something like that happens on a new install you get that sinking feeling that it's going to be a long night.&lt;br /&gt;&lt;br /&gt;Fortunately a quick search came up with the solution. Install ISA 2004 SP2. ISA 2004 SP2 corrects an issue where ISA misidentifies the number of processors in the system. This can happen for a variety of reasons, one of which is multi-core processors.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/884569"&gt;Here's the kb reference &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-6990759568776250001?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Multi-Core Processors: Another reason for SP2'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/6990759568776250001/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=6990759568776250001&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/6990759568776250001'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/6990759568776250001'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/04/multi-core-processors-another-reason.html' title='Multi-Core Processors: Another reason for SP2'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-1256064297396320068</id><published>2007-04-03T10:58:00.000-04:00</published><updated>2007-04-03T11:05:21.722-04:00</updated><title type='text'>Vista 64-Bit Can't Join Domain</title><content type='html'>Found a kb article that resolved a perplexing problem for us today. A Vista 64-Bit Ultimate edition PC was unable to join the domain. The error message stated a problem with RPC. This usually points to the local firewall but in this case it was ISA and a hotfix is needed to resolve it. This hotfix is available from the download center. No call to PSS required!&lt;br /&gt;&lt;br /&gt;The kb article id is 917903; last updated March 15, 2007.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;You cannot join a computer that is running a 64-bit version of Windows Vista to a Windows domain on which ISA Server 2004 is configured as a firewall&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;SYMPTOMS&lt;br /&gt;&lt;br /&gt;Consider the following scenario. You have a Windows domain on which Microsoft Internet Security and Acceleration (ISA) Server 2004 is configured as a firewall. You try to add to the domain a client computer that is running a 64-bit version of Windows Vista. However, you receive an "RPC Server unavailable" error message on the client computer. Additionally, the computer is not added to the domain.Note This problem occurs primarily in a Microsoft Windows Small Business Server 2003 (Windows SBS) domain.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;CAUSE&lt;br /&gt;&lt;br /&gt;This problem occurs because 64-bit Windows Vista client computers add a third context element structure to a remote procedure call (RPC) bind call. However, the ISA Server RPC application filter drops this bind call as an incorrect RPC bind packet.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-1256064297396320068?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Vista 64-Bit Can&apos;t Join Domain'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/1256064297396320068/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=1256064297396320068&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/1256064297396320068'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/1256064297396320068'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/04/vista-64-bit-cant-join-domain.html' title='Vista 64-Bit Can&apos;t Join Domain'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-3497110588167042890</id><published>2007-03-29T09:50:00.000-04:00</published><updated>2007-03-29T09:52:45.144-04:00</updated><title type='text'>ISA and Windows 2003 SP2</title><content type='html'>The ISA team has blogged about some issues affecting ISA after an installation of Windows 2003 SP2. The original post is &lt;a href="http://blogs.technet.com/isablog/archive/2007/03/27/isa-server-and-windows-server-2003-service-pack-2.aspx"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;ISA Server and Windows Server 2003 Service Pack 2&lt;br /&gt;&lt;br /&gt;Recently Microsoft released Service Pack (SP) 2 for Windows Server 2003 (&lt;a href="http://www.microsoft.com/technet/windowsserver/sp2.mspx"&gt;http://www.microsoft.com/technet/windowsserver/sp2.mspx&lt;/a&gt;). We tested ISA Server with the Windows service pack quite extensively. Unfortunately we discovered after the release of the Windows service pack that there are several issues that have potential ill-effects on ISA Server. This blog summarizes the currently known issues, and suggestions on how to mitigate those issues.&lt;br /&gt;&lt;br /&gt;1.     If you run ISA Server 2004 Enterprise Edition with or without the ISA Server SP2, you must install ADAM SP1 on the ISA Server Configuration Storage Server prior to installing the Windows Server 2003 SP2. ADAM SP1 can be downloaded from &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=9688F8B9-1034-4EF6-A3E5-2A2A57B5C8E4&amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyId=9688F8B9-1034-4EF6-A3E5-2A2A57B5C8E4&amp;amp;displaylang=en&lt;/a&gt;. If you install Windows Server 2003 SP2 without first installing the ADAM SP1, ISA Server will not start after the installation, and you will have to uninstall Windows Server 2003 SP2. Further information is available in the Windows Server 2003 SP2 release notes, at &lt;a href="http://technet2.microsoft.com/WindowsServer/en/library/ed5382af-e819-4d33-ace0-225d31b7ab751033.mspx?mfr=true"&gt;http://technet2.microsoft.com/WindowsServer/en/library/ed5382af-e819-4d33-ace0-225d31b7ab751033.mspx?mfr=true&lt;/a&gt; .&lt;br /&gt;&lt;br /&gt;2.     If you run ISA Server 2000, 2004 or 2006 Standard or Enterprise editions on a multi-core / multi-processor 32-bit computer, and the CPU is heavily utilized, you might experience performance degradation in certain deployment scenarios after installing Windows Server 2003 SP2. The issue stems from a change in interrupt handling introduced in SP2.To correct the issue you must download and run the Interrupt Affinity Tool (intfiltr) available in Windows Server 2003 resource kit (&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=9d467a69-57ff-4ae7-96ee-b18c4790cffd&amp;DisplayLang=en"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=9d467a69-57ff-4ae7-96ee-b18c4790cffd&amp;amp;DisplayLang=en&lt;/a&gt;). You can read about installation and usage of intfiltr.exe in &lt;a href="http://support.microsoft.com/kb/252867"&gt;http://support.microsoft.com/kb/252867&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;3.     If your network adaptors (NICs) support receive-side scaling (RSS), then in certain NAT scenarios ISA Server 2000, 2004 or 2006 Standard or Enterprise editions might not transfer packets from one NIC to the other after installation of Windows Server 2003 SP2.To correct the issue you must disable RSS support &amp;shy;&amp;shy;- follow the instructions in &lt;a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;927695"&gt;http://support.microsoft.com/default.aspx?scid=kb;EN-US;927695&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Neta Amit&lt;br /&gt;Program manager&lt;br /&gt;ISA Server Sustained Engineering Team&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-3497110588167042890?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='ISA and Windows 2003 SP2'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/3497110588167042890/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=3497110588167042890&amp;isPopup=true' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/3497110588167042890'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/3497110588167042890'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/03/isa-and-windows-2003-sp2.html' title='ISA and Windows 2003 SP2'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-5769060933604548338</id><published>2007-02-27T08:19:00.000-05:00</published><updated>2007-02-27T08:21:55.679-05:00</updated><title type='text'>ISA 2008 Needs Your Help</title><content type='html'>The Microsoft ISA Product Team is working on the next version of ISA. As part of the work, the team is currently recruiting customers for its internal customer programs namely TAP (Technology Adoption Program) and the Advisory Group). Interested customers, consultants, solution provides and others can contact &lt;a title="mailto:ngtprcrt@microsoft.com" href="mailto:ngtprcrt@microsoft.com"&gt;ngtprcrt@microsoft.com&lt;/a&gt; to start the nomination process.&lt;br /&gt;Please note:&lt;br /&gt;-          The information about these specific programs is Microsoft-confidential. Therefore, nomination to these programs requires the nominees to already have or sign a non-disclosure-agreement (NDA) with Microsoft.&lt;br /&gt;-          Nominees who wish to participate (after they are accepted to the program) in the TAP kickoff event on April 16-18, are advised to follow-up immediately.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-5769060933604548338?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='ISA 2008 Needs Your Help'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/5769060933604548338/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=5769060933604548338&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/5769060933604548338'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/5769060933604548338'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/02/isa-2008-needs-your-help.html' title='ISA 2008 Needs Your Help'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-8078984886797440922</id><published>2007-02-14T21:19:00.000-05:00</published><updated>2007-02-14T21:28:41.848-05:00</updated><title type='text'>SMBTN Conference ISA Session</title><content type='html'>There's a great conference coming up March 15-18th. It's the &lt;a href="http://www.smbsummit.com"&gt;SMB Summit&lt;/a&gt;, the 3rd annual SMB Technology Network conference. It's being held at Disneyland. Have a look at the sessions and the speakers. If you are a small IT firm looking to grow, this is the place to be.&lt;br /&gt;&lt;br /&gt;I'll be presenting a technical session on using ISA to build your security practice. I'll show off wireless network security, advanced DMZ controls and monitoring and reporting, then we'll open it up for discussion on adding security services to your standard service offerings.&lt;br /&gt;&lt;br /&gt;Hope to see you there!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-8078984886797440922?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='SMBTN Conference ISA Session'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/8078984886797440922/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=8078984886797440922&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/8078984886797440922'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/8078984886797440922'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/02/smbtn-conference-isa-session.html' title='SMBTN Conference ISA Session'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-1968046706668021913</id><published>2007-02-05T10:27:00.000-05:00</published><updated>2007-02-05T10:50:06.435-05:00</updated><title type='text'>Update: iTunes ISA 2004 SP2</title><content type='html'>In a previous blogpost I pointed you to the ISA Product Team blog for instructions on how to allow iTunes through ISA. I've got a little personal experience with this now and some new information for you.&lt;br /&gt;&lt;br /&gt;If you're having problems visiting the iTunes site, you'll notice in the ISA logs that the packets are being rejected because ISA wasn't expecting compressed content but the iTunes responds with compressed content. I think this is a web development issue. The tighter we make our firewall configurations the more we expect development to follow the rules. Repsonding with compressed content when it wasn't requested is a no-no and the packet will be handled according to the settings under General, Define HTTP Compression Preferences. You'll notice that by default any packets trying to send compressed content that you didn't ask for will be dropped.&lt;br /&gt;&lt;br /&gt;Following the instructions in the previous blog you'll need to provide a "site" for the exception to our compressed content restrictions. By "site" what is really meant is computer set. So create one and let's call it iTunes. Add the following IP addresses to this set.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;89.149.169.80-.89.149.169.97&lt;/li&gt;&lt;li&gt;194.109.192.22&lt;/li&gt;&lt;li&gt;194.109.192.7&lt;/li&gt;&lt;li&gt;17.250.236.65&lt;/li&gt;&lt;li&gt;69.44.123.19&lt;/li&gt;&lt;li&gt;69.44.123.26&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Once you have your "site" created check the box Request Compressed HTTP Content from Servers.&lt;/p&gt;&lt;p&gt;You'll be able to speak to the iTunes servers now.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-1968046706668021913?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Update: iTunes ISA 2004 SP2'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/1968046706668021913/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=1968046706668021913&amp;isPopup=true' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/1968046706668021913'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/1968046706668021913'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/02/update-itunes-isa-2004-sp2.html' title='Update: iTunes ISA 2004 SP2'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-6730936000418829111</id><published>2007-02-01T14:26:00.000-05:00</published><updated>2007-02-01T14:31:08.106-05:00</updated><title type='text'>Strong Authentication for SBS</title><content type='html'>Good news! Today is the official release day for AuthAnvil. This is an excellent addition to the RWW Guard product that Scorpion Software also offers. I've seen it in action. This is a must have for IT firms servicing multiple clients and for all small businesses taking advantage of the many remote access features of SBS. There's nothing like knowing for certain who is logging into your server.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Scorpion Software releases AuthAnvil Strong Authentication System (SAS) for Small Business&lt;br /&gt;Chilliwack, BC: February 1, 2007 - Scorpion Software Corp. today announced the general availability of version 1.0 of AuthAnvil, a strong authentication system (SAS) to protect small businesses and enhance their remote access security with the introduction of two-factor authentication server software for Microsoft's Small Business Server (SBS) 2003 and Windows Server 2003 platforms. AuthAnvil enhances online trust and enables secure remote access to protected information assets by offering the ability to reliably prove user identities through the use of strong authentication. More information about AuthAnvil is available at &lt;/em&gt;&lt;a title="http://www.mymailout.com/MyMailout/Redirect.aspx?u=" q="26389569&amp;amp;lm=" r="40744&amp;amp;qz=" href="http://www.scorpionsoft.com/products/authanvil/" target="_blank"&gt;&lt;em&gt;http://www.scorpionsoft.com/products/authanvil/&lt;/em&gt;&lt;/a&gt;&lt;em&gt;. &lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;"AuthAnvil is our second and most crucial piece to our strong authentication solution for small business. It helps to eliminate the insecurities and weaknesses in static reusable passwords by offering more perfected one time passwords that can be easily deployed and managed." says Dana Epp, Scorpion Software's President and Computer Security Software Architect. "In combination with our &lt;/em&gt;&lt;a title="http://www.mymailout.com/MyMailout/Redirect.aspx?u=" q="26389569&amp;amp;lm=" r="40744&amp;amp;qz=" href="http://www.mymailout.com/MyMailout/Redirect.aspx?u=32730&amp;q=26389569&amp;amp;lm=3821570&amp;r=40744&amp;amp;qz=7c8b08d80c5d5d5e2b5cca096b67e088" target="_blank"&gt;&lt;em&gt;RWW-Guard&lt;/em&gt;&lt;/a&gt;&lt;em&gt; product we can now offer a complete solution to help protect the remote access to critical information assets in small businesses who leverage Microsoft server technology like SBS 2003 and Remote Web Workplace."&lt;br /&gt;&lt;/em&gt;&lt;br /&gt;&lt;em&gt;About Scorpion Software Corp.&lt;br /&gt;Scorpion Software Corp provides the premium solution for SMBs to reduce the risks associated with the use of weak static reusable passwords and provide a higher level of confidence that only authorized users can access their company's most important business assets - their proprietary information. Headquartered in British Columbia, Canada, Scorpion Software helps small businesses manage online risk while offering unprecedented password protection. More information about the company is available at &lt;/em&gt;&lt;a title="http://www.mymailout.com/MyMailout/Redirect.aspx?u=" q="26389569&amp;amp;lm=" r="40744&amp;amp;qz=" href="http://www.mymailout.com/MyMailout/Redirect.aspx?u=27699&amp;q=26389569&amp;amp;lm=3821570&amp;r=40744&amp;amp;qz=b186c82a0f0113ba591f5e1e65c135ea" target="_blank"&gt;&lt;em&gt;www.scorpionsoft.com&lt;/em&gt;&lt;/a&gt;&lt;em&gt;. &lt;/em&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-6730936000418829111?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Strong Authentication for SBS'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/6730936000418829111/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=6730936000418829111&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/6730936000418829111'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/6730936000418829111'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/02/strong-authentication-for-sbs.html' title='Strong Authentication for SBS'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-3094559814554903753</id><published>2007-01-11T12:53:00.000-05:00</published><updated>2007-01-11T13:03:28.598-05:00</updated><title type='text'>2 1/2 Conferences</title><content type='html'>I'll be attending the SMBSummit a Disneyland from March 15-17. This conference is organized by the SMB Technology Network. If you are looking for good technical information on SBS and good business information on running a small consulting firm this is the place to be.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.smbsummit.com"&gt;http://www.smbsummit.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I am also hoping to attend Jeff Middleton's Small Business IT Disaster Recovery and Crises Recovery conference from May 26th - June 2nd.  Jeff's conference is the 1 1/2 part in the title of this post. The first two days are land based in New Orleans. The remaining 5 are on a Cruiseship leaving New Orleans headed for Mexico. You can attend the first part, the second part or both. It's a round table discussion type conference with leaders rather than speakers happening for the majority of it. Great concept. Should also be a great time. There's plenty of fun time built into this one.&lt;br /&gt;&lt;br /&gt;&lt;a title="http://conference2007.sbsmigration.com" href="http://conference2007.sbsmigration.com"&gt;http://conference2007.sbsmigration.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Hope to meet you there!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-3094559814554903753?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='2 1/2 Conferences'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/3094559814554903753/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=3094559814554903753&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/3094559814554903753'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/3094559814554903753'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/01/2-12-conferences.html' title='2 1/2 Conferences'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-6228367715039425394</id><published>2007-01-11T12:49:00.000-05:00</published><updated>2007-01-11T12:52:11.188-05:00</updated><title type='text'>Creating a Visited Websites Report by User</title><content type='html'>Many admins learned how to create reports by opening up the log files in ISA 2000 and using Excel features to organize the data in a meaningful way. Contrary to popular opinion, you can use Excel to generate a report using ISA 2004 with MSDE logging much easier than in ISA 2000 flat files.&lt;br /&gt;&lt;br /&gt;Start by trimming out what you don't want to see, right in ISA.&lt;br /&gt;&lt;br /&gt;In the monitoring tab create a query with the information you want to view.&lt;br /&gt;&lt;br /&gt;Logging last 7  days&lt;br /&gt;Protocol HTTP&lt;br /&gt;Action Allowed Connection&lt;br /&gt;Rule SBS Internet Access Rule&lt;br /&gt;Client Username Not Equal Annonymous&lt;br /&gt;&lt;br /&gt;This will display in the monitoring viewer a list of packets going to websites. Press the Copy to Clipboard and then paste into Excel to start organizating the data into a report.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-6228367715039425394?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Creating a Visited Websites Report by User'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/6228367715039425394/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=6228367715039425394&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/6228367715039425394'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/6228367715039425394'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/01/creating-visited-websites-report-by.html' title='Creating a Visited Websites Report by User'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-1922058225744675163</id><published>2007-01-11T09:30:00.000-05:00</published><updated>2007-01-11T09:35:02.293-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Logging'/><title type='text'>How ISA MSDE Logging Works</title><content type='html'>Recently on a mailing list a question was asked for someone to explain how ISA does logging to MSDE and why you sometimes see a lot of log files for the same day. Dana Epp, of Scorpion Software, quickly responded with a very concise and clear response.&lt;br /&gt;&lt;em&gt;&lt;/em&gt;&lt;br /&gt;&lt;em&gt;When using MSDE, ISA stores the logs in daily database files. If you make any policy changes to the firewall, it stops the instance and restarts it with a new name. As an example for today the database would be called ISALOG_20070110_FWS_000. (That is the format YYYYMMDD in case you missed it). If you stopped and restarted ISA, it would then be ISALOG_20070110_FWS_001. You would need to function concat() {    [native code]}the 000 and the 001 to get the complete set of log events for the day. For the web proxy, its "_WEB_" instead of of "_FWS_". Microsoft does this to apparently prevent data corruption, although I have yet to see how that matters in this regard. There is no reason it couldn't be merged. (IMNSHO). I think they do it to prevent the DB size limitation for MSDN databases.&lt;br /&gt;&lt;br /&gt;Depending on your audit log retention policy, you might have up to a month or two of these hanging around. What Firewall Dashboard&lt;/em&gt; (Dana's ISA add-on)&lt;em&gt; does is merge all the data together, consolidate all the events down to remove log events not helpful in analysis, and import them into the FWDB database instance. Thats how we can literally go from a few hundred thousand events down to a few hundred, depending on the scenario.&lt;br /&gt;&lt;br /&gt;The actual table structure for the whole lot is stored under the ISA directory. If you wish to see the structure of the data, its in *.sql scripts in the base dir of ISA.&lt;br /&gt;&lt;br /&gt;If you are finding that the files are hanging around past the date you want, you can freely delete them... with one caveat. If you are consolidating the data with the ISA reporting engine, make sure you aren't deleting the summary/archive data.&lt;br /&gt;&lt;br /&gt;There is a KB on configuring logging for ISA. Not sure if you would find that useful or not. You can see it at: &lt;/em&gt;&lt;a title="http://support.microsoft.com/?id=" href="http://support.microsoft.com/?id=302372"&gt;&lt;em&gt;http://support.microsoft.com/?id=302372&lt;/em&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-1922058225744675163?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='How ISA MSDE Logging Works'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/1922058225744675163/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=1922058225744675163&amp;isPopup=true' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/1922058225744675163'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/1922058225744675163'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/01/how-isa-msde-logging-works.html' title='How ISA MSDE Logging Works'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-7660549329625976108</id><published>2007-01-03T19:25:00.000-05:00</published><updated>2007-01-03T19:26:38.521-05:00</updated><title type='text'>New RSS Feed</title><content type='html'>Google converted my blog over to the new format and because of this the RSS feed address changed. Here's the new one: &lt;a href="http://isainsbs.blogspot.com/feeds/posts/default?alt=rss"&gt;http://isainsbs.blogspot.com/feeds/posts/default?alt=rss&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The old one was so much simpler.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-7660549329625976108?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='New RSS Feed'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/7660549329625976108/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=7660549329625976108&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/7660549329625976108'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/7660549329625976108'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/01/new-rss-feed.html' title='New RSS Feed'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-1639044168437204741</id><published>2007-01-03T10:00:00.000-05:00</published><updated>2007-01-03T10:04:16.228-05:00</updated><title type='text'>MVP Awarded</title><content type='html'>For the second year I have been awarded an MVP for ISA. This recognition means more to me than any certification because it is a peer nominated award for my participation and contribution to the ISA community. A lot of &lt;a href="https://mvp.support.microsoft.com/communities/mvp.aspx"&gt;amazing people&lt;/a&gt; are MVP's and I'm honored to be in their company.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-1639044168437204741?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='MVP Awarded'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/1639044168437204741/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=1639044168437204741&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/1639044168437204741'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/1639044168437204741'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/01/mvp-awarded.html' title='MVP Awarded'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-116776027861310588</id><published>2007-01-02T12:22:00.000-05:00</published><updated>2007-01-02T12:51:18.706-05:00</updated><title type='text'>Thank you!</title><content type='html'>I'd like to put in a big thank you to several people that made a difference in the world of ISA support in 2006. &lt;br /&gt;&lt;br /&gt;Jim Harrison - Without Jim there would be no ISA community. He's a man of infinite patience and belief in community. We only managed to push him over the edge twice this year and given how many buttons were pushed, only twice says a lot for his character and ability to see beyond the surface bull to the real issues. &lt;br /&gt;&lt;br /&gt;Susan Bradley - The World News, the Great Library of Susan, the ever helpful and passionate about community nearly to a fault Susan. If you haven't heard the name then you must live underwater someplace. No one can read Susan and always agree with her but that's part of what makes her voice invaluable. Susan isn't afraid to ask the difficult, the unsaid, or to point out the elephant in the room and when you need her support she's right there. I love that.&lt;br /&gt;&lt;br /&gt;Tom Shinder - Given Tom's opinions about SBS some will question my sanity for mentioning him here, but just as many will question my mention of Susan above. Truth be told the combined passion that these two have for their respective communities, if harnessed, could resolve the west coast summer power problems. Tom's dedication to ISA and community through his articles and forum support surpasses the rest of us combined. His comments can be harshly worded but I value them even so. Besides, I think we have an understanding.&lt;br /&gt;&lt;br /&gt;Andy Goodman - Andy will probably fall off his chair if he's sees this but Andy has done some excellent work detailing what needs to be done to stop CRM and ISA from trying to kill one another and CRM works as an SSL site to boot. Since Microsoft put out the SBS version of CRM and didn't include instructions that made any sense, they owe him some thanks as well. But since that probably isn't coming Andy, you'll have to get by with just mine.&lt;br /&gt;&lt;br /&gt;Eriq Neale - Because he said after reading the chapters I wrote for his book that he's converting his clients over to ISA. When your boss says that, well, you've got to say thank you.&lt;br /&gt;&lt;br /&gt;Thanks also to the readers. Most of you find this blog through Google or links from other blogs. I get a couple of comments every week usually direct to my mailbox. Thanks for those; they mean a lot.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-116776027861310588?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Thank you!'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/116776027861310588/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=116776027861310588&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/116776027861310588'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/116776027861310588'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/01/thank-you.html' title='Thank you!'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-116775832280998329</id><published>2007-01-02T11:56:00.000-05:00</published><updated>2007-01-02T12:18:43.003-05:00</updated><title type='text'>Adding Exchange Defender for SMTP Security</title><content type='html'>A price we pay for putting ISA on the same physical box as our Exchange server in SBS 2003 is that we're unable to make use of the SMTP features in ISA. You can however use Exchange Defender, a third party SMTP filtering service, to reduce incoming spam. (among other nice features) If you are planning to implement Exchange Defender you'll want to have a look at Susan Bradley's article on how to configure ISA to work with it. You can find it &lt;a href="http://msmvps.com/blogs/bradley/archive/2006/12/29/using-isa-to-protect-the-sbs-mail-server-just-a-smidge-more.aspx"&gt;here&lt;/a&gt;. I'll add this reference to the App section on the blog website as well.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-116775832280998329?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Adding Exchange Defender for SMTP Security'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/116775832280998329/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=116775832280998329&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/116775832280998329'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/116775832280998329'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2007/01/adding-exchange-defender-for-smtp.html' title='Adding Exchange Defender for SMTP Security'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-116663919333349671</id><published>2006-12-20T13:26:00.000-05:00</published><updated>2006-12-20T13:26:33.420-05:00</updated><title type='text'>ISA 2004 Installation Fails Creating Sotrage</title><content type='html'>&lt;a href="http://isainsbs.blogspot.com/"&gt;ISA in SBS - yes, it's secure&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This response by Mark Stanfill saved me last night. (Thank you Mark) The only additional thing I would add is that this installation method also does not create a share to hold the firewall client for you. So after you have sucessfully installed ISA go into add/remove programs, Choose ISA, select Modify and select the Firewall Client Share item.&lt;br /&gt;&lt;br /&gt;Note: The original question came from a person with a HP Server. My problem machine was also an HP.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Dave,&lt;br /&gt;&lt;br /&gt;We've seen a few instances of this, usually related to MSDE install errors.&lt;br /&gt;Please try the following:&lt;br /&gt;&lt;br /&gt;1. Launch the ISA 2004 MSI package manually and install ISA manually from&lt;br /&gt;CD #6:&lt;br /&gt;&lt;br /&gt;&lt;cd drive&gt;:\ISA2004\FPC\MS_FPC_SERVER.MSI&lt;br /&gt;&lt;br /&gt;2. The installation should be successful but this only installs the&lt;br /&gt;console. The&lt;br /&gt;MSDE instance has not yet been installed. Go ahead and run the Setup.EXE&lt;br /&gt;for ISA&lt;br /&gt;2004 so that all the additional components will install.&lt;br /&gt;&lt;br /&gt;3. If the installation of MS_FPC_SERVER.MSI is NOT installed successfully,&lt;br /&gt;then run&lt;br /&gt;it with the following command to create a LOG file of the installation:&lt;br /&gt;&lt;br /&gt;msiexec.exe /i D:\ISA2004\FPC\MS_FPC_SERVER.msi /l* c:\isa.txt&lt;br /&gt;&lt;br /&gt;4. The log file will be located on C:\isa.txt&lt;br /&gt;&lt;br /&gt;The verbose log file will help us in the next step of troubleshooting.&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;__&lt;br /&gt;Mark Stanfill, MCSE+I, MCSE 2000, MCDBA, MCSA&lt;br /&gt;Microsoft Corporation&lt;br /&gt;&lt;/em&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-116663919333349671?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com/' title='ISA 2004 Installation Fails Creating Sotrage'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/116663919333349671/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=116663919333349671&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/116663919333349671'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/116663919333349671'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/12/isa-2004-installation-fails-creating.html' title='ISA 2004 Installation Fails Creating Sotrage'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-116654070749833481</id><published>2006-12-19T10:01:00.000-05:00</published><updated>2006-12-19T10:05:07.513-05:00</updated><title type='text'>Vista Firewall Client</title><content type='html'>&lt;a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;929556&amp;sd=rss&amp;spid=2108"&gt;How to obtain the version of Firewall Client for ISA Server (December 2006) that includes Windows Vista support&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This KB article will take you to the page that lists the new features of the client as well as a link on where to download it. According to this KB the correct version is 1.0. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;New features&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;The following features are new in this version of Firewall Client for ISA Server:&lt;br /&gt;&lt;br /&gt;• Support for client computers that are running Windows Vista &lt;br /&gt;• Software updates that improve the security and stability of Firewall Client for ISA Server&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-116654070749833481?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Vista Firewall Client'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/116654070749833481/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=116654070749833481&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/116654070749833481'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/116654070749833481'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/12/vista-firewall-client.html' title='Vista Firewall Client'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-116498767657771422</id><published>2006-12-01T10:13:00.000-05:00</published><updated>2006-12-01T10:41:17.146-05:00</updated><title type='text'>Protecting Wireless Networks - 3 Ways</title><content type='html'>Recently there's been a rash of clients needing to setup open wireless access for visitors. For the record, I hate open wireless. But some clients won't be convinced. Since this is the real world we do what we can do to protect them. Depending on the circumstances there are 3 options:&lt;br /&gt;&lt;br /&gt;1. Install a 3rd NIC into your server. Create a network for this NIC corresponding to your wireless network and assign rules accordingly. Keep in mind, that if this is an SBS server, this is an unsupported option. The reason it is unsupported is that the Connect to the Internet Wizard will choke on the extra NIC. It was written to expect only 2 NICs. To work around this problem you should disable your 3rd NIC and the rules associated with it before running that wizard.&lt;br /&gt;&lt;br /&gt;2. Use a different public IP for your wireless router and create an entirely seperate network for wireless. Most of the time an ISP will provide 5 IP addresses to business accounts. Most businesses are only using one of those. Plug the wireless router directly into the router provided by your ISP and assign the wireless router one of your unused IP address. Configure the wireless router as needed.&lt;br /&gt;&lt;br /&gt;3. Connect the wireless router to your internal network and give it a static IP address. Set it up to assign DHCP addresses to the wireless guests that are on a seperate network. For example, if your internal network is 192.168.16 then setup the wireless router's built-in DHCP server to pass out 192.168.17 addresses. Assign rules to keep the wireless router away from everything but the Internet. &lt;br /&gt;&lt;br /&gt;Here's what option 3 looks like in practice:&lt;br /&gt;&lt;br /&gt;1. Create a DHCP reservation for your wireless router.&lt;br /&gt;2. In ISA, create an Address Range Object for the wireless router.&lt;br /&gt;3. In ISA, create a new Access Rule. From Wireless Router, To External, Specified Protocols: HTTP, HTTPS. Other protocols your guests might need include FTP, ICA and SMTP but keep the list as short as possible. Place this rule above the SBS Protected Networks Access Rule.&lt;br /&gt;4. In ISA, create a new Acces Rule. From Wireless Router, to LocalHost, Specified Protocols: DNS. This will allow the wireless router to resolve addresses. Place this rule above the one you just created.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-116498767657771422?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Protecting Wireless Networks - 3 Ways'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/116498767657771422/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=116498767657771422&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/116498767657771422'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/116498767657771422'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/12/protecting-wireless-networks-3-ways.html' title='Protecting Wireless Networks - 3 Ways'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-116137037251697102</id><published>2006-10-20T14:48:00.000-04:00</published><updated>2006-10-20T16:00:23.483-04:00</updated><title type='text'>DHCP Not Working After Applying ISA 2004 SP2?</title><content type='html'>I've come across reports of 7 seperate servers where after installing ISA 2004 SP2, the DHCP server does not work as expected. Reports are that the DHCP receive/request rules are in place but not functioning. The current resolution is to create a new set of DHCP receive/request rules. &lt;br /&gt;&lt;br /&gt;Follow this &lt;a href="http://www.microsoft.com/technet/isa/2004/plan/isaondhcpserver.mspx"&gt;article&lt;/a&gt; to create the rules, if you are having this problem. Hopefully later, I'll be able to post more on why the system rules are broken.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-116137037251697102?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='DHCP Not Working After Applying ISA 2004 SP2?'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/116137037251697102/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=116137037251697102&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/116137037251697102'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/116137037251697102'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/10/dhcp-not-working-after-applying-isa.html' title='DHCP Not Working After Applying ISA 2004 SP2?'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-116101223180428334</id><published>2006-10-16T11:19:00.000-04:00</published><updated>2006-10-16T11:23:51.846-04:00</updated><title type='text'>Troubleshooting ISA Performance</title><content type='html'>The configuration of your NICs can have a significant and difficult to diagnose effect upon your ISA server. If you are using auto negotiation on your NICs and Switches it may slow down the performance of your server while under load. Read the article below for an explanation and considerations.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://blogs.technet.com/isablog/archive/2006/10/14/isa-server-troubleshooting-layer-1.aspx"&gt;ISA Server Troubleshooting; Layer 1&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-116101223180428334?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Troubleshooting ISA Performance'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/116101223180428334/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=116101223180428334&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/116101223180428334'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/116101223180428334'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/10/troubleshooting-isa-performance.html' title='Troubleshooting ISA Performance'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-116040164243762954</id><published>2006-10-09T09:46:00.000-04:00</published><updated>2006-10-09T09:47:22.450-04:00</updated><title type='text'>ISAtools.org Make Over</title><content type='html'>&lt;a href="http://www.isatools.org"&gt;ISATools.org&lt;/a&gt; has gotten a make over and it looks great. The site is much easier to navigate now.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-116040164243762954?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='ISAtools.org Make Over'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/116040164243762954/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=116040164243762954&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/116040164243762954'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/116040164243762954'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/10/isatoolsorg-make-over.html' title='ISAtools.org Make Over'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-116017114771193027</id><published>2006-10-06T17:36:00.000-04:00</published><updated>2006-10-06T17:45:47.736-04:00</updated><title type='text'>Mailbag: To Firewall or not?</title><content type='html'>I received this question in my mailbox the other day. It wasn't the first time. Thought I may as well post the answer too.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Amy, I've heard you on the SBS Show and read your comments in the Yahoo&lt;br /&gt;groups and on your own blog. I recently ran across Thomas Shinder's&lt;br /&gt;blog post called "Why SBS is Insecure by Design and Not Even an ISA&lt;br /&gt;Firewall can Fix the Problem" which can be found here:&lt;br /&gt;&lt;br /&gt;http://blogs.isaserver.org/shinder/2006/09/03/why-sbs-is-insecure-by-des&lt;br /&gt;ign-and-not-even-an-isa-firewall-can-fix-the-problem/&lt;br /&gt;&lt;br /&gt;I wanted to get your opinion on a specific statement Mr. Shinder makes&lt;br /&gt;in this post:&lt;br /&gt;&lt;br /&gt;"The SBS 2003 SP1/ISA firewall box with a "hardware" firewall or NAT&lt;br /&gt;device in front of it is no more secure than the SBS 2003 SP1 box&lt;br /&gt;without the "hardware" firewall or NAT device in front of it. Putting a&lt;br /&gt;"hardware" firewall in front of the SBS box is psychological exercise in&lt;br /&gt;futility, and the money spent on the PIX 501 would be much better spent&lt;br /&gt;on a couple hours of psychotherapy or a few bottles of Dom P. Whether&lt;br /&gt;you choose the PIX, the shrink or the Dom, you'll end up with the same&lt;br /&gt;level of security."&lt;br /&gt;&lt;br /&gt;Do you think a hardware firewall in front of an SBS box is no more&lt;br /&gt;secure then an SBS box without a hardware firewall in front of it? Do&lt;br /&gt;the companies you consult for usually have a hardware firewall in front&lt;br /&gt;of the SBS box, regardless of whether or not they are running ISA on&lt;br /&gt;SBS?&lt;br /&gt;&lt;br /&gt;Your opinion on this would be greatly appreciated!&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;______________________________________________________________________&lt;br /&gt;&lt;br /&gt;Dear Reader, &lt;br /&gt;&lt;br /&gt;Security is not an absolute. Most people agree that it is about risk mitigation. As a small business consultant I can say with certainty that SBS does make small business more functional and more secure. Without exception when I make first contact with a small business they are operating their business without backup, with expired anti-virus software, with a high speed Internet connection and without a firewall. After we install SBS, provide for backup, subscribe and deploy an anti-virus solution, configure monitoring and patching and deploy a firewall the business is more secure than before we started. Are they as secure as an enterprise that has embraced least privilege and separation of duties? No, but at least they are now on the right path. &lt;br /&gt;&lt;br /&gt;You should always deploy a firewall. I only use SBS Premium in my practice because I believe that ISA can protect Microsoft products better than the competition and I've got a lot of Microsoft products running on SBS. Now, is a hardware firewall necessary in front of ISA? No, this will not make you anymore secure. If my clients have an ISP supplied router with some firewall capabilities built-in, then I enable that only because they already have it. I would never recommend that they go out and purchase one. &lt;br /&gt;&lt;br /&gt;If you are using SBS standard, then you had better go out and purchase the best firewall that money can buy to protect it. You've got a lot of eggs in your basket to protect.&lt;br /&gt;&lt;br /&gt;Amy Babinchak&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-116017114771193027?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Mailbag: To Firewall or not?'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/116017114771193027/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=116017114771193027&amp;isPopup=true' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/116017114771193027'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/116017114771193027'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/10/mailbag-to-firewall-or-not.html' title='Mailbag: To Firewall or not?'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-115987843920511007</id><published>2006-10-03T08:19:00.000-04:00</published><updated>2006-10-03T08:27:19.220-04:00</updated><title type='text'>Updated Firewall Client Available</title><content type='html'>The new firewall client is available for &lt;a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;FamilyID=45855498-66BA-43D3-A8F1-37837D380389"&gt;download &lt;/a&gt;and should be installed on all workstations. This new firewall client supports 64-bit OS and resolves a conflict with Defender. All versions of ISA are supported.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-115987843920511007?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Updated Firewall Client Available'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/115987843920511007/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=115987843920511007&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115987843920511007'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115987843920511007'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/10/updated-firewall-client-available.html' title='Updated Firewall Client Available'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-115978998061351460</id><published>2006-10-02T07:43:00.000-04:00</published><updated>2006-10-02T07:53:00.623-04:00</updated><title type='text'>Publishing Project Server Portal</title><content type='html'>Over at &lt;a href="http://www.smallbizserver.net/"&gt;SmallBizServer.net&lt;/a&gt; a new article has been published on how to publish a Microsoft Project Server portal through ISA 2004. You can read the article &lt;a href="http://www.smallbizserver.net/tabid/266/articleType/ArticleView/articleId/208/Default.aspx"&gt;here.&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;Many of the articles from SmallBizServer.net require a subscription. This one doesn't seem to, so get it while it's available. My only comment is that in Step 1 under ISA, it says Create a New Rule. Since we have 3 types of rules to choose from in ISA, this really ought to read Create a New Web Publishing rule. &lt;br /&gt;&lt;br /&gt;They are doing some great work over at SmallBizServer.net so if you aren't familar with them it would be a good idea to check out the entire site.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-115978998061351460?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Publishing Project Server Portal'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/115978998061351460/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=115978998061351460&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115978998061351460'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115978998061351460'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/10/publishing-project-server-portal.html' title='Publishing Project Server Portal'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-115971287886391179</id><published>2006-10-01T10:19:00.000-04:00</published><updated>2006-10-01T10:27:58.876-04:00</updated><title type='text'>Replacing the SBS self-signed SSL certificate with an 'el cheapo one from GoDaddy</title><content type='html'>Jeff at ABC Solutions has created a PDF file documeting how to replace the self-signed SSL certificate that the SBS wizard creates for you with a certificate from GoDaddy. Since this involves both IIS and ISA I wanted to call it to your attention. Good job Jeff and nice work on the PDF too. &lt;a href="http://abc-solutions.org/Documents/How to install a cheap GoDaddy certificate.pdf"&gt;You can download the PFD here.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-115971287886391179?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Replacing the SBS self-signed SSL certificate with an &apos;el cheapo one from GoDaddy'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/115971287886391179/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=115971287886391179&amp;isPopup=true' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115971287886391179'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115971287886391179'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/10/replacing-sbs-self-signed-ssl.html' title='Replacing the SBS self-signed SSL certificate with an &apos;el cheapo one from GoDaddy'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-115971104629788850</id><published>2006-10-01T09:55:00.000-04:00</published><updated>2006-10-01T09:57:26.360-04:00</updated><title type='text'>ISA in SBS Blog Website Updated</title><content type='html'>Finally getting a few moments to update the blog and accompanying website. What else are Sunday mornings for?&lt;br /&gt;&lt;br /&gt;The website for this blog has been updated. &lt;br /&gt;&lt;br /&gt;Changes:&lt;br /&gt;&lt;br /&gt;RSS Feed Link&lt;br /&gt;4 new Amy's Voice Links added&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-115971104629788850?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='ISA in SBS Blog Website Updated'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/115971104629788850/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=115971104629788850&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115971104629788850'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115971104629788850'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/10/isa-in-sbs-blog-website-updated.html' title='ISA in SBS Blog Website Updated'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-115971036088260991</id><published>2006-10-01T09:42:00.000-04:00</published><updated>2006-10-01T09:46:00.883-04:00</updated><title type='text'>RSS Feed Now Available</title><content type='html'>Thank you Susan Bradley for pointing out that Blogger now, finally, supports RSS. Effective immediately the RSS address is: http://isainsbs.blogspot.com/rss.xml&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-115971036088260991?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='RSS Feed Now Available'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/115971036088260991/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=115971036088260991&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115971036088260991'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115971036088260991'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/10/rss-feed-now-available.html' title='RSS Feed Now Available'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-115971008546344002</id><published>2006-10-01T09:35:00.000-04:00</published><updated>2006-10-01T09:41:25.463-04:00</updated><title type='text'>Deciding Where to put the rule you just created</title><content type='html'>Lately I've seen too many ISA Firewall Policies with all of the custom created rules sitting at the top of the firewall policy. At the top isn't always the best place for a new rule. New rules should be placed according to function. There is a great &lt;a href="http://www.microsoft.com/technet/isa/2004/help/SRSP2_FWPolBestPractice.mspx?mfr=true"&gt;TechNet article &lt;/a&gt;that explains how to determine where to place your new rule.&lt;br /&gt;&lt;br /&gt;The article starts like this and then goes into further detail about how to order the rules within these categories:&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Ordering the rule base&lt;br /&gt;We recommend that you organize your access rules in this order:&lt;br /&gt;&lt;br /&gt;1.&lt;br /&gt; Global deny rules. Rules that deny specific access to all users. These rules should use the rule elements that require simple networking information. An example of such a rule would be a rule that denies all users access from anywhere to anywhere on protocols used for peer-to-peer file sharing.&lt;br /&gt; &lt;br /&gt;2.&lt;br /&gt; Global allow rules. Rules that allow specific access to all users. These rules should use the rule elements that require simple networking information. An example of this would be a rule allowing access on the Domain Name System (DNS) protocol from the Internal network to the External network.&lt;br /&gt; &lt;br /&gt;3.&lt;br /&gt; Rules for specific computers. Rules that allow or deny access for specific computers, for example, a rule allowing UNIX computers access to the Internet.&lt;br /&gt; &lt;br /&gt;4.&lt;br /&gt; Rules for specific users, URLs, and MIME types, and also publishing rules. Rules that contain rule elements that require additional networking information, and that enforce policy for specific users, or for specific Uniform Resource Locators (URLs) or Multipurpose Internet Mail Extensions (MIME) types. Publishing rules should also occur at this point in the rule order.&lt;br /&gt; &lt;br /&gt;5.&lt;br /&gt; Other allow rules. Rules that handle traffic that does not match rules that occur previously in the list of rules, assuming the traffic is allowed by your corporate policy. For example, a rule allowing all traffic from the Internal network to the Internet. &lt;br /&gt; &lt;br /&gt;&lt;/em&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-115971008546344002?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Deciding Where to put the rule you just created'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/115971008546344002/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=115971008546344002&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115971008546344002'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115971008546344002'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/10/deciding-where-to-put-rule-you-just.html' title='Deciding Where to put the rule you just created'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-115970974260324641</id><published>2006-10-01T09:09:00.000-04:00</published><updated>2006-10-01T09:35:42.670-04:00</updated><title type='text'>Filter the Internet?</title><content type='html'>Occasionally I get requests for Internet Filtering. My answer is always the same. "If you need to filter the Internet you have an HR problem, not an IT problem." Once I get that out I back peddle a bit and let them know that we can create a list of allowed websites provided it isn't too long. If you would like to know how to do this then download the instructions under Amy's How To Articles at &lt;a href="http://isainsbs.blogspot.com"&gt;ISAinSBS&lt;/a&gt;. Then I back up a little bit further and let the client know that they can subscribe to a service like &lt;a href="http://www.surfcontrol.com/"&gt;Surf Control&lt;/a&gt; or &lt;a href="http://www.websense.com/global/en/"&gt;Web Sense&lt;/a&gt; and they'll let you slice, dice and filter the Internet in a huge variety of ways; but they're not cheap. The Internet landscape is constantly changing and these companies have poor souls whose job it is to view possible objectionable websites and assign them a filter category. &lt;br /&gt;&lt;br /&gt;Then there's Steve. Some people make a hobby out of creating destination sets for ISA. Steve either is one of these people or he knows a lot of them. The destination sets can be had for free over at &lt;a href="http://isaserver.bm/destination_sets.html"&gt;Steve's site&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;Now if you decide to use one of these destination sets be sure to place the deny rule in position just above your SBS Internet Access rule. Why not put it at the top of your firewall policy? Well think about what you're asking ISA to do. For example, the sex site destination set contains 169,299 URL's, the porn URL set 214,835; the porn domains 469,759. Every time a request hits that rule, ISA will look through each of those URL's and/or Domain names to see if the request should be blocked. The potential to bog down your Internet access is real.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-115970974260324641?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Filter the Internet?'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/115970974260324641/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=115970974260324641&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115970974260324641'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115970974260324641'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/10/filter-internet.html' title='Filter the Internet?'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-115970766133085167</id><published>2006-10-01T08:34:00.000-04:00</published><updated>2006-10-01T09:01:01.350-04:00</updated><title type='text'>Secure FTP through ISA 2004</title><content type='html'>At first I thought they were joking...FTPS...Never heard of it...you can't secure FTP without an application filtering firewall like ISA...that's right an FTP application filter. But twice recently something called FTPS has come to my attention and finally I had a situation where a client needed to access an FTPS server but couldn't. &lt;br /&gt;&lt;br /&gt;ISA 2004 has an FTP Application Filter that inspects FTP traffic as it passes through. It also dynamically opens the high port required for the connection. There is an excellent article by Stefaan Pouseele called &lt;a href="http://www.isaserver.org/articles/How_the_FTP_protocol_Challenges_Firewall_Security.html"&gt;How the FTP Protocol Challenges Firewall Security&lt;/a&gt; over on the ISAserver.org website. In it Stefaan explains why FTP is insecure by design, how ISA can secure FTP for you and all of the details in between. It is an excellent article.&lt;br /&gt;&lt;br /&gt;FTPS creates an interesting challenge though. FTPS was developed in an attempt to secure FTP transmission. It's FTP with SSL encrypted information running inside. The owners of an FTPS website assume that you are using a simple packet filtering 'el cheapo firewall and can't secure your own network. FTPS proposes to do this for you using SSL. But if you are using a quality application filtering firewall with an FTP filter like ISA 2004 then you'll run into a problem because the FTP application filter can't see into the SSL encrypted packets and will therefore deny them.&lt;br /&gt;&lt;br /&gt;Solution 1: Disable the FTP Application filter. This will work IF FTPS is the only kind of FTP site you will ever need to connect to. If you disable the FTP filter all "normal" FTP traffic will be denied.&lt;br /&gt;&lt;br /&gt;Solution 2: Create a new Access Rule for FTP for traffic going from your network to the FTPS destination that does not use the FTP filter. &lt;br /&gt;&lt;br /&gt;Here's what your rule should look like:&lt;br /&gt;&lt;br /&gt;Allow -- Selected Protocols, FTP. Highlight FTP, Press Edit, Uncheck the FTP Access Filter -- Traffic from your Internal Network --- Traffic to New, Address Range, Enter IP address of the FTPS server you need to reach -- SBS Internet Users or User group of your choice.&lt;br /&gt;&lt;br /&gt;FTPS will now work to that destination for all but SecureNat clients. So make sure you've got the Firewall Client installed on all of your workstations.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-115970766133085167?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Secure FTP through ISA 2004'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/115970766133085167/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=115970766133085167&amp;isPopup=true' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115970766133085167'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115970766133085167'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/10/secure-ftp-through-isa-2004.html' title='Secure FTP through ISA 2004'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-115911266507887934</id><published>2006-09-24T11:34:00.000-04:00</published><updated>2006-09-24T11:44:25.090-04:00</updated><title type='text'>Blocking the zero day VML vuln...</title><content type='html'>The patch for this vulernability is scheduled to be released in October. Meanwhile if you are concerned and would like to prevent this attack sooner, Microsoft has released instructions for configuring your ISA to block it. The TechNet article is &lt;a href="http://www.microsoft.com/technet/isa/2006/how-to-block-vml.mspx"&gt;Learn How Your ISA Server Helps Block VML Vulnerability Traffic&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;You may also be interested in what Jesper Johnansson has to say about VML attack and how to prevent it. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://msinfluentials.com/blogs/jesper/archive/2006/09/19/Block-VML-Zero_2D00_Day-Vuln-on-a-domain.aspx"&gt;Block-VML-Zero_2D00_Day-Vuln-on-a-domain&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://msinfluentials.com/blogs/jesper/archive/2006/09/22/More-options-on-protecting-against-the-VML-vulnerability-on-a-domain.aspx"&gt;More-options-on-protecting-against-the-VML-vulnerability-on-a-domain&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Security is a personal decision. For my users I'm reasonably certain that they will not come into contact with this vuln before the patch is deployed. This one is starting to spread but it's spreading slowly for now and in obsecure places.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-115911266507887934?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Blocking the zero day VML vuln...'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/115911266507887934/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=115911266507887934&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115911266507887934'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115911266507887934'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/09/blocking-zero-day-vml-vuln.html' title='Blocking the zero day VML vuln...'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-115832892180324556</id><published>2006-09-15T09:57:00.000-04:00</published><updated>2006-09-15T10:02:01.816-04:00</updated><title type='text'>PPTP Out Disabled by Default</title><content type='html'>&lt;a href="http://support.microsoft.com/?kbid=923836"&gt;The Microsoft Internet Security and Acceleration (ISA) Server 2004 firewall policy blocks outgoing PPTP connections in Microsoft Windows Small Business Server 2003 Premium Edition SP1&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is one of those by design things that the SBS team saddled us with. The KB will walk you through the official way to add PPTP outbound to your rule set.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-115832892180324556?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='PPTP Out Disabled by Default'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/115832892180324556/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=115832892180324556&amp;isPopup=true' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115832892180324556'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115832892180324556'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/09/pptp-out-disabled-by-default.html' title='PPTP Out Disabled by Default'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-115625090124042397</id><published>2006-08-22T08:46:00.000-04:00</published><updated>2006-08-22T08:48:21.250-04:00</updated><title type='text'>Going to SMBNation Redmond</title><content type='html'>I'll be attending the SMBNation in Redmond from September 7th - 11th. If you'll also be there look up me. It's always good to put a face with the comments!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-115625090124042397?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Going to SMBNation Redmond'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/115625090124042397/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=115625090124042397&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115625090124042397'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115625090124042397'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/08/going-to-smbnation-redmond.html' title='Going to SMBNation Redmond'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-115620299844572734</id><published>2006-08-21T19:27:00.000-04:00</published><updated>2006-08-21T19:29:58.456-04:00</updated><title type='text'>Request For Post Ideas</title><content type='html'>It's been a slow summer blog wise because it's been an unusually busy summer business wise. I promise to get back on schedule. If you have an idea for a blog post, please submit it to the comments. Thanks! Amy&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-115620299844572734?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Request For Post Ideas'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/115620299844572734/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=115620299844572734&amp;isPopup=true' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115620299844572734'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115620299844572734'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/08/request-for-post-ideas.html' title='Request For Post Ideas'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-115089376082940438</id><published>2006-06-21T08:36:00.000-04:00</published><updated>2006-06-21T08:42:40.846-04:00</updated><title type='text'>Walking the Line - A New Blog</title><content type='html'>&lt;a href="http://keepitsecure.blogspot.com/"&gt;Walking the Line&lt;/a&gt; is my new blog on small business security. While this blog is exclusively about configuring ISA, the other blog will cover a wide variety of security topics. It also won't be purely technical but will contain opinion. I'm a small business consultant out there in the field with my techs maintaining real life small business networks. If you're into keeping it real and want to know what happens to your clients when you implement "best practices", then this blog will be the place to be. I also plan to call out security screw ups by vendors. Yep, sometimes I'll rant a bit. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I expect to post to Walking the Line a couple of times a month. So please check it out and subscribe.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-115089376082940438?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://keepitsecure.blogspot.com/' title='Walking the Line - A New Blog'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/115089376082940438/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=115089376082940438&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115089376082940438'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115089376082940438'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/06/walking-line-new-blog.html' title='Walking the Line - A New Blog'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-115089099201819539</id><published>2006-06-21T07:44:00.000-04:00</published><updated>2006-06-21T07:58:01.486-04:00</updated><title type='text'>Enable this App: Lacerte</title><content type='html'>How to Allow Lacerte. This information comes from Jim Page. My comments are in italics. However, take my comments with a grain of salt because I have no clients using Lacerte to test them.&lt;br /&gt;&lt;br /&gt;Basically create an "New Access Rule", "ALLOW",  "PROTOCOLS" create OUTBOUND TCP for 10010,10020,10030,10040,10050-10052,10060,10070,10099, and I did 1275,1277,1278 (was in the MS 839503 article.  Not sure if it's needed) &lt;em&gt;Workstations running the Firewall client should be able to request use of any outbound protocol. So this step should not be necessary if you have installed the Firewall Client.&lt;/em&gt; &lt;br /&gt;FROM="All Protected Networks"&lt;br /&gt;TO= Created two sets, 1 is range 198.31.208.130-198.31.208.145 the other is just 208.240.240.200&lt;br /&gt; &lt;br /&gt; &lt;br /&gt;Users= "All users"  Can't get it to work if I pick anything else. &lt;em&gt;This means that Lacerte doesn't authenticate to the server when it requests access to the Internet.&lt;/em&gt;&lt;br /&gt; &lt;br /&gt;Schedule="Always"&lt;br /&gt; &lt;br /&gt;Content Types="All content types"&lt;br /&gt; &lt;br /&gt;Now I have seen that Lacerte is using other ports to communicate to 208.240.240.200, and ISA denies access.  These ports so far are 3106,3130,3132, and some in the 8000 range (didn't right them all down)  I have a call into Lacerte to see if they do anything.&lt;br /&gt; &lt;br /&gt;The mistakes that I have seen in other articles:  They say to setup INBOUND and that the FROM and TO objects were incorrect.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-115089099201819539?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Enable this App: Lacerte'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/115089099201819539/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=115089099201819539&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115089099201819539'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/115089099201819539'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/06/enable-this-app-lacerte.html' title='Enable this App: Lacerte'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114899249022410170</id><published>2006-05-30T08:33:00.000-04:00</published><updated>2006-05-30T08:34:50.240-04:00</updated><title type='text'>Update to SBS WPAD available</title><content type='html'>From Jim Harrison:&lt;br /&gt;&lt;br /&gt;&lt;em&gt;http://isatools.org/sbs_wpad_3.zip&lt;br /&gt;&lt;br /&gt;Thanx to Jonathon Howey for a bug report in the _2 version to the isaserver.org list and playing guinea pig for my troubleshooting.&lt;br /&gt;&lt;br /&gt;Short story: WinHTTP proxy configuration (or auto-proxy behavior) can cause the script to make the wpad request as a CERN proxy request instead of a direct request.&lt;br /&gt;Needless to say, this causes the mechanism to fail.&lt;br /&gt;&lt;br /&gt;I've fixed this and stashed it as http://isatools.org/sbs_wpad_3.zip.&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;I'll post this update into the original WPAD blog entry as well.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114899249022410170?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Update to SBS WPAD available'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114899249022410170/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114899249022410170&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114899249022410170'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114899249022410170'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/05/update-to-sbs-wpad-available.html' title='Update to SBS WPAD available'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114781005341889386</id><published>2006-05-16T16:05:00.000-04:00</published><updated>2006-05-17T17:35:52.666-04:00</updated><title type='text'>Force Reboot, Update for HTTP issues in Internet Security and Acceleration Server 2004 Service Pack 2</title><content type='html'>From the SBS Product Team blog. &lt;br /&gt;&lt;br /&gt;We've seen a few cases now where ISA Hotfix 916106 does not prompt for a reboot, as the hotfix indicates it should.  The hotfix does, however, successfully install.  In addition, after the hotfix is installed the following services will be in a stopped state:&lt;br /&gt;&lt;br /&gt;Microsoft Firewall &lt;br /&gt;Exchange Routing Engine &lt;br /&gt;Simple Mail Transfer Protocol (SMTP) &lt;br /&gt;World Wide Web Publishing Service&lt;br /&gt;&lt;br /&gt;The Microsoft Firewall service not restarting will throw ISA in to lockdown mode, which can potentially prevent remote administrators from being able to connect to manually reboot the server.  In either case, the server should be rebooted.&lt;br /&gt;&lt;br /&gt;A knowledgebase article is now available. &lt;br /&gt;&lt;br /&gt;If you use a computer that is running Microsoft Small Business Server &lt;br /&gt;2003 Premium Edition with ISA 2004, you may not be prompted for reboot.&lt;br /&gt;&lt;br /&gt;See the rest of the &lt;a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;916106"&gt;knowledgebase article&lt;/a&gt; for a suggested solution.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114781005341889386?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Force Reboot, Update for HTTP issues in Internet Security and Acceleration Server 2004 Service Pack 2'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114781005341889386/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114781005341889386&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114781005341889386'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114781005341889386'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/05/force-reboot-update-for-http-issues-in.html' title='Force Reboot, Update for HTTP issues in Internet Security and Acceleration Server 2004 Service Pack 2'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114748154041133127</id><published>2006-05-12T20:00:00.000-04:00</published><updated>2006-05-12T20:52:20.426-04:00</updated><title type='text'>DMZ - SBS special considerations</title><content type='html'>So you'd like to create a DMZ? It's easy to do with ISA 2004 but don't forget that you've got pre-defined rules in SBS that are going to open up your DMZ to more that you might want.&lt;br /&gt;&lt;br /&gt;Step 1: Create the DMZ. To do this use &lt;a href="http://www.isaserver.org/articles/2004multdmzp2.html"&gt;this article&lt;/a&gt; but start at the section titled Create The Anonymous DMZ and continue through the section titled Create the Network (routing) Rule between the Anonymous Access DMZ and the External Network, then stop. &lt;br /&gt;&lt;br /&gt;If this were a non-SBS implementation of ISA you'd have a DMZ with no rules defining access to it. But we live in a pre-configured world so the next step is to add a new rule to the ISA 2004 Firewall Policy to exclude the DMZ network from our pre-existing rule set. &lt;br /&gt;&lt;br /&gt;Step 2: Open up the ISA 2004 management console and expand Configuration. Click on Networks. Move to the Network Sets tab. Click on Create new Network Set. Call it something like All Protected, Except DMZ. Make this network set look just like All Protected Networks except add your DMZ network to the exclusions list. &lt;br /&gt;&lt;br /&gt;Step 3: Move to the Firewall Policy and edit the SBS Protected Networks Access Rule. Move to the From tab and replace All Protected Networks with the network set that you just created. This will prevent all traffic from the DMZ reaching your internal network. Now you've isolated the DMZ from your Internal network.&lt;br /&gt;&lt;br /&gt;Step 4: Create a Rule so that the server in the DMZ can communicate with the other servers in your network. (this assumes that the server in the DMZ is a member server) Open up the ISA 2004 management console and click on Firewall Policy. Scroll down to the bottom. Highlight the SBS Protected Networks Access Rule. In the taskpad click New Access Rule. Call it something like DMZ Server Communications. Allow traffic from the DMZ to Internal Network with the following protocols: DNA, Kerberos-Sec (UDP), Kerberos - Sec (TCP), LDAP, Microsoft CIFS (TCP) Netbios Datagram, Netbios Name Service, Netbios Session, RPC (all interfaces), LDAP (UDP), Kerberos-ADM, ping and NTP. Make sure that this rule is placed just ahead of the SBS Protected Networks Rule.&lt;br /&gt;&lt;br /&gt;Step 4: Create a Rule for any additional ports that the application running on the server in the DMZ requires. Place this rule above the SBS Protected Networks Rule as well.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114748154041133127?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='DMZ - SBS special considerations'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114748154041133127/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114748154041133127&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114748154041133127'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114748154041133127'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/05/dmz-sbs-special-considerations.html' title='DMZ - SBS special considerations'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114713810365927731</id><published>2006-05-08T21:25:00.000-04:00</published><updated>2006-05-08T21:28:23.673-04:00</updated><title type='text'>DNS Related Performace Problems for ISA</title><content type='html'>Tom Shinder has a nice little blog post on &lt;a href="http://blogs.isaserver.org/shinder/2006/05/08/dns-related-performance-problems-for-the-isa-firewall/"&gt;DNS related performance problems for ISA&lt;/a&gt;. If your Internet access seems slower than it should be, check your DNS server configuration first.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114713810365927731?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='DNS Related Performace Problems for ISA'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114713810365927731/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114713810365927731&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114713810365927731'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114713810365927731'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/05/dns-related-performace-problems-for.html' title='DNS Related Performace Problems for ISA'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114623141579529371</id><published>2006-04-28T09:29:00.000-04:00</published><updated>2006-04-28T09:36:55.826-04:00</updated><title type='text'>KB: How to configure ISA Server 2004 after you add a new network adapter or you replace a network adapter</title><content type='html'>&lt;a href="http://support.microsoft.com/kb/840698/en-us"&gt;How to configure ISA Server 2004 after you add a new network adapter or you replace a network adapter&lt;/a&gt; is handy kb article but it needs a little modification for SBS. &lt;br /&gt;&lt;br /&gt;Be sure to interpret step &lt;em&gt;7. Configure the TCP/IP configuration&lt;/em&gt; as configure the new Network card TCP/IP settings exactly as they were on the old Network card.&lt;br /&gt;&lt;br /&gt;and step &lt;em&gt;9 c.  Manually configure the network and add any rules, or select a network template from the right pane to specify your new configuration&lt;/em&gt; as run the Connect to the Internet Wizard.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114623141579529371?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='KB: How to configure ISA Server 2004 after you add a new network adapter or you replace a network adapter'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114623141579529371/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114623141579529371&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114623141579529371'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114623141579529371'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/04/kb-how-to-configure-isa-server-2004.html' title='KB: How to configure ISA Server 2004 after you add a new network adapter or you replace a network adapter'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114591879261985508</id><published>2006-04-24T18:46:00.000-04:00</published><updated>2006-04-24T18:46:32.640-04:00</updated><title type='text'>ISA SP2 Update Released</title><content type='html'>&lt;a href="http://isainsbs.blogspot.com/2006/03/information-on-sp2.html"&gt;ISA in SBS - yes, it's secure: Information on SP2&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;How off the press! ISA SP2 update has been released. This update replaces the previous hotfix for these issues:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This update addresses the following HTTP issues for ISA Server 2004 Standard and Enterprise Editions with Service Pack 2 (SP2):&lt;br /&gt;&lt;br /&gt;• KB 915045: Error 502 "The HTTP request includes a non-supported Header" when accessing certain web servers. This occurs when accessing certain Web servers that return headers that are incompatible with each other. &lt;br /&gt;&lt;br /&gt;• KB 915421: Errors 11001 or 400 when accessing certain web servers. This is caused by a misinterpretation of spaces in headers provided by ISA Server, and results in a corrupted URL and failure to load the Web page. &lt;br /&gt;&lt;br /&gt;• KB 915422: Event ID 23004 when accessing web sites that respond with compressed content. Some Web servers always return compressed content, which is denied by ISA Server when it did not request compressed content. &lt;br /&gt;&lt;br /&gt;• KB 916573: Error 500 (Internal Server Error. Not implemented (-2147467263)) when trying to download zip attachments from an Outlook Web Access server. The header returned by Outlook Web Access causes ISA Server to deny the response. &lt;br /&gt;&lt;br /&gt;• KB 917134: Grayed out checkbox “Enable caching of content received through the BITS service”&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;System Requirements&lt;br /&gt;Supported Operating Systems: Windows Server 2003&lt;br /&gt;• ISA Server 2004 Standard Edition with Service Pack 2&lt;br /&gt;&lt;br /&gt;You can download it &lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=2aa53ee6-527c-4398-ab7c-fcf8e8dde8ce&amp;displaylang=en"&gt;here&lt;/a&gt; or it's available in WSUS.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114591879261985508?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com/2006/03/information-on-sp2.html' title='ISA SP2 Update Released'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114591879261985508/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114591879261985508&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114591879261985508'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114591879261985508'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/04/isa-sp2-update-released.html' title='ISA SP2 Update Released'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114537226295513543</id><published>2006-04-18T10:56:00.000-04:00</published><updated>2006-04-18T11:03:29.276-04:00</updated><title type='text'>Install CRM SBE on SBS 2003 Premium with ISA 2004</title><content type='html'>Handy Andy over at &lt;a href="http://www.sbs-rocks.com/"&gt;SBS Rocks&lt;/a&gt; has written a step by step how to titled &lt;a href="http://www.sbs-rocks.com/CRM/CRMsbeInstall.htm"&gt;Install CRM SBE on SBS 2003 Premium with ISA 2004&lt;/a&gt;. I have not used it myself but after watching a live install during our last SBS user group meeting and reading Andy's article I now feel ready to give it a go. Check out his article if you'll be installing CRM.&lt;br /&gt;&lt;br /&gt;There's couple of tweaks you need to make and the unmake after the installation. Be sure to also read the manual on this one. CRM is going to put its hooks into every nook and cranny of your SBS server and you'll need to be aware of what's going on.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114537226295513543?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com3' title='Install CRM SBE on SBS 2003 Premium with ISA 2004'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114537226295513543/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114537226295513543&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114537226295513543'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114537226295513543'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/04/install-crm-sbe-on-sbs-2003-premium.html' title='Install CRM SBE on SBS 2003 Premium with ISA 2004'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114494231250164070</id><published>2006-04-13T11:21:00.000-04:00</published><updated>2006-04-14T20:02:35.080-04:00</updated><title type='text'>Internet Proxies can by-pass your ISA settings</title><content type='html'>Today I learned from Steve Moffat about Internet Proxies. The type of proxy we're talking about here are websites that filter the Internet for you. Traditionally these were used by schools to filter the Internet in a manner appropriate for children. When I was in the educational tech support business most schools subscribed to a service to filter the Internet for them. On the tech end we'd redirect all Internet requests to the site we subscribed to and simply didn't allow any other sites. Worked great. &lt;br /&gt;&lt;br /&gt;Of course, someone figured out, and about 700 or so people copied the idea, that they could put up an Internet proxy that does no filtering. Why? To get around the URL blocking that you've put in place of course. Say you're blocking users from getting to yahoo mail, if the user can get to the proxy site they can enter mail.yahoo.com and bring up yahoo mail and your URL blocker is none the wiser because the mail site is being viewed from within the proxy site. Fun!&lt;br /&gt;&lt;br /&gt;The solution is to get Steve's &lt;a href="http://isaserver.bm"&gt;proxy site block list&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114494231250164070?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Internet Proxies can by-pass your ISA settings'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114494231250164070/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114494231250164070&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114494231250164070'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114494231250164070'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/04/internet-proxies-can-by-pass-your-isa.html' title='Internet Proxies can by-pass your ISA settings'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114471191196492202</id><published>2006-04-10T19:20:00.000-04:00</published><updated>2006-04-10T19:31:51.986-04:00</updated><title type='text'>SP2 hot fix is now available</title><content type='html'>I've updated the original post on ISA SP2 to include the hotfix URL for the issues raised by SP2. If you have to access non-RFC compliant websites, then this hotfix might be for you. Be sure to read the details carefully. The hotfix will turn off certain security feature updates that the service pack made so be aware of what you're asking for.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114471191196492202?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='SP2 hot fix is now available'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114471191196492202/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114471191196492202&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114471191196492202'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114471191196492202'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/04/sp2-hot-fix-is-now-available.html' title='SP2 hot fix is now available'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114469968823079770</id><published>2006-04-10T16:05:00.000-04:00</published><updated>2006-04-10T16:08:08.256-04:00</updated><title type='text'>By Popular Request</title><content type='html'>By popular request, I finally managed to get a photo of myself on the blog site and also on the MVP awardees site. If you read the book, (SBS Unleashed) then you know that without the boat I'd shrivel up and die. This photo is scanned and cropped out of picture of me on the boat.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114469968823079770?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='By Popular Request'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114469968823079770/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114469968823079770&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114469968823079770'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114469968823079770'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/04/by-popular-request.html' title='By Popular Request'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114408403996421770</id><published>2006-04-03T13:07:00.000-04:00</published><updated>2006-04-03T13:07:20.016-04:00</updated><title type='text'>Blocking URL's using Destination Sets</title><content type='html'>&lt;a href="http://isainsbs.blogspot.com/"&gt;ISA in SBS - yes, it's secure&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Steve has updated his destination sets for blocking Porn, Sex, Advertising, Online Dating, Chat, Gambling and MSN Messenger Advertising sites. &lt;br /&gt;&lt;br /&gt; &lt;a href="http://www.isaserver.bm/destination_sets.html"&gt;Get 'em here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I'll soon post a How To for using the destination sets.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114408403996421770?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com/' title='Blocking URL&apos;s using Destination Sets'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114408403996421770/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114408403996421770&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114408403996421770'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114408403996421770'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/04/blocking-urls-using-destination-sets.html' title='Blocking URL&apos;s using Destination Sets'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114382942372026597</id><published>2006-03-31T13:16:00.001-05:00</published><updated>2006-03-31T13:23:43.723-05:00</updated><title type='text'>Enable Reynolds &amp; Reynolds SDC Server</title><content type='html'>Here's the information that you'll need to enable a Reynolds &amp; Reynolds Linux server to communicate through your ISA 2004 Server. If you support auto dealerships, you know what I'm talking about. Ignore the comment that you've probably gotten from R&amp;R that they can't work behind an ISA server.&lt;br /&gt;&lt;br /&gt;First, make the R&amp;R server a SecureNat client buy assigning it a static IP address and setting its gateway and DNS to the Internal NIC address of your SBS server. Create an access rule and place it above the SBS Internet Users rule. Create the rule such that traffic will flow from the R&amp;R server to External allowing only the protocols listed below. Then, apply the rule and have R&amp;R test. Everything should work flawlessly.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;·         TCP port 80                   HTTP &lt;br /&gt;&lt;br /&gt;·         TCP port 443                 HTTPS &lt;br /&gt;&lt;br /&gt;·         TCP port 53                   DNS &lt;br /&gt;&lt;br /&gt;·         TCP port 20 / 21            FTP &lt;br /&gt;&lt;br /&gt;·         TCP port 23                   TELNET &lt;br /&gt;&lt;br /&gt;·         TCP port 25                   SMTP &lt;br /&gt;&lt;br /&gt;·         TCP port 110                 POP3 &lt;br /&gt;&lt;br /&gt;·         UDP port 123                 NTP      (National time protocol; this should be set up for both outbound and inbound)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114382942372026597?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Enable Reynolds &amp; Reynolds SDC Server'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114382942372026597/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114382942372026597&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114382942372026597'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114382942372026597'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/03/enable-reynolds-reynolds-sdc-server_31.html' title='Enable Reynolds &amp; Reynolds SDC Server'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114382891007746785</id><published>2006-03-31T13:12:00.000-05:00</published><updated>2006-03-31T13:15:10.093-05:00</updated><title type='text'>Enable iTunes after ISA 2004 SP2</title><content type='html'>A useful snippet from the ISA Server team blog.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;You can configure ISA Server so that ITunes will work. Here’s how:&lt;br /&gt;&lt;br /&gt;1.      On the General node, click Define HTTP Compression Preferences.&lt;br /&gt;&lt;br /&gt;2.      On the Settings tab, add the site to the list. &lt;br /&gt;&lt;br /&gt;3.      Select the site and click Set Compression. &lt;br /&gt;&lt;br /&gt;4.      Enable Request compressed HTTP content from servers.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114382891007746785?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Enable iTunes after ISA 2004 SP2'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114382891007746785/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114382891007746785&amp;isPopup=true' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114382891007746785'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114382891007746785'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/03/enable-itunes-after-isa-2004-sp2.html' title='Enable iTunes after ISA 2004 SP2'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114307246844895910</id><published>2006-03-22T19:07:00.000-05:00</published><updated>2006-03-22T19:07:48.463-05:00</updated><title type='text'>The new Firewall Dashboard is Here!</title><content type='html'>&lt;a href="http://isainsbs.blogspot.com/"&gt;ISA in SBS - yes, it's secure&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Fellow MVP Dana Epp has created a useful add-on tool for ISA. It's a Firewall Dashboard application that takes the ISA logs and presents the information in an easy to use graphic format. You can also configure it to send you a report on your firewall activity daily. It's a nice addition to the native monitoring tools built into ISA. I've been using the Beta and have found it easy to install and the reports easy to configure and understand. You'll learn things you never knew about your firewall. Why didn't you know? Because you weren't looking. Scorpion Software's Firewall Dashboard makes it easy to look. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.scorpionsoft.com/products/fwdashboard/"&gt;Click here to go to Scorpion Software&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114307246844895910?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com/' title='The new Firewall Dashboard is Here!'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114307246844895910/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114307246844895910&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114307246844895910'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114307246844895910'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/03/new-firewall-dashboard-is-here.html' title='The new Firewall Dashboard is Here!'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114306944030082075</id><published>2006-03-22T18:10:00.000-05:00</published><updated>2006-03-22T18:17:20.326-05:00</updated><title type='text'>How To Doc: Limit Internet Access to a Few URL's using ISA 2004 and Group Policy</title><content type='html'>The first document to populate the new Amy's How To document space on the blog is on Limiting Internet Access to a Few URL's using ISA 2004 and Group Policy. It is available for download from the link in the right hand column. &lt;br /&gt;&lt;br /&gt;This document is handy when you want to limit internet access to a select few URL's. I use a combination of ISA and Group Policy to achieve Internet Access control bliss. ISA controls where users can go and group policy pre-populates the Favorites list in IE with the allowed destinations. This prevents users from having to guess which sites they are allowed to visit. &lt;br /&gt;&lt;br /&gt;I hope that you will find this article useful.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114306944030082075?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='How To Doc: Limit Internet Access to a Few URL&apos;s using ISA 2004 and Group Policy'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114306944030082075/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114306944030082075&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114306944030082075'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114306944030082075'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/03/how-to-doc-limit-internet-access-to.html' title='How To Doc: Limit Internet Access to a Few URL&apos;s using ISA 2004 and Group Policy'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114306820295423657</id><published>2006-03-22T17:53:00.000-05:00</published><updated>2006-03-22T17:56:42.953-05:00</updated><title type='text'>New: Blog Feature, How-to Docs available</title><content type='html'>By popular demand I'm now going to be posting how-to documents on this blog. Look in the right hand column for Amy's How To Docs. Click on the link to download the pdf.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114306820295423657?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='New: Blog Feature, How-to Docs available'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114306820295423657/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114306820295423657&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114306820295423657'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114306820295423657'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/03/new-blog-feature-how-to-docs-available.html' title='New: Blog Feature, How-to Docs available'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114174358976402199</id><published>2006-03-07T09:39:00.000-05:00</published><updated>2006-04-10T19:35:09.820-04:00</updated><title type='text'>Information on SP2</title><content type='html'>As you know, there has been a flurry of information on whether or not to install ISA 2004 SP2 and what happens afterwards. &lt;br /&gt;&lt;br /&gt;Here's the situation, SP2 contains some new features which add to the security that ISA can provide to our networks. Therefore after you install SP2 you might come across a few websites that will error out. While it might look like it's SP2 causing the problem it's actually the website causing the problem by not following the rules. &lt;br /&gt;&lt;br /&gt;There are two things that are causing headaches for those that rushed to install SP2, compression filtering and HTTP Request Smuggling. The new compression filter is "on" by default under SP2. If you access a website that attempts to place a compressed file on your box using anything other than gzip encoding, it will fail. Most, but not all websites use gzip encoding. If you need to use a website that doesn't you'll have to disable compression filtering. For an explanation of HTTP Request Smuggling protection, we turn now to our guru, Jim Harrison... &lt;br /&gt;&lt;br /&gt;&lt;em&gt;Disabling filters may not help with www.delta.com, www.sun.com or any&lt;br /&gt;site that causes ISA 2004 SP2 to generate the following message:&lt;br /&gt;&lt;br /&gt;Error Code: 502 Proxy Error. The HTTP request includes a non-supported header. Contact your ISA Server administrator. (12156)&lt;br /&gt;&lt;br /&gt;The reason for the behavior youre seeing is that new logic that was added in ISA 2004 SP2 to mitigate HTTP request smuggling The process for this attack is a bit involved but the short story is that HRS depends on sending response headers that include both Content-length: and transfer-encoding: chunked.&lt;br /&gt;&lt;br /&gt;A whitepaper on the subject is available here:&lt;br /&gt;https://www.watchfire.com/securearea/whitepapers.aspx&lt;br /&gt;&lt;br /&gt;RFC-2616 defines those two headers for the purpose of providing quantitative content validation for the receiver and states *very clearly* that the server MUST NOT combine them in the same response.&lt;br /&gt;&lt;br /&gt;If the server is configured such that it does violate this edict, RFC-2616 then requires the receiving entity to ignore the content-length value and instead use the chunked-encoding technique to validate the length of the HTTP body.&lt;br /&gt;&lt;br /&gt;This places a processing burden on the receiving entity (ISA, in this case), since a chunked-encoded transfer can't be quantitatively validated until the transfcompletedeted. In the case of a proxy, additional processing is imposed due to caching behavior that may be dependent on content-size.&lt;br /&gt;&lt;br /&gt;The reason those sites are either failing outright (www.delta.com) or rendering poorly (www.sun.com) is because we chose to reject those responses out of hand. Since RFC-2616 clearly states don't combine those headers and doing so is a demonstrably malicious act, it seemed unlikely that ISA would cause problems for any other than malicious sites, and in fact, our testing validated this belief.&lt;br /&gt;&lt;br /&gt;As it turns out, there are quite a few legitimate sites out there that violate this part of RFC-2616 and so we have had to rethink our answer to this problem.&lt;br /&gt;&lt;br /&gt;PSS will have a public fix available shortly.&lt;br /&gt;Jim &lt;/em&gt;&lt;br /&gt;&lt;br /&gt;There's going to be a hotfix. Not because ISA did anything wrong but because there are enough sites out there causing pain for MS customers, that they are going to change things accommodate them. &lt;br /&gt;&lt;br /&gt;I for one, am not disappointed by SP2. The security improvements are significant, I just wish we didn't have to dilute security to accommodate a few sites not playing by the rules. It's really the same thing we do for Java apps that won't authenticate or workstation apps that won't run as anything but local admin. It's a compromise and it's one we should be complaining about loudly. This time, not at Microsoft but at the legions of others not playing by the rules.&lt;br /&gt;&lt;br /&gt;UPDATE: &lt;a href="http://support.microsoft.com/kb/916106"&gt;Click here for the hotfix.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114174358976402199?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Information on SP2'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114174358976402199/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114174358976402199&amp;isPopup=true' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114174358976402199'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114174358976402199'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/03/information-on-sp2.html' title='Information on SP2'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114173970071359713</id><published>2006-03-07T08:55:00.000-05:00</published><updated>2006-05-30T08:38:04.733-04:00</updated><title type='text'>Blocking MSN Messenger for some users</title><content type='html'>&lt;a href="http://isainsbs.blogspot.com/"&gt;ISA in SBS - yes, it's secure&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Tom Shinder has published an article that will be of interest to SBS users. It's called &lt;br /&gt;&lt;a href="http://www.isaserver.org/tutorials/ISA-Firewall-Quick-Tip-Blocking-MSN-Messenger-Access-Enabling-Access-Some-Users.html"&gt;ISA Firewall Quick Tip: Blocking MSN Messenger Access through the ISA Firewall while Enabling Access to Some Users&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;Besides providing information on how to do this, it will also introduce you to HTTP filtering.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114173970071359713?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com/' title='Blocking MSN Messenger for some users'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114173970071359713/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114173970071359713&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114173970071359713'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114173970071359713'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/03/blocking-msn-messenger-for-some-users.html' title='Blocking MSN Messenger for some users'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114070442337863211</id><published>2006-02-23T09:10:00.000-05:00</published><updated>2006-02-23T12:56:10.103-05:00</updated><title type='text'>ISA Team Blog on Http Filtering</title><content type='html'>The ISA team has started blogging and today's post inparticulr is an interesting one. &lt;a href="http://blogs.technet.com/isablog/archive/2006/02/23/Nathan.aspx"&gt;ISA Server Product Team Blog&lt;/a&gt; Because it's a short post I've copied it below but do be sure to check out their blog directly as well. What I like about this post is it describes how easy it is to use one of the most over looked features of ISA, Http Filtering. Http Filtering lets you block unwanted applications. You simply add the applications signature to the filter and you'll never see that app again on your network. It works for file types to as &lt;a href="http://www.isatools.org/"&gt;several&lt;/a&gt; &lt;a href="http://msmvps.com/blogs/bradley/archive/2005/12/28/79908.aspx"&gt;people&lt;/a&gt; pointed out during the .WMF scare.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Application Signatures for HTTP Filtering&lt;br /&gt;You allow your internal clients to access the Internet, but want to limit their use of some applications. You can block their use of applications that run over HTTP by using the HTTP filtering capability of ISA Server 2004. But to block the application, you need the application signature. Here's how you find the signature:&lt;br /&gt;&lt;br /&gt;Use a network traffic capturing utility, such as Network Monitor (known affectionately in some circles as NetMon). Install the utility on ISA Server. Best to do this sort of thing in a lab, unless you're completely comfortable about the security effects of the utility you use. Configure the utility to capture packets from a specific client.&lt;br /&gt;&lt;br /&gt;On that client, access the application you're interested in. In the monitoring utility, find the HTTP request packet from the client (usually follows handshake packets) and look for a signature in the packet. A little finesse is needed, because you want to pick a signature that is general enough to always block the application, but not so specific that it blocks everything. For example, the signature "a" is a little too generic. &lt;br /&gt;&lt;br /&gt;Once you've located a signature, you can add it to the Signatures tab of the HTTP policy for the access rule, and test it in production.&lt;br /&gt;&lt;br /&gt;You can read more about this in the document "HTTP Filtering in ISA Server 2004", at &lt;a href="http://http://www.microsoft.com/technet/prodtechnol/isa/2004/plan/httpfiltering.mspx"&gt;White Paper&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Nathan Bigman, ISA Server Product Team&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114070442337863211?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114070442337863211/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114070442337863211&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114070442337863211'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114070442337863211'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/02/isa-team-blog-on-http-filtering.html' title='ISA Team Blog on Http Filtering'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114055787278081981</id><published>2006-02-21T16:35:00.000-05:00</published><updated>2006-02-21T16:37:52.780-05:00</updated><title type='text'>Enable This App</title><content type='html'>I've created a new section of links on the blog site called Enable This App. It's a simple list of applications that you can click and go directly to instructions for configuring ISA to work with that particular application. &lt;br /&gt;&lt;br /&gt;Thought you might find it a handy reference. I know I will.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114055787278081981?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='Enable This App'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114055787278081981/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114055787278081981&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114055787278081981'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114055787278081981'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/02/enable-this-app.html' title='Enable This App'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114055673444790684</id><published>2006-02-21T16:18:00.000-05:00</published><updated>2006-02-21T16:18:54.446-05:00</updated><title type='text'>There's a New ISA website in town</title><content type='html'>&lt;a href="http://isainsbs.blogspot.com/"&gt;ISA in SBS - yes, it's secure&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.isaserver.bm"&gt;Steve Moffat&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;You've seen him on the sbs2k yahoo site. He also hangs out on the isaserver.org site. Add it to your favorites.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114055673444790684?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com/' title='There&apos;s a New ISA website in town'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114055673444790684/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114055673444790684&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114055673444790684'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114055673444790684'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/02/theres-new-isa-website-in-town.html' title='There&apos;s a New ISA website in town'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114055619165620931</id><published>2006-02-21T16:09:00.000-05:00</published><updated>2006-02-21T16:09:51.683-05:00</updated><title type='text'>Allowing NOAH</title><content type='html'>&lt;a href="http://isainsbs.blogspot.com/"&gt;ISA in SBS - yes, it's secure&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;NOAH is a client server application used in medical facilities. It uses DCOM to communicate from client to server. New in ISA 2004 is a system policy that requires strict RPC compliance. You'll quickly find out which application comply and which ones don't now that this is by default requirement in ISA 2004. &lt;br /&gt;&lt;br /&gt;To enable NOAH to communicate we need to not require it to adhere to strict RPC compliance.&lt;br /&gt;&lt;br /&gt;1. Open ISA 2004 Management and select Firewall Policy.&lt;br /&gt;2. Click on View and select Show System Policy Rules.&lt;br /&gt;&lt;br /&gt;System Policy Rules detemine how traffic is allowed to get to the ISA server. We need to change what kind of traffic is allow to speak to the ISA server.&lt;br /&gt;&lt;br /&gt;3. Right click on Allow RPC from ISA Server to trusted servers and select Edit System Policy.&lt;br /&gt;4. Uncheck Enforce Strict RPC Compliance.&lt;br /&gt;5. Click OK.&lt;br /&gt;&lt;br /&gt;Press the Apply button to have your changes take effect.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114055619165620931?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com/' title='Allowing NOAH'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114055619165620931/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114055619165620931&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114055619165620931'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114055619165620931'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/02/allowing-noah.html' title='Allowing NOAH'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-114055548895547910</id><published>2006-02-21T15:58:00.000-05:00</published><updated>2006-02-21T15:58:08.990-05:00</updated><title type='text'>Allowing MetaGraph</title><content type='html'>&lt;a href="http://isainsbs.blogspot.com/"&gt;ISA in SBS - yes, it's secure&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;MetaGraph is a client server medical billing application. It FTP's files out of your server AND client workstations as part of it's licensing verification. By default this behavior is not allowed in ISA 2004. Here's how to configure ISA to allow this application through your ISA server.&lt;br /&gt;&lt;br /&gt;1. Open ISA Management and click on Firewall Policy.&lt;br /&gt;2. Right click on the SBS Internet Access rule and select Configure FTP.&lt;br /&gt;3. Uncheck the Read Only box. Click OK.&lt;br /&gt;&lt;br /&gt;Follow the same procedure for the SBS FTP Outbound Access Rule. This rule change is needed for the client setup portion.&lt;br /&gt;&lt;br /&gt;The server and workstation appear to always be connecting to the same destination server (204.11.215.162). You may wish to undo these rule changes after initial setup of the application is complete or create a new FTP rule only allowing FTP out to the above IP address.&lt;br /&gt;&lt;br /&gt;Commentary: With all of the new HIPPA regulations that medical institutions must comply with a software package that is FTPing anything out of the server and workstations is just asking for trouble.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-114055548895547910?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com/' title='Allowing MetaGraph'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/114055548895547910/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=114055548895547910&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114055548895547910'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/114055548895547910'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/02/allowing-metagraph.html' title='Allowing MetaGraph'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-113873507162764512</id><published>2006-01-31T14:17:00.000-05:00</published><updated>2006-05-30T08:40:00.473-04:00</updated><title type='text'>Articles: Troubleshooting, Connection Limits, Logging</title><content type='html'>Articles of Interest to SBS.&lt;br /&gt;&lt;br /&gt;Troubleshooting Unsupported Configurations &lt;br /&gt;(http://www.microsoft.com/technet/prodtechnol/isa&lt;br /&gt;/2004/plan/unsupportedconfigs.mspx). &lt;br /&gt;This article provides a quick look-up resource for some common unsupported &lt;br /&gt;configuration scenarios that customers may encounter.&lt;br /&gt;&lt;br /&gt;Deployment Recommendations for Connection Limits in ISA Server 2004 &lt;br /&gt;http://www.microsoft.com/technet/prodtechnol/isa/2004/&lt;br /&gt;plan/connectionlimits.mspx). &lt;br /&gt;This paper explains the connection limit quota mechanism, and how to define &lt;br /&gt;custom limits. It also includes information on troubleshooting connection &lt;br /&gt;limits.&lt;br /&gt;&lt;br /&gt;Logging Best Practices &lt;br /&gt;(http://www.microsoft.com/technet/prodtechnol/isa/2004/plan/logging-best-practices.mspx). &lt;br /&gt;This article provides tips for configuring ISA Server 2004 logging. It &lt;br /&gt;includes recommendations for logging formats, and capacity guidelines.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-113873507162764512?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com/' title='Articles: Troubleshooting, Connection Limits, Logging'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/113873507162764512/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=113873507162764512&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113873507162764512'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113873507162764512'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/01/articles-troubleshooting-connection.html' title='Articles: Troubleshooting, Connection Limits, Logging'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-113854417369305666</id><published>2006-01-29T09:11:00.000-05:00</published><updated>2006-02-24T17:34:55.220-05:00</updated><title type='text'>What we do after installing ISA 2004</title><content type='html'>Configuring ISA 2004 To Do List&lt;br /&gt;&lt;br /&gt;1. Increase Client Connection Limits to 160 for everyone. Adjust for individual workstations upward if necessary.&lt;br /&gt;&lt;br /&gt;2. Enable Intrusion Detection and DNS Attack Detection, except DNS Zone Transfer.&lt;br /&gt;&lt;br /&gt;3. Change Web Proxy and Firewall Logging limits to 4 GB, retain for 30 days, minimum disk space 512MB, maximum log size 4GB and convert to MSDE. Double check that the log files are stored on the data drive.&lt;br /&gt;&lt;br /&gt;4. Configure Report, publish report to folder&lt;br /&gt;&lt;br /&gt;5. Adjust Cache Size. Add 1MB per user and round up.&lt;br /&gt;&lt;br /&gt;6. Turn off Logging on System Policy #19, Allow Access from Trusted Computer to the Firewall Client Installation share on the ISA Server.&lt;br /&gt;&lt;br /&gt;7. Change Alert for Log Failure to stop Firewall Service&lt;br /&gt;&lt;br /&gt;8. Change Alert for Connection Limit Exceeded to Immediately.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-113854417369305666?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='What we do after installing ISA 2004'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/113854417369305666/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=113854417369305666&amp;isPopup=true' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113854417369305666'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113854417369305666'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/01/what-we-do-after-installing-isa-2004.html' title='What we do after installing ISA 2004'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-113849387575819959</id><published>2006-01-28T19:11:00.000-05:00</published><updated>2006-01-28T19:17:55.783-05:00</updated><title type='text'>The best explanation of why ISA Logs always contain Anonymous connections</title><content type='html'>Jim Harrison does it again! This is by far the best explanation of why the ISA logs always contain anonymous entries even when our SBS ISA is configured by default to require authenticated access. &lt;br /&gt;&lt;br /&gt;Tom Shinder beat me to posting it so click .&lt;a href="http://spaces.msn.com/drisa/Blog/cns!BC3213176E0489FD!435/"&gt;here&lt;/a&gt; to read Jim's excellent explanation&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-113849387575819959?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/113849387575819959/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=113849387575819959&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113849387575819959'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113849387575819959'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/01/best-explanation-of-why-isa-logs.html' title='The best explanation of why ISA Logs always contain Anonymous connections'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-113849318644097313</id><published>2006-01-28T18:33:00.000-05:00</published><updated>2006-01-28T19:06:26.453-05:00</updated><title type='text'>Allowing Lacerte</title><content type='html'>There's a kb article out there that appears to be providing incorrect information as to how to allow Lacerte to work with ISA. It's KB 839503. In fairness it is written for ISA 2000, but even when translated into ISA 2004 lanuage it still appears incorrect. Jim Barr found a rule that works. Here's how to create it.&lt;br /&gt;&lt;br /&gt;1.   Click Create New Access Rule, call it Lacerte Outbound and make it an Allow rule.&lt;br /&gt;&lt;br /&gt;2.   Apply the rule to All Outbound traffic.&lt;br /&gt;&lt;br /&gt;3.   Traffic will be from the Internal Network Set.&lt;br /&gt;&lt;br /&gt;4.   The rule applies to traffic to these two Address Sets: 198.31.208.130-140 and 208.240.240.200. &lt;br /&gt;&lt;br /&gt;5.   This rules applies to all users. &lt;br /&gt;&lt;br /&gt;Click on Apply to let the rule take effect.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-113849318644097313?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/113849318644097313/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=113849318644097313&amp;isPopup=true' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113849318644097313'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113849318644097313'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/01/allowing-lacerte.html' title='Allowing Lacerte'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-113834050348679424</id><published>2006-01-27T00:38:00.000-05:00</published><updated>2006-01-27T00:41:43.500-05:00</updated><title type='text'>Allowing ADP through ISA 2004</title><content type='html'>Using ADP for payroll and need to allow it to communicate out of your network with the ADP servers? Here's how:&lt;br /&gt;&lt;br /&gt;1.       Open the ISA 2004 Management Console (start-&gt;programs-&gt;Microsoft ISA Serer-&gt;ISA Server Management)&lt;br /&gt;2.       Expand the &lt;servername&gt; node and select the “Firewall Policy” tab.&lt;br /&gt;3.       Select the Tasks tab on the right side of the console.&lt;br /&gt;4.       Select Create New Access Rule.&lt;br /&gt;5.       Name: ADP.  Pick next.&lt;br /&gt;6.       Allow rule. Click next.&lt;br /&gt;7.       Chose Selected Protocols form the applies to box and click Add.&lt;br /&gt;     a.       Expand ‘Web’&lt;br /&gt;     b.       Select ‘HTTP’ and click add.&lt;br /&gt;     c.       Select ‘HTTPS’ and click add.&lt;br /&gt;     d.       Click close.&lt;br /&gt;8.       In the ‘rule applies to traffic from these sources’ click add.&lt;br /&gt;     a.       Expand network sets.&lt;br /&gt;     b.       Select All Protected Networks and click add. &lt;br /&gt;     c.       Click close.&lt;br /&gt;     d.       Click next.&lt;br /&gt;9.       In the ‘rule applies to traffic sent to these destinations’ click add.&lt;br /&gt;     a.       Select New from the top menu and select ‘Domain Name Set’&lt;br /&gt;          1.       Name:  ADP&lt;br /&gt;          2.       Click New and enter: *.adp.com&lt;br /&gt;          3.       Click Ok.&lt;br /&gt;     b.       Expand Domain Name Sets and click ADP.  Click Add.&lt;br /&gt;     c.       Click Close.&lt;br /&gt;     d.       Click next.&lt;br /&gt;10.   Leave the setting for All Users and click next.&lt;br /&gt;11.   Click Finish.&lt;br /&gt;12.   Click apply in the ISA management snapin.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-113834050348679424?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/113834050348679424/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=113834050348679424&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113834050348679424'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113834050348679424'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/01/allowing-adp-through-isa-2004.html' title='Allowing ADP through ISA 2004'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-113805285597687333</id><published>2006-01-23T16:20:00.000-05:00</published><updated>2006-01-23T16:47:35.990-05:00</updated><title type='text'>How to Allow Schwab Portfolio Center</title><content type='html'>There are two components to making Schwab Performance Technologies Portfolio Center work with ISA 2004, 1 workstation and 1 server. Portfolio Center uses DCOM to communicate between the clients and the server. DCOM must be allowed on both ends for it to work. This means changing the firewall configuration on both the workstation and the server.&lt;br /&gt;&lt;br /&gt;On the workstation you need to allow DCOM through the XP SP2 firewall. Schwab has created a little utility that you can download from the support tools site on their website &lt;a href="http://www.schwabpt.com/support/upgrades/tools/"&gt;here&lt;/a&gt;. You'll need your customer ID. &lt;br /&gt;&lt;br /&gt;On the server, we've also got to allow DCOM communications. By default ISA 2004 is configured with strict RPC compliance in the system policy. This will have to be turned off. Open the ISA Management MMC, Click on Firewall Policy. Click View, System Policy. The System Policy will be displayed above the Firewall Policy. Look for the system policy item called Allow RPC from ISA to Trusted Servers. Right click on it and select edit System Policy. Uncheck Enforce Strict RPC Compliance. This will allow the DCOM communications between the workstations and the server that Portfolio Center requires.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-113805285597687333?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/113805285597687333/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=113805285597687333&amp;isPopup=true' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113805285597687333'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113805285597687333'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/01/how-to-allow-schwab-portfolio-center.html' title='How to Allow Schwab Portfolio Center'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-113759601785506981</id><published>2006-01-18T09:50:00.000-05:00</published><updated>2006-01-18T09:53:37.866-05:00</updated><title type='text'>Free Securing SBS with ISA Training</title><content type='html'>I have not taken this course myself so I can't speak as to how well the content is delivered but the description sounds good. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.msreadiness.com/ws_abstract.asp?eid=15003637 "&gt;Securing Small Business Server 2003 using ISA Server 2004&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Event Date:&lt;br /&gt;1/24/2006&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;Presenter:&lt;br /&gt;Beatrice Mulzer&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;Event Time:&lt;br /&gt;11:00 AM Pacific, USA &amp; Canada (DST) = GMT - 08:00&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;Duration:&lt;br /&gt;90 minutes&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;Description:&lt;br /&gt;The course material will consist of advanced features of Small Business Server (SBS) 2003 that are of interest to Microsoft partners. You will receive a first look at utilizing Small Business Server Service Pack 1 Premium Edition featuring ISA Server 2004 to secure your network and to provide secure access to Exchange Server 2003 and Web resources. At the conclusion of the series, attendees will have a better understanding of how to secure Web applications, business applications, and remote access on SBS 2003 using ISA Server 2004.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-113759601785506981?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/113759601785506981/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=113759601785506981&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113759601785506981'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113759601785506981'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/01/free-securing-sbs-with-isa-training.html' title='Free Securing SBS with ISA Training'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-113750557521314482</id><published>2006-01-17T08:30:00.000-05:00</published><updated>2006-01-17T08:46:15.226-05:00</updated><title type='text'>Access Policy or Server Policy? Which one do I use?</title><content type='html'>The ISA Product Team put out a nice blog entry titled &lt;a href="http://blogs.technet.com/isablog/archive/2006/01/16/AccessPolicyRulesVsServerPublishingRules.aspx"&gt;Access Rules vs Server Publishing Rules.&lt;/a&gt;  The article is written in an easy to read numbered list format. I think this take some of the sting out of a subject that has caused so much confusion.  Most firewalls don't make a distinction between different types of rules (because most of them don't offer different type of rules) and the reasons for this distinction are well explained by the product guys in this blog entry. &lt;br /&gt;&lt;br /&gt;For what it's worth, I use this rule of thumb (which of course has exceptions): &lt;br /&gt;&lt;br /&gt;If I need to grant access out of my network use Access Rules.&lt;br /&gt;If I need to grant access into my network use Server or Web Publishing rules. &lt;br /&gt;&lt;br /&gt;That latter statement particularily refers to allowing users on the outside of your network access to websites or applications hosted on your non-SBS server sitting next to your SBS. For example an SQL, Web, or Video server.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-113750557521314482?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/113750557521314482/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=113750557521314482&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113750557521314482'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113750557521314482'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/01/access-policy-or-server-policy-which.html' title='Access Policy or Server Policy? Which one do I use?'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-113708443774132932</id><published>2006-01-12T11:43:00.000-05:00</published><updated>2006-01-12T11:47:17.756-05:00</updated><title type='text'>All Port Scan False Positives Explained</title><content type='html'>The security column of the month has produced a whammy of an article on Technet titled &lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/community/columns/sectip/default.mspx"&gt;ISA Server Port Scan Alerts&lt;/a&gt;. Not a catchy title but it is a must read. Here's a little snip from the beginning of the article:&lt;br /&gt;&lt;br /&gt;"Overview&lt;br /&gt;Since the dawn of ISA Server time (2000, if you haven’t been watching), ISA Server administrators have received practical but often confusing notifications of “all port scan” and “port scan” intrusion attempt alerts. &lt;br /&gt;&lt;br /&gt;Although the ability to notify administrators when potentially malicious traffic is detected is a useful feature of any firewall, these alerts in particular seem to cause more confusion than do other ISA Server alerts. It’s this confusion that we’ll try to eliminate today. &lt;br /&gt;&lt;br /&gt;To keep things simple (and short), we’ll limit our examples to ISA Server 2004. The same general principles apply to ISA Server 2000, but the ISA Server user interface and log review examples differ greatly."&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-113708443774132932?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/113708443774132932/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=113708443774132932&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113708443774132932'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113708443774132932'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/01/all-port-scan-false-positives.html' title='All Port Scan False Positives Explained'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-113707740291757144</id><published>2006-01-12T09:47:00.000-05:00</published><updated>2006-01-12T09:50:02.936-05:00</updated><title type='text'>NEW ISA MVP's Awarded</title><content type='html'>Tom Shinder blogs that several new ISA Server MVP's have been awarded. Here's reprinter of his blog entry.&lt;br /&gt; &lt;br /&gt;Hey folks,&lt;br /&gt;&lt;br /&gt;I had no idea until today how many new ISA firewall MVPs we have! Check&lt;br /&gt;this out:&lt;br /&gt;&lt;br /&gt;Amy Babinchak -- Amy enters the ISA firewall space via SBS 2003 SP1. Amy is the leading contributor of ISA firewall information on the SBS platform over at www.isaserver.org &lt;br /&gt;&lt;br /&gt;Jason Fossen -- new MVP and he's located here in my neck of the woods -- Dallas, Texas. Jason runs the ISA firewall scripting Web site www.isascripts.org&lt;br /&gt;&lt;br /&gt;Moez Mezghani -- new MVP from North Africa&lt;br /&gt;&lt;br /&gt;Martin Pavlis -- MVP from the Czech Republic&lt;br /&gt;&lt;br /&gt;Alessandro Perilli -- MVP from Italy and the genius who taught me how to support four NICs in a VMware virtual machine :))&lt;br /&gt;&lt;br /&gt;Meibo Zhang -- a friend of mine from China who has a tremendous Chinese language ISA firewall site at www.isacn.org&lt;br /&gt;&lt;br /&gt;Hong Zhi Zhu -- another new MVP from China, Chong Qing. He's active in the Windows IT Pro magazine web boards and has written a number of articles on the ISA firewall&lt;br /&gt;&lt;br /&gt;Hopefully one day all the ISA firewall MVPs will be able to get together at the same time in the Redmond world wide MVP conference.&lt;br /&gt;&lt;br /&gt;Welcome them to the club!&lt;br /&gt;&lt;br /&gt;DISCUSS THIS POST AT: http://forums.isaserver.org/Roll_up_discussion_link_for_posts_up_to_01-14-2006/m_2002002974/tm.htm&lt;br /&gt;&lt;br /&gt;Thanks!&lt;br /&gt;Tom&lt;br /&gt;&lt;br /&gt;Thomas W Shinder, M.D.&lt;br /&gt;Site: www.isaserver.org&lt;br /&gt;Blog: http://spaces.msn.com/members/drisa/&lt;br /&gt;Book: http://tinyurl.com/3xqb7&lt;br /&gt;MVP -- ISA Firewalls&lt;br /&gt;**Who is John Galt?**&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-113707740291757144?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/113707740291757144/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=113707740291757144&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113707740291757144'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113707740291757144'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/01/new-isa-mvps-awarded.html' title='NEW ISA MVP&apos;s Awarded'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-113640754464932671</id><published>2006-01-04T15:43:00.000-05:00</published><updated>2006-01-04T15:48:29.650-05:00</updated><title type='text'>ISA Product Team Blog</title><content type='html'>The ISA Product Team has finally started blogging. We should see some interesting posts once they get rolling. Those of us running ISA as an SBS component this blog offers special opportunity to get to the heart of ISA and make sure our voices are heard when it comes to improving ISA's support on SBS. Keep them honest. SBS sales of ISA make up a large portion of the total ISA deployments in the market.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://blogs.technet.com/isablog/default.aspx"&gt;ISA Product Team&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-113640754464932671?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/113640754464932671/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=113640754464932671&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113640754464932671'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113640754464932671'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/01/isa-product-team-blog.html' title='ISA Product Team Blog'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-113630027532911524</id><published>2006-01-03T09:53:00.001-05:00</published><updated>2006-01-03T09:57:55.330-05:00</updated><title type='text'>Authentication Problems</title><content type='html'>Microsoft has addressed the most common question about ISA Server. "Why won't my ________ app go through ISA?" Because it won't authenticate and our SBS installations of ISA are setup to require authentication to get access to the Internet. If someone or something is using your Internet access, you want to know who and from where.&lt;br /&gt;&lt;br /&gt;Check out this TechNet article:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/prodtechnol/isa/2004/plan/ts_client_rules.mspx"&gt;Troubleshooting Client Authentication on Access Rules in ISA Server 2004&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-113630027532911524?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/113630027532911524/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=113630027532911524&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113630027532911524'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113630027532911524'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2006/01/authentication-problems_03.html' title='Authentication Problems'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-113405478342887862</id><published>2005-12-08T10:06:00.000-05:00</published><updated>2005-12-08T10:13:03.440-05:00</updated><title type='text'>Article: Basic ISA 2004 Troubleshooting</title><content type='html'>I've written a new article for &lt;a href="http://www.isaserver.org"&gt;ISAServer.org&lt;/a&gt; titled &lt;a href="http://www.isaserver.org/articles/Basic-ISA-2004-Troubleshooting.html"&gt;Basic ISA 2004 Troubleshooting&lt;/a&gt;. It's an introduction to configuring ISA logs and using the log information to determine whether or not ISA is blocking traffic that you might need to allow. &lt;br /&gt;&lt;br /&gt;Enjoy! Feedback on the article can be posted on&lt;a href="http://forums.isaserver.org/ISA_2004_SBS/forumid_46/tt.htm"&gt; the ISA 2004 SBS forum.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-113405478342887862?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/113405478342887862/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=113405478342887862&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113405478342887862'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113405478342887862'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2005/12/article-basic-isa-2004-troubleshooting.html' title='Article: Basic ISA 2004 Troubleshooting'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-113399680549035321</id><published>2005-12-07T17:54:00.000-05:00</published><updated>2005-12-07T18:06:45.503-05:00</updated><title type='text'>Interesting PodCasts</title><content type='html'>Here are a couple of interesting podcasts:&lt;br /&gt;&lt;br /&gt;Eriq Neale knows how to run a show. Each is less than 15 minutes long, very professional sound, just plain excellent. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;What it's like to write a technical book (specifically SBS 2003 Unleashed)&lt;/strong&gt; &lt;br /&gt;&lt;a href="http://www.eoncall.com/Portals/0/eonCall1207Show_1st1a.mp3"&gt;Part 1&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.eoncall.com/Portals/0/eonCall1207Show_2nd1a.mp3"&gt;Part 2&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;SBS CSS Team will Podcast on ISA 2004 on Friday.&lt;/strong&gt; The podcast will be &lt;a href="http://sbspod.libsyn.com/index.php?post_category=podcasts"&gt;here&lt;/a&gt; once recorded. Unlike Eriq's, these podcasts are rough through and through and will soak you for an hour of your time. Still there's bound to be good content from the guru's at CSS.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-113399680549035321?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/113399680549035321/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=113399680549035321&amp;isPopup=true' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113399680549035321'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113399680549035321'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2005/12/interesting-podcasts.html' title='Interesting PodCasts'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-113251205309339209</id><published>2005-11-20T13:40:00.000-05:00</published><updated>2005-11-20T13:40:53.126-05:00</updated><title type='text'>ISA2004 Recorded Live Meeting Available</title><content type='html'>On Saturday morning I gave a presentation via Live Meeting to the San Antonio geeks. These guys have been getting together for years on Saturday morning to each tacos, study for exams or just plain IT knowledge and eat more tacos. Pretty cool concept. We all need time to just sit and learn something new and having a group of friends/collegues that you can do it with would make it all the more fun. So they've been studying ISA 2004 for a few months now and asked if I would do a presentation for them. So I did; lingering cold and all. &lt;br /&gt;&lt;br /&gt;My presentation was recorded for your viewing pleasure. It can be accessed by the public for the next month or so &lt;a href="https://www120.livemeeting.com/cc/winserver_usergroup/view?id=Q78FXW&amp;pw=SqPq4%60P"&gt;here&lt;/a&gt;. After that it'll only be available to SBS User Group Leads for use at the local SBS User Group Meetings. &lt;br /&gt;&lt;br /&gt;It's not exactly an introduction. It's not exactly advanced. I'd put it somewhere in the middle. It assumes that you've at least seen the Management console and have been poking around in a bit.&lt;br /&gt;&lt;br /&gt;As this is the first live meeting recording done for the user groups, the beginning is a little rough and sometimes the sounds isn't the best. But I listened to it and it works. Enjoy!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-113251205309339209?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/113251205309339209/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=113251205309339209&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113251205309339209'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113251205309339209'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2005/11/isa2004-recorded-live-meeting.html' title='ISA2004 Recorded Live Meeting Available'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-113206482703353515</id><published>2005-11-15T09:27:00.000-05:00</published><updated>2005-11-15T09:27:07.070-05:00</updated><title type='text'>MSDE Loggging Memory Use KB</title><content type='html'>&lt;a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;909636&amp;sd=rss&amp;spid=2108"&gt;You may experience high memory usage on an ISA Server 2004-based computer that logs messages to an MSDE database&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This information has been around for a while in the newsgroups. Now it's available as a knowledgebase article. Interestingly of all of the ISA servers that I manage, only 1 has come down with this problem. I be interested to know what triggers it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-113206482703353515?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/113206482703353515/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=113206482703353515&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113206482703353515'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113206482703353515'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2005/11/msde-loggging-memory-use-kb.html' title='MSDE Loggging Memory Use KB'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-113199344386960384</id><published>2005-11-14T13:03:00.000-05:00</published><updated>2005-11-14T13:37:23.890-05:00</updated><title type='text'>Allowing the HP Indigo Press to Phone Home</title><content type='html'>Clients that own the HP Indigo printing press are billed by Hewlett Packard on a per page basis. Maintenance costs and print costs are based on usage. To get this information up to HP so they can bill the client a software package runs several times a day and phones (or rather Internets) home how much the press has printed. This traffic occurs on a specific range of ports. Fortunately for me, HP provided good documentation on which ports their software requires. &lt;br /&gt;&lt;br /&gt;Ports Required: 40000-40199 out and 6055 out. &lt;br /&gt;&lt;br /&gt;Before beginning I started live logging on ISA and watched the packets get denied. I really didn't want to enable such a large grouping of ports so I watched to see what the software was actually trying to do. As it turns out the software sends a small packet of information over a large number of ports simultaneously. &lt;br /&gt;&lt;br /&gt;We have a limitation in that the HP press can't join the domain and it won't authenticate. The HP tech set it up as a SecureNat client on the network, in a workgroup called workgroup. Being a SecureNat client really limits our ability to control access. Since the HP press isn't capable of telling us who it is, we'll have to allow these ports out for everyone. At least we don't have to allow access to any additional ports in to make this work.&lt;br /&gt;&lt;br /&gt;Here's how I did it. Open ISA Management. Click on Firewall Policy. Click Create New Access Rule. Name the rule HP Indigo 40000-41999. Click Next. Choose Allow. Click Next. Leave This Rule Applies to Outbound Traffic and click the Ports button. Click on Limit Traffic to This range of Source Ports and enter 40000 in the From box and 40199 in the To box. Click OK. Click Next. Click the Add button, expand Networks and choose Internal. Click Close. Click Next. Leave this rule applies to All Users and click Next. Click Finish. Follow the same procedure to allow outbound traffic over port 6055.  &lt;br /&gt;&lt;br /&gt;Apply the rule and fire up live logging and have the press operator send data to HP. You should now see only successful packets in the log.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-113199344386960384?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/113199344386960384/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=113199344386960384&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113199344386960384'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113199344386960384'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2005/11/allowing-hp-indigo-press-to-phone-home.html' title='Allowing the HP Indigo Press to Phone Home'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-113154344014172646</id><published>2005-11-09T08:33:00.000-05:00</published><updated>2005-11-09T08:37:20.156-05:00</updated><title type='text'>Silent Install of ISA2004 Firewall Client</title><content type='html'>In his blog, Tom Shinder makes note of and expands upon an excellent isaserver.org Member Board post from Ben on how to install the ISA2004 Firewall Client without user interaction. Pair this with WPAD and you've got a real nice way to automatically deploy and configure the Firewall Client on all of your workstations.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://spaces.msn.com/members/drisa/Blog/cns!1p9yz6owxXl-uIlyqIZXkCrg!310.entry"&gt;Tom's Blog&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-113154344014172646?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/113154344014172646/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=113154344014172646&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113154344014172646'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113154344014172646'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2005/11/silent-install-of-isa2004-firewall.html' title='Silent Install of ISA2004 Firewall Client'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-113139670045974668</id><published>2005-11-07T15:51:00.000-05:00</published><updated>2005-11-07T15:52:42.240-05:00</updated><title type='text'>ISA2004 and Macintosh Computers</title><content type='html'>Eriq Neale has written a couple of nice blog entries recently on issues involved in connecting MAC's through ISA2004. &lt;br /&gt;&lt;br /&gt;Instructions on how to allow Macintosh computers to work through ISA2004 as securenat clients. A securenat client is a non-Windows operating system client computer that wishes to access the Internet while not having ISA 2004 act as a Proxy for them. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://simultaneouspancakes.com/Lessons/archives/2005/11/internet_access_1.shtml"&gt;Internet Access for Macintoshes behind ISA 2004&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Comment: I'd prefer that the Macintosh computers be configured as Web Proxy Clients and use a browser that supports proxy settings. Any other apps on the Mac that do not support proxy can be handled as any non-authenticating application. &lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;How to Publish Timbuktu to one Internal Client:&lt;br /&gt;&lt;a href="http://simultaneouspancakes.com/Lessons/archives/2005/10/publishing_timb.shtml"&gt;Publishing Timbuktu through ISA 2004&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-113139670045974668?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/113139670045974668/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=113139670045974668&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113139670045974668'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113139670045974668'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2005/11/isa2004-and-macintosh-computers.html' title='ISA2004 and Macintosh Computers'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-113033319056137425</id><published>2005-10-26T09:24:00.000-04:00</published><updated>2005-10-26T09:26:30.563-04:00</updated><title type='text'>The missing xml password has been found!</title><content type='html'>The post titled ISA2004 Installation Fails during SBS 2003 SP1 Install has been amended to include the solution to the missing password. Thanks once again to Jim Harrison for digging this information up, when PSS was unable to.&lt;br /&gt;&lt;br /&gt;..and the answer is:&lt;br /&gt;&lt;br /&gt;%programfiles%\microsoft windows small business server\support\sbsisa2k4setuplog.txt&lt;br /&gt;&lt;br /&gt;..has the password embedded in it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-113033319056137425?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/113033319056137425/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=113033319056137425&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113033319056137425'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113033319056137425'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2005/10/missing-xml-password-has-been-found.html' title='The missing xml password has been found!'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-113026246264631497</id><published>2005-10-25T13:00:00.000-04:00</published><updated>2005-10-27T10:33:52.946-04:00</updated><title type='text'>ISA2004 Installation Fails during SBS 2003 SP1 Install</title><content type='html'>Subtitle: In which Amy spends 5+ hours on the phone with PSS on a Service Pack installation problem and the issue doesn't get resolved. Or, in which after 3 days and 5 different support specialists the problem is mostly resolved.&lt;br /&gt;&lt;br /&gt;Here's the situation:&lt;br /&gt;&lt;br /&gt;It was a dark but otherwise lovely week night evening and the SBS 2003 SP1 installation was humming along. I was only 3 hours into the installation and ready to install ISA2004. Record time! 27 PC's already had the old ISA2000 client removed and were awaiting the new client. Then it happened. &lt;insert erie music here&gt;&lt;br /&gt;&lt;br /&gt;"The wizard cannot install ISA Server 2004.  Try to install it again by restarting this wizard.  If the problem persists, see http://www.microsoft.com/windowsserver2003/sbs/support for additional help and support." &lt;br /&gt;&lt;br /&gt;From the sbsisa2k log:&lt;br /&gt;&lt;br /&gt;SBSISA2K4SETUP: CreateProcess returned OK&lt;br /&gt;SBSISA2K4SETUP: ISA2k4 setup completed before post config&lt;br /&gt;SBSISA2K4SETUP: *** WaitingForMultipleObjects returned ERROR 0x80004005&lt;br /&gt;SBSISA2K4SETUP: *** LaunchISA2k4NativeSetup returned ERROR 0x80004005&lt;br /&gt;SBSISA2K4SETUP: *** Running ISA2k4 setup unattended returned ERROR 0x80004005&lt;br /&gt;SBSISA2K4SETUP: Entering IsISA2k4Installed&lt;br /&gt;IsISA2k4Installed returned FALSE&lt;br /&gt;SBSISA2K4SETUP: ISA2k4 is NOT installed&lt;br /&gt;SBSISA2K4SETUP: *** CSbsIsa2k4SetupCommit::CommitEx returned ERROR 0x80004005&lt;br /&gt;SBSISA2K4SETUP: *** CommitEx returned ERROR 0x80004005&lt;br /&gt;SBSISA2K4SETUP: Committer failed&lt;br /&gt;SBSISA2K4SETUP: (error message is generic.)&lt;br /&gt;SBSISA2K4SETUP: *** Commit returned ERROR 0x80004005&lt;br /&gt;SBSISA2K4SETUP: *** Commit returned ERROR 0x80004005&lt;br /&gt;SBSISA2K4SETUP: Setting the event to signal post setup&lt;br /&gt;SBSISA2K4SETUP: *** InstallISA2k4 returned ERROR 0x80004005&lt;br /&gt;SBSISA2K4SETUP: *** Installing ISA2k4 returned ERROR 0x80004005&lt;br /&gt;SBSISA2K4SETUP: Exiting&lt;br /&gt;&lt;br /&gt;This story could go on and on for about 3 days but I'll keep it short and to the point. The problem was that the ISA setup couldn't load the performace monitor counters. This resulted in MSDE not be able to load and although the base of ISA installed the failures were noted and the install rolled back and rebooted the server with having removed ISA2000 but failed to install ISA2004. When this happened I thought, oh no, my ISA2000 settings! I wasn't smart enough to have made a backup of ISA2000 first. The complancy of many successful upgrades had gotten the best of me. So PSS directed me to go to C:\program files\Microsoft Small Business Server\Support\Premium and save the .xml file that the upgrade process had created of my ISA2000 settings. This particular client had a few that I didn't want to have to recreate. The thought was that we could import this xml file later.&lt;br /&gt;&lt;br /&gt;This is where the first 2 support specialists left me. The next day I emailed the most helpful Jim Harrison and he said what do the ISA detailed install logs say? Where are they, says I? The detail ISA install logs live in C:\windows\temp and are called ISAWRAP_number.log, ISAMDSE_number.og and ISAFWSV_number.log. The installation process uses verbose logging so there are a lot of log files with a lot of text in them. I pulled out this error message: Setup failed. Error returned: 0x643&lt;br /&gt;MSDE Installation failed, hr=80070643 and then emailed it to the support technician. He passed it on to yet another technician who got an MSDE support specialist on the line and he solved the problem.&lt;br /&gt;&lt;br /&gt;Here's how to resolve this problem. If you are getting this error message, open up Performance Monitor on the server. Click the + sign to add a new counter. If your counters are numbers rather than friendly descriptions, then you have corrupt performance counters, just like this server did.&lt;br /&gt;&lt;br /&gt;Open a command prompt and running the following:&lt;br /&gt;&lt;br /&gt;lodctr /r:perfstringbackup.ini &lt;br /&gt;&lt;br /&gt;Now go back into Performance Monitor and verify that the counters have friendly names and descriptions. Commence to install ISA2004.&lt;br /&gt;&lt;br /&gt;Unfortunately this story has no ending as I've not yet been able to import the xml file with my ISA2000 settings in it. Apparently the unattended install of ISA2004 uses a password to protect this file and no one has been able to tell me what that password is.&lt;br /&gt;&lt;br /&gt;Good news: ISA2004 is installed and working. &lt;br /&gt;Bad news: My ISA2000 settings are locked in a password protected file...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;A solution to the missing password has been found! Thanks, yet again to Jim Harrison and the SBS Team.&lt;br /&gt;&lt;br /&gt;..and the answer is:&lt;br /&gt;&lt;br /&gt;%programfiles%\microsoft windows small business server\support\sbsisa2k4setuplog.txt&lt;br /&gt;&lt;br /&gt;..has the password embedded in it.&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;This log file and it's associated XML file give anyone a complete view of your Firewall configuration. Leaving this information exposed for anyone to view is not recommended. Take care not to change any of the security settings on these files. The SBS team as protected this information by setting the ACLs on this resource to admin / system by default. Be sure to keep it that way.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-113026246264631497?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/113026246264631497/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=113026246264631497&amp;isPopup=true' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113026246264631497'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/113026246264631497'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2005/10/isa2004-installation-fails-during-sbs.html' title='ISA2004 Installation Fails during SBS 2003 SP1 Install'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-112899943121885690</id><published>2005-10-10T22:57:00.000-04:00</published><updated>2005-10-10T23:09:54.840-04:00</updated><title type='text'>Yes, but why don't the new alerts show up right away?</title><content type='html'>I learned something new today about ISA 2004 in SBS support podcast #2. I wasn't expecting to. If you haven't checked out the podcasts yet, do. They're great.&lt;br /&gt;&lt;br /&gt;Here's what I learned. The alerts don't update continuously. Just because you don't see a new alert doesn't mean that an alert condition didn't occur. You may not see a new alert, if an existing alert of the same type is already there. So if you applied a fix that is supposed to keep your ISA2004 server happy and not throwing alerts you might falsely think that your solution worked because a new alert didn't appear right away.&lt;br /&gt;&lt;br /&gt;The solution given by the guys was to acknowledge all of your alerts before running your test to see if the fix you applied has worked.&lt;br /&gt;&lt;br /&gt;This will work but it left me wondering why the alerts weren't showing up. So I dug...&lt;br /&gt;&lt;br /&gt;Open up ISA 2004 Management, go to Monitoring, select the alerts tab. There are several things here that will effect how often new alerts are triggered. In the tasks pane notice that there's a box where you can choose how often this page is refreshed. You choices are None, Low, Medium or High. Medium is the default setting. This will effect how quickly you'll get to see new alerts messages. If you want to be alerted sooner bump it up to high. Now click on the Configure Alert Definitions link. This will open up the Alerts Properties box. Continuing with the podcast theme, select the Connection Limits alert definition and press the Edit button. The Connection Limit Exceeded alert definition properties box will open. Move to the Events tab. On this tab you get to set how often this alert will be triggered. The default is "only if the alert was manually reset". This explains why if you're having trouble with an SSL website because your connections limits are too low you won't see a new alert about it until you acknowledge the old alert.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If I were PSS and troubleshooting this type of problem I'd bump up the alert frequency to Immediately. Kind of like when you are troubleshooting an Exchange issue, first thing you do is bump up the monitoring so you can see more of what's going on. Bonus, you don't have to keep acknowledging alerts during the troubleshooting process. Just let them flow.&lt;br /&gt;&lt;br /&gt;I feel better knowing why.&lt;br /&gt;&lt;br /&gt;If you haven't listened to the podcasts I highly recommend them.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-112899943121885690?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com/' title='Yes, but why don&apos;t the new alerts show up right away?'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/112899943121885690/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=112899943121885690&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112899943121885690'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112899943121885690'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2005/10/yes-but-why-dont-new-alerts-show-up.html' title='Yes, but why don&apos;t the new alerts show up right away?'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-112895529559237994</id><published>2005-10-10T10:06:00.000-04:00</published><updated>2005-10-10T10:41:35.610-04:00</updated><title type='text'>Troubleshoot Using Live Logging</title><content type='html'>I'm a little embarrassed that it has taken so log to introduce you to my best friend, Live Logging. We've been best friends since the day we met when I opened up the new ISA management console, there she was hiding behind the Start Query button.&lt;br /&gt;&lt;br /&gt;Live Logging is the best troubleshooting tool we've got in ISA. Remember how difficult the logs were to read in ISA2000? Now, you can not only read them, but query them and copy them out to Excel.&lt;br /&gt;&lt;br /&gt;Let's take a quick look.&lt;br /&gt;&lt;br /&gt;Open up ISA Management, Click on Monitoring. At the top of the page are your Log Query Filters. To see everything you should have the following filters configured: Log Record Type = Firewall Or Web Proxy Filter. Log Time = Live. Action not equal to Connection Status. These will give you high quality output.&lt;br /&gt;&lt;br /&gt;Next Click the Start Query link. You'll get a little message that says Fetching Results, then the log information will start flowing. It's a beautiful thing.&lt;br /&gt;&lt;br /&gt;Once you have a few items in your list click on the Stop Query link. Here's where the fun begins.&lt;br /&gt;&lt;br /&gt;Right click on the column name and select add/remove columns. Here you can not only add or remove columns of information to view but it will take effect immediately on that data that you've already collected! Try it. Add a column, remove a column, reorder a column. You get the manipulate what's on the screen, even for the now historical data.&lt;br /&gt;&lt;br /&gt;Next, select a group of log items by either clicking on the top item and shift-clicking on the last one you want to select or by crtl-clicking individual log items that you want to select until you have a few. Now that they're highlighted, click the copy to clipboard link in the tasks pane on the far right. Open Excel and paste. You get little more than you bargained for as you get all possible columns of information and you also get a line of column headings. Sweet. Now you've got your ISA log selections into Excel making them easy to save and ponder over, send to someone, while you're troubleshooting ISA.&lt;br /&gt;&lt;br /&gt;How will you use this Live Logging feature to troubleshoot ISA. Here's how I do it. Open up the ISA management console. Start the query. Have the person that can't do what ever it is, say open an SSL page, do it, while you are watching the logs. When you see the traffic generated by this attempt go by, stop the query. Then review the denied connection items for that persons name or IP address. If need be remove or add the columns of information that you need. I like to get it down to just the relevant information and get rid of the columns I don't need to see, like the empty ones. I find them distracting. Now you should be able to see what is stopping the user from getting to that SSL page. Once you have the what, you're well on your way to a solution. If you need to save this information for later, or you need to send it to someone to help you resolve the problem, then copy and paste only the relevent columns into Excel.&lt;br /&gt;&lt;br /&gt;Once you get the hang of it, Live Logging will be your new best friend too.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-112895529559237994?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/112895529559237994/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=112895529559237994&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112895529559237994'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112895529559237994'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2005/10/troubleshoot-using-live-logging.html' title='Troubleshoot Using Live Logging'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-112855587640052450</id><published>2005-10-05T19:37:00.000-04:00</published><updated>2005-10-05T19:44:36.400-04:00</updated><title type='text'>Finally Categories, sort of</title><content type='html'>I recently discovered the power of Blogger Search and have implemented it on this site. Finally you and I will be able to search the blog and locate the information that we're looking for. I've added two things. The first is a Search This Blog link. This will take you to the Blogger Search page for this blog. Once there Just add your search term into the box like this blogurl:isainsbs.blogspot.com firewall client, where firewall client is the search term that I added to the end of the search string. &lt;br /&gt;&lt;br /&gt;The second thing I added are category links. These are pre-defined search terms. Just click the link you like and blogger search will bring up the relevant posts.&lt;br /&gt;&lt;br /&gt;The only snafu I've run into with this so far is that it won't search back farther than March 2005. What's up with that? Even so, this feature makes the blog so much more useful that I'm going to live with it for now. Enjoy!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-112855587640052450?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/112855587640052450/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=112855587640052450&amp;isPopup=true' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112855587640052450'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112855587640052450'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2005/10/finally-categories-sort-of.html' title='Finally Categories, sort of'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-112836300281372909</id><published>2005-10-03T14:10:00.000-04:00</published><updated>2005-10-03T14:10:09.386-04:00</updated><title type='text'>From Jim Harrison - Add this to your ISA TO DO List</title><content type='html'>Jim Harrison posted are very useful email on several lists in which he outlines 2 quick registry changes that you'll want to make to improve the performance of your ISA 2004 Server. Here's his text unedited:&lt;br /&gt;&lt;br /&gt;- Tired of the ISA sending NetBT broadcasts when DNS lookups fail?&lt;br /&gt;&lt;br /&gt;This setting:&lt;br /&gt;&lt;br /&gt;HKLM\SystemCurrentControlSet\Services\NetBT\Parameters NodeType, DWORD, 0x2&lt;br /&gt;&lt;br /&gt;..will cure that.&lt;br /&gt;&lt;br /&gt;By setting this to a value of 2, You’re telling Windows to limit its name lookup efforts to defined DNS and WINS servers.&lt;br /&gt;&lt;br /&gt;As a result, Windows will no longer wait for NetBT broadcasts to fail before reporting a name lookup failure.&lt;br /&gt;&lt;br /&gt;Can you say “faster lookup responses and therefore faster connections (or failures)”, boys and girls?&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;- MS05-019 fixed an ICMP MTU vulnerability that existed in Windows.&lt;br /&gt;&lt;br /&gt;Because the ISA team was aware of this issue before ISA 2004 shipped, they opted to give you a “safe by default” configuration since they had no idea if or when the Windows issue might be fixed.&lt;br /&gt;&lt;br /&gt;Unfortunately, it also has the unfortunate side effect of limiting Windows to 576-byte packets on all interfaces, reducing network efficiency&lt;br /&gt;&lt;br /&gt;This setting:&lt;br /&gt;&lt;br /&gt;HKLM\SystemCurrentControlSet\Services\Tcpip\Parameters EnablePMTUDiscovery, DWORD, 0x0&lt;br /&gt;&lt;br /&gt;..is what the ISA installer creates.&lt;br /&gt;&lt;br /&gt;This setting:&lt;br /&gt;&lt;br /&gt;HKLM\SystemCurrentControlSet\Services\Tcpip\Parameters EnablePMTUDiscovery, DWORD, 0x1&lt;br /&gt;&lt;br /&gt;..is what will remove this protection (or you can delete the “EnablePMTUDiscovery” value).&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Both settings require a machine reboot to take effect.&lt;br /&gt;&lt;br /&gt;Both settings will clean up your network traffic a bit.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-112836300281372909?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/112836300281372909/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=112836300281372909&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112836300281372909'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112836300281372909'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2005/10/from-jim-harrison-add-this-to-your-isa.html' title='From Jim Harrison - Add this to your ISA TO DO List'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-112826804116961719</id><published>2005-10-02T11:44:00.000-04:00</published><updated>2005-10-02T11:47:21.170-04:00</updated><title type='text'>Spammers Be gone</title><content type='html'>I didn't want to do it but I had to. The comment section of this blog got spammed. You'll now be required to enter word verification in order to post. Sorry about that.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-112826804116961719?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/112826804116961719/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=112826804116961719&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112826804116961719'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112826804116961719'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2005/10/spammers-be-gone.html' title='Spammers Be gone'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-112706162936260604</id><published>2005-09-18T11:54:00.000-04:00</published><updated>2005-09-18T12:40:29.370-04:00</updated><title type='text'>Sometimes VOIP w/SIP works with ISA</title><content type='html'>...other times it doesn't. The determination depends completely upon who wrote the software for the VOIP system. &lt;br /&gt;&lt;br /&gt;System types that work include those that come with their own router and those that encapsulate SIP. For example I use Lingo. Lingo comes with its own router and uses regular phones. This router ends up as the only device with an IP on your network and it handles all of the SIP stuff internally. It's managed from Lingo's website. On my network I put the device on the outside because I don't know enough about the internal workings of the router to trust it. On the flip side, I know someone else that put it on the inside of the network for the exact same reason. The point is because it doesn't ask ISA to handle SIP for it, it works. &lt;br /&gt;&lt;br /&gt;I also recently worked on getting a SIP CRM application through ISA. This app by five9.com has two java apps that have to work together. One app handles the phone call and the other app handles the CRM and pops up the contact info when a call comes in. It's a slick distributed call center. It worked with ISA because the SIP was actually being handled on the host end with the results being passed through a java client to the end user. So what on the surface appeared to be a SIP VOIP application was really just 2 java apps and an SSL website. &lt;br /&gt;&lt;br /&gt;The difficult part of implementing these solutions for clients is working your way through the documentation provided by the vendor. Here's what we got from five9 when we asked what ports were required: &lt;br /&gt;1) IP (local machine)/ Port 8443 (HTTPS)&lt;br /&gt;2) IP 64.69.76.10 / Port 80 (HTTP)&lt;br /&gt;3) Port 5060 UDP (SIP)&lt;br /&gt;4) Port 8000 UDP (RTP)&lt;br /&gt;5) Port 8001 UDP (RTCP)&lt;br /&gt;6) Port 3478 UDP (STUN)&lt;br /&gt;6) Allow incoming TCP traffic from IP addresses ranges&lt;br /&gt;207.218.174.65 - 207.218.174.95&lt;br /&gt;206.132.222.224 - 206.132.222.254&lt;br /&gt;208.49.229.64 - 208.49.229.124 &lt;br /&gt;&lt;br /&gt;If you have personal firewall installed on the PC, please also make sure the following ports are opened for the loopback (127.0.0.1)&lt;br /&gt;traffic:&lt;br /&gt;&lt;br /&gt;1) Port 1196&lt;br /&gt;2) Port 1197&lt;br /&gt;&lt;br /&gt;Outgoing traffic to UDP Port 5060.&lt;br /&gt;&lt;br /&gt;Full access to these URL:&lt;br /&gt;http://apps.five9.com&lt;br /&gt;&lt;br /&gt;All incoming traffic to these IP address:&lt;br /&gt;207.218.174.70 &lt;br /&gt;or &lt;br /&gt;All Incoming traffic to this IP range:&lt;br /&gt;207.218.174.65 to 207.218.174.95&lt;br /&gt;&lt;br /&gt;My reaction to any request that has this many open port requirements is  &lt;em&gt;no&lt;/em&gt; and that’s what I would have advised my client. In this case the situation came to me after the money had already been spent. &lt;br /&gt;&lt;br /&gt;Now don't get me wrong I'd rather have vendors fess up than deny that they require anything out of the ordinary. I just get a little bent when a single app requires many ports.&lt;br /&gt;&lt;br /&gt;The first thing I did was load up the application without making any ISA changes, I then watched the logs for what happened when I ran the app. Next I added 8443 to the SSL range, then I ran the app and let the logs tell me what happened. The next thing I did was wonder if I had the right set of instructions from the vendor because what I saw in the logs had very little in common with the instructions I received. &lt;br /&gt;&lt;br /&gt;&lt;em&gt;Vendors take note: in this case the app is very cool and it works. But at this time it appears you are going to loose the customer because you dragged them through a month of unnecessary ugliness that finally resulted in them giving up on your support and hiring outside help at their own expense. Vendors if you don’t know ISA, then you’d better contract with someone who does or you’ll probably loose the client. If you are to promise full configuration services then you’d better make sure you can deliver.&lt;/em&gt; &lt;br /&gt;&lt;br /&gt;As it happens all we needed to do to get this VOIP app to work through ISA was make sure that the java apps could get through ISA using direct access, add to our tunnel port range and make sure everyone using the app was running the latest version of the firewall client. &lt;br /&gt;&lt;br /&gt;The moral of the story is that you can’t trust vendor instructions when it comes to ISA. Do your own DD (due diligence) and use the ISA logs to determine what steps you need to take. The firewall client is your friend. It’ll handle a lot of port availability issues for your clients on the fly without admin intervention.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-112706162936260604?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/112706162936260604/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=112706162936260604&amp;isPopup=true' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112706162936260604'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112706162936260604'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2005/09/sometimes-voip-wsip-works-with-isa.html' title='Sometimes VOIP w/SIP works with ISA'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-112663177625547506</id><published>2005-09-13T13:15:00.000-04:00</published><updated>2005-09-13T13:16:16.256-04:00</updated><title type='text'>Update to WPAD post made</title><content type='html'>I updated the wpad post to reflect the latest beta version on the file and instructions. Also, note that I've been told that the final version will appear on the Microsoft ISA downloads page.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-112663177625547506?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/112663177625547506/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=112663177625547506&amp;isPopup=true' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112663177625547506'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112663177625547506'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2005/09/update-to-wpad-post-made.html' title='Update to WPAD post made'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-112609950162282090</id><published>2005-09-07T09:25:00.000-04:00</published><updated>2005-09-07T09:27:16.693-04:00</updated><title type='text'>SBS 2003 Unleashed Discount Offered</title><content type='html'>Eriq blogs that a discount is being offered for early orders of the SBS Unleashed book. Order now to save a few bucks.&lt;br /&gt;&lt;br /&gt;See the post &lt;a href="http://www.eonconsulting.net/OnQ/archives/2005/09/on_preorders.shtml"&gt;at On Q&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-112609950162282090?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/112609950162282090/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=112609950162282090&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112609950162282090'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112609950162282090'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2005/09/sbs-2003-unleashed-discount-offered.html' title='SBS 2003 Unleashed Discount Offered'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-112437036083047125</id><published>2005-08-18T09:06:00.000-04:00</published><updated>2005-08-22T13:46:16.423-04:00</updated><title type='text'>SBS2003 Unleashed Coming Soon - 2 ISA2004 Chapters</title><content type='html'>I was recently privileged to write 2 chapters on ISA2004 for the soon to be released SBS 2003 Unleashed book by SAMS. The first announcement that I've seen is available &lt;br /&gt;&lt;a href="http://www.amazon.com/exec/obidos/ASIN/0672328054/qid%3D1124365889/sr%3D11-1/ref%3Dsr%5F11%5F1/104-7774913-1669516"&gt;at Amazon&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The book is meant as a more advanced look at SBS post SP1. &lt;br /&gt;&lt;br /&gt;The lead author is Eriq Neale. I am merely the author of 2 of the books 27 chapters. Great care has gone into making this book full of real how-to examples and troubleshooting by individuals with expertise in the specific area. If you are looking to learn more about ISA and SBS2003 SP1 this is going to be the book to get. Expected availability is November 22.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-112437036083047125?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com' title='SBS2003 Unleashed Coming Soon - 2 ISA2004 Chapters'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/112437036083047125/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=112437036083047125&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112437036083047125'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112437036083047125'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2005/08/sbs2003-unleashed-coming-soon-2.html' title='SBS2003 Unleashed Coming Soon - 2 ISA2004 Chapters'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-112421956214796421</id><published>2005-08-16T15:12:00.000-04:00</published><updated>2005-08-16T15:12:42.156-04:00</updated><title type='text'>Interesting ISA2004 KB's </title><content type='html'>&lt;a href="http://isainsbs.blogspot.com/"&gt;ISA in SBS - yes, it's secure&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;898553&amp;sd=rss&amp;spid=2108"&gt;ISA Server 2004 may stop responding when IP addresses from multiple subnets are bound to the same adaptor&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;895190&amp;sd=rss&amp;spid=2108"&gt;The daily summary and the log report do not contain details of network traffic that passes through an ISA Server 2004 computer&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-112421956214796421?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com/' title='Interesting ISA2004 KB&apos;s '/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/112421956214796421/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=112421956214796421&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112421956214796421'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112421956214796421'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2005/08/interesting-isa2004-kbs.html' title='Interesting ISA2004 KB&apos;s '/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-112421121660458230</id><published>2005-08-16T12:53:00.000-04:00</published><updated>2005-08-16T12:53:36.633-04:00</updated><title type='text'>New ISA Scripts Website</title><content type='html'>&lt;a href="http://isainsbs.blogspot.com/"&gt;ISA in SBS - yes, it's secure&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;In his own words:&lt;br /&gt;&lt;br /&gt;My name is Jason Fossen and I'm a consultant specializing in Microsoft Windows security. I regularly teach a six-day course on Windows security for the SANS Institute, including a course on ISA Server. This web site is where I share materials with my conference attendees, consulting clients, and anyone interested in Windows network security. &lt;a href="http://www.isascripts.org/"&gt;isascripts.org&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The scripts come packaged in a single zip file and admittedly most won't be of use to SBS admins but a few of them will be, like these:&lt;br /&gt;&lt;br /&gt;ISA_Server_2004_Error_Codes.xls&lt;br /&gt;Spreadsheet of names, descriptions and hex numbers of ISA Server 2004 error, cache and response codes.&lt;br /&gt;&lt;br /&gt;ISA_Manage_SSL_Ports.vbs&lt;br /&gt;View and edit permitted outbound HTTPS ports (see KB283284).&lt;br /&gt;&lt;br /&gt;Download and be careful.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-112421121660458230?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com/' title='New ISA Scripts Website'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/112421121660458230/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=112421121660458230&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112421121660458230'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112421121660458230'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2005/08/new-isa-scripts-website.html' title='New ISA Scripts Website'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10396525.post-112377437894549039</id><published>2005-08-11T11:32:00.000-04:00</published><updated>2005-08-11T11:32:58.980-04:00</updated><title type='text'>Top Issues After SBS SP1 Upgrade</title><content type='html'>&lt;a href="http://isainsbs.blogspot.com/"&gt;ISA in SBS - yes, it's secure&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Check out &lt;a href="http://msmvps.com/bradley/archive/2005/08/08/62004.aspx"&gt;Susan Bradley's Blog entry on SBS SP1&lt;/a&gt;. She lists the most common issues and a couple could apply to your upgrade from ISA2000 to ISA2004. &lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10396525-112377437894549039?l=isainsbs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isainsbs.blogspot.com/' title='Top Issues After SBS SP1 Upgrade'/><link rel='replies' type='application/atom+xml' href='http://isainsbs.blogspot.com/feeds/112377437894549039/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10396525&amp;postID=112377437894549039&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112377437894549039'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10396525/posts/default/112377437894549039'/><link rel='alternate' type='text/html' href='http://isainsbs.blogspot.com/2005/08/top-issues-after-sbs-sp1-upgrade.html' title='Top Issues After SBS SP1 Upgrade'/><author><name>Amy - Harbor Computer Services</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_5TevcQE9OIs/TCoW0z3q-HI/AAAAAAAAARw/UUaFVNwVG0A/S220/amysailboatcloser.jpg'/></author><thr:total>0</thr:total></entry></feed>
