Re: ISA Server or Firewall Appliance?

From: Thor (Hammer of God) (thor_at_hammerofgod.com)
Date: 11/16/05

  • Next message: Derick Anderson: "RE: Renaming Administrator account"
    To: "Marcos Marrero" <mmarrero@LLOYDSTSB-USA.com>
    Date: Wed, 16 Nov 2005 11:23:29 -0800
    
    

    If that is your main argument, the concern of deploying internet services
    with the Windows OS, then why do you guys use Exchange Server for your mail?
    Sounds a tad hypocritical to me.

    t

    p.s. You (or your vendor) are also running V6.0.6603.0- you might want to
    get the latest service pack on your MLVEXCH host.

    ----- Original Message -----
    From: "Marcos Marrero" <mmarrero@LLOYDSTSB-USA.com>
    To: "Jim Harrison (ISA)" <Jim.Harrison@microsoft.com>; "James Eaton-Lee"
    <james.mailing@gmail.com>
    Cc: <focus-ms@securityfocus.com>
    Sent: Wednesday, November 16, 2005 8:26 AM
    Subject: RE: ISA Server or Firewall Appliance?

    I think that the main argument for not deploying ISA in an internet
    facing environment is because of the underlying OS; Windows.

    Windows has been under attack for how many years now? I believe that if
    windows is locked down appropriately it can be used as described above.

    Regards
    Marcos Marrero

    -----Original Message-----

    **********************************************************************
    This Email is intended for the exclusive use of the addressee only.
    If you are not the intended recipient, you should not use the
    contents nor disclose them to any other person and you should
    immediately notify the sender and delete the Email.

    Lloyds TSB Bank plc is registered in England and Wales Number: 2065.
    Registered office: 25 Gresham Street, London EC2V 7HN.

    **********************************************************************

    From: Jim Harrison (ISA) [mailto:Jim.Harrison@microsoft.com]
    Sent: Tuesday, November 15, 2005 5:49 PM
    To: James Eaton-Lee; Marcos Marrero
    Cc: focus-ms@securityfocus.com
    Subject: RE: ISA Server or Firewall Appliance?

    This:
    " The only last point I'd make is that I'd be hesitant in deploying ISA
    in an internet facing role (although I do and have done that before) -
    but I don't really have a justification for this aside from "it just
    doesn't feel quite right".
    "

    ..statement is something that is expressed fairly often, but fortunately
    has not a single grain of substance to it. To James' credit, he does
    qualify his hesistation...
    I know it sounds like marketing spew, but the simple fact is; in 5+
    years of service on anything from an SBS server, OEM appliance to HUGE
    enterprise deployments, ISA server has the distinction of not having
    been the recipient of one single exploit in the wild.

    Yes; we've shipped patches for it and the odds are (realistically
    speaking), we may well do so again. So do Cisco, Juniper, et al and we
    don't hear the "just doesn't feel right" when they need patching.

    Contrast this with literally *no other* firewall maker (truthfully)
    making this claim and you have quite a piece of information at your
    disposal when you present your options in CxO-land.

    Jim Harrison
    Security Platform Group (ISA SE)
    If We Can't Fix It - It Ain't Broke!

    This email has been scanned for all viruses by the MessageLabs SkyScan
    service.

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Derick Anderson: "RE: Renaming Administrator account"

    Relevant Pages

    • RE: 403 forbidden with new server
      ... if you add the windows server 2003 to your SBS 2003 ... How to install Small Business Server 2003 in an existing Active Directory ... How to configure Internet access in Windows Small Business Server 2003 ... configure ISA server as your Proxy ...
      (microsoft.public.windows.server.sbs)
    • Re: Window could not search for new updates.
      ... and " Obtain DNS server address automatically " are marked. ... Windows Update error 8024402C ... Turn on the "Automatically detect ISA server" feature in ISA ... | If you are using Microsoft ISA Firewall Client, ...
      (microsoft.public.windowsupdate)
    • Re: ISA 2004
      ... >> Small Business Server 2003 Premium Edition? ... >> into the Windows Small Business Server 2003 setup and management tools ... Note ISA Server 2004 is only available in the Windows Small ...
      (microsoft.public.windows.server.sbs)
    • Re: ISA2004 for SBS2003?
      ... | Can I obtain ISA 2004 as soon as it ships and install it on Windows ... | Small Business Server 2003 Premium Edition? ... | because ISA Server is integrated (both ISA Server 2000 and ISA Server ...
      (microsoft.public.windows.server.sbs)
    • Re: SBS + Firewall?
      ... Small Business Server 2003 Premium Edition? ... because ISA Server is integrated ... updated wizards will ship as part of Service Pack 1 for Windows Small ...
      (microsoft.public.windows.server.sbs)