RE: ISA Server or Firewall Appliance?

From: Jim Harrison (ISA) (Jim.Harrison_at_microsoft.com)
Date: 11/17/05

  • Next message: John Kinsella: "Re: ISA Server or Firewall Appliance?"
    Date: Wed, 16 Nov 2005 15:23:27 -0800
    To: "Marcos Marrero" <mmarrero@LLOYDSTSB-USA.com>, "James Eaton-Lee" <james.mailing@gmail.com>
    
    

    There is a clear distinction between "under attack" and "compromised".
    If you still live in the NT4 days of "a vuln a week", then you need to
    move with us into the 21st century.

    The biggest advantage to ISA 2004 in particular is that it's
    self-protecting; even in a single-net deployment. IOW, Joe Virus has a
    much smaller attack surface and consequently has to work much harder to
    get to the Os that's also considerably hardened since NT4.

    Jim Harrison
    Security Platform Group (ISA SE)
    If We Can't Fix It - It Ain't Broke!

    -----Original Message-----
    From: Marcos Marrero [mailto:mmarrero@LLOYDSTSB-USA.com]
    Sent: Wednesday, November 16, 2005 8:26 AM
    To: Jim Harrison (ISA); James Eaton-Lee
    Cc: focus-ms@securityfocus.com
    Subject: RE: ISA Server or Firewall Appliance?

    I think that the main argument for not deploying ISA in an internet
    facing environment is because of the underlying OS; Windows.

    Windows has been under attack for how many years now? I believe that if
    windows is locked down appropriately it can be used as described above.

    Regards
    Marcos Marrero

    -----Original Message-----

    **********************************************************************
    This Email is intended for the exclusive use of the addressee only.
    If you are not the intended recipient, you should not use the
    contents nor disclose them to any other person and you should
    immediately notify the sender and delete the Email.

    Lloyds TSB Bank plc is registered in England and Wales Number: 2065.
    Registered office: 25 Gresham Street, London EC2V 7HN.

    **********************************************************************

    From: Jim Harrison (ISA) [mailto:Jim.Harrison@microsoft.com]
    Sent: Tuesday, November 15, 2005 5:49 PM
    To: James Eaton-Lee; Marcos Marrero
    Cc: focus-ms@securityfocus.com
    Subject: RE: ISA Server or Firewall Appliance?

    This:
    " The only last point I'd make is that I'd be hesitant in deploying ISA
    in an internet facing role (although I do and have done that before) -
    but I don't really have a justification for this aside from "it just
    doesn't feel quite right".
    "

    ..statement is something that is expressed fairly often, but fortunately
    has not a single grain of substance to it. To James' credit, he does
    qualify his hesistation...
    I know it sounds like marketing spew, but the simple fact is; in 5+
    years of service on anything from an SBS server, OEM appliance to HUGE
    enterprise deployments, ISA server has the distinction of not having
    been the recipient of one single exploit in the wild.

    Yes; we've shipped patches for it and the odds are (realistically
    speaking), we may well do so again. So do Cisco, Juniper, et al and we
    don't hear the "just doesn't feel right" when they need patching.

    Contrast this with literally *no other* firewall maker (truthfully)
    making this claim and you have quite a piece of information at your
    disposal when you present your options in CxO-land.

    Jim Harrison
    Security Platform Group (ISA SE)
    If We Can't Fix It - It Ain't Broke!

    This email has been scanned for all viruses by the MessageLabs SkyScan
    service.

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: John Kinsella: "Re: ISA Server or Firewall Appliance?"

    Relevant Pages

    • RE: ISA, VPNs and false positives
      ... You can configure ISA 2004 log as follows: ... ISA Server features an intrusion-detection ... mechanism that identifies when an attack is attempted against your network. ... If you have enabled the intrusion detection on ISA, ...
      (microsoft.public.windows.server.sbs)
    • Re: Publishing ftp server
      ... if the attack "fits" one of the attack profiles ISA is built to look ... Understanding the ISA 2004 Access Rule Processing ... Microsoft Internet Security & Acceleration Server: Partners ... Microsoft ISA Server Partners: Partner Hardware Solutions ...
      (microsoft.public.isa.publishing)
    • RE: ISA Server or Firewall Appliance?
      ... it was because whomever deployed ISA did so very poorly. ... ISA Server or Firewall Appliance? ... " The only last point I'd make is that I'd be hesitant in deploying ISA ...
      (Focus-Microsoft)
    • Re: Port Scan Warnings from ISA
      ... > "ISA Server name: OURSERVER ... > ISA Server detected a well-known port scan attack from Internet Protocol ...
      (microsoft.public.backoffice.smallbiz2000)
    • Port Scan Warnings from ISA
      ... "ISA Server name: OURSERVER ... ISA Server detected a well-known port scan attack from Internet Protocol ...
      (microsoft.public.backoffice.smallbiz2000)