Re: MS ISA any good?

From: David (davidwnh@adelphia.net)
Date: 11/21/02


From: "David" <davidwnh@adelphia.net>
Date: Thu, 21 Nov 2002 01:01:55 GMT

I think ISA is fabulous! and so far it seems to be doing its job quite
well(and securely). Once you have it set up it is easy to reconfigure and
monitor. And the amount of control you have over both inbound and outbound
access is tremendous. The logging out of the box is lacking but it is easy
to integrate the logs into SQL server which makes things quite nice.

Is it worth the price? I got it through a developers license so it's hard
for me to comment on this since I don't know what they currently charge per
server and/or seat. I'm sure you can set up most of the same functionality
on a Linux box with cheaper or free software, but the question is do you
have someone who knows Linux well enough, or will the extra time spent
because you don't cost more in the long run? You may not be able to control
the firewall clients on a per application basis as well (if at all) if you
go this route however. As far as the Windows Platform I would imagine you
can get all the same functionality for less however I don't know if it would
all be in the same package or as easy to set up and integrate within your
network. The big difference I see from other solutions is the firewall
client. It allows you to control access on a per application basis without
the configuration hassles of desktop firewalls. This functionality alone
puts this product ahead of many of the other applications I have seen. The
control you have of what happens from inside may be worth any additional
expense this product may have.

Securitywise I wouldn't doubt it has some yet to be discovered flaws,
however overall it is just like everything else they sell. You have to be
sure to tweak the settings. Tweak the OS and uninstall all the extra apps
which expose many of the holes. Also be very careful with other services on
the same machine since they can add certain issues which require further
configuration. With minimal additional services you can probably tighten up
an ISA server quite well.

Go to the Microsoft ISA messageboards and try to get a thread going with Tom
Shindler. He's one of the most knowledgeable I've seen discussing this
product. You may also be able to contact him via isaserver.org

"buzzard" <jwstepanek@yahoo.com> wrote in message
news:c670e63f.0211201416.5c5b5a9e@posting.google.com...
> We have a person at my place of work suggesting implementation of a MS
> Internet Security and Acceleration Server. This will be the primary
> security device, as well as providing web cache services.
>
> My questions would be:
> A) it is really secure? MS does not exactly have a stellar reputation
> for security overall. Is there something about this product which
> would exempt it from this expectation?
> B) Is it worth the money? Are there better alternatives for a better
> price?
> C) Somewhat related to the previous question- is it not possible to
> set up equivalent functions on a BSD or linux box which would have
> comparable functionality (we don't need VPN) and likely better
> security?
>
> Thanks for any help.
>
> James



Relevant Pages

  • RE: Front End/Back End communication
    ... MVP -- ISA Firewalls ... There is no such thing as security perfection. ... single front-end/back-end Exchange Server will find this setup to be ...
    (Focus-Microsoft)
  • Re: Forest/Domain in the "DMZ" to accomodate web, front-end servers
    ... I don't know where you came up with the idea that ISA Server doesn't ... as it's been doing that since ISA 2000 debuted a number of years ago now. ... Who cares if untrusted hosts compromise ... My point is the network edge is not the place to have all your security. ...
    (microsoft.public.security)
  • Re: Security experts criticize an SBS installation
    ... If I had a dime every time some two bit "security expert" thought Microsoft products were insecure I'd have a lot of dimes and a lot of folks that haven't looked at Microsoft products since WinNT. ... I have a GSEC security credential, volunteer for the Center for Internet Security and know that my security of my network is based more on the lack of control of my workstations than it is with that ISA box. ... I cannot, to the best of my knowledge, remember a SBS box that has been hacked when the passwords are long/strong/secure, the box is patched, and the workstations are configured based on the risk of each person. ... But a SBS server ..even with that "so called" hacked in umpteen minutes ISA server ...Get him to tell you in details how he hacked into ISA server. ...
    (microsoft.public.windows.server.sbs)
  • Re: Can not access web from ISA Server
    ... a mail server and a stats server. ... Thank you for your patience with my security noobishness... ... > publish a web site that is behind the ISA. ... > browser and you must configure an Access Rule just for it. ...
    (microsoft.public.isa)
  • RE: [fw-wiz] Microsoft ISA
    ... Believe it or not ISA is one of the first software packages from ... Depending on your security ... Server off the DMZ interface). ... other Microsoft Documentation. ...
    (Firewall-Wizards)