Re: IAS gurus?

From: Daniel Billingsley (dbillingsley_at_NO.durcon.SPAAMM.com)
Date: 04/25/03


Date: Fri, 25 Apr 2003 10:35:12 -0400


First, it's ISA not IAS. :)

And yes it will do what you want quite easily. You would also get some
additional benefits which you may not need, like firewall capabilities and
ability to log users' internet access (where and when they went).

"Mark" <mwilson@cahga.com> wrote in message
news:076601c30a5d$8488cce0$a401280a@phx.gbl...
> ENVIRONMENT:
> Single Win2K AD domain
> 100 XP clients
>
> OBJECTIVE:
> To restrict outgoing http traffic- 3 groups
>
> FullAccess
> LimitedAccess (allowed to access only certain pre-
> defined/configured sites)
> NoAccess
>
> I can do "authentication" on our firewall, but then I
> would have to create/maintain an additional user
> database. I can configure the firewall
> to send authentication requests to a Radius server.
> However, in both these scenarios users would need to
> authenticate to the firewall via a java
> applet, which MUST remain open (or internet access is cut
> off).
>
> A third option that was vaguely recommended was to set up
> an IAS server & proxy Internet usage from there.
>
> QUESTIONS:
>
> Is just setting up IAS/proxy sufficient to meet my
> objecive? Can I control internal internet access,
> configuring the IAS server to proxy http connection
> attmepts based on user authenticatino? Is this
> over-kill?
>
> ANY RECOMMENDATIONS FOR MEETING THE OBJECTIVE GREATLY
> APPRECIATED!
>
> Thanks upfront,
> Mark
>



Relevant Pages

  • IAS gurus?
    ... To restrict outgoing http traffic- 3 groups ... I can do "authentication" on our firewall, ... an IAS server & proxy Internet usage from there. ... Can I control internal internet access, ...
    (microsoft.public.security)
  • Re: EAP-TLS Radius problem
    ... Do I understand you correctly that with IAS it is not possible to ... domain that the IAS server is in? ... server that is a member of Domain 1. ... Domain1 runs a Radius server to do authentication for wired 802.1x. ...
    (microsoft.public.internet.radius)
  • Re: IAS server stops authenticating workstations and users
    ... Have you tested communication between the IAS server and the RADIUS clients ... Also wondering if you have viewed the IAS ... The IAS server stopped logging. ... server and the authentication process has resumed. ...
    (microsoft.public.internet.radius)
  • Re: IAS and workgroup computers.
    ... guess is that the because PEAP authentication fails, the IAS server does ... IAS can return three responds to authentication equests: ... In this case IAS drops the request, but I would like it to reject it. ...
    (microsoft.public.windows.server.networking)
  • Re: IAS and workgroup computers.
    ... guess is that the because PEAP authentication fails, the IAS server does not ... IAS can return three responds to authentication equests: ... In this case IAS drops the request, but I would like it to reject it. ...
    (microsoft.public.windows.server.networking)