Interesting ... Anyway if ISA FW Service is in stopped state you LAN isn't exposed to the Internet as ISA becomes "closed box" which is called Lockdown mode.
What is your ISA's version: 2k, 2k4 or 2k6?
Have it aver worked before? What did you change and after that FW service can not start? What...
You have 2 options:
1. Use ISA box as a Second FW to form your DMZ (which is a network between PIX internal interface and ISA external interface)
2. Use ISA box as a Router between PIX and Internal network. (with packet inspection, but not "really" like a Protection mechanism)
Further ISA conf...
You can use the same External Interface to terminate multiple Site-to-Site VPN tunnels. No problem.
Victor(MCS)
MCSA/MCSE:Security & Messaging;CNE;CCSE+;CIWSP;CIWSA;Network+;Security+;CCNA;nCSE;CISSP
Hello,
I think you can use DFS for this purpose: server to server Folder replication mechanism.
Or you'd like to replicate Folders from the server to the clients?
Victor(MCS)
MCSA/MCSE:Security & Messaging;CNE;CCSE+;CIWSP;CIWSA;Network+;Security+;CCNA;nCSE;CISSP
NO, it's not the same as the system policy. System policy is being applied first before all the other rules. But anyway, the recommendation given by nhidalgo is very correct as well.
Victor(MCS)
MCSA/MCSE:Security & Messaging;CNE;CCSE+;CIWSP;CIWSA;Network+;Security+;CCNA;nCSE;CISSP
You can create a rule which will allow users to access a specific URL. You have to place this rule before the rule which does not allow access to the internet (or whatever you have)
Victor(MCS)
MCSA/MCSE:Security & Messaging;CNE;CCSE+;CIWSP;CIWSA;Network+;Security+;CCNA;nCSE;CISSP
The answer is: no. There is a clear statement in Exch2k7 help: Only the Mailbox server role can be installed in a cluster. No other server roles can be installed on a computer that is part of a server cluster.
Victor(MCS)
MCSA/MCSE:Security &...
Hi,
Look here for great tools: http://www.isatools.org/tools.asp?Context=ISA2000
Victor(MCS)
MCSA/MCSE:Security & Messaging;CNE;CCSE+;CIWSP;CIWSA;Network+;Security+;CCNA;nCSE;CISSP
Hi,
First of all we (MS) do not recommend to put Exchange 2003 FE server in the DMZ which is separated by FW, because the Exchange 2003 FE should be a member of the AD domain and thus your BE FW will be like a swiss cheese and will not really be a FW.
Put your Exch FE in the LAN.
IF you 're...
Why do you need iSA, - you'll use it as a Firewall or as a Proxy server only or both?
I would recommend to install ISA 2004 (2006 - better), but not ISA 2000, because ISA 2000 is not a Firewall at all and it can not protect your assets effectively.
Victor(MCS)
MCSA/MCSE:Security &...
Do you have your ISA as the domain member or it's in a workgroup?
Did you exclude your local domain in Internal LAN settings?
Victor(MCS)
MCSA/MCSE:Security & Messaging;CNE;CCSE+;CIWSP;CIWSA;Network+;Security+;CCNA;nCSE;CISSP
Do you have all PCs with FW Client installed? Then it's better to use this client to automatically configure IE Proxy settings through WPAD file rather than to use GPO.
Look here for more info on trobleshooting ISA client: http://www.microsoft.com/technet/isa/2004/plan/troubleshooting_fwc.mspx...
Hello,
Interesting issue ... does this behavior relates to all traffic going through ISA or just to a particular protocol?
Did I understand you correctly:
You do have the following topology: Internet - ISA2k6 Box - Intranet. Here you have mentioned issue. If you remove ISA box and will conect...
In Exchange 2007 this is not very straightforward. Here is the article which will guide you step-by-step: http://msexchangeteam.com/archive/2006/12/28/432013.aspx
Victor(MCS)
MCSA/MCSE:Security & Messaging;CNE;CCSE+;CIWSP;CIWSA;Network+;Security+;CCNA;nCSE;CISSP
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.