Microsoft Qualified Consulting Microsoft ISA Server 2006 Help: Design, Integration, Troubleshooting
Introduction to Microsoft ISA Server 2006
Microsoft Internet Security and Acceleration (ISA) Server 2006 is an important part of any security solution for organizations ranging from small businesses to global enterprises. As with ISA Server 2004, Microsoft Internet Security and Acceleration Server 2006 combines an application-layer firewall with virtual private networking (VPN), proxy, and Web-caching capabilities. Features of ISA Server 2006 that make it the platform of choice for solving main office and branch office security concerns include:
Integrated intrusion detection system and intrusion prevention system
Web proxy access controls
Web proxy Web application inspection filters
Comprehensive logging and reporting
Real-time alerting
Microsoft ISA Server 2006 and Secure Application Publishing
Secure Application Publishing with ISA Server 2006 allows greater control over intranet resources while enabling increased productivity by making these resources available to authorized remote users. ISA Server 2006 helps protect corporate applications, services, and data across all network layers with stateful packet inspection, application-layer filtering, and comprehensive publishing tools. A major advantage of ISA Server 2006 is its tight integration with other key business applications and services such as Microsoft Exchange Server, Microsoft SharePoint Portal Server, Active Directory, and Terminal Services. For organization that need to provide secure access to these vital internal resources, ISA Server 2006 is the natural choice.
Intelligent Application Gateway (IAG) 2006
Microsoft offers the Intelligent Application Gateway (IAG) 2007 as a high-performance application access and security appliance integrated with ISA Server 2006. IAG 2007 provides SSL VPN, a Web application firewall, and endpoint security management that enable access control, authorization and content inspection for a wide variety of line-of-business applications. these technologies provide mobile and remote workers with easy and flexible secure access from a broad range of devices and locations including PCs, and mobile devices. IAG also enables IT administrators to enforce compliance with application and information usage guidelines through a customized remote access policy based on device, user, application or other business criteria.
Secure Server Publishing
Businesses typically need to make web servers, email servers, and e-commerce applications available to authorized external users and customers without compromising the protection of those resources against a variety of threats. Traditional firewalls can be difficult to configure for these purposes, leading to misconfigurations. Microsoft estimates that 95% of application layer breaches result from poor configurations. ISA Server 2006 can impersonate internal servers through a reverse proxy process known as publishing to add a layer of security at the network edge.
Web Server Publishing with ISA Server 2006 is more secure and flexible than traditional web publishing. Because ISA Server 2006 inspects HTTP content before it reaches the web servers, it provides one element of a defense-in-depth strategy. It can also be used as a central location to block disallowed web requests, which is easier than configuring each web server individually. ISA Server 2006 processes only allowed URLs and blocks any disallowed or invalid HTTP syntax. It can also block based on signatures in the HTTP request or response. ISA Server 2006 builds upon the functionality of ISA Server 2004 to enable and optimize secure web publishing scenarios, including Windows SharePoint Services publishing, Microsoft Outlook Web Access (OWA) publishing, publishing of multiple Web sites, and publishing of Web server farms.
Windows SharePoint Services are a popular solution for companies to enable internal collaboration. The SharePoint Publishing Wizard introduced in ISA Server 2006 makes it easy to provide that same collaborative functionality to external audiences including remote employees and business partners. With this wizard, publishing multiple sites simultaneously is quick, easy and secure, with link translation being implemented automatically so that remote clients can resolve the addresses of internal server pages with externally accessible pages. The Microsoft SharePoint Portal Server Application Optimizer included with IAG 2007 delivers out-of-the-box capabilities to extend extranet access to SharePoint from any Internet-enabled device. The SharePoint Application Optimizer provides the ability to:
Ensure controlled access for unmanaged endpoints to SharePoint, enabling broader access that incorporates partners and customers
Delivers full Microsoft Office compatibility functionality without the need to download network tunneling components
Integrate third-party, legacy or client / server applications into SharePoint Portal Server
Microsoft Exchange Server Publishing is provided with added security in ISA Server 2006. This includes support for Microsoft Outlook Mobile Access and Microsoft Exchange ActiveSync for PocketPC. Exchange Server publishing allows administrators to provide secure access to internal Exchange servers. The New Mail Server Publishing Rule Wizard makes it easy for administrators to publish email servers using RPC, IMAP, POP3, and SMTP for client access. It also allows for server-to-server communications using SMTP and Network News Transfer Protocol (NNTP). ISA Server 2006 allows remote users to connect to Exchange using the fully functional Outlook MAPI client over the Internet. The Outlook client may be configured to use secure RPC so that the connection is encrypted and the ISA Server 2006 firewall can be configured to require only encrypted communications from the full Outlook MAPI client. The Exchange Server Application Optimizer included with IAG 2007 enables a seamless user experience through support for Windows-based login scripts and Single Sign-on, removing the need for multiple authentication requests.
Outlook Web Access (OWA) is integrated into ISA Server 2006. A new publishing wizard makes it easy to allow secure remote access to Outlook Web Access Web sites. You can easily publish Exchange through traditional protocols, Web client access (including Outlook Web Access, Outlook Mobile Access, and Exchange ActiveSync), or server-to-server communication. When publishing Outlook Web Access, you can choose to include any combination of popular methods including Outlook Web Access, Outlook RPC over HTTP, Outlook Mobile Access, and Exchange ActiveSync. You also have the option of publishing a single server or a server farm.
The Application Optimizer for Microsoft Dynamics CRM 3.0 included with IAG 2007 helps provide secure publishing of the CRM Web portal, with customized policies that handle CRM-specific user actions, security and information safeguards. The Microsoft Dynamics Application Optimizer includes:
Upload / Download URL controls
Restricted Zones – Block Access to Settings area
Policy-based access control with Microsoft CRM 3.0 Enhanced Security
How Progent's Consultants Provide Help for Microsoft ISA Server 2006
Progent's Microsoft-qualified Internet Security and Acceleration (ISA) 2006 consultants can help you plan, install, configure, and support ISA Server 2006 on your network so that your business achieves a smart and affordable combination of security, convenience, and performance. Progent's ISA Server 2004 consultants and ISA Server 2000 experts have experience helping companies of all sizes migrate to ISA Server 2006 in ways that minimize business disruption, management hassle, and IT expense. Progent's CISM and CISSP certified security consultants can help you develop a comprehensive security strategy that integrates key platforms including Exchange Server 2007 for secure messaging and Microsoft Operations Manager for server monitoring and alerts as well as automated repair. Progent's large team of Cisco CCIE network engineers can deliver top-level consulting in designing and troubleshooting a sophisticated security infrastructure that is built on Cisco's powerful products including PIX and ASA appliances.
If you want help with planning, maintaining or troubleshooting ISA Server 2006, call 800-993-9400 or contact isa-server-help@progent.com