Firewall Wizards mailing list archives
Re: Microsoft ISA Server
From: "Patrick M. Hausen" <hausen () punkt de>
Date: Sat, 22 Jun 2002 20:18:13 +0200 (CEST)
Hi wizards! Ron Woerner wrote:
We are looking at possibly using Microsoft's ISA Server as our organization's firewall. There are few reviews of it and it doesn't appear that it is used by many organizations. Is anyone on the list using it? Does anyone have an opinion on it? How well does it work as a firewall? What are its pros and cons?
One of our customers uses it extensively - not as a firewall, though. Being almost an old timer in setting up firewalls and always using a conservative if not fashist approach to policies, I was amazed, or better yet, stunned, by the wealth of features and granularity of control ISA provided. This was exactly what the customer demanded - fine grained control about which user is allowed to do what at which time, etc. All this based on MS Active Directory users and groups. This is where the Gauntlet I sold them failed cold. Of course you can set up Gauntlet (or any other decent firewall for that matter) to authenticate users using RADIUS or LDAP and interface to NT Domains or Active Directory that way. Maybe you can even use M$ group memberships. But one thing Gauntlet can't do: NTLM authentication. This is a M$ proprietary protocol that takes care of "single sign on", i.e. you authenticate to your Active Directory once - and that's that. No HTTP 401 asking you for a username and password _again_ when you first use the proxy. Authentication for using services that don't support authentication themselves. You can even allow or disallow ICMP (ping) to the Internet based on Active Directory user/group. User starts to ping an external host. The ISA can use NT protocol to ask who's logged on to the workstation and ask the Active Directory server if said user is part of the "Allow Ping" group. Weird. Honestly, I've never seen something like this - no wonder M$ gained such a huge market share.
P.S. My instincts say "don't trust Microsoft", however I want to be fair.
Well, the drawback - it's from M$. It runs on Win2k only. _I_ for once would _never_ put a Win2K machine on an Internet uplink without an additional layer of security in front. Remember, a firewall is a policy enforcement device. ISA does a hell of a good job about policies - as far as _internal_ users are concerned. Given the long history of exploit after exploit M$ products had, I wouldn't trust it to enforce policies against malicious attacks from the outside. Second - if you use it as your only line of defense and you like and use the features - you are really locked in to M$ once and for all. Our customer runs a Gauntler firewall in front of an ISA server and is really really happy with it. They "pretend" ISA isn't a firewall but only does internal policies based on Active Directory. If they are ever unhappy with their "real" firewall (Gauntlet) - well, switch it for something better. Enough babble for now - hope, that's helpful, Patrick M. Hausen Technical Director -- punkt.de GmbH Internet - Dienstleistungen - Beratung Scheffelstr. 17 a Tel. 0721 9109 -0 Fax: -100 76135 Karlsruhe http://punkt.de _______________________________________________ firewall-wizards mailing list firewall-wizards () nfr com http://list.nfr.com/mailman/listinfo/firewall-wizards
Current thread:
- Microsoft ISA Server RWoerner (Jun 21)
- RE: Microsoft ISA Server B. Scott Harroff (Jun 21)
- RE: Microsoft ISA Server Bill Royds (Jun 21)
- Re: Microsoft ISA Server Mikael Olsson (Jun 22)
- Re: Microsoft ISA Server R. DuFresne (Jun 22)
- Re: Microsoft ISA Server Patrick M. Hausen (Jun 22)
- RE: NTLM on firewalls (was: Microsoft ISA Server) Ben Nagy (Jun 24)
- Re: NTLM on firewalls (was: Microsoft ISA Server) Darren Reed (Jun 25)
- RE: NTLM on firewalls (was: Microsoft ISA Server) Ben Nagy (Jun 24)
- <Possible follow-ups>
- Re: Microsoft ISA Server R. DuFresne (Jun 26)
