Firewall Wizards mailing list archives

Re: Microsoft ISA Server


From: "Patrick M. Hausen" <hausen () punkt de>
Date: Sat, 22 Jun 2002 20:18:13 +0200 (CEST)

Hi wizards!

Ron Woerner wrote:

We are looking at possibly using Microsoft's ISA Server as our
organization's firewall.
There are few reviews of it and it doesn't appear that it is used by many
organizations.
Is anyone on the list using it?
Does anyone have an opinion on it?
How well does it work as a firewall?
What are its pros and cons?

One of our customers uses it extensively - not as a firewall, though.

Being almost an old timer in setting up firewalls and always using
a conservative if not fashist approach to policies, I was amazed, or
better yet, stunned, by the wealth of features and granularity of
control ISA provided.

This was exactly what the customer demanded - fine grained control
about which user is allowed to do what at which time, etc.
All this based on MS Active Directory users and groups. This is
where the Gauntlet I sold them failed cold. Of course you can
set up Gauntlet (or any other decent firewall for that matter)
to authenticate users using RADIUS or LDAP and interface to NT Domains
or Active Directory that way. Maybe you can even use M$ group memberships.

But one thing Gauntlet can't do: NTLM authentication. This is a
M$ proprietary protocol that takes care of "single sign on",
i.e. you authenticate to your Active Directory once - and that's
that. No HTTP 401 asking you for a username and password _again_
when you first use the proxy. Authentication for using services
that don't support authentication themselves. You can even
allow or disallow ICMP (ping) to the Internet based on Active
Directory user/group. User starts to ping an external host.
The ISA can use NT protocol to ask who's logged on to the workstation
and ask the Active Directory server if said user is part of the
"Allow Ping" group. Weird.

Honestly, I've never seen something like this - no wonder
M$ gained such a huge market share.

P.S.  My instincts say "don't trust Microsoft", however I want to be fair.

Well, the drawback - it's from M$. It runs on Win2k only.
_I_ for once would _never_ put a Win2K machine on an Internet uplink
without an additional layer of security in front.

Remember, a firewall is a policy enforcement device. ISA does a hell
of a good job about policies - as far as _internal_ users are concerned.
Given the long history of exploit after exploit M$ products had,
I wouldn't trust it to enforce policies against malicious attacks
from the outside.

Second - if you use it as your only line of defense and you
like and use the features - you are really locked in to M$ once
and for all.

Our customer runs a Gauntler firewall in front of an ISA server
and is really really happy with it.
They "pretend" ISA isn't a firewall but only does internal
policies based on Active Directory. If they are ever unhappy with
their "real" firewall (Gauntlet) - well, switch it for something better.

Enough babble for now - hope, that's helpful,

Patrick M. Hausen
Technical Director
-- 
punkt.de GmbH         Internet - Dienstleistungen - Beratung
Scheffelstr. 17 a     Tel. 0721 9109 -0 Fax: -100
76135 Karlsruhe       http://punkt.de
_______________________________________________
firewall-wizards mailing list
firewall-wizards () nfr com
http://list.nfr.com/mailman/listinfo/firewall-wizards


Current thread: