The Experts below are selected from a list of 6 Experts worldwide ranked by ideXlab platform
Thomas W. Shinder - One of the best experts on this subject based on the ideXlab platform.
-
Chapter 7 – ISA 2006 Stateful Inspection and Application Layer Filtering
Dr. Tom Shinder's ISA Server 2006 Migration Guide, 2007Co-Authors: Thomas W. ShinderAbstract:Publisher Summary This chapter describes ISA 2006 stateful inspection and application layer filtering. The ISA firewall's Simple Mail Transfer Protocol (SMTP) filter configuration interface can be accessed by opening the Microsoft Internet Security and Acceleration Server 2006 management console, expanding the server name and then, expanding the Configuration node. The Post Office Protocol (POP) Intrusion Detection filter protects POP3 servers published by the ISA firewall using Server Publishing Rules from POP services buffer overflow attacks. There is no configuration interface for the POP Intrusion Detection filter. The Firewall client is a generic Winsock Proxy client application. All applications designed to the Windows Sockets specification will automatically use the Firewall client. The Maximum headers length option allows you to configure the maximum length of all headers included in a request Hypertext Transfer Protocol (HTTP) communication. This setting applies to all Rules that use the HTTP Security filter. The Allow only specified methods option allows you to specify the exact methods you want to allow through the ISA firewall. It is found that an HTTP policy can be exported from or imported into an Access Rule that uses the HTTP protocol, or a Web Publishing Rule.
-
Publishing Network Services with ISA 2004 Firewalls
How to Cheat at Configuring ISA Server 2004, 2006Co-Authors: Thomas W. ShinderAbstract:The chapter discusses features and capabilities of Web and Server Publishing Rules. Web Publishing and Server Publishing Rules allow making servers and services on ISA firewall protected networks available to users on both protected and non-protected networks. Web and Server Publishing Rules allow to make popular services, such as SMTP, NNTP, POP3, IMAP4, Web, OWA, NNTP, Terminal Services, and many more available to users on remote networks or on other internal or perimeter networks. Web Publishing Rules and Server Publishing Rules provide very different feature sets and are used for very different purposes. In general, Web Publishing Rules should be used to publish Web servers and services, and Server Publishing Rules should be used to publish non-Web servers and services. Web Publishing Rules are used to publish Web sites and services. Web Publishing is sometimes referred to as “reverse proxy.” When one publishes a Website, the ISA firewall's Web Proxy filter always intercepts the request and then proxies the request to the Website published by the Web Publishing Rule.