đź“°

Server Publishing

Reverse Proxy + Reverse Cache
Doesn’t expose any details of internal web server, no routing.
Web Publishing Supports HTTP, HTTPS, FTP
Server Publishing supports other services but loses cache features

Local Domain Table (LDT)

Firewall client uses ISA as a DNS proxy.
Local Domain Table
Webproxy use ISA as a DNS Proxy, doesn’t look at local domain table by default
notion image

Destination Set

Can be restricted to a virtual directory
Internal Web Server Destination Set

Incoming Web Requests Listener

Default port 80
notion image

Web Publishing

Default rule, order is last. Deny request.
notion image
notion image

Server Publishing

  1. Name the rule
  1. Map the addresses
  1. Chose the protocol (create a protocol definition)
  1. Select the clients
Only shows inbound protocol definitions
  • You can only publish a service once per external interface
  • You cannot redirect ports (Except on web server publishing)
  • ISA server does not support address binding
  • Publishing a web server though server publishing causes the loss of caching features

Mail Server Publishing

Secure mail server wizard
notion image
Recommend not to enable Exchange/Outlook and use VPN instead.
Doesn’t create rules for Outlook Web Access, use web publishing wizard

Message screener

Filter incoming email based on
  • Attachments
  • Users/domains
  • Keywords
  • SMTP domains
Requires the following
  • ISA SMTP filter configured and active
  • Server running IIS 5.0 (or later) with SMTP service running & message screener installed
  • Internal mail server
    • notion image
Change IP to only internal
Add all domains to receive mail for
notion image
Add Exchange server IP as smart host, need to be in square brackets
notion image
Create SMTP rule with internal IP of IIS server
Enable SMTP filter

H.323 Gatekeepers

ITU standard defining
  • how audio/video connections are established
  • how devices negotiate capabilities
  • how audio/video codecs are used
Functions of the gatekeeper
  • Watch bandwidth
  • Resolve numbers and /or emails
Configured from separate section of ISA Management, need to be selected during install.
notion image
 
notion image
notion image
notion image
notion image
Â