<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/MU" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Should You Install Anti-virus Software on Your ISA Firewall?</title>
	<link>http://blogs.isaserver.org/shinder/2006/05/05/should-you-install-anti-virus-software-on-your-isa-firewall/</link>
	<description>Written by Dr Thomas W Shinder, consultant to Microsoft, HP and many Fortune 500 companies on ISA firewall and Web proxy deployments this blog is where administrators get information about ISA Server Universal Threat Management firewalls. Topics include how to manage, deploy, and troubleshoot ISA Server as a network firewall, Web proxy/Web cache, remote access VPN server and VPN gateway to provide a high level of network security for all corporate computers.</description>
	<pubDate>Sat, 22 Nov 2008 12:20:32 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>

	<item>
		<title>by: Mike Hoerner</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/05/should-you-install-anti-virus-software-on-your-isa-firewall/#comment-206921</link>
		<pubDate>Wed, 03 Sep 2008 19:46:51 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/05/should-you-install-anti-virus-software-on-your-isa-firewall/#comment-206921</guid>
					<description>I have ISA 2004 Server configured in Reverse Proxy Mode (Single NIC).  Would your comments above regarding a file-level anti-virus scanner on ISA apply for an ISA Server running as a Reverse Proxy?</description>
		<content:encoded><![CDATA[<p>I have ISA 2004 Server configured in Reverse Proxy Mode (Single NIC).  Would your comments above regarding a file-level anti-virus scanner on ISA apply for an ISA Server running as a Reverse Proxy?
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: tshinder</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/05/should-you-install-anti-virus-software-on-your-isa-firewall/#comment-179748</link>
		<pubDate>Tue, 06 May 2008 23:23:15 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/05/should-you-install-anti-virus-software-on-your-isa-firewall/#comment-179748</guid>
					<description>Hi Paulo,

Not true. You may be thinking of the ISA 2000 networking model. With ISA 2004/2006, internal network users have no more access to the ISA Firewall than external network users. The ISA2004/2006 network model applies stateful packet and application layer inspection on *all* interfaces. So, unless you create a rule that allows internal users and malware access, there's no reason to install AV software on the ISA Firewall (assuming again, that you do not bring the malware in yourself by using the ISA Firewall as a workstation).

Note that is is NOT true for SBS installations -- they broke the ISA networking model to support SBS, so in that case, you would need to use AV/AM software on the SBS machine.

HTH,
Tom</description>
		<content:encoded><![CDATA[<p>Hi Paulo,</p>
<p>Not true. You may be thinking of the ISA 2000 networking model. With ISA 2004/2006, internal network users have no more access to the ISA Firewall than external network users. The ISA2004/2006 network model applies stateful packet and application layer inspection on *all* interfaces. So, unless you create a rule that allows internal users and malware access, there&#8217;s no reason to install AV software on the ISA Firewall (assuming again, that you do not bring the malware in yourself by using the ISA Firewall as a workstation).</p>
<p>Note that is is NOT true for SBS installations &#8212; they broke the ISA networking model to support SBS, so in that case, you would need to use AV/AM software on the SBS machine.</p>
<p>HTH,<br />
Tom
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: paulo.oliveira</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/05/should-you-install-anti-virus-software-on-your-isa-firewall/#comment-179710</link>
		<pubDate>Tue, 06 May 2008 21:56:41 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/05/should-you-install-anti-virus-software-on-your-isa-firewall/#comment-179710</guid>
					<description>Hi Tom,

this is a very unusual opinion, because even if no one uses ISA as &quot;workstation&quot; (not browsing around, download e-mails...) the people from internal network is in charge to do that and a lot more!
So, ISA is &quot;exposed&quot; to the internal network whose, in my opinion is the most untrusted network. All because of the f... users who download e run viruses, worms...</description>
		<content:encoded><![CDATA[<p>Hi Tom,</p>
<p>this is a very unusual opinion, because even if no one uses ISA as &#8220;workstation&#8221; (not browsing around, download e-mails&#8230;) the people from internal network is in charge to do that and a lot more!<br />
So, ISA is &#8220;exposed&#8221; to the internal network whose, in my opinion is the most untrusted network. All because of the f&#8230; users who download e run viruses, worms&#8230;
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Gary Hawkins</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/05/should-you-install-anti-virus-software-on-your-isa-firewall/#comment-166593</link>
		<pubDate>Tue, 11 Mar 2008 13:02:51 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/05/should-you-install-anti-virus-software-on-your-isa-firewall/#comment-166593</guid>
					<description>Hi Tom,

Another great informative article but I need a little more info...

We're running MS ISA 2006 STD both as a web browsing gateway and as a web publisher for internal IIS websites to the external web.

Our outbound web browsing traffic is routed to an MSP and so that traffic does not need AV filtering on-the-box (to reduce user licence costs).

It's proving difficult to find a product that filters the inbound traffic to published websites and which can also be applied to specific rules/groups.

Are you able to provide any further advice on this?

Regards,
G</description>
		<content:encoded><![CDATA[<p>Hi Tom,</p>
<p>Another great informative article but I need a little more info&#8230;</p>
<p>We&#8217;re running MS ISA 2006 STD both as a web browsing gateway and as a web publisher for internal IIS websites to the external web.</p>
<p>Our outbound web browsing traffic is routed to an MSP and so that traffic does not need AV filtering on-the-box (to reduce user licence costs).</p>
<p>It&#8217;s proving difficult to find a product that filters the inbound traffic to published websites and which can also be applied to specific rules/groups.</p>
<p>Are you able to provide any further advice on this?</p>
<p>Regards,<br />
G
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Neil Scott</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/05/should-you-install-anti-virus-software-on-your-isa-firewall/#comment-145238</link>
		<pubDate>Mon, 17 Dec 2007 10:41:59 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/05/should-you-install-anti-virus-software-on-your-isa-firewall/#comment-145238</guid>
					<description>I can't believe this to be the case... if your are running a back-toback firewall then yes I can see that you wouldn't need it on your front-end ISA servers but what about your CSS server that is on the normal LAN and open to attack?

You are saying never to run Internet Explorer on the servers but every admin does this when they quickly need to check something on the web when they are investigating issues.</description>
		<content:encoded><![CDATA[<p>I can&#8217;t believe this to be the case&#8230; if your are running a back-toback firewall then yes I can see that you wouldn&#8217;t need it on your front-end ISA servers but what about your CSS server that is on the normal LAN and open to attack?</p>
<p>You are saying never to run Internet Explorer on the servers but every admin does this when they quickly need to check something on the web when they are investigating issues.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Tom Shinder</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/05/should-you-install-anti-virus-software-on-your-isa-firewall/#comment-1394</link>
		<pubDate>Fri, 09 Jun 2006 14:19:22 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/05/should-you-install-anti-virus-software-on-your-isa-firewall/#comment-1394</guid>
					<description>It should be made clear that you SHOULD NOT install a host AV on the ISA firewall. It doesn't require it if you are a competent ISA firewall admin</description>
		<content:encoded><![CDATA[<p>It should be made clear that you SHOULD NOT install a host AV on the ISA firewall. It doesn&#8217;t require it if you are a competent ISA firewall admin
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Joyce</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/05/should-you-install-anti-virus-software-on-your-isa-firewall/#comment-1385</link>
		<pubDate>Fri, 09 Jun 2006 07:45:49 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/05/should-you-install-anti-virus-software-on-your-isa-firewall/#comment-1385</guid>
					<description>We are living in an internet time where you can not without Anti Virus Software and such. Too bad, but I think it will only get worse by time.

My place for free Anti Virus Software is:
http://www.freespamfilter.nl/uk/anti-virus.htm

They always have the latest and best anti virus  available and have good reviews of all available anit virus programs.

Viruses should be stopped and people distributing these viruses should be put in jail. They jeopardize our operating system.

Joyce</description>
		<content:encoded><![CDATA[<p>We are living in an internet time where you can not without Anti Virus Software and such. Too bad, but I think it will only get worse by time.</p>
<p>My place for free Anti Virus Software is:<br />
<a href='http://www.freespamfilter.nl/uk/anti-virus.htm' rel='nofollow'>http://www.freespamfilter.nl/uk/anti-virus.htm</a></p>
<p>They always have the latest and best anti virus  available and have good reviews of all available anit virus programs.</p>
<p>Viruses should be stopped and people distributing these viruses should be put in jail. They jeopardize our operating system.</p>
<p>Joyce
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
