Thomas Shinder Blog RSS

All Blogs  »  Thomas Shinder Blog  »  ISA Central  »  Blog article: Three Tips for Configuring the HTTP Secuirty Filter for OWA Rules

Three Tips for Configuring the HTTP Secuirty Filter for OWA Rules

One thing that is often forgotten after configuring an OWA Web Publishing Rule on the ISA firewall is configuration of the HTTP Security Filter. This is unfortunate, as the HTTP Security Filter is one of the core security technologies that makes the ISA firewall superior to the typical "hardware" firewall you may have in use today.

If you have configured the HTTP Security Filter for your OWA rule, here are three tips that can help you out with configuration and troubleshooting of the OWA Web Publishing Rule:

Tip 1
Blocking .exe file extensions and enabling Block responses containing Windows executable content for Outlook Web Access will block access to the S/MIME control. If the S/MIME control is required for Outlook Web Access on Exchange Server 2003, do not include .exe in the blocked extensions list or enable Block responses containing Windows executable content.

Tip 2
Blocking .dll file extensions for Outlook Web Access will block access to the online spelling checker that is built into Outlook Web Access.

Tip 3
Including the strings “..” (two dots), "%" (percent sign), and "&" (ampersand)can prevent certain types of potential attacks but it will also reduce access to certain e-mail messages. An e-mail message subject line forms part of the URL to access the message and thus any e-mail message containing one of these characters will be blocked. A balance must be found between extra security and functionality. Do not include the ":" (colon) character in this list because this will block access to the majority of e-mail messages. Many message subject lines contains RE: and FW: if they are replies or forwards.

For detailed  information on configuring the HTTP Security Filter, check out HTTP Filtering for ISA 2004 Firewalls at http://www.microsoft.com/technet/prodtechnol/isa/2...g.mspx

HTH,

Tom

Thomas W Shinder, M.D.

Site: www.isaserver.org

Blog: http://blogs.isaserver.org/shinder/

Book: http://tinyurl.com/3xqb7

MVP — ISA Firewalls

2 Responses to “Three Tips for Configuring the HTTP Secuirty Filter for OWA Rules”

  1. Steven Hope Says:

    July 22nd, 2006 at 7:05 am

    And of course if you want granular HTTP & SMTP filter settings for publishing exchange take a look here:

    http://www.microsoft.com/technet/prodtechnol/isa/2...3.mspx

    Steven Hope
    Vircom Ltd
    Microsoft Gold Partners
    htp://www.vircom.co.uk

  2. Dll Files Dude Says:

    July 27th, 2007 at 6:50 pm

    We have had a bear of a time with this issue, probably should have called in an expert on this, but we did it ourself.

    We went from Pop 3 Squirrel Mail to Exchage server and OWA options…

    Nice article wish i would have read this 3 weeks ago… still doing my homework and its friday night… and im off the clock if that tells you anything.

    Thanks
    Mike Miller
    NC Tech Support Team

Leave a Reply

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 5 chars within 0..9 and A..F, and submit the form.

  

If CAPTCHA image is missing or you cannot read the characters above, please generate a




Receive all the latest articles by email!

Receive Real-Time & Monthly ISAserver.org article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become an ISAserver.org member!

Discuss your ISA Server issues with thousands of other ISA Server experts. Click here to join!

Solution Center