<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/MU" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: 2006 ISA Firewall New Feature Contest</title>
	<link>http://blogs.isaserver.org/shinder/2006/08/08/2006-isa-firewall-new-feature-contest/</link>
	<description>Written by Dr Thomas W Shinder, consultant to Microsoft, HP and many Fortune 500 companies on ISA firewall and Web proxy deployments this blog is where administrators get information about ISA Server Universal Threat Management firewalls. Topics include how to manage, deploy, and troubleshoot ISA Server as a network firewall, Web proxy/Web cache, remote access VPN server and VPN gateway to provide a high level of network security for all corporate computers.</description>
	<pubDate>Wed,  7 Jan 2009 20:58:23 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>

	<item>
		<title>by: Sam</title>
		<link>http://blogs.isaserver.org/shinder/2006/08/08/2006-isa-firewall-new-feature-contest/#comment-113029</link>
		<pubDate>Mon, 13 Aug 2007 15:11:51 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/08/08/2006-isa-firewall-new-feature-contest/#comment-113029</guid>
					<description>I've got to stop drinking and computing, it doesn't seem to be a productive combination :)

I've just spotted the book on Amazon so will toddle off to get it.

All the best,

Sam</description>
		<content:encoded><![CDATA[<p>I&#8217;ve got to stop drinking and computing, it doesn&#8217;t seem to be a productive combination <img src='http://blogs.isaserver.org/shinder/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I&#8217;ve just spotted the book on Amazon so will toddle off to get it.</p>
<p>All the best,</p>
<p>Sam
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Tom Shinder</title>
		<link>http://blogs.isaserver.org/shinder/2006/08/08/2006-isa-firewall-new-feature-contest/#comment-112143</link>
		<pubDate>Thu, 09 Aug 2007 22:10:47 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/08/08/2006-isa-firewall-new-feature-contest/#comment-112143</guid>
					<description>Hi Sam,

It's a great list! The contest has been over for awihle though :)

Tom</description>
		<content:encoded><![CDATA[<p>Hi Sam,</p>
<p>It&#8217;s a great list! The contest has been over for awihle though <img src='http://blogs.isaserver.org/shinder/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Tom
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Sam Price</title>
		<link>http://blogs.isaserver.org/shinder/2006/08/08/2006-isa-firewall-new-feature-contest/#comment-112132</link>
		<pubDate>Thu, 09 Aug 2007 20:30:42 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/08/08/2006-isa-firewall-new-feature-contest/#comment-112132</guid>
					<description>ISA 2004 seemed the business after ISA 2000.  The upgrade to ISA 2006 has made ISA 2004 start to seem a bit holey and unfinished.  ISA 2006 fills in many of these gaps nicely.  Here follows my (slightly plagiarised) list of swanky new ISA 2006 features...  

Support of secure LDAP authentication rather than sniffable LDAP support
LDAPS for publishing authentication for to multiple forests making LDAP auth a secure, slick, and simple replacement for RADIUS/ RADIUS proxy services
Built in wizard for Exchange 2007 publishing
Built in wizard for Microsoft SharePoint publishing
Return of the VPN wizard, for branch office connections etc
VPN unattended answer file support
Supports single sign-on, if you visit web sites in the same domain and by the same web lisener you'll use cached credentials rather than having to re-authenticate
Cross-Array link translation allowing published web sites across multiple arrays with global entries within the link translation dictionary
Ability to perform website load balancing on the cheap
Forms based authentication for all published web sites
Support for password changes on the log in page
Log on form warns users about pending password expiration
Better support for hardware SSL kit when using ms network load balancing 
Lets you add multiple VIP's through the web interface rather than having to configure your NIC
Improved flood resiliency, i.e. more options
Log throttling to protect the server from DOS against itself
Web Publishing Load Balancing with cookie-based affinity for Integrated NLBS
Better certificate management and Link translation
Support for published configuration storage servers
Improved MOM management pack
Logging supports logging the referring server for connections made to published servers


And for good measure, some things that have been removed... 

ISA 2006 drops support for Windows 2000 as the host platform (no great loss there then)
ISA 2006 isn’t yet EAL4+ certified (come on ISA 2006, you can do it!)

Apologies to any writers of ISA books who may have been plagiarised in the making of this post....  at least I've bought your other books, which continue to save my bacon on most ISA installations!

Kind Regards

Sam</description>
		<content:encoded><![CDATA[<p>ISA 2004 seemed the business after ISA 2000.  The upgrade to ISA 2006 has made ISA 2004 start to seem a bit holey and unfinished.  ISA 2006 fills in many of these gaps nicely.  Here follows my (slightly plagiarised) list of swanky new ISA 2006 features&#8230;  </p>
<p>Support of secure LDAP authentication rather than sniffable LDAP support<br />
LDAPS for publishing authentication for to multiple forests making LDAP auth a secure, slick, and simple replacement for RADIUS/ RADIUS proxy services<br />
Built in wizard for Exchange 2007 publishing<br />
Built in wizard for Microsoft SharePoint publishing<br />
Return of the VPN wizard, for branch office connections etc<br />
VPN unattended answer file support<br />
Supports single sign-on, if you visit web sites in the same domain and by the same web lisener you&#8217;ll use cached credentials rather than having to re-authenticate<br />
Cross-Array link translation allowing published web sites across multiple arrays with global entries within the link translation dictionary<br />
Ability to perform website load balancing on the cheap<br />
Forms based authentication for all published web sites<br />
Support for password changes on the log in page<br />
Log on form warns users about pending password expiration<br />
Better support for hardware SSL kit when using ms network load balancing<br />
Lets you add multiple VIP&#8217;s through the web interface rather than having to configure your NIC<br />
Improved flood resiliency, i.e. more options<br />
Log throttling to protect the server from DOS against itself<br />
Web Publishing Load Balancing with cookie-based affinity for Integrated NLBS<br />
Better certificate management and Link translation<br />
Support for published configuration storage servers<br />
Improved MOM management pack<br />
Logging supports logging the referring server for connections made to published servers</p>
<p>And for good measure, some things that have been removed&#8230; </p>
<p>ISA 2006 drops support for Windows 2000 as the host platform (no great loss there then)<br />
ISA 2006 isn’t yet EAL4+ certified (come on ISA 2006, you can do it!)</p>
<p>Apologies to any writers of ISA books who may have been plagiarised in the making of this post&#8230;.  at least I&#8217;ve bought your other books, which continue to save my bacon on most ISA installations!</p>
<p>Kind Regards</p>
<p>Sam
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Thomas Shinder</title>
		<link>http://blogs.isaserver.org/shinder/2006/08/08/2006-isa-firewall-new-feature-contest/#comment-7482</link>
		<pubDate>Wed, 09 Aug 2006 15:02:35 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/08/08/2006-isa-firewall-new-feature-contest/#comment-7482</guid>
					<description>OK, folks. We have one winner already. There are still two more books to win!
Thanks!
Tom</description>
		<content:encoded><![CDATA[<p>OK, folks. We have one winner already. There are still two more books to win!<br />
Thanks!<br />
Tom
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Thomas Shinder</title>
		<link>http://blogs.isaserver.org/shinder/2006/08/08/2006-isa-firewall-new-feature-contest/#comment-7463</link>
		<pubDate>Wed, 09 Aug 2006 13:07:54 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/08/08/2006-isa-firewall-new-feature-contest/#comment-7463</guid>
					<description>Hi Deigo,
Close, but you need to be more specific on many of these. Check the email I sent to the mailing list.
Tom</description>
		<content:encoded><![CDATA[<p>Hi Deigo,<br />
Close, but you need to be more specific on many of these. Check the email I sent to the mailing list.<br />
Tom
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Steven Hope</title>
		<link>http://blogs.isaserver.org/shinder/2006/08/08/2006-isa-firewall-new-feature-contest/#comment-7461</link>
		<pubDate>Wed, 09 Aug 2006 12:03:44 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/08/08/2006-isa-firewall-new-feature-contest/#comment-7461</guid>
					<description>There are some “new” features that have also been put back into ISA 2004 in SP2, which I think more people should know about. So, apart from:
- BITS caching 
- HTTP compression (with fixes) 
- Bandwidth management for HTTP (which isn't used much)

… ISA 2006 also has:

- Flexible forms based authentication filter (not just for exchange)
- More wizards for publishing SharePoint
- Updated wizards to include RPC/HTTP (oops, Outlook Anywhere access as its now called)
- Web single sign on
- RADIUS one time password authentication - saves the bacon of 2 factor auth companies
- User objects allowed from LDAP namespace
- VERY flexible authentication delegation e.g. forms/basic/certificate to Kerberos (and many more combinations)

Strange new things:
- For some bizarre reason a &quot;Server publishing rule&quot; is now a &quot;non-web server protocol publishing rule&quot; - sheeeesh!
- There is no longer a &quot;Firewall Client&quot; option in the setup, it’s just vanished. The binaries don't seem to be included in the serve install either but there is a client folder on the installation CD - MSFT, why did you do this???

I don’t want to focus on the dark side as ISA 2006 is great, but we are still missing:
- 1:1 NAT - for some reason MS don't realise that every other firewall, even low cost silly ones, can do this and ISA needs to also!
- VPN access based on VPN protocol (either PPTP or L2TP/IPSEC), you can do this already in RRAS but not in ISA.
- AES encryption for VPN's - again MS need to play catch up on the basic infrastructure.
- Central management for ISA SE
- Simple certificate wizard for requesting certs and generation self signed ones, a bit like SBS and Exchange 2007 can do.


It’s not 20 I know, but I’ve already got the book :)

Steven Hope
Architectural Consultant
ViRCOM
Microsoft Gold Certified Partner
Web: www.vircom.co.uk
Email: steven@vircom.co.uk
Blog: http://spaces.msn.com/members/stevenhope</description>
		<content:encoded><![CDATA[<p>There are some “new” features that have also been put back into ISA 2004 in SP2, which I think more people should know about. So, apart from:<br />
- BITS caching<br />
- HTTP compression (with fixes)<br />
- Bandwidth management for HTTP (which isn&#8217;t used much)</p>
<p>… ISA 2006 also has:</p>
<p>- Flexible forms based authentication filter (not just for exchange)<br />
- More wizards for publishing SharePoint<br />
- Updated wizards to include RPC/HTTP (oops, Outlook Anywhere access as its now called)<br />
- Web single sign on<br />
- RADIUS one time password authentication - saves the bacon of 2 factor auth companies<br />
- User objects allowed from LDAP namespace<br />
- VERY flexible authentication delegation e.g. forms/basic/certificate to Kerberos (and many more combinations)</p>
<p>Strange new things:<br />
- For some bizarre reason a &#8220;Server publishing rule&#8221; is now a &#8220;non-web server protocol publishing rule&#8221; - sheeeesh!<br />
- There is no longer a &#8220;Firewall Client&#8221; option in the setup, it’s just vanished. The binaries don&#8217;t seem to be included in the serve install either but there is a client folder on the installation CD - MSFT, why did you do this???</p>
<p>I don’t want to focus on the dark side as ISA 2006 is great, but we are still missing:<br />
- 1:1 NAT - for some reason MS don&#8217;t realise that every other firewall, even low cost silly ones, can do this and ISA needs to also!<br />
- VPN access based on VPN protocol (either PPTP or L2TP/IPSEC), you can do this already in RRAS but not in ISA.<br />
- AES encryption for VPN&#8217;s - again MS need to play catch up on the basic infrastructure.<br />
- Central management for ISA SE<br />
- Simple certificate wizard for requesting certs and generation self signed ones, a bit like SBS and Exchange 2007 can do.</p>
<p>It’s not 20 I know, but I’ve already got the book <img src='http://blogs.isaserver.org/shinder/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Steven Hope<br />
Architectural Consultant<br />
ViRCOM<br />
Microsoft Gold Certified Partner<br />
Web: <a href='http://www.vircom.co.uk' rel='nofollow'>www.vircom.co.uk</a><br />
Email: <a href="mailto:steven@vircom.co.uk">steven@vircom.co.uk</a><br />
Blog: <a href='http://spaces.msn.com/members/stevenhope' rel='nofollow'>http://spaces.msn.com/members/stevenhope</a>
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Diego Pietruszka</title>
		<link>http://blogs.isaserver.org/shinder/2006/08/08/2006-isa-firewall-new-feature-contest/#comment-7378</link>
		<pubDate>Tue, 08 Aug 2006 19:09:51 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/08/08/2006-isa-firewall-new-feature-contest/#comment-7378</guid>
					<description>- Better AD integration
- Better compression scheme
- New policy tools
- Auto Configuration features
- Better support for Monad scripting
- New MOM management pack
- Improved Attack alerts
- Better Attack detection tools
- The server publishing is much better
- Owa wizard publication
- Digital certificates
- Publishing exchange ask for exchange version
- Web farm publishing
- Include a 64 bits client
- Sharepoint tools
- Branch office functionality
- Flood and Worm Resiliancy
- BITS caching
- You need to do mork work to configure a Web Listener
- Better than ever (I hope this one count)!</description>
		<content:encoded><![CDATA[<p>- Better AD integration<br />
- Better compression scheme<br />
- New policy tools<br />
- Auto Configuration features<br />
- Better support for Monad scripting<br />
- New MOM management pack<br />
- Improved Attack alerts<br />
- Better Attack detection tools<br />
- The server publishing is much better<br />
- Owa wizard publication<br />
- Digital certificates<br />
- Publishing exchange ask for exchange version<br />
- Web farm publishing<br />
- Include a 64 bits client<br />
- Sharepoint tools<br />
- Branch office functionality<br />
- Flood and Worm Resiliancy<br />
- BITS caching<br />
- You need to do mork work to configure a Web Listener<br />
- Better than ever (I hope this one count)!
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
