<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/MU" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Using ISA Server to Extend Server and Domain Isolation Interoperability</title>
	<link>http://blogs.isaserver.org/shinder/2007/01/24/using-isa-server-to-extend-server-and-domain-isolation-interoperability/</link>
	<description>Written by Dr Thomas W Shinder, consultant to Microsoft, HP and many Fortune 500 companies on ISA firewall and Web proxy deployments this blog is where administrators get information about ISA Server Universal Threat Management firewalls. Topics include how to manage, deploy, and troubleshoot ISA Server as a network firewall, Web proxy/Web cache, remote access VPN server and VPN gateway to provide a high level of network security for all corporate computers.</description>
	<pubDate>Thu,  4 Dec 2008 20:30:42 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>

	<item>
		<title>by: Thomas Shinder</title>
		<link>http://blogs.isaserver.org/shinder/2007/01/24/using-isa-server-to-extend-server-and-domain-isolation-interoperability/#comment-199032</link>
		<pubDate>Wed, 30 Jul 2008 13:27:21 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2007/01/24/using-isa-server-to-extend-server-and-domain-isolation-interoperability/#comment-199032</guid>
					<description>Hi Matthew,

I have that document. Send me a note at tshinder@isaserver.org and I'll send it to you.
Thanks!
Tom</description>
		<content:encoded><![CDATA[<p>Hi Matthew,</p>
<p>I have that document. Send me a note at <a href="mailto:tshinder@isaserver.org">tshinder@isaserver.org</a> and I&#8217;ll send it to you.<br />
Thanks!<br />
Tom
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Matthew Morris</title>
		<link>http://blogs.isaserver.org/shinder/2007/01/24/using-isa-server-to-extend-server-and-domain-isolation-interoperability/#comment-199017</link>
		<pubDate>Wed, 30 Jul 2008 09:28:22 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2007/01/24/using-isa-server-to-extend-server-and-domain-isolation-interoperability/#comment-199017</guid>
					<description>Gudday Tom,

Does anyone know where this article has gone?...

If not maybe I can request some knowledge from the ISA expert.

I'm trying to see if I can extend domain isolation for Vista Laptop clients that use an SSL VPN for termination (unfortunately I didn't have a choice) to then pass through the ISA server into the domain zone based upon authenticated domain isolation policies tied to certificate based IPSEC (Especially AD which is 2008).  This way I can allow full domain access to long term remote access laptops while maintaining the integrity of the network via User certs - SSL vpn and device certs - ipsec domain isolation....

This approach should minimise the session cookie risk of the SSL VPN as you would also need a domain device cert for the ipsec into the domain environment....

Any thoughts you have on this would be very greatly appreciated.

Best Regards

Matthew Morris</description>
		<content:encoded><![CDATA[<p>Gudday Tom,</p>
<p>Does anyone know where this article has gone?&#8230;</p>
<p>If not maybe I can request some knowledge from the ISA expert.</p>
<p>I&#8217;m trying to see if I can extend domain isolation for Vista Laptop clients that use an SSL VPN for termination (unfortunately I didn&#8217;t have a choice) to then pass through the ISA server into the domain zone based upon authenticated domain isolation policies tied to certificate based IPSEC (Especially AD which is 2008).  This way I can allow full domain access to long term remote access laptops while maintaining the integrity of the network via User certs - SSL vpn and device certs - ipsec domain isolation&#8230;.</p>
<p>This approach should minimise the session cookie risk of the SSL VPN as you would also need a domain device cert for the ipsec into the domain environment&#8230;.</p>
<p>Any thoughts you have on this would be very greatly appreciated.</p>
<p>Best Regards</p>
<p>Matthew Morris
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
