Thomas Shinder Blog RSS

All Blogs  »  Thomas Shinder Blog  »  ISA Central  »  Blog article: Jim Harrison's Guide to ISA 2006 Firewall Authentication -- Everything You Ever Wanted to Know and More

Jim Harrison’s Guide to ISA 2006 Firewall Authentication — Everything You Ever Wanted to Know and More

Another one of the stellar sessions we had at the MVP conference last week was given by Jim Harrison. If you don’t know Jim, he’s one of the technical PMs on the ISA Firewall team. Jim is a literal river of technical information when it comes to the ISA Firewall, so if you ever get a chance to hear Jim speak, do so!

Jim talked about the 2006 ISA Firewall’s new authentication schemes. In case you’re not aware, previous versions of the ISA Firewall supported authentication delegation, but only delegation of basic credentials. With the new ISA Firewall, you can delegate credentials other than basic, including NTLM and Kerberos (via Kerberos Constrained Delegation).

However, with new features come new troubleshooting problems. Jim brought up one of the most common ones being an authentication error that leads to the user seeing page that says “you are not authorized to see this page”.

The problem comes when the ISA Firewall admin configures the Web publishing rule to use forms-based authentication, but then doesn’t configure authentication delegation correctly. You’ll see this problem when you configure the ISA Firewall to either delegate authentication using a method not supported on the Web server, or allowing authentication directly to the Web server but not enabling a method that can be used from the Internet.

Jim had dozens of cool examples, many to many to mention here. However, you will have the chance to hear the talk yourself if you attend TechEd this year. If you’re going to TechEd, then put Jim’s session on the top of your list!

HTH,

Tom

tshinder@isaserver.org

One Response to “Jim Harrison’s Guide to ISA 2006 Firewall Authentication — Everything You Ever Wanted to Know and More”

  1. Fahad Khan Says:

    March 11th, 2008 at 12:44 pm

    Hi,

    I installed ISA 2006 Standard Edition But Firewall Client Didnot Refreshed On Client Side,

    Can You Tell Me Step By Step Configuration So That I Configure My Server By Limited Open Ports,

    Thanks.

    Fahad Khan
    0300-3013240

Leave a Reply

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 5 chars within 0..9 and A..F, and submit the form.

  

If CAPTCHA image is missing or you cannot read the characters above, please generate a




Receive all the latest articles by email!

Receive Real-Time & Monthly ISAserver.org article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become an ISAserver.org member!

Discuss your ISA Server issues with thousands of other ISA Server experts. Click here to join!

Solution Center