<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/MU" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Putting the ISA and TMG Firewall in a Trusting Domain</title>
	<link>http://blogs.isaserver.org/shinder/2008/05/12/putting-the-isa-and-tmg-firewall-in-a-trusting-domain/</link>
	<description>Written by Dr Thomas W Shinder, consultant to Microsoft, HP and many Fortune 500 companies on ISA firewall and Web proxy deployments this blog is where administrators get information about ISA Server Universal Threat Management firewalls. Topics include how to manage, deploy, and troubleshoot ISA Server as a network firewall, Web proxy/Web cache, remote access VPN server and VPN gateway to provide a high level of network security for all corporate computers.</description>
	<pubDate>Sat, 30 Aug 2008 01:07:49 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>

	<item>
		<title>by: tshinder</title>
		<link>http://blogs.isaserver.org/shinder/2008/05/12/putting-the-isa-and-tmg-firewall-in-a-trusting-domain/#comment-182483</link>
		<pubDate>Wed, 14 May 2008 15:57:33 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2008/05/12/putting-the-isa-and-tmg-firewall-in-a-trusting-domain/#comment-182483</guid>
					<description>Hi Jason,

Exactly. That's the &quot;take home&quot; message. There are no &quot;right answers&quot; there a good, better and best, and that depends on the customer's resources and requirements.

Thanks!
Tom</description>
		<content:encoded><![CDATA[<p>Hi Jason,</p>
<p>Exactly. That&#8217;s the &#8220;take home&#8221; message. There are no &#8220;right answers&#8221; there a good, better and best, and that depends on the customer&#8217;s resources and requirements.</p>
<p>Thanks!<br />
Tom
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Jason Jones</title>
		<link>http://blogs.isaserver.org/shinder/2008/05/12/putting-the-isa-and-tmg-firewall-in-a-trusting-domain/#comment-182459</link>
		<pubDate>Wed, 14 May 2008 14:43:30 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2008/05/12/putting-the-isa-and-tmg-firewall-in-a-trusting-domain/#comment-182459</guid>
					<description>Hi Tom,

Always happy to provide consultancy if customers need it, good rates offered :-)

One of the key things Jim mentioned was that the separate forest model is not designed to protect in the event that ISA is compromised, but more in the event that an administrative user account is compromised. If this is a big worry then a separate forest makes sense (like does using a separate forest to store external non-employee user accounts) however people often think that the extra forest needs to be created because ISA can't be trusted, which as you know given all possible weaknesses in a security design, ISA is likely to be one of the the stronger links in the chain...not the weakest...

As ever there is no &quot;right answer&quot; just lots of possible options that need to be considered and matched to the exact requirements.

Cheers

JJ</description>
		<content:encoded><![CDATA[<p>Hi Tom,</p>
<p>Always happy to provide consultancy if customers need it, good rates offered <img src='http://blogs.isaserver.org/shinder/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>One of the key things Jim mentioned was that the separate forest model is not designed to protect in the event that ISA is compromised, but more in the event that an administrative user account is compromised. If this is a big worry then a separate forest makes sense (like does using a separate forest to store external non-employee user accounts) however people often think that the extra forest needs to be created because ISA can&#8217;t be trusted, which as you know given all possible weaknesses in a security design, ISA is likely to be one of the the stronger links in the chain&#8230;not the weakest&#8230;</p>
<p>As ever there is no &#8220;right answer&#8221; just lots of possible options that need to be considered and matched to the exact requirements.</p>
<p>Cheers</p>
<p>JJ
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
