<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/MU" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: ISA Server Branch Office Policies Best Practices: ISA Server co-location with a domain controller</title>
	<link>http://blogs.isaserver.org/shinder/2008/09/02/isa-server-branch-office-policies-best-practices-isa-server-co-location-with-a-domain-controller/</link>
	<description>Deb Shinder, MVP (Enterprise Security) continues the Shinder tradition of providing ISAserver.org readers with the latest and greatest news, tips and tricks for optimizing your ISA Server or TMG based network security infrastructure. This blog will address all topics pertaining to the Microsoft firewall products and how ISA/TMG administrators can get the most out of them so your company’s employees can use the Internet safely and productively.</description>
	<pubDate>Sat, 13 Mar 2010 09:11:38 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>

	<item>
		<title>by: Office Rental Space</title>
		<link>http://blogs.isaserver.org/shinder/2008/09/02/isa-server-branch-office-policies-best-practices-isa-server-co-location-with-a-domain-controller/#comment-211979</link>
		<pubDate>Mon, 13 Oct 2008 17:01:45 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2008/09/02/isa-server-branch-office-policies-best-practices-isa-server-co-location-with-a-domain-controller/#comment-211979</guid>
					<description>I\'m not a big fan of the concept of dual deployment since I deem it necessary for each DC to have it\'s own firewall ingeniousness to the others in a enterprise unless top-level execs and/or senior techs need another way into systems that have been compromised.  I\'m not saying that ISA itself is garbage because it really isn\'t.  It\'s just that there\'s little or no room for error when deploying it.  Until they work out all the kinks, I don\'t see a problem with setting up the firewall separate from dc configurations.</description>
		<content:encoded><![CDATA[<p>I\&#8217;m not a big fan of the concept of dual deployment since I deem it necessary for each DC to have it\&#8217;s own firewall ingeniousness to the others in a enterprise unless top-level execs and/or senior techs need another way into systems that have been compromised.  I\&#8217;m not saying that ISA itself is garbage because it really isn\&#8217;t.  It\&#8217;s just that there\&#8217;s little or no room for error when deploying it.  Until they work out all the kinks, I don\&#8217;t see a problem with setting up the firewall separate from dc configurations.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Jim Harrison</title>
		<link>http://blogs.isaserver.org/shinder/2008/09/02/isa-server-branch-office-policies-best-practices-isa-server-co-location-with-a-domain-controller/#comment-207095</link>
		<pubDate>Thu, 04 Sep 2008 15:21:59 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2008/09/02/isa-server-branch-office-policies-best-practices-isa-server-co-location-with-a-domain-controller/#comment-207095</guid>
					<description>for Ian - 
- the bad news is that ISA doesn't install; much less run on WS08.
- the good news is that the traffic profiles defined in that article can be used regardless of whether ISA or TMG are co-located iwth the DC or merely another guest in that deployment.

Given the licensing freedom offered for Hyper-V deployments, I really don't see the value in a co-located deploment.</description>
		<content:encoded><![CDATA[<p>for Ian -<br />
- the bad news is that ISA doesn&#8217;t install; much less run on WS08.<br />
- the good news is that the traffic profiles defined in that article can be used regardless of whether ISA or TMG are co-located iwth the DC or merely another guest in that deployment.</p>
<p>Given the licensing freedom offered for Hyper-V deployments, I really don&#8217;t see the value in a co-located deploment.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Thomas Shinder</title>
		<link>http://blogs.isaserver.org/shinder/2008/09/02/isa-server-branch-office-policies-best-practices-isa-server-co-location-with-a-domain-controller/#comment-207091</link>
		<pubDate>Thu, 04 Sep 2008 15:04:42 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2008/09/02/isa-server-branch-office-policies-best-practices-isa-server-co-location-with-a-domain-controller/#comment-207091</guid>
					<description>It does that to me too :)

Thanks!
Tom</description>
		<content:encoded><![CDATA[<p>It does that to me too <img src='http://blogs.isaserver.org/shinder/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Thanks!<br />
Tom
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Jim Harrison</title>
		<link>http://blogs.isaserver.org/shinder/2008/09/02/isa-server-branch-office-policies-best-practices-isa-server-co-location-with-a-domain-controller/#comment-207089</link>
		<pubDate>Thu, 04 Sep 2008 15:01:43 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2008/09/02/isa-server-branch-office-policies-best-practices-isa-server-co-location-with-a-domain-controller/#comment-207089</guid>
					<description>You're right; I suspect the Percocet is making things a bit fuzzy.</description>
		<content:encoded><![CDATA[<p>You&#8217;re right; I suspect the Percocet is making things a bit fuzzy.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Thomas Shinder</title>
		<link>http://blogs.isaserver.org/shinder/2008/09/02/isa-server-branch-office-policies-best-practices-isa-server-co-location-with-a-domain-controller/#comment-207076</link>
		<pubDate>Thu, 04 Sep 2008 11:43:36 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2008/09/02/isa-server-branch-office-policies-best-practices-isa-server-co-location-with-a-domain-controller/#comment-207076</guid>
					<description>Hey Jim,

I think we agree -- you said that the article provides the groundwork for &quot;don't be stupid&quot; - I essentially say the same thing in a more long winded way:

&quot;Why would Microsoft write such an article? Because the fact is that people have been installing the ISA firewall on branch office domain controllers. While Microsoft can’t come out and say “hey, this is a great idea” any more than parents and teachers can say to kids “hey kids, its a great thing that you run with scissors in your hands”, the fact is that kids will run with scissors in their hands, and admins will install the ISA firewall on a branch office domain controller. So, as responsible adults, we need to round the ends of the kid’s scissors and “round the edges” of the firewall policies on the branch office domain controller that also hosts an ISA firewall.&quot;

Agreed?

Thanks!
Tom</description>
		<content:encoded><![CDATA[<p>Hey Jim,</p>
<p>I think we agree &#8212; you said that the article provides the groundwork for &#8220;don&#8217;t be stupid&#8221; - I essentially say the same thing in a more long winded way:</p>
<p>&#8220;Why would Microsoft write such an article? Because the fact is that people have been installing the ISA firewall on branch office domain controllers. While Microsoft can’t come out and say “hey, this is a great idea” any more than parents and teachers can say to kids “hey kids, its a great thing that you run with scissors in your hands”, the fact is that kids will run with scissors in their hands, and admins will install the ISA firewall on a branch office domain controller. So, as responsible adults, we need to round the ends of the kid’s scissors and “round the edges” of the firewall policies on the branch office domain controller that also hosts an ISA firewall.&#8221;</p>
<p>Agreed?</p>
<p>Thanks!<br />
Tom
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Jim Harrison</title>
		<link>http://blogs.isaserver.org/shinder/2008/09/02/isa-server-branch-office-policies-best-practices-isa-server-co-location-with-a-domain-controller/#comment-207019</link>
		<pubDate>Thu, 04 Sep 2008 05:37:38 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2008/09/02/isa-server-branch-office-policies-best-practices-isa-server-co-location-with-a-domain-controller/#comment-207019</guid>
					<description>I'm actually quite surprised at your response to this article, Tom.
You know exactly why we wrote it - to provide the ground work for a &quot;don't be stupid&quot; support policy.  Although you can't tell from the publishing dates, this article predates the Hyper-V article by some months.  Now that there is prescriptive guidance on how to virtualize your edge deployments (another subject where Tom feels very strongly), this one should get short notice.  

If not, then this one is article what CSS engineers can point to when customer X asks &quot;show me how to do this without an &quot;allow all&quot; policy.

Jim</description>
		<content:encoded><![CDATA[<p>I&#8217;m actually quite surprised at your response to this article, Tom.<br />
You know exactly why we wrote it - to provide the ground work for a &#8220;don&#8217;t be stupid&#8221; support policy.  Although you can&#8217;t tell from the publishing dates, this article predates the Hyper-V article by some months.  Now that there is prescriptive guidance on how to virtualize your edge deployments (another subject where Tom feels very strongly), this one should get short notice.  </p>
<p>If not, then this one is article what CSS engineers can point to when customer X asks &#8220;show me how to do this without an &#8220;allow all&#8221; policy.</p>
<p>Jim
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Ian Banyard</title>
		<link>http://blogs.isaserver.org/shinder/2008/09/02/isa-server-branch-office-policies-best-practices-isa-server-co-location-with-a-domain-controller/#comment-206874</link>
		<pubDate>Wed, 03 Sep 2008 09:06:48 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2008/09/02/isa-server-branch-office-policies-best-practices-isa-server-co-location-with-a-domain-controller/#comment-206874</guid>
					<description>Absolutely agree with Don - while i didnt specifically mention hype-v that was the intention - perhaps the new licensing for EBS already caters for this? One to look up later!</description>
		<content:encoded><![CDATA[<p>Absolutely agree with Don - while i didnt specifically mention hype-v that was the intention - perhaps the new licensing for EBS already caters for this? One to look up later!
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Don Adams</title>
		<link>http://blogs.isaserver.org/shinder/2008/09/02/isa-server-branch-office-policies-best-practices-isa-server-co-location-with-a-domain-controller/#comment-206825</link>
		<pubDate>Tue, 02 Sep 2008 23:14:45 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2008/09/02/isa-server-branch-office-policies-best-practices-isa-server-co-location-with-a-domain-controller/#comment-206825</guid>
					<description>Whoops ... pasted my comment above into the wrong blog....  It was meant for your EBS post.

In a branch environment (focus of the MS article) it seems to me that virtualizing all the roles is where everything is heading.  I see one big-ass physical machine running a hypervisor with ISA/TMG as the gatekeeper virtual appliance and all the other roles running behind it.  I can even see the desktops running on the same physical device.  Add a small SAN device capable of replicating with home base and backing up the virtual machines and I think we're done!

Don Adams
USEast Technologies</description>
		<content:encoded><![CDATA[<p>Whoops &#8230; pasted my comment above into the wrong blog&#8230;.  It was meant for your EBS post.</p>
<p>In a branch environment (focus of the MS article) it seems to me that virtualizing all the roles is where everything is heading.  I see one big-ass physical machine running a hypervisor with ISA/TMG as the gatekeeper virtual appliance and all the other roles running behind it.  I can even see the desktops running on the same physical device.  Add a small SAN device capable of replicating with home base and backing up the virtual machines and I think we&#8217;re done!</p>
<p>Don Adams<br />
USEast Technologies
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Don Adams</title>
		<link>http://blogs.isaserver.org/shinder/2008/09/02/isa-server-branch-office-policies-best-practices-isa-server-co-location-with-a-domain-controller/#comment-206822</link>
		<pubDate>Tue, 02 Sep 2008 23:01:44 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2008/09/02/isa-server-branch-office-policies-best-practices-isa-server-co-location-with-a-domain-controller/#comment-206822</guid>
					<description>Hi Tom;

EBS could be a good solution to build into a hardware appliance based on Windows 2008 Server Core running Hyper V.   The EBS servers would run as two or three separate virtual machines (TMG by itself) on top of Hyper V.

This would violate your “don’t mix zones” philosophy but plays into an “ISA/TMG on every Virtual Host” philosophy.

What do you think?

Don Adams
USEast Technologies</description>
		<content:encoded><![CDATA[<p>Hi Tom;</p>
<p>EBS could be a good solution to build into a hardware appliance based on Windows 2008 Server Core running Hyper V.   The EBS servers would run as two or three separate virtual machines (TMG by itself) on top of Hyper V.</p>
<p>This would violate your “don’t mix zones” philosophy but plays into an “ISA/TMG on every Virtual Host” philosophy.</p>
<p>What do you think?</p>
<p>Don Adams<br />
USEast Technologies
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Ian Banyard</title>
		<link>http://blogs.isaserver.org/shinder/2008/09/02/isa-server-branch-office-policies-best-practices-isa-server-co-location-with-a-domain-controller/#comment-206723</link>
		<pubDate>Tue, 02 Sep 2008 15:57:50 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2008/09/02/isa-server-branch-office-policies-best-practices-isa-server-co-location-with-a-domain-controller/#comment-206723</guid>
					<description>I'd prefer to see a W2008 based installation with necessary network interfaces to support an instance of ISA, and an instance of the DC role, just cant my head around the co-location of the 2 roles - I can understand the intention, to make life easy for small or remote deployed infrastructure, and if people are doing this then at least there's something of a best (er maybe Better?!) practise to follow.

 (Quick issue with the Captcha not displaying, when you refresh you loose the text in the form, how about positioning the captcha above the form so that your aware of a problem before typing an essay!!!)</description>
		<content:encoded><![CDATA[<p>I&#8217;d prefer to see a W2008 based installation with necessary network interfaces to support an instance of ISA, and an instance of the DC role, just cant my head around the co-location of the 2 roles - I can understand the intention, to make life easy for small or remote deployed infrastructure, and if people are doing this then at least there&#8217;s something of a best (er maybe Better?!) practise to follow.</p>
<p> (Quick issue with the Captcha not displaying, when you refresh you loose the text in the form, how about positioning the captcha above the form so that your aware of a problem before typing an essay!!!)
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
