• RSS
  • Twitter
  • FaceBook

Deb Shinder Blog RSS

All Blogs  »  Deb Shinder Blog  »  ISA Central  »  Blog article: AV Software on the ISA Firewall?

AV Software on the ISA Firewall?

Years ago I published a list of dumb ISA firewall tricks, which was a collection of what I considered “ISA firewall worst practices”. Near the top of the list was putting host based AV software on the ISA firewall.image

There are number of reasons why putting a host based AV system on the ISA firewall is a dumb idea. Among the most significant are:

  • It’s not required when the ISA firewall is configured an used correctly
  • If the ISA firewall isn’t configured and used correctly, you’re going to have much more profound problems than those due to not having host-based AV software on the firewall
  • You increase your overall software costs with no return on investment
  • You degrade the performance of your ISA firewall
  • You interfere with normal firewall operations
  • It encourages the mindset that the firewall is a server, which leads panoply of problems. The ISA firewall is a firewall, and must not be thought of, operated as, to managed as a “server”

For a little different perspective on this issue, check out Tristan’s post over at:

http://blogs.technet.com/tristank/archive/2009/04/...r.aspx

(by the way, its a “saving” not a “savings”) :)

HTH,

Tom

Thomas W Shinder, M.D., MCSE
Sr. Consultant / Technical Writer

image
Prowess Consulting www.prowessconsulting.com

PROWESS CONSULTING | Microsoft Forefront Security Specialist
Email: tshinder@isaserver.org
MVP — Forefront Edge Security (ISA/TMG/IAG)

Leave a Reply


Receive all the latest articles by email!

Receive Real-Time & Monthly ISAserver.org article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become an ISAserver.org member!

Discuss your ISA Server issues with thousands of other ISA Server experts. Click here to join!