Jump to content

Firewall for Windows server 2003


Recommended Posts


ISA server 2004 is a better choice. While ISA 2000 and 2004 allow you to filter inbound and outbound traffic, 2004 has new features that are useful, and it performs better than ISA 2000.

Link to comment
Share on other sites

ISA 2004 trusts ZERO networks. External or internal makes no difference.

ISA 2004 is completely different than what was available with ISA Server 2000. Most importantly, there is no longer a LAT. That’s right, there is no LAT.

The next major point regarding the ISA firewall’s Networking model is how it performs spoof detection. The ISA firewall uses its Network definitions to determine if a packet is spoofed. If a network interface defined as the root of an ISA firewall Network receives a packet that isn’t directly reachable from that interface, as defined by the Windows routing table, then the packet is considered spoofed.

The practical result of this spoof detection mechanism is that all IP addresses directly reachable from a NIC on the ISA firewall must be defined as part of the same ISA firewall Network.

Another side effect of this spoof detection mechanism is that you need to use Direct Access for host to host communications on the same ISA firewall Network. One way to think of an ISA firewall Network is that the ISA firewall doesn’t perform stateful packet and stateful application layer inspection on communications between hosts on the same ISA firewall Network.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...