ICT_GUY Posted May 20, 2008 Posted May 20, 2008 I have the time limited demo of isa server installed and working for clients. It is set up as a caching proxy, and seems to be working well. I have issues though. 1. I cannot access the internet from the isa server when logged on to it. That is when on the server if I fire up IE it gives an error (Error Code: 502 Proxy Error. The ISA Server denied the specified Uniform Resource Locator (URL). (12202) ) Thats with IE pointing itself, if pointing towards the normal school proxy it times out. 2. Is it possible to run IIS as well? Along with WSUS on the same server? I had it set up and it died.
ArchersIT Posted May 20, 2008 Posted May 20, 2008 By default later versions of ISA do not allow web browsing from the local machine. There is a system ploicy you can change so that this will work. I would not recommend running anything else on the ISA machine. Jonathan 1
ICT_GUY Posted May 20, 2008 Author Posted May 20, 2008 I would not recommend running anything else on the ISA machine. Jonathan Please can you give me your thoughts on why, ease of config or capacity maybe?
localzuk Posted May 20, 2008 Posted May 20, 2008 Please can you give me your thoughts on why, ease of config or capacity maybe? Running something else increases the vulnerability of the isa machine as a firewall. So rather than only having ISA and windows to attack, you gain the vulnerabilities of, say, IIS. If the ISA box is your edge firewall, this is a huge risk. 1
GlennT Posted May 20, 2008 Posted May 20, 2008 Please can you give me your thoughts on why, ease of config or capacity maybe? IIS running on ISA would pose a security risk if run as an edge firewall. I guess as you are using it to cache only you have something else between the ISA and the internet? 1
ICT_GUY Posted May 20, 2008 Author Posted May 20, 2008 I should mention that it is only being used as a proxy. Though I could use it as a second firewall, at the momment its just to accellerate the kiddiwinks browsing.
ICT_GUY Posted May 20, 2008 Author Posted May 20, 2008 Also, double Doh! Although I had allowed all internal networks access, the local host had been dnied by the default rule. So I fixed that doh!
SYNACK Posted May 20, 2008 Posted May 20, 2008 If it has no security role then it should be alright to add other services to it, you will just need to add rules to allow the specific traffic from the local network to the 'local host' ISA network and they should run fine. I run all of our mail and internet filtering on our ISA server and just have the managment ports open to the local side. Admittedly given the amount of hits that it takes we had to get a big 8 core monster for it to be responsive to hosts and also handle all of the filtering database work. ISA and the web proxying are quite taxing on the hardware not because of the complexity of the requests but due to the shear number of requests that must be responded to quickly before people get ansy. In this respect if you have a lot of clients running through the ISA proxy and it is not a hefty box in terms of simultanious processing it may not be a good idea to add the load of IIS and WSUS on it as well.
ArchersIT Posted May 20, 2008 Posted May 20, 2008 As the other people have already said - the main reason is to reduce the attack profile. In your case where you are not using it as an edge firewall then it may be possible to configure it correctly - but as has already been indicated, loading may be an issue. Jonathan
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now