Nick_Parker Posted August 1, 2009 Posted August 1, 2009 Hi everyone Quick question, is it possible to have ISA 2006/TMG Beta setup as a gateway for your network and still be able to log web requests on a per user basis and still be able to restrict access on a per user basis? I.E. Can I have a rule saying that any user in the OU "Deny Internet Access" will be denied access? and will I be able to look in logs and see who is the biggest user etc... These are all things I can currently do if ISA/TMG is configured as a Proxy Server, not sure if it's do-able when configured as a gateway?
SYNACK Posted August 1, 2009 Posted August 1, 2009 (edited) Yes you can still implement per group rules when it is in gateway mode. It usually does not log usernames in this config and to actually apply per user your allow rule requires that authentication is enabled. This can cause issues with non-win clients though. Edited August 1, 2009 by SYNACK 1
Nick_Parker Posted September 13, 2009 Author Posted September 13, 2009 Yes you can still implement per group rules when it is in gateway mode. It usually does not log usernames in this config and to actually apply per user your allow rule requires that authentication is enabled. This can cause issues with non-win clients though. I've been playing around with this and it doesn't seem to work. My rules allow through only 'Authenticated Users' and when in Gateway/SecureNAT mode, it doesn't ask the user for any credentials, nor does it use the integrated ones and so it will not allow browsing. Looks like I'm going to have to use the proxy server settings...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now