Index
I
IBM firewalls, 20
ICMP (Internet Control Message Protocol)attacks, 1034ISA Server 2004 support for, 106
and router redirection, 1016use of, 369
ICP (Internet Cache Protocol), 55, 903
ICSA Labs, 158
IDS/IPS (intrusion detection system/intrusion prevention system), 43, 48-49, 155
IEAK (Internet Explorer Administration Kit), 418
IEEE 802.x wireless standards, 1018IMAP4 Server Publishing Rule configuration, 704
implementingsecurity plan, policy, 1046-1047system hardening plan with ISA, 1053-1054importingcache rules, 922-925
configuration data, 64
content download job configurations, 933
filter definitions, 975, 986
function described, 86-87
Web site certificates into ISA firewall store, 674-676
Information Technology (IT), understanding of network security, 1006-1007Information Technology Security Evaluation Criteria (ITSEC), 158
infrastructureestablishing corporate network name-resolution, 464-467
key issues, 7
split DNS, 373, 540
.ini files, Firewall client, 396-397
inspection, application-layer connections, 633, 826
installationsautomatic, summary, 453
automating Firewall client, 438-448
installingCA certificates, 741-743
DHCP server, relay agent, on ISA firewall, 800-802
DHCP Server service on ISA firewall, 503-506
Firewall clients, 386-388
ISA firewall. See ISA firewall installation
management console, 103
Web Proxy, Firewall clients automatically, 417-438
Windows Server 2003, 262-267
integrity of data defined, 1011Intelencryption on chips, 40
hardware, firewalls and, 23
hardware platform, and ISA firewalls, 248, 252
Internal Network, ISA firewall, 281-290, 356
Internetconfiguring outbound VPN connections through ISA firewall, 797-800
games, connections, 455
SecureNAT client connections, 366, 376
VPN clients' access, risks, 717
Internet Acceleration and Security Server (ISA)See also ISA Server 2000
development of, 15
Internet Assigned Number Authority (IANA), 1037Internet Cache Protocol (ICP), 55, 903
Internet Control Message Protocol. See ICMP
Internet Edge of firewall ring, 68-70
Internet edge of firewall ring, 238-239, 242
Internet Explorer Administration Kit (IEAK), 418
Internet Network computers, configuring, 517-520
Internet Protocol (IP) addresses. See IP addresses
Internet Protocol security. See IPSec
Internet Service Providers (ISPs) and firewalls, 38
intradomain communications, allowing through firewall, 613-622, 626-627
intrusion detection and preventionSee also network security
common attacks detection, prevention, 882-890
DNS attacks, 890-891
on firewalls, 48-49
IP Options, fragment filtering, 891-892
ISA Server 2004 capabilities, 173
intrusion detection system (IDS) and firewalls, 48-49
intrusion detection system/intrusion prevention system (IDS/IPS), 43
intrusion prevention system (IPS), 48-49
IP addressesadding to remote management, 102
assignment, ISA firewall, 494-497
configuring Web listener, 685
controlling routing with Network Rules, 295
dynamic assignment on ISA firewall's external interface, 329-330
hard-coding in links, 373
multiple network IDs, 541
and network objects, 109
setting for virtual machine, 269-271
‘sniffing,' 1016IP filtering and intrusion detection, prevention, 882-892
IP Fragment filtering, 890-891
IP half scan attacks, 1038, 1052IP Masquerade, 218
IP Options, fragment filtering, 891-892
IP spoofing, 1038IPchains, 218, 234
IPCop firewall, 219-220, 234
IPSec (Internet Protocol security)and Firewall clients, 384
and host-based security rings, 246
ISA Server 2004 support for, 106
and NAT-T, 175
Tunnel Mode, 47, 718
Tunnel Mode site-to-site VPNs, 774
VPN connections, pre-shared key support for, 719-720
ISA firewallSee also ISA Server 2004
Access Rules. See Access Rules
Backbone and Asset Network configuration, 254
and caching solution, 138
client and administrative roles, permissions, 526-530
comparisons with other firewalls. See firewall comparisons
configuring network interfaces, 464-468
configuring outbound VPN access to Internet, 797-800
configuring to publish autodiscovery information, 436-437
configuring to support RADIUS authentication, 785-787
creating groups on, 734
creating new Networks, 291-295
creating site-to-site VPN between ISA Server 2000 and, 802-814
default networks, 279-290
DMZ Firewall Segment configuration, 255
dynamic assignment on external interface, 329-330
external network, 290-291
fallacies about, 19-25, 247-248
features, new and improved in networking model (table), 274-276
flexibility in locating, 236
importing Web site certificates into machine certification store, 674-676
improvements, 105-112
installing. See ISA firewall installation
intradomain communications, allowing, 613-622
Link Translation Filter, 873-878
link translator, 635-636
lockdown mode, 530-531
‘looping back' through, 371-373, 375
Network Objects, 297-309, 335
network templates, 310-329
networks and network relationships, 273-276
‘open ports,' 614
policy node, 93-94
pre-installation tasks and considerations, 537
and proxy servers, 22
Service dependencies, 521-526
SSL bridging feature, 669-671
troubleshooting, 356-357
VPN networking. See VPN networkingVPN Quarantine feature, 291
Web Publishing Rules and, 632-641
ISA firewall installationdefault post-installation configuration, 477-479
installing, configuring ISA Server 2004 software, 506-517
performing on multihomed machine, 471-477, 537
performing single NIC installation, 490-491
performing upgrade installation, 489
post-installation System Policy, 479-488
pre-installation tasks and considerations, 458-470
quick start configuration for, 492-520, 537
ISA management console, 100-103, 476
ISA Server 2000creating site-to-site VPN to ISA firewall, 802-814
development of, 54-57
differences from ISA Server 2004, 2
upgrading, migrating to ISA Server 2004, 12-13, 540
VPN Deployment Kit, 740
vs. ISA Server 2004 authentication, 107
ISA Server 2004See also ISA firewall
Access Rules. See Access Rules
alerts. See alerts
clients. See clients
compared with other firewall products, summary, 227-230configuration node, 95-98
Dashboard, exploring sections, 943-951
defense-in-depth security, 66-75, 237-247
differences from ISA Server 2000, 2
enterprise and standard editions, 3-4, 232
features overview, 5
hotfixes, and Windows, 21-22
incorporating in security plan, 1052-1054installing and configuring generally, 8
interface, generally, 134
interface, introduction, 80-83
intrusion detection, 1052logs. See logs
in mixed environment, 166
monitoring node, 87-93
multinetworking, 140, 276-277, 591
new features, 58-65, 134-137
Performance Monitor, 994-997, 1002
protocol support, 106-107
security. See network security
setup program, 103
Shinder network layout, configuring, 255-272
system requirements, 161
using firewall with, 24-25
virtual private networks (VPN) node, 94-95
VPN improved functionality, 712-713
VPN quarantine, 128-129
VPN support, 47-48
Web caching capabilities, 904-910
ISA Server 2004 Management Console, 100-103, 476
ISA Server Firewall Packet Engine object counters, 994-996
ISA Server Job Scheduler service, running, 928-929
ISA Server Performance Monitor, 951
ISA Server Web Proxy object counters, 996-997
ISA Servers, managing remotely, 103-105
isaautorun.exe, 103
isa.chm, 99
ISO security standards, specifications, 26
.iso files, 260
ISS's RealSecure, 1052