Frequently Asked Questions
The following Frequently Asked Questions, answered by the authors of this book, are designed to both measure your understanding of the concepts presented in this chapter and to assist you with real-life implementation of these concepts. To have your questions about this chapter answered by the author, browse to www.syngress.com/solutions and click on the 'Ask the Author' form. You will also gain access to thousands of other FAQs at ITFAQnet.com.
Q: Can I use Forms-based Authentication for non-OWA sites?
A: Yes. You can use FBA for any site you publish using a Web Publishing Rule. However, some users have reported unexpected results, so you should test this feature thoroughly before using it for non-OWA sites in a production environment.
Q: Can I install the SMTP Message Screener on the ISA firewall machine?
A: Yes. The ISA firewall machine can be configured as an inbound and outbound SMTP relay for your company. In addition, you can install the SMTP Message Screener on the Exchange Server. However, we do not recommend that you install the SMTP Message Screener on the Exchange Server machine.
Q: Some of the URLs returned by my SharePoint site aren't reachable from remote clients via a Web Publishing Rule. I configured the Link Translator to changes the links, but it doesn't seem to work all the time. What's up with that?
A: While the Link Translator can reliably change the links returned to the Web client by the SharePoint site, some of the links are actually created on the client machine itself via a client-side script. Since the ISA firewall's Link Translator does not pre-process the client-side script during the translation, these links break. We expect either a feature pack or future versions of the ISA firewall to include enhanced support for SharePoint server publishing and solve this problem.
Q: Our security officer won't allow us to join the ISA firewall to the domain, although he can't come up with any cogent reason for not making the ISA firewall a domain member. However, we must go by his policy. We would like to use the ISA firewall's Forms-based Authentication feature for OWA publishing, but we will need to use RADIUS authentication. Is there any way we can do this?
A: Yes. However, at the time of writing, the fix is part of a hotfix. We expect the hotfix to be rolled up in the first ISA firewall feature pack. Check out You cannot use the RADIUS authentication protocol when you use the Outlook Web Access (OWA) Forms-Based Authentication on a Web publishing rule to publish an internal Web site such as OWA in ISA Server 2004 at http://support.microsoft.com/default.aspx?scid=kb;en-us;884560 for more information.
Q: You didn't include much information about the SecurID filter and how to use SecurID in this chapter. Why is that, and how can I get more information on SecurID?
A: We wanted to put some detailed information on SecurID in this book, but unfortunately were not able to get anyone at RSA to answer our requests for information. If we are able to get someone at RSA to follow up with us, we'll include detailed SecurID authentication information at www.isaserver.org.
Q: Does the MMS filter work for both inbound and outbound connections? I tried to publish a Microsoft Media Server on a Windows Server 2003 machine using an MMS Server Publishing Rule but it didn't work. Is there a way to configure the filter to support MMS Server Publishing Rules?
A: .The MMS filter does work for both inbound and outbound connections. However, your site may be using RTSP instead of MMS. Try creating a Server Publishing Rule using the RTSP protocol and see if that solves your problem.