Labels

Showing posts with label ISA. Show all posts
Showing posts with label ISA. Show all posts

Thursday, December 29, 2011

ISA TO ISA CONFIGURATION STORAGE DATABASE REPLICATION

Do the following steps on ISA1

For Windows2003 SP2

  • Open regedit
  • Select HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
  • Edit or Create REG_DWORD – EnableRSS – give value =0
  • Edit or Create REG_DWORD – DisableTaskOffload – give value =1
  • Restart the system.

Open ISA Management console

  • Click on Enterprise as per below screen shots.

clip_image002

  • In Enterprise PoliciesàDefault Policyà on Right Menuà Click on Toolbox.
  • Click on Network ObjectsàComputer SetsàDouble Click on Enterprise Remote ManagementàAdd Your Domain Controller server and Your ISA2( Replication server). As per below screen shots.

clip_image004

  • Now Double Click on Replicate Configuration Storage serversàAdd Your ISA2 (Replication server). As per below screen shots.

clip_image006

  • To open system policyàClick on ArraysàISA1 (as per your array name) àRight Click on Firewall Policy (ISA1)àSelect Edit System Policy.. As per below screen shots.

clip_image008

  • Click on DNSà Click on To TABàAdd your Domain server as per below screen shots.

clip_image010

  • Click on Authentication ServicesàActive DirectoryàUncheck (Enforce strict RPC compliance as per screen shots.

clip_image012

  • Click on Authentication ServicesàActive DirectoryàTOàAdd your Domain server.
  • Enable RSA Secur ID.

clip_image014

  • Click on Remote ManagementàMicrosoft ManagementàFromà Remote Management ComputersàAdd Your ISA2 server and DC server.

clip_image016

  • Click on Diagnostic ServicesàWindows NetworkingàToàAdd Your DC server.

clip_image018

  • Add both ISA server in Array Member communication.
  • Create access Rule for connectivity between your Domain server to Local host and ISA1 to ISA2.

clip_image020

  • Open ISA ManagementàArraysàISA1 (as per your arrays server name) àclick on Monitoringàclick on Connectivity TAB as per below screen shots.

clip_image022

  • From TASK menu—Create Connectivity Verifier Rule. give rule Name ISA1( or as per you)

clip_image024

  • Browse your ISA1 server (local host)àSelect Group TypeàActive DirectoryàSelect Establish a TCP ConnectionàConnection portàselect MS Firewall Storage ReplicationàSpecify the timeout response-10 (or as per your connectivity)àSelect Trigger an alert optionàApplyàOk.

clip_image026

  • Open ArrayàRight click on Array server (ISA1)àPropertiesàAssign RoleàAdd Domain Administrator IDàRoleàISA Server Array Administrator.
  • Now following settings do on your Domain server.
  • EnableàTrust computer for delegationàon your both ISA servers properties as per below screen shots.

clip_image028

ISA Firewall Quick Tip: Creating Detailed Reports Using ISA Server 2006 and Excel

Configuration on ISA Server

  1. Open ISA Management Console
    clip_image001
  2. Under the Monitoring node, click on Logging
    clip_image002
  3. We will create a report with the following filters ( you can customize your reports as needed)
    a. Logging Last 7 Days
    b. Action Allowed Connection
    c. Protocol HTTP
    d. Client Username Not Equal to Anonymous ( Here you can choose a specific user for example )
    e. Specify on which Firewall Policy we want to run the logging for.
  4. Click on Edit Filter, to start editing and adding our filters.
  5. Click on Log Time, then under the Condition drop down list, choose Last 7 Days, and click on Update
    clip_image003
  6. Click on Action, then under the Condition drop down list, choose Equals, and under the Value drop down list choose  Allow Connection and click on Update
    clip_image004
  7. Under the Filter By choose Protocol, under the Condition choose Equals, and under the Value choose HTTP then click on Add To List
    clip_image005
  8. Under the Filter By choose Client Username, under the Condition choose Not Equals, and under the Value write Anonymous then click on Add To List ( we want to monitor all authenticated users by username )
    clip_image006
  9. Under the Filter By choose Rule, under the Condition choose Equals, and under the Value choose the Firewall Policy you want to run the report for, in this article we have a rule called Allow Internet For All then click on Add To List
    clip_image007

    clip_image008
  10. The Filter will look like :
    clip_image009
  11. Click on the Start Query
  12. The Results will be fetched and displayed . Note that a pop up windows will state that a maximum of 10,000 records can be displayed only. Click OK
    clip_image010
    If you clicked on Help, you will know the reason why a maximum of 10,000 resulted can be displayed.
    clip_image011
  13. Now, to copy the results to Excel, on the Right Side Pane, under Tasks, click on Copy All Result to Clipboard
    clip_image012
  14. Now open Microsoft Excel , and paste the result. You can remove any column you find it not to be necessary and keep only the columns you want.

Summary
In this article, we learned how to create a report without the need for any third party application or web filter. All what we used is ISA
Server 2006 with MSDE logging and Excel.

BLOCK ATTACHMENT AND DOWNLOAD FROM HTTP AND HTTPS SITE

  1. Open ISA Management Console.
  2. Select your Array serveràFirewall Policy.
  3. Select your Web Access Rule, Right click on that.
  4. Configure HTTP Policy.
  5. To Block Download with Extension.
  6. Click on Extension TABàAddàExtension (Example to block exe- .exe) as per below screen shots.

clip_image002

  1. To Block Chat application and Attachment upload.
  2. Click on Signatures TABàAdd
  3. See the below screen shots.

clip_image004

Examples

Application

Location

HTTP header

Signature

MSN Messenger

Request headers

User-Agent:

MSN Messenger

Windows Messenger

Request headers

User-Agent:

MSMSGS

Netscape 7

Request headers

User-Agent:

Netscape/7

Netscape 6

Request headers

User-Agent:

Netscape/6

AOL Messenger (and all Gecko browsers)

Request headers

User-Agent:

Gecko/

Yahoo Messenger

Request headers

Host

msg.yahoo.com

Kazaa

Request headers

P2P-Agent

Kazaa

Kazaaclient:

Kazaa

Request headers

User-Agent:

KazaaClient

Kazaa

Request headers

X-Kazaa-Network:

KaZaA

Gnutella

Request headers

User-Agent:

Gnutella

Gnucleus

Edonkey

Request headers

User-Agent:

e2dk

Internet Explorer 6.0

Request headers

User-Agent:

MSIE 6.0

Morpheus

Response header

Server

Morpheus

Bearshare

Response header

Server

Bearshare

BitTorrent

Request headers

User-Agent:

BitTorrent

SOAP over HTTP

Request headers

User-Agent:

SOAPAction

Response headers

Kazaa

Headers

Request Header

X-Kazaa-Username: X-Kazaa-IP: X-Kazaa-SupernodeIP:

BitTorrent

Extensions

None

torrent

Many peer-to-peer clients

Headers

Request Header

P2P-Agent

Attachment upload Block

Response header

Content-Type

multipart/form-data