<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Reviewing the Microsoft ISA Server 2006 System Policy</title>
	<atom:link href="http://tmgblog.richardhicks.com/2009/07/08/reviewing-the-microsoft-isa-server-2006-system-policy/feed/" rel="self" type="application/rss+xml" />
	<link>http://tmgblog.richardhicks.com/2009/07/08/reviewing-the-microsoft-isa-server-2006-system-policy/</link>
	<description>Microsoft Forefront TMG 2010 and ISA Server 2004/2006 News and Information</description>
	<lastBuildDate>Thu, 09 Feb 2012 00:57:15 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Richard Hicks</title>
		<link>http://tmgblog.richardhicks.com/2009/07/08/reviewing-the-microsoft-isa-server-2006-system-policy/#comment-68</link>
		<dc:creator><![CDATA[Richard Hicks]]></dc:creator>
		<pubDate>Tue, 14 Jul 2009 21:23:59 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=458#comment-68</guid>
		<description><![CDATA[This should provide some clarification - &lt;a href=&quot;http://tmgblog.richardhicks.com/2009/07/14/microsoft-isa-server-2006-web-based-management-console/&quot; rel=&quot;nofollow&quot;&gt;http://tmgblog.richardhicks.com/2009/07/14/microsoft-isa-server-2006-web-based-management-console/&lt;/a&gt;.  Thanks!]]></description>
		<content:encoded><![CDATA[<p>This should provide some clarification &#8211; <a href="http://tmgblog.richardhicks.com/2009/07/14/microsoft-isa-server-2006-web-based-management-console/" rel="nofollow">http://tmgblog.richardhicks.com/2009/07/14/microsoft-isa-server-2006-web-based-management-console/</a>.  Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: reza</title>
		<link>http://tmgblog.richardhicks.com/2009/07/08/reviewing-the-microsoft-isa-server-2006-system-policy/#comment-66</link>
		<dc:creator><![CDATA[reza]]></dc:creator>
		<pubDate>Tue, 14 Jul 2009 13:13:22 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=458#comment-66</guid>
		<description><![CDATA[Thanks for your reply.

When we look at the properties of this rule, in the Protocols tab, we can see the &quot;ISA Server Web Management&quot;. What this protocol? What do you mean about &quot;old days when the operating system included a web-based management facility&quot;?

Thanks a lot!

-Reza]]></description>
		<content:encoded><![CDATA[<p>Thanks for your reply.</p>
<p>When we look at the properties of this rule, in the Protocols tab, we can see the &#8220;ISA Server Web Management&#8221;. What this protocol? What do you mean about &#8220;old days when the operating system included a web-based management facility&#8221;?</p>
<p>Thanks a lot!</p>
<p>-Reza</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Hicks</title>
		<link>http://tmgblog.richardhicks.com/2009/07/08/reviewing-the-microsoft-isa-server-2006-system-policy/#comment-65</link>
		<dc:creator><![CDATA[Richard Hicks]]></dc:creator>
		<pubDate>Mon, 13 Jul 2009 16:00:39 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=458#comment-65</guid>
		<description><![CDATA[I believe this is a leftover from the old days when the operating system included a web-based management facility.  There is no remote management utility for Microsoft ISA Server 2006, unless of course you have a &lt;strong&gt;&lt;a href=&quot;http://www.celestix.com/products/msa/index.html&quot; rel=&quot;nofollow&quot;&gt;Celestix MSA Series&lt;/a&gt; security appliance&lt;/strong&gt; which &lt;strong&gt;does&lt;/strong&gt; include a web-based management tool!  If you are interested in seeing a demonstration, send me a note and I&#039;ll provide you with a URL to our live online demonstration site.]]></description>
		<content:encoded><![CDATA[<p>I believe this is a leftover from the old days when the operating system included a web-based management facility.  There is no remote management utility for Microsoft ISA Server 2006, unless of course you have a <strong><a href="http://www.celestix.com/products/msa/index.html" rel="nofollow">Celestix MSA Series</a> security appliance</strong> which <strong>does</strong> include a web-based management tool!  If you are interested in seeing a demonstration, send me a note and I&#8217;ll provide you with a URL to our live online demonstration site.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: reza</title>
		<link>http://tmgblog.richardhicks.com/2009/07/08/reviewing-the-microsoft-isa-server-2006-system-policy/#comment-64</link>
		<dc:creator><![CDATA[reza]]></dc:creator>
		<pubDate>Mon, 13 Jul 2009 15:32:57 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=458#comment-64</guid>
		<description><![CDATA[In System Policy Editor, what is Web Management section. How can I manage ISA Server by using Web applications?

Thanks]]></description>
		<content:encoded><![CDATA[<p>In System Policy Editor, what is Web Management section. How can I manage ISA Server by using Web applications?</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Hicks</title>
		<link>http://tmgblog.richardhicks.com/2009/07/08/reviewing-the-microsoft-isa-server-2006-system-policy/#comment-61</link>
		<dc:creator><![CDATA[Richard Hicks]]></dc:creator>
		<pubDate>Thu, 09 Jul 2009 16:40:59 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=458#comment-61</guid>
		<description><![CDATA[&lt;a href=&quot;http://technet.microsoft.com/en-us/library/bb794718.aspx&quot; rel=&quot;nofollow&quot;&gt;http://technet.microsoft.com/en-us/library/bb794718.aspx&lt;/a&gt;]]></description>
		<content:encoded><![CDATA[<p><a href="http://technet.microsoft.com/en-us/library/bb794718.aspx" rel="nofollow">http://technet.microsoft.com/en-us/library/bb794718.aspx</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: reza</title>
		<link>http://tmgblog.richardhicks.com/2009/07/08/reviewing-the-microsoft-isa-server-2006-system-policy/#comment-58</link>
		<dc:creator><![CDATA[reza]]></dc:creator>
		<pubDate>Thu, 09 Jul 2009 08:34:43 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=458#comment-58</guid>
		<description><![CDATA[Can you please give the link of the ISA Security Guide IIRC?

Thanks]]></description>
		<content:encoded><![CDATA[<p>Can you please give the link of the ISA Security Guide IIRC?</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jason Jones</title>
		<link>http://tmgblog.richardhicks.com/2009/07/08/reviewing-the-microsoft-isa-server-2006-system-policy/#comment-57</link>
		<dc:creator><![CDATA[Jason Jones]]></dc:creator>
		<pubDate>Wed, 08 Jul 2009 22:51:51 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=458#comment-57</guid>
		<description><![CDATA[Nice post Rich ;)

This approach should be part of any least privilege design/implementation and is actually quite easy to do.

Although Microsoft did a good job with system policy, it can never reflect the actual needs of the environment and therefore needs to be &quot;tuned&quot; as necessary by thinking about what the ISA deployment actually requires.

This approach is a standard part of our ISA builds and is also recommended in the ISA security guide IIRC. Personally, I try and disable as many policies as possible and then create specific computer sets for each rule to remove the default objects. Well worth spending 5 mins on any deployment if you ask me ;)

Cheers

JJ]]></description>
		<content:encoded><![CDATA[<p>Nice post Rich <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>This approach should be part of any least privilege design/implementation and is actually quite easy to do.</p>
<p>Although Microsoft did a good job with system policy, it can never reflect the actual needs of the environment and therefore needs to be &#8220;tuned&#8221; as necessary by thinking about what the ISA deployment actually requires.</p>
<p>This approach is a standard part of our ISA builds and is also recommended in the ISA security guide IIRC. Personally, I try and disable as many policies as possible and then create specific computer sets for each rule to remove the default objects. Well worth spending 5 mins on any deployment if you ask me <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Cheers</p>
<p>JJ</p>
]]></content:encoded>
	</item>
</channel>
</rss>

