<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Exchange Server Pro &#187; ISA 2004</title>
	<atom:link href="http://exchangeserverpro.com/tag/isa-2004/feed" rel="self" type="application/rss+xml" />
	<link>http://exchangeserverpro.com</link>
	<description>Microsoft Exchange Server news, tips, tricks and tutorials</description>
	<lastBuildDate>Tue, 31 Aug 2010 12:02:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Tom Shinder on “hardware” firewalls</title>
		<link>http://exchangeserverpro.com/tom-shinder-on-hardware-firewalls</link>
		<comments>http://exchangeserverpro.com/tom-shinder-on-hardware-firewalls#comments</comments>
		<pubDate>Fri, 31 Aug 2007 04:19:07 +0000</pubDate>
		<dc:creator>Paul Cunningham</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Cisco Pix]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[ISA 2004]]></category>
		<category><![CDATA[ISA 2006]]></category>
		<category><![CDATA[ISA Server]]></category>
		<category><![CDATA[OpenBSD]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.capslockassassin.com/2007/08/31/tom-shinder-on-hardware-firewalls/</guid>
		<description><![CDATA[Tom Shinder of ISAServer.org takes an amusing shot at the myth in some circles that a &#8220;hardware&#8221; firewall or &#8220;firewall appliance&#8221; offers more security than a Microsoft ISA Server firewall. I was drawn to a particular quote in his article about the relative security of ISA Server to other popular firewalls in the context of [...]]]></description>
			<content:encoded><![CDATA[<p>Tom Shinder of <a href="http://www.isaserver.org" title="Tom Shinder's ISAServer.org">ISAServer.org</a> takes an <a href="http://blogs.isaserver.org/shinder/2007/08/29/exchange-deployment-and-isa-firewall-nightmare-scenarios-getting-to-know-the-nightmare-on-exchange-street-and-hork-mode-sandwich-scenarios/" title="Exchange Deployment and ISA Firewall Nightmare Scenarios — Getting to Know the ">amusing shot </a>at the myth in some circles that a &#8220;hardware&#8221; firewall or &#8220;firewall appliance&#8221; offers more security than a Microsoft ISA Server firewall.</p>
<p><a href="http://www.exchangeserverpro.com/wp-content/uploads/2007/08/shinderonfirewalls.jpg" title="Tom Shinder on “Hardware” firewalls"><img src="http://www.exchangeserverpro.com/wp-content/uploads/2007/08/shinderonfirewalls.jpg" alt="Tom Shinder on “Hardware” firewalls" /></a></p>
<p>I was drawn to a particular quote in his article about the relative security of ISA Server to other popular firewalls in the context of the number of reported security vulnerabilities for each product.</p>
<blockquote><p>A quick look at <a href="http://www.secunia.com/" title="Secunia.com"><font color="#003399">www.secunia.com</font></a> shows that the ISA Firewall (2004 and 2006) have no active security issues. Compare this with any “hardware” firewall and you will see that the ISA Firewall is more secure than just about any hardware firewall.</p></blockquote>
<p>There are a lot of firewall appliances out there so I didn&#8217;t do an exhaustive search of their stats on Secunia, but I did take a look at the stats for ISA Server, Cisco Pix, and OpenBSD as those are the three firewalls I am most familiar with in my professional life.</p>
<p><strong>ISA Server</strong></p>
<p><a href="http://www.exchangeserverpro.com/wp-content/uploads/2007/08/secunia_isa2004.JPG" title="secunia_isa2004.JPG"><img src="http://www.exchangeserverpro.com/wp-content/uploads/2007/08/secunia_isa2004.thumbnail.JPG" alt="secunia_isa2004.JPG" /></a><a href="http://www.exchangeserverpro.com/wp-content/uploads/2007/08/secunia_isa2006.JPG" title="secunia_isa2006.JPG"><img src="http://www.exchangeserverpro.com/wp-content/uploads/2007/08/secunia_isa2006.thumbnail.JPG" alt="secunia_isa2006.JPG" /></a></p>
<p><strong>Cisco Pix</strong></p>
<p><a href="http://www.exchangeserverpro.com/wp-content/uploads/2007/08/secunia_pix6.JPG" title="secunia_pix6.JPG"><img src="http://www.exchangeserverpro.com/wp-content/uploads/2007/08/secunia_pix6.thumbnail.JPG" alt="secunia_pix6.JPG" /></a><a href="http://www.exchangeserverpro.com/wp-content/uploads/2007/08/secunia_pix7.JPG" title="secunia_pix7.JPG"><img src="http://www.exchangeserverpro.com/wp-content/uploads/2007/08/secunia_pix7.thumbnail.JPG" alt="secunia_pix7.JPG" /></a></p>
<p><strong>OpenBSD</strong></p>
<p><a href="http://www.exchangeserverpro.com/wp-content/uploads/2007/08/secunia_obsd3.JPG" title="secunia_obsd3.JPG"><img src="http://www.exchangeserverpro.com/wp-content/uploads/2007/08/secunia_obsd3.thumbnail.JPG" alt="secunia_obsd3.JPG" /></a><a href="http://www.exchangeserverpro.com/wp-content/uploads/2007/08/secunia_pix71.JPG" title="secunia_pix71.JPG"><img src="http://www.exchangeserverpro.com/wp-content/uploads/2007/08/secunia_pix71.thumbnail.JPG" alt="secunia_pix71.JPG" /></a></p>
<p>I found those numbers to be pretty interesting.  It is not unusual to have a customer request that a two-tiered firewall infrastructure be implemented on their environment.  Often this means they request that some type of &#8220;appliance&#8221;, be that a Cisco Pix or some other third party box painted red and given a secure sounding name, be placed between the internet and the ISA Server that we are implementing for them.  Sometimes this is based on the principle of defense in depth, whereas other times it is based on a false belief that a product from Microsoft couldn&#8217;t possibly be secure.  Maybe if they saw the stats above they would think otherwise.</p>
<h3  class="related_post_title">Related posts:</h3><ul class="related_post"><li><a href="http://exchangeserverpro.com/well-designed-security-systems-fail-gracefully-sonicwall-does-not" title="Well-designed security systems fail gracefully, SonicWALL does not">Well-designed security systems fail gracefully, SonicWALL does not</a></li><li><a href="http://exchangeserverpro.com/microsoft-exam-70-350-implementing-microsoft-internet-security-and-acceleration-isa-server-2004" title="Microsoft Exam 70-350: Implementing Microsoft Internet Security and Acceleration (ISA) Server 2004">Microsoft Exam 70-350: Implementing Microsoft Internet Security and Acceleration (ISA) Server 2004</a></li><li><a href="http://exchangeserverpro.com/security-hole-found-in-openbsd" title="Security hole found in OpenBSD">Security hole found in OpenBSD</a></li><li><a href="http://exchangeserverpro.com/ssl-certificate-trust-errors-for-new-thawte-certificates" title="SSL Certificate Trust Errors for New Thawte Certificates">SSL Certificate Trust Errors for New Thawte Certificates</a></li><li><a href="http://exchangeserverpro.com/how-to-configure-a-relay-connector-for-exchange-server-2010" title="How to Configure a Relay Connector for Exchange Server 2010">How to Configure a Relay Connector for Exchange Server 2010</a></li></ul><hr />
<p>This article <a href="http://exchangeserverpro.com/tom-shinder-on-hardware-firewalls">Tom Shinder on “hardware” firewalls</a> is © 2007 ExchangeServerPro.com</p>
<p>Get more <a href="http://exchangeserverpro.com">Exchange Server tips</a> at <a href="http://exchangeserverpro.com">ExchangeServerPro.com</a></p>]]></content:encoded>
			<wfw:commentRss>http://exchangeserverpro.com/tom-shinder-on-hardware-firewalls/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Microsoft Exam 70-350: Implementing Microsoft Internet Security and Acceleration (ISA) Server 2004</title>
		<link>http://exchangeserverpro.com/microsoft-exam-70-350-implementing-microsoft-internet-security-and-acceleration-isa-server-2004</link>
		<comments>http://exchangeserverpro.com/microsoft-exam-70-350-implementing-microsoft-internet-security-and-acceleration-isa-server-2004#comments</comments>
		<pubDate>Thu, 05 Jul 2007 02:31:38 +0000</pubDate>
		<dc:creator>Paul Cunningham</dc:creator>
				<category><![CDATA[Reviews]]></category>
		<category><![CDATA[Books]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[ISA 2004]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.capslockassassin.com/2007/07/05/microsoft-exam-70-350-implementing-microsoft-internet-security-and-acceleration-isa-server-2004/</guid>
		<description><![CDATA[This morning I sat the Microsoft certification exam 70-350 for ISA Server 2004.  I&#8217;d been putting this one off for a while, having already worked through the Microsoft Press training guide, a lot of whitepapers, and worked with the product for a lot of different customers over the last couple of years.  I passed the [...]]]></description>
			<content:encoded><![CDATA[<p>This morning I sat the<a target="_blank" href="http://www.microsoft.com/learning/exams/70-350.mspx" title="Preparation Guide for Exam 70-350 at Microsoft.com"> Microsoft certification exam 70-350 </a>for ISA Server 2004.  I&#8217;d been putting this one off for a while, having already worked through the Microsoft Press training guide, a lot of whitepapers, and worked with the product for a lot of different customers over the last couple of years.  I passed the exam with plenty of room to spare.</p>
<p>Someone gave me the tip that the exam is not particularly difficult.  I tend to agree, but that would largely have to do with all of the work and study I&#8217;ve put into it beforehand.  ISA Server 2004 is a great product, and the new versions are excellent too.  The biggest hurdles in understanding it seem to be early on when you first start using it.</p>
<p>If you&#8217;re looking to do some training on ISA Server 2004 with the goal of certifying then I would strongly recommend the <a target="_blank" href="http://www.amazon.com/exec/obidos/ASIN/0735621691/ref=nosim/roblog-21" title="MCSA/MCSE Self-Paced Training Kit (Exam 70-350): Implementing Microsoft Internet Security and Acceleration Server 2004 at Amazon.com">Microsoft Press training guide</a>.  The books contents will thoroughly prepare you for the exam provided you work through the material properly and don&#8217;t skimp on the practical exercises or review questions.</p>
<p>You can also make use of the extensive <a href="http://www.microsoft.com/technet/isa/2004/library/default.mspx" title="ISA 2004 Technical Library at Microsoft.com">ISA 2004 Technical Library </a>on the Microsoft website.  The documentation there could be used for all of your training instead of using the training guide, but won&#8217;t take you through the subject in the same fashion.  However it does make for excellent complimentary material for your training and for your real world work with the product.</p>
<p>I would give you tips on which areas to focus on but really the exam questions I faced pretty well broadly covered the entire product.  There was no particular areas to focus on to the exclusion of others.  I would certainly recommend though that you do not sit the exam until you are thoroughly familiar with fundamental networking concepts such as subnetting and routing, and with the ISA Server 2004 networking model.</p>
<h3  class="related_post_title">Related posts:</h3><ul class="related_post"><li><a href="http://exchangeserverpro.com/the-essential-exchange-server-2007-toolkit" title="The Ultimate Exchange Server 2007 Toolkit">The Ultimate Exchange Server 2007 Toolkit</a></li><li><a href="http://exchangeserverpro.com/microsoft-certification-the-mark-russinovich-exam" title="Microsoft Certification – The Mark Russinovich Exam">Microsoft Certification – The Mark Russinovich Exam</a></li><li><a href="http://exchangeserverpro.com/microsoft-exam-70-236-exchange-server-2007-configuration-mcts" title="Microsoft Exam 70-236: Exchange Server 2007 Configuration (MCTS)">Microsoft Exam 70-236: Exchange Server 2007 Configuration (MCTS)</a></li><li><a href="http://exchangeserverpro.com/tom-shinder-on-hardware-firewalls" title="Tom Shinder on “hardware” firewalls">Tom Shinder on “hardware” firewalls</a></li><li><a href="http://exchangeserverpro.com/two-security-books" title="Two Security Books">Two Security Books</a></li></ul><hr />
<p>This article <a href="http://exchangeserverpro.com/microsoft-exam-70-350-implementing-microsoft-internet-security-and-acceleration-isa-server-2004">Microsoft Exam 70-350: Implementing Microsoft Internet Security and Acceleration (ISA) Server 2004</a> is © 2007 ExchangeServerPro.com</p>
<p>Get more <a href="http://exchangeserverpro.com">Exchange Server tips</a> at <a href="http://exchangeserverpro.com">ExchangeServerPro.com</a></p>]]></content:encoded>
			<wfw:commentRss>http://exchangeserverpro.com/microsoft-exam-70-350-implementing-microsoft-internet-security-and-acceleration-isa-server-2004/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
