Re: How to disable all applications by default

Tech-Archive recommends: Fix windows errors by optimizing your registry



But keep in mind that a firewall analyzes *data* not the source. And the
FWC is there to enable non-proxy aware applications.

=?Utf-8?B?S1Q=?= <KT@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
news:58EE06FA-64C6-4FDD-8FAD-D4F8DDA9990E@xxxxxxxxxxxxx:

Thanks for answering my question Jim.
I've got say that I'm pretty disappointed in Microsoft if this is the
case.

Any like minded IT security people know that security products "deny
by default" and only authorised connections/applications are
permitted.

The firewall client (which is a great enabler) is now worthless to us,
as undesirable applications will be able to access the Internet unless
we know the name of all of them so we can disable all of them . This
equals a massive administration overhead for us.

What do you do in your organisation ??
"Jim Harrison (MSFT)" wrote:

Sorry - this isn't possible.
The Firewall client is designed to be an "enabler".

--
--
Jim Harrison [ISA SE]
Read the help, books and articles!

This posting is provided "AS IS" with no warranties, and confers no
rights.

"KT" <KT@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:416A97B4-2C42-4157-AFFE-09BCA56FE1D5@xxxxxxxxxxxxxxxx Yes by
default ISA's firewall policy will deny all by default. Sorry I
should have made myself clearer.

We have a rule in the firewall policy that allows our Internal
network to be able to access the Internet (External) via HTTP.

Now when using the firewall client this rule allows any application
to access the Internet via HTTP even if it is not listed in the
application settings under the Firewall Client on the ISA server.

I want to be able to disable all applications by default and then
only enable specific ones that we want to access the Internet i.e.
iexplore.exe acrord32.exe realplayer etc.

Is this Possible ?? The ISA documentation from Microsoft is very
limited (unless I'm looking in the wrong place)
BTW - We are running Win 2003 Sp1 with ISA2004 SP2.

"Asher_N" wrote:

ISA is set to Deny All by default.

=?Utf-8?B?S1Q=?= <KT@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
news:91477FB8-9B71-43D9-A0A2-B2B0487901AF@xxxxxxxxxxxxx:

Hi - Is it possible to deny all applications access to the
Internet by default when using the Firewall client and ISA 2004
SP2 ??

I know you can disable individual applications but I want to be
able to deny all applications and only allow a handful of
specific ones.

Thanks for your help.
Kurt.








.



Relevant Pages

  • Re: Intruders
    ... - Strong passwords for all your accounts - changed regularly. ... More full function applications for CD/DVD burning would be: ... Empty your Temporary Internet Files and shrink the size it stores to a ... Why you should use a computer firewall.. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: spyware menace
    ... Immunize with the appropriate applications, ... or use an alternate browser, get that firewall turned on, use that antivirus ... You should also empty your Internet Explorer Temporary Internet ... ANTIVIRUS SOFTWARE ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Recoverd mahine from SP2 nightmare
    ... It contains advice ... using Windows XP "prettifications". ... applications you do not use. ... You should at least turn on the built in firewall. ...
    (microsoft.public.windowsupdate)
  • Re: Report on services running
    ... two applications (These two applications may give you more than you knew you ... You should also empty your Internet Explorer Temporary Internet ... using Windows XP "prettifications". ... You should at least turn on the built in firewall. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: After Installing SP-2 my applications wont run
    ... I have several applications that are web based -developed 4+ years ago. ... I got a new computer and installed XP SP2 and I am unable to run these apps. ... > has been made to be general and an assumption of a "Windows" operating ... You should at least turn on the built in firewall. ...
    (microsoft.public.windowsxp.help_and_support)