Re: Domain groups

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Hi.

tahnks for the answer.

But it doesnt work. when I user all users in my policy i get access. When i
use my AD user or a group I get access denied.

Can You help me futher?
/Horslev

"Phillip Windell" wrote:

You create a User Set in ISA,...then add domain users or domain groups to
the User Set. The User Set is what you use in the Access Rule.
The User Sets are more-or-less Groups but are unique to ISA. They exist
this way because not all ISA deployments are domain members and cannot use
AD Users and Group without a RADIUS server, so the User Sets provide a means
to group them together. This also helps you keep AD more simpler and not
have to create a bunch of special groups in AD for ISA's use, so you just
add whatever combination of AD Users and existing AD Groups to the User Set
to get the results you want.

You may find the links that I usually leave in my signature useful.
--
Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com

The views expressed are my own (as annoying as they are), and not those of
my employer or anyone else associated with me.
-----------------------------------------------------
Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Microsoft Internet Security & Acceleration Server: Guidance
http://www.microsoft.com/isaserver/techinfo/Guidance/2004.asp
http://www.microsoft.com/isaserver/techinfo/Guidance/2000.asp

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.asp

Deployment Guidelines for ISA Server 2004 Enterprise Edition
http://www.microsoft.com/technet/prodtechnol/isa/2004/deploy/dgisaserver.mspx
-----------------------------------------------------



"Horslev" <Horslev@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:BD7D383F-4671-4341-AE55-D42AF4F4518C@xxxxxxxxxxxxxxxx
Hi.

Have a Windows2003 server (incl sp) and ISA 2006.

I would like to use windows domain groups to control access to certain
ports
(outgoing). But i dont seem to work.

fx:
allow: internal->external, protocols, IF member of "domain group".

I keep getting access denied i log.

HELP!



.



Relevant Pages

  • RE: ISA Server failed to load the firewall policy configuration.
    ... I have this problem on several ISA, ... ISA2006 have this problem, but server ... doesnt work as router too. ...
    (microsoft.public.isa.configuration)
  • RE: Sercond ISA on SBS Member Server
    ... ISA on a SBS member server. ... Without a good backup, it's difficult to have the server ... - This is often used for ISA server configuration recovery. ...
    (microsoft.public.windows.server.sbs)
  • RE: Internet Usage Reports
    ... There is no other application on the SBS server box that can monitor ... internet activities as your needs rather than ISA server. ... Microsoft Internet Security and Acceleration Server 2004 is the ... Microsoft is providing this information as a convenience to you. ...
    (microsoft.public.windows.server.sbs)
  • Re: Nagging Autorization issue for Companyweb after ISA04 install
    ... Check the companyweb CNAME entry in the DNS Server. ... Does the situation occur when you access companyweb from the ISA ... > 'Microsoft Firewall' service. ... > This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • RE: OWA page not displayed Outside
    ... Open the ISA Server management console, ... On the ISA Server computer, stop the Microsoft Firewall service. ...
    (microsoft.public.windows.server.sbs)