Re: Domain groups

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Hi. Yes - I made the server a domain member before installing ISA2006.

Best Regards - Michael Horslev

"Phillip Windell" wrote:

Was the ISA box already a Domain Member before the ISA software was
installed or was it made a Domain Member afterwards?

--
Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com

The views expressed are my own (as annoying as they are), and not those of
my employer or anyone else associated with me.


"Horslev" <Horslev@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:DA26C2C5-50AC-4B82-A292-D7CE024DF9FB@xxxxxxxxxxxxxxxx
Hi.

tahnks for the answer.

But it doesnt work. when I user all users in my policy i get access. When
i
use my AD user or a group I get access denied.

Can You help me futher?
/Horslev

"Phillip Windell" wrote:

You create a User Set in ISA,...then add domain users or domain groups to
the User Set. The User Set is what you use in the Access Rule.
The User Sets are more-or-less Groups but are unique to ISA. They exist
this way because not all ISA deployments are domain members and cannot
use
AD Users and Group without a RADIUS server, so the User Sets provide a
means
to group them together. This also helps you keep AD more simpler and not
have to create a bunch of special groups in AD for ISA's use, so you just
add whatever combination of AD Users and existing AD Groups to the User
Set
to get the results you want.

You may find the links that I usually leave in my signature useful.
--
Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com

The views expressed are my own (as annoying as they are), and not those
of
my employer or anyone else associated with me.
-----------------------------------------------------
Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Microsoft Internet Security & Acceleration Server: Guidance
http://www.microsoft.com/isaserver/techinfo/Guidance/2004.asp
http://www.microsoft.com/isaserver/techinfo/Guidance/2000.asp

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.asp

Deployment Guidelines for ISA Server 2004 Enterprise Edition
http://www.microsoft.com/technet/prodtechnol/isa/2004/deploy/dgisaserver.mspx
-----------------------------------------------------



"Horslev" <Horslev@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:BD7D383F-4671-4341-AE55-D42AF4F4518C@xxxxxxxxxxxxxxxx
Hi.

Have a Windows2003 server (incl sp) and ISA 2006.

I would like to use windows domain groups to control access to certain
ports
(outgoing). But i dont seem to work.

fx:
allow: internal->external, protocols, IF member of "domain group".

I keep getting access denied i log.

HELP!






.



Relevant Pages

  • Re: SBS2003 Prem with member Web server
    ... What needs to be understood is *why* exactly the OP wants it to be a domain member? ... Jim Harrison [ISA SE] ... Yes - adding a public server to your domain increases your domain attack ... Charlie mentions placing the web server external to ISA as ...
    (microsoft.public.windows.server.sbs)
  • Re: From Cisco Pix to ISA.
    ... "Phillip Windell" wrote: ... running the ISA Best Practices Analyser will help find any configuration ... Microsoft Internet Security & Acceleration Server: ...
    (microsoft.public.isa.publishing)
  • Re: Allow SNMP Traffic
    ... "Phillip Windell" wrote: ... Protocol: SNMP, SNMP Trap ... My name is Durgesh Uniyal and i am using ISA 2004 Ent. ... machine and i am using this server as a proxy server as ...
    (microsoft.public.isa.configuration)
  • Re: Rule blocks OutLook Mail
    ... I previusly used ISA 2000 and there was no problem with outlook. ... I had old firewall client instaled and I tried to change it with new client ... your outlook clients are unable to connect to an external mail server? ... Phillip Windell ...
    (microsoft.public.isa)
  • Re: Problem Administering W2K3 Server w/ISA 2006
    ... Thank you Phillip for your responce. ... This ensures that the ISA System Policies get created properly ... Debunking the Myth that the ISA Firewall Should Not be a Domain Member ... Troubleshooting Client Authentication on Access Rules in ISA Server 2004 ...
    (microsoft.public.isa)