Re: SSL VPN appliance vs ISA server



If you have the opportunity to use IAG then do it.
I disagree with the term SSL VPN,...it may be SSL but there is nothing "VPN"
about it,...it is a marketing term. What IAG does really in no way
resembles anything close to what RRAS does or ISA Publishing features do.
It is a complete, total "apples and oranges", there is no direct comparison.
What AIG does is more similar to a Citrix setup with their web interface
that makes individual Applications available to user with a web browser.

I don't know anything about SharePoint. Other than it being a glorified web
site, I know "zero" about it.

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.asp

Microsoft ISA Server Partners: Partner Hardware Solutions
http://www.microsoft.com/forefront/edgesecurity/partners/hardwarepartners.mspx
-----------------------------------------------------

"Coop" <Coop@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:D06BE77F-F861-41E3-9464-CFB95161C1D8@xxxxxxxxxxxxxxxx
Hi,
I'm getting ready to expose my SharePoint farm for remote access from the
Internet. Everything I read about setting up a SharePoint extranet
topology
points to using a reverse proxy like ISA server or a SSL VPN appliance to
front-end everything. (BTW, currently, we have only PPTP/IPSEC VPN into
our
RRAS box which is a IAS (RADIUS) client.) I'm debating whether to push to
replace RRAS with a SSL VPN appliance - maybe Microsoft's IAG - or just an
ISA server in reverse proxy mode. But my question is what is the
effective
difference in terms oif security between an SSL VPN appliance vs putting
an
SSL server certificate on an ISA box? Is that the way I would set up
ISA -
with a server cert? Do they both create an encryption tunnel for
authentication and data stream? From a remote client browser point of
view,
both would behave the same, right - i.e., just use "HTTPS" in the URL.

Thanks for helping me understand what approach to take.


.



Relevant Pages

  • RE: ISA 2006 and SSL
    ... In ISA Server 2006, SSL bridging is automatically configured when the ... A client requests an SSL object. ... The Web server returns the HTTP object to ...
    (microsoft.public.isa)
  • Re: ISA - IIS - SSL question
    ... > IIS. ... Enabled SSL Listeners on ISA server for our public IP ... > that is made available to the internet by a device other than your ISA ...
    (microsoft.public.isaserver)
  • Re: ISA wildcard certificate
    ... | I'm having trouble to configure my setup with a wildcard SSL. ... The subject of the certificate presented to the webclient from ISA MUST be ... The subject of the certificate presented to the ISA server from IIS MUST be ...
    (microsoft.public.isa)
  • FW: MS04-11, SSL, and ISA Server
    ... I found this response to be very interesting. ... > Can this DoS be performed against an ISA server which proxies the SSL ... > Mitsubishi Digital Electronics America ...
    (NT-Bugtraq)