ISA 2004 Quarantine w/XP SP2 & Firewall Client?



Hello,

ISA 2004SE SP1. VPN and quarantine are working nicely. Here is the
question:

We have some XP SP2 mobile machines (laptops) that are joined to our domain
and also have the Firewall Client installed. I've noticed that when these
laptops traverse outside of our network and VPN back to ISA, at times the
ISA logs/authenticates the session as user: domain\%machinename% Which
causes the user to not authenticate as themself, but now as their domain
laptop.

Firewall Client is disabled during this VPN process. Furthermore, this only
occurs during quarantine afterwards the logs show the correct username
instead of machine name. Finally, the domain\%machinename% confusion only
appears with machines that: 1) Are joined to the domain and 2) Have the
Firewall Client installed & disabled. FC is enabled when laptops are local
on network.

It is not consistent whether authentication will be client username or
domain\%machinename%. Should the firewall client be uninstalled for domain
laptops that VPN back to ISA? Also, ISA did not recognize user "Domain
Computers" when added to the VPN allowed users list. =)

Thanks!
Edgardo



.



Relevant Pages

  • Re: Nortel VPN Client
    ... Turn off the firewall client from ISA. ... VPN negotiation and the actual tunnel cannot go through separate routes. ... If I run port 500 through ISA but run port 10001 ...
    (microsoft.public.windows.server.sbs)
  • RE: ISA 2004 - Internet Access without using Firewall Client
    ... you can not install ISA firewall client on mobile laptops but meanwhile ... make the laptops to access Internet through ISA server. ... we can make the laptops to access Internet without ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN to server and then cant browse the internet
    ... the firewall client. ... > select the VPN connection and open properties. ... > the users will now access the internet via ISA and FW ...
    (microsoft.public.backoffice.smallbiz2000)
  • RE: Remote Exchange Server Access broken
    ... the firewall client application identifies the internal/external ... firewall client application and then sent to the ISA server. ... Generally speaking, to use a VPN client through the ISA server, we ...
    (microsoft.public.windows.server.sbs)
  • Re: Access rule/Authentication problem in ISA 2004
    ... With the VPN I ment from internal to external. ... says that the Firewall Client supports 'All Winsock applications'. ... The problem is that the Firewall Client can not authenticate all programs ... In ISA 2000 this was possible. ...
    (microsoft.public.isa)