ISA server 2004 is not checking AD for groups membership of groups added in the user sets?

From: yoSneiuQnebaSoNsopaX (pochacoxxx_at_yahoo.com)
Date: 11/09/04


Date: 9 Nov 2004 13:56:54 -0800

Hi, I am evaluating the ISA server 2004 at my work, but I don't know
if I am doing something wrong, but when I set up a new firewall policy
and
in the Users Tab of that policy, said explicitly that this firewall
rule apply for a user sets by example called "NAVIGATION BY USERS"
whose only members are domain's Active Directory Users, everything
goes well, BUT ("the infamous undocumented BUT") when I set up the
same firewall policy with a user sets called "NAVIGATION BY GROUPS"
whose only members are domain's
Active Directory Groups this rule doesn't WORKS, and even WORST this
rule apply for ALL the user, without cares if the user is member of
the active directory group that belong to the user sets or not.

I'm using ISA server 2004 Standard Edition, Windows 2000 Server SP4
all updates from windowsupdate apply,
apply the patch set kb821887, etc, etc.

Thanks for any Help!!!



Relevant Pages

  • Re: ISA server 2004 is not checking AD for groups membership of groups added in the user sets?
    ... > if I am doing something wrong, but when I set up a new firewall policy ... > whose only members are domain's Active Directory Users, ... > Active Directory Groups this rule doesn't WORKS, ...
    (microsoft.public.isaserver)
  • Re: WindowsPrincipal.IsInRole not working
    ... > That is an Active Directory question, but you should be able to change the ... > type of the group unless it contains members that they current group ... be a good way to start down the path of 'knowing when you should use it'! ...
    (microsoft.public.dotnet.security)
  • Re: Active Directory as a X.500 metadirectory
    ... A group object can contain other objects, ... The group object's members attribute contains the DN of each member. ... >>> Active Directory is a little new from the vantage of its implementation, ... >>> console, the containers appear empty, even though, for example the ...
    (microsoft.public.win2000.active_directory)
  • Re: Public Folder Forwarding
    ... It shows only mailbox-enabled objects when you're ... adding members. ... Multiple Contacts are configured in Active Directory ... you could set up a distribution group ...
    (microsoft.public.exchange.admin)
  • Active Directory Only Displays Local Objects
    ... all set up as members of the domain. ... The SBS Server is the DC. ... up/restore Active Directory and restore it, ... the only thing displayed is the local computer. ...
    (microsoft.public.windows.server.active_directory)