Re: How to restrict incoming VPN to one internal IP address

From: Scott Harding - MS MVP (scrockel_at_**NO_SPAM**hotmail.com)
Date: 11/12/04


Date: Fri, 12 Nov 2004 13:20:00 -0700

Checkpoint and Watchguard have had several updates over the years as well
and usually MS fixes are the only ones people seem so upset by anyways. You
reasons are obviously personal. I also love Checkpoint and the Watchguard
boxes and many of the other hardware firewalls but in reality most of them
perform almost identically and most people choose one or the other based on
price/features and not on some personal bias ;) I currently have ISA and
Checkpoint(different networks) in my office and have used several scanners
including Nessus and many others and they both report the same things.
Obviously everyone will have a different opinion on this so I don't want to
squabble and typically personal experience or other factors lead people to
purchase different things but that isn't always based on fact.

-- 
Scott Harding
MCSE, MCSA, A+, Network+
Microsoft MVP - Windows NT Server
"Leythos" <void@nowhere.org> wrote in message
news:MPG.1bfb10d7c0d297719899ce@news-server.columbus.rr.com...
> In article <eQSCLzaxEHA.2876@TK2MSFTNGP12.phx.gbl>,
> scrockel@**NO_SPAM**hotmail.com says...
> > Why would you never use ISA? Just because it is MS doesn't mean it isn't
> > secure. I personally believe it is one of the best and I have tried them
> > ALL!!
>
> This might explain it - since I've never seen an alert for the firewalls
> that I use like this in years.
>
>    MS04-039   - Vulnerability in ISA Server 2000 and Proxy Server
>                 2.0 Could Allow Internet Content Spoofing (888258)
>
>               - Affected Software:
>                 - Microsoft Proxy Server 2.0 Service Pack 1
>                 - Microsoft Internet Security and Acceleration
>                   Server 2000 Service Pack 1 and Microsoft Internet
>                   Security and Acceleration Server 2000
>                   Service Pack 2
>                 - Microsoft Small Business Server 2000 (which
>                   includes Microsoft Internet Security and
>                   Acceleration Server 2000)
>                 - Microsoft Small Business Server 2003 Premium
>                   Edition (which includes Microsoft Internet
>                   Security and Acceleration Server 2000)
>
>               - Impact: Spoofing
>               - Version Number: 1.0
>
> -- 
> -- 
> spamfree999@rrohio.com
> (Remove 999 to reply to me)


Relevant Pages

  • Re: ISA Server versus Checkpoint Firewall
    ... Also, there is more to "stateful" than you describe; it goes all the way to L7, something Checkpoint doesn't yet do. ... Checkpoint is only recently starting to realize the value of application-layer filtering; something ISA has had for years. ... ISA Server can be fairly easy to just plug in, ... Unfortunately that can often be a bad thing as it is very easy to misconfigure a firewall and the ...
    (microsoft.public.isa.enterprise)
  • Re: Retiring ISA Server 2000 in 10.0.x.x Network with two Routers
    ... but to be really exact our ISA is configured as a Firewall and ... provides Proxy server services. ... clients to the other default gateway (WatchGuard) and stop all of the ISA ... >> router (a Windows 2000 Server with three NICs and running ISA Server ...
    (microsoft.public.isa)
  • Re: S2S Verbindung: ISA 2004 SP2 mit Watchguard
    ... Die Watchguard steht auf einer Serverfarm und davor ist "nichts", ... Watchguard und am ISA richtig sind und zudem auf beiden Seiten die ... Hilfe & Infos rund um den ISA Server: http://www.msisafaq.de ... Bei einem Ping vom ISA kommt: ...
    (microsoft.public.de.german.isaserver)
  • Re: CheckPoint + ISA2004 Nating
    ... "There is no NATing to DMZ from Checkpoint. ... By default ISA will NAT everything to its external IP address, ... You will have to publish the servers on ISA. ...
    (microsoft.public.isa.configuration)
  • Re: Bei Ping von ISA nach Remote, IP-Sicherheit wird verhandelt
    ... Netz an der WG angeben, ... Tunnel, obwohle ISA und WG anzeigen das der Tunnel steht. ... du musst in der Netzwerkdefinition des Remotenetzwerks in der Watchguard, ...
    (microsoft.public.de.german.isaserver)