Module 1: Overview of Micros oft ISA Server 2004

Overview

Introducing Microsoft ISA Server 2004

Deployment Scenarios for ISA Server 2004

Lesson: Introducing ISA Server 2004

What Are the Benefits of ISA Server 2004?

Multimedia: Overview of ISA Server 2004 Functionality

ISA Server 2004 Management Interface

ISA Server 2004 Enterprise Edition Features

Differences Between ISA Server 2000 and ISA Server 2004

What Are the Benefits of ISA Server 2004?

Advanced Advanced Protection Protection

Multi-layer packet Multi-layer packet inspection inspection Unified firewall and Unified firewall and VPN server VPN server Multi-networking Multi-networking Application-layer Application-layer filtering filtering Efficient management Ease of Use Efficient management Ease of Use tools tools Network templates Network templates Product integration Product integration Ease of use for clients Ease of use for clients

Enhanced Enhanced Performance Performance

Optimized for Optimized for performance performance Integrated functionality Integrated functionality Scalability Scalability Web caching Web caching

Multimedia: Overview of ISA Server 2004 Functionality

ISA Server 2004 Management Interface

ISA Server 2004 Enterprise Edition Features

ISA Server 2004 Enterprise Edition provides enhanced scalability by:  Providing centralized storage and

configuration of the ISA Server configuration data

 Supporting CARP for distributed caching  Providing NLB integration

Differences Between ISA Server 2000 and ISA Server 2004

Multiple network support

Policies assigned per network

Routed and NAT network relationships

Extended protocol support

Advanced application filtering

Enhanced authentication options

VPN and quarantine integration

Stateful inspection for VPN

Export and import

Delegated permissions wizard for firewall administrator roles

Lesson: Deployment Scenarios for ISA Server 2004

How ISA Server Works as an Internet Edge Firewall

How ISA Server Works as a Back-End Firewall

How ISA Server Works as a Branch Office Firewall

How ISA Server Works as an Integrated Firewall, Proxy, and Caching Server

How ISA Server Works as a Proxy- and Caching-Only Server

How ISA Server Works as an Internet Edge Firewall

Use ISA Server to:  Block all Internet traffic unless explicitly

allowed

 Publish internal servers such as Web or

Exchange servers

LAN

 Provide a VPN gateway for remote users Web Server  Provide proxy and caching services

ISA Server

Web Serve r

VP N

Intern et

Serve r

User

Remote User

Exchange Server

How ISA Server Works as a Back-End Firewall

Use ISA Server to:  Securely publish Exchange servers  Securely publish other internal Web servers  Provide proxy and caching services

LAN

Web Server

Web Server

ISA Server

Firew all

Web Serv er

Serve r

Intern et

User

Remote User

Exchange Server

How ISA Server Works as a Branch Office Firewall

Use ISA Server to:  Create an IPSec tunnel-mode VPN between

offices

 Create a PPTP or L2TP with IPSec VPN between

offices

LAN

ISA Server

 Inspect and filter all traffic between offices LAN  Provide secure access to the Internet at the

branch office

ISA Server or other VPN gateway

Branch Office

VPN Tunnel

Serve r

Intern et

Corporate Headquarters

User

How ISA Server Works as an Integrated Firewall, Proxy, and Caching Server

Internet bandwidth

 Configure dial-up connections to the Internet  Block all inbound network traffic  Provide secure configurations using network templates

and server publishing wizards

Use ISA Server to:  Provide proxy and caching services to conserve

LAN

ISP Server

Intern et

ISA Server

Serve r

Web Server

User

How ISA Server Works as a Proxy- and Caching-Only Server

Use ISA Server with a single network adapter to provide proxy and caching services

Deploying ISA Server with a single network adapter means that it does not provide additional security ISA LAN functionality Server

Web Serv er

Serve r

Firew all

Intern et

User

Lab: Designing an ISA Server 2004 Implementation

Exercise 1: Designing an ISA Server Deployment at Contoso Pharmaceuticals

Exercise 2: Designing an ISA Server Deployment at Blue Yonder Airlines