ISA 2000 - Policy Elements

ISA Server 2000 Feb 2, 2025
ISA Policy Elements
  • Schedules - hours for which the policy is active/inactive
ISA Schedule
  • Bandwidth Priorities - prioritise traffic types - range 1 -200 compared as a ratio to other priorities
  • Destination Sets
ISA Destination sets
  • Client Address sets
ISA Client Address set
  • Protocol definitions (most common are defined by default)
ISA Protocol definitions
  • Content Groups - MIME Types
ISA Content Groups
  • Dial-up Entries - backup connection using modem

Rules

Order of processing:

  1. Does a protocol rule deny the request
  2. Does a protocol rule allow the request
  3. Does a site & content rule deny the request
  4. Does a site & content rule allow the request
  5. Does a packet filter block the request

Protocol Rule

No protocol rule is created by default; all traffic will be denied.

Site and Content Rules

Allow any rule is created by default.

Can redirect denied HTTP requests

Bandwidth Rules

Bandwidth by ratio

  • Network Allocation - traffic types
  • User Allocation - groups
  • Unused priorities - if reserved used, can be used by others
  • rule order - first rule that matches
  • default rule - if not matching other rules

Authentication

SecureNAT client - no auth - no user or group restrictionsFirewall Client - requires install, only Windows devicesWeb Proxy Clients - can use auth 

  • Basic Authentication - any device can support, details sent in clear text
  • Digest Authentication - Requires IE 5.0+
  • Integrated Windows Authentication - Kerberos , IE 2.0+
  • Client Certificate Authentication - every client needs a certificate

 Enabled per-server, needs to restart services. Default is integrated

Tags