introduction to isa 2004 dana epp microsoft security mvp

39
Introduction to ISA 2004 Dana Epp Microsoft Security MVP

Post on 18-Dec-2015

224 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

Introduction to ISA 2004

Dana Epp

Microsoft Security MVP

Page 2: Introduction to ISA 2004 Dana Epp Microsoft Security MVP
Page 3: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

Who am I?

Page 4: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

Microsoft Windows Security MVP

Page 5: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

Information Security Professional

Page 6: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

Computer Security Software Architect

Page 7: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

Small Business Owner

Page 8: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

What do I know about firewalls?

Page 9: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

I’ve written firewall code

Page 10: Introduction to ISA 2004 Dana Epp Microsoft Security MVP
Page 11: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

I’ve deployed firewalls(big and small)

Page 12: Introduction to ISA 2004 Dana Epp Microsoft Security MVP
Page 13: Introduction to ISA 2004 Dana Epp Microsoft Security MVP
Page 14: Introduction to ISA 2004 Dana Epp Microsoft Security MVP
Page 15: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

• 100’s of small businesses• Many different verticals

• Manufacturing• Medical• Professional Services• Educational• Financial• etc

Page 16: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

I’ve invented new firewalls

Page 17: Introduction to ISA 2004 Dana Epp Microsoft Security MVP
Page 18: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

I know a bit about them.

Page 19: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

caching

Content filtering

application publishing

advanced application layer firewall

caching

content filtering

application publishing

advanced application layer firewall / vpn

ISA Server 2004

Page 20: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

What’s the differencebetween ISA and other

SMB firewalls?

Page 21: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

Simple Ingress Filtering

Simple Egress Filtering

Complex Ingress Filtering

Complex Egress Filtering

Application Content Filtering

Virtual Private Networking

Web Caching

MicrosoftISA 2004

NATDevice

Typical HardwareFirewall

Some have limited VPN

AD Authentication

Advanced HardwareFirewall

Rarelyavailable

Differences in SMB Firewalls

Page 22: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

Patch management issues for the firewall

Page 23: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

What’s the important difference?

Page 24: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

A traditional firewall’s view of a packet

Application Layer Application Layer ContentContent

????????????????????????????????????????????

• Only packet headers are inspected– Application layer content appears as “black box”

IP HeaderIP HeaderSource Address,Dest. Address,

TTL, Checksum

TCP TCP HeaderHeaderSequence Number

Source Port,Destination Port,

Checksum

• Forwarding decisions based on port numbers– Legitimate traffic and application layer attacks use identical ports

Internet

Expected HTTP Traffic

Unexpected HTTP Traffic

Attacks

Non-HTTP Traffic

Corporate Network

Page 25: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

Problem. UFBP!

Page 26: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

ISA Server’s view of a packet• Packet headers and application content are inspected

Application Layer ContentApplication Layer Content<html><head><meta http-

quiv="content-type" content="text/html; charset=UTF-8"><title>MSNBC - MSNBC Front Page</title><link rel="stylesheet"

IP HeaderIP Header

Source Address,Dest. Address,

TTL, Checksum

TCP TCP HeaderHeader

Sequence NumberSource Port,

Destination Port,Checksum

• Forwarding decisions based on content– Only legitimate and allowed traffic is processed

Internet Expected HTTP Traffic

Unexpected HTTP Traffic

Attacks

Non-HTTP Traffic

Corporate Network

Page 27: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

What’s new in ISA 2004?

Page 28: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

Updated security architecture

Advanced ProtectionApplication layer security designed to protect

Microsoft applications

Deep content inspection Enhanced, customizable HTTP protocol filters Comprehensive and flexible policies Stateful routing for all IP protocols

Enhanced Exchange Server Integration

Support for Outlook RPC over HTTP Enhanced Outlook Web Access security Easy to use configuration wizards

Fully integrated VPN Unified firewall -- VPN filtering Site-to-site IPsec Tunnel Mode support Network access quarantine

Secure Internet Information Server

and SPS

SSL Bridging for IIS and SPS Easy to use Web publishing wizards AD, RADIUS, SecurID authentication

Page 29: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

New management tools and UI

Ease of UseEfficient and cost effective network security

Multi-network architecture

Unlimited network definitions and types Firewall policy applied to all traffic Per network routing relationships

Network templates and wizards

Wizard simplifies routing configuration Easy setup for common network topologies Easily customized for sophisticated scenarios

Visual policy editor Firewall policy with single, ordered rule-base Drag and drop editing, scenario-driven wizards XML-based configuration import and export

Enhanced trouble-shooting

Monitoring dashboard Real-time log viewer Content sensitive task panes

Page 30: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

Commitment to integration

Fast, Secure AccessEmpowers you to connect users to relevant information on

yournetwork in a cost efficient manner

Enhanced architecture High speed data transport Utilizes latest Windows and PC hardware High speed application filtering platform

Web cache Updated policy rules Serve content locally Pre-fetch content during low activity periods

Internet access control User- and group-based Web usage policy Extensible by third parties

Comprehensive authentication

New support for RADIUS and RSA SecurID User- and group-based access policy Third-party extensibility

Page 31: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

Sample Scenarios

Page 32: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

Scenario: Securely make email available to outside employees

Page 33: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

Solution: Outlook over RPC, OMA, Virtual Private Networking

Page 34: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

Scenario: Control Internet access and protect clients from malicious

Internet traffic

Page 35: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

Solution: Content filtering, scheduled access, firewall client

Page 36: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

Scenario: Ensure fast access to the most frequently used web content

Page 37: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

Solution: Web Proxy

Page 38: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

Call to Action

• Give ISA 2004 a try

• Consider buying SBS Premium instead of SBS Standard.

• If managing hardware firewalls, CHECK FOR FIRMWARE UPDATES.

Page 39: Introduction to ISA 2004 Dana Epp Microsoft Security MVP

For more information:• Amy’s ISA in SBS blog: http://isainsbs.blogspot.com• ISA Server Resource site http://www.isaserver.org• Dana’s security blog: http://silverstr.ufies.org• Firewall Dashboard http://www.scorpionsoft.com

Dana Epp

Microsoft Security MVP