?
Solved

ISA server 2004 and users in rules

Posted on 2006-07-11
14
Medium Priority
?
3,690 Views
Last Modified: 2013-11-16
Hello. I have Isa server 2004 in an active directory environment. I have 1 simple rule, that all authenticated users have rights to port 80 and https. I want to add a rule for skype for certain users but when I add the rule it doesnt matter which users I select, all the users can use skype.
0
Comment
Question by:editperfil
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 5
  • 3
14 Comments
 
LVL 1

Expert Comment

by:cbeee
ID: 17082685
make sure the skype rule is above your 'simple' rule in the rulebase.
0
 

Author Comment

by:editperfil
ID: 17082739
Yes, is the first rule
0
 
LVL 1

Expert Comment

by:cbeee
ID: 17082819
so presumably nobody could access skype before you put the rule in ?

you have an AD group with the skype users in ?
0
Need protection from advanced malware attacks?

Look no further than WatchGuard's Total Security Suite, providing defense in depth against today's most headlining attacks like Petya 2.0 and WannaCry. Keep your organization out of the news with protection from known and unknown threats.

 

Author Comment

by:editperfil
ID: 17082848
Yes. I define the users in Isa server. I create a group where I add the AD users
0
 
LVL 1

Expert Comment

by:cbeee
ID: 17082893
Best Practice and easier is to add the users to and AD group then use teh group for the rule.  The same goes for the simple rule.
0
 

Author Comment

by:editperfil
ID: 17082959
But it doesnt work!!!
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 17084135
I assume Skype is going out over port 80 also?
Open the gui,
select monitoring - logging - click on start query.
Make a Skype connection; are you seeing any additional traffic pass through the log?

Is the ISA in firewall mode or cache mode (one ot two nic's installed)?
Are you using the ISA client on your workstations?
Are you using SecureNAT?
0
 

Author Comment

by:editperfil
ID: 17084166
Is in firewall. In fact skype is an example. I tried other ports, for example radio and again if i put a rule all users can use it.
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 17084284
Can you answer the rest of the questions please?
0
 

Author Comment

by:editperfil
ID: 17084430
Is in firewall more
With isa client and without isa client
Yes securenat
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 17085613
How have you set the ISA Proxy?
open the GUI
Select configuration - networks
double-click internal and view the properties.
How are users authenticating for socks and web traffic? Over port 8080?

Open the gui,
select monitoring - logging - click on start query.
Make a Skype connection; are you seeing any additional traffic pass through the log?
0
 

Author Comment

by:editperfil
ID: 17098990
Over port 8080 with integrated security. I see traffic with skype.
0
 
LVL 51

Accepted Solution

by:
Keith Alabaster earned 750 total points
ID: 17125196
If Skype is using the same port as your standard web proxy traffic then you will not be able to block it in the normal way.

Right-click the outgoing rule and select configure http.
Select signatures.
See the attached link
http://forums.isaserver.org/Skype_Signature/m_2002004505/tm.htm

Regards
Keith
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 17131729
Thank you :)
0

Featured Post

2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Forefront is the brand name for Microsoft's major security product. Forefront covers a number of specific security areas and has 'swallowed' a number of applications under this umbrella including Antigen, ISA Server, the Integrated Access Gateway (t…
To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…
Suggested Courses

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question