Solved

Limiting OWA Access With ISA

Posted on 2006-11-10
6
467 Views
Last Modified: 2010-03-06
Hi Everybody,

 We have an Exchange 2003 environment that has been in place for a little over a month now. We are still actively migrating users from our Domino 5 server. Our next batch of migrations includes users that have no permanent desks. Currently, when we have finished migrating a group of users we will manually apply a profile that has been created using the Office Deployment Tools. However, despite our test environment showing a different result, anytime a user logs into a machine that is not their own, Outlook tries to run the manual configuration again (in our test lab the profile that was installed via the GPO installation of Outlook was applied for all users).

 As a result of this situations our helpdesk has been configuring the handful of users that use more than one computer. For this next batch of users this is unacceptable - both because we are talking about 200 users and fifty workstations but also because of the rotational nature of their shifts many are working when our helpdesk is closed.

 Roaming windows profiles are not an option.

 The ideal solution that I see is to give these users access only to OWA. However, because they deal with information of an extremely sensitive nature, management does not want to allow 95% of these users to access OWA from anywhere outside of our  network. Our OWA is currently published to the outside world through and ISA 2004 server. So my question is this, given that OWA is published through ISA is there a way to use the users tab of the OWA publishing rule to block the users that do not need external access while still allowing all other users through?

 Our ISA server is not a member server of our Active Directory environment and contains two NICs, on one connected to our internal network and the other connected to our DMZ.

Thanks,
MD
0
Comment
Question by:danielsm
  • 2
  • 2
6 Comments
 
LVL 26

Expert Comment

by:Vahik
ID: 17916947
i am sure u folks use SSL for ur OWA access....
for those users that u do not wish to access OWA from outside....do not issue certificates....
0
 

Author Comment

by:danielsm
ID: 17917373
Vahik,

 We are using SSL but we only have a single server side SSL certificate. We are not using certificates on the client side.

MD
0
 
LVL 26

Expert Comment

by:Vahik
ID: 17918001
Ok so u dont require client side certificate....no problem... now lets try another suggestion...

I am not a firewall expert but for instance in pix u can deny entry or outside access for certain GROUPS and for specific protocols....i am not an ISA expert and hopefully someone could tell u with certainty wherher this will be possible with ISA.....or u could try ur REAL firewall and see if it is capable of blocking certain groups for specific protocol
0
 

Author Comment

by:danielsm
ID: 17948327
Apparently with ISA it is possible. Where I have been going wrong with my tests is our ISA box is not a member of our AD domain (as it should not have been). Limiting access to certain users requires the box to be a member server in order to add AD accounts to the access rules.

This may be the route we pursue - its not such a big deal that the ISA box is a member server as its not our perimeter firewall but everything has been put on hold for the time being - management has decided to go ahead with the deployment and configuration (and reconfiguration, and reconfiguration, and reconfiguration...) of Outlook on those workstations.

MD
0
 
LVL 1

Accepted Solution

by:
Computer101 earned 0 total points
ID: 18176982
PAQed with points refunded (250)

Computer101
EE Admin
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Find out what you should include to make the best professional email signature for your organization.
This article lists the top 5 free OST to PST Converter Tools. These tools save a lot of time for users when they want to convert OST to PST after their exchange server is no longer available or some other critical issue with exchange server or impor…
In this video we show how to create an Accepted Domain in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Ac…
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now