ISA Server 2004 deployment

versello

2[H]4U
Joined
Nov 19, 2003
Messages
2,061
Would you reccomend ISA Server 2004 be a member server or a standalone server?
 
For security purposes, a standalone server is the best choice. If you are doinig a multi-layered approach, your edge firewall should always be a standalone.

If you go with standalone, you can still authenticate with AD. But, a member server isn't that big of a deal on an internal firewall.

Also, SP2 just came out for the Standard version.
 
Yea, I've been testing SP2 on my home server and I really like the added features.

Unfortunately, we only have one server to spare, so I can't do multi-layers.
 
If you are going with a single firewall solution, you can use RADIUS to authenticate the users with AD. I would not joing the ISA server to the domain. If the server would ever become compramised, the attacker would not be able to use that domain membership as a starting point for an attack on the rest of your network.
 
Back
Top