Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

79
Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa

Transcript of Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Page 1: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Microsoft ISA Server 2000

Presented byRicardo DiazRyan Fansa

Page 2: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Module 1

Introduction

Page 3: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

The Purpose of the ISA Server Microsoft® Internet Security and Acceleration Server 2000 (ISA

Server) is an extensible enterprise firewall and Web cache server built on the Windows® 2000 operating system security, management and directory for policy-based access control, acceleration and management of internetworking.

ISA Server Enterprise Edition adds support for clustering, but makes modifications to the local domain's Microsoft Active Directory® active directory schema. For evaluation purposes, you should set up a four-computer test environment that is isolated from your production network.

With the ISA Server Standard Edition, you can review the core firewall and caching functionality of ISA Server without an update to your Active Directory schema.

Page 4: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

The Purpose of The ISA Server (cont.) ISA Server 2000 is an intelligent application layer firewall and Web caching

server that helps protect the network from external attacks and from exploits that may originate from the internal network behind the ISA Server 2000 machine.

The ISA Server 2000 Web cache helps network users reduce overall bandwidth utilization and can provide for a faster Web access experience for campus Internet users by returning popular Web content from the ISA Server 2000 Web cache on the local network instead of from a increasingly congested Internet.

ISA Server can provide value to information technology managers, network administrators, and information security professionals who are concerned about the security, performance, manageability, or operating costs of their networks.

ISA Server can be used in a wide range of scenarios, from small schools, districts and satellite campuses to major, multi-campus systems and statewide networks.

Page 5: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

End of Module

Page 6: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Module 2

ISA Server Installation

Page 7: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Installation Process

Page 8: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Installation Process (cont.)

Page 9: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Installation Process (cont.)

Page 10: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Installation Process (cont.)

Page 11: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Installation Process (cont.)

Page 12: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Installation Process (cont.)

Page 13: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Installation Process (cont.)

Page 14: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Installation Process (cont.)

Page 15: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Installation Process (cont.)

Page 16: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Installation Process (cont.)

Page 17: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

End of Module

Page 18: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Module 3

Network Security

Page 19: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Network Security

The Threat (Internet)– Hackers/Crackers– Script Kiddies

Type of Firewalls– Traditional– Application

Page 20: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Hackers/Cracker

Skill Level– High Level

Motivation– Test Skill Level– Monetary Gain– Freedom

Page 21: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Script Kiddies

Skill Level– Low to Medium Level

Motivation– Imitation– Curiosity– Build Skill Level

Page 22: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Traditional Firewall OSI Layer 3 & Layer 4

NAT

Function of SPI firewall– source address, destination address, source port,

destination port and direction– Denial of Service (DoS) attacks, Ping of Death, SYN

Flood, LAND Attack, and IP Spoofing (Pattern)

Great at lower level protocol attacks

Page 23: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Application Firewall (Proxies)

OSI Layer 7

Application Level Filtering (Going up the OSI Layer)– OS vulnerabilities, Application vulnerabilities– Nimda, Code Red, SQL Slammer worm, SQL

poisoning – Most likely to spread via email or

unfiltered/open port

Page 24: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

End of Module

Page 25: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Module 4

ISA Server to the Rescue

Page 26: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server Architecture

Standalone Enterprise

– Firewall– Cache Proxy– Integrated

Page 27: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server as a Standalone

[1]

Page 28: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server in the Enterprise

[1]

Page 29: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Multi-layered Firewall

Static and Dynamic packet filtering

Circuit Filtering (ISA Client)

Application Filtering

Page 30: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Features of ISA Server

Stateful Inspection Secure Server Publishing Intrusion Detection Client Transparency (SecureNAT) Strong Authentication SDK

Page 31: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Stateful Inspection

Allows ISA Server to determine the state of a given session

Configurable through access policy rules that open ports automatically (dynamic IP packet filtering)

Excellent for filtering streaming media applications

Page 32: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Secure Publishing

Web Server

Email Server (Exchange)

Servers are Never Exposed

Page 33: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Intrusion Detection

Licensed technology from Internet Security Systems

Administrator can set triggers

Triggers can be configured to stop the firewall, write to system log or run script

Page 34: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Client Transparency

SecureNAT

No client to install

Configurable for outbound traffic

Page 35: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Software Development Kit SDK

Create Custom Extensions

Comes with Sample Code

Detailed Documentation

Page 36: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Authentication Web ProxyIncoming/Outgoing Web Traffic

Basic (plain text) (Not Strong!) Digest Integrated Windows (NTLM & Kerberos) Client Certificates Pass-through authentication

Page 37: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

End of Module

Page 38: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Module 5

A Closer Look to The ISA Server Management Tool

Page 39: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ManagementConsole

Page 40: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server – Web Publishing Feature

Page 41: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server – Web Publishing Feature (cont.)

Page 42: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server – Web Publishing Feature (cont.)

Page 43: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server – Web Publishing Feature (cont.)

Page 44: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server – Web Publishing Feature (cont.)

Page 45: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server – Web Publishing Feature (cont.)

Page 46: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server – Web Publishing Feature (cont.)

Page 47: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server – Web Publishing Feature (cont.)

Page 48: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server – Web Publishing Feature (cont.)

Page 49: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server – Web Publishing Feature (cont.)

Page 50: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server – Web Publishing Feature (cont.)

Page 51: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server – Web Publishing Feature (cont.)

Page 52: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server – Web Publishing Feature (cont.)

Page 53: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server – Web Publishing Feature (cont.)

Page 54: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server – Web Cashing Feature

Page 55: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server – Web Cashing Feature (cont.)

Page 56: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server – Web Cashing Feature (cont.)

Page 57: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server – Web Cashing Feature (cont.)

Page 58: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server – Web Cashing Feature (cont.)

Page 59: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server – Web Cashing Feature (cont.)

Page 60: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

ISA Server – Web Cashing Feature (cont.)

Page 61: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Module 6

SQL Slammer Filter

Page 62: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Creating a Filter for SQL Slammer

Create a definition

Create a rule

Page 63: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Step 1 – Create Definition

Page 64: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Step 2

Page 65: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Step 3

Page 66: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Step 4

Page 67: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Step 5

Page 68: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Step 6

Page 69: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Step 7 – Create Rule

Page 70: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Step 8

Page 71: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Step 9

Page 72: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Step 10

Page 73: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Step 11

Page 74: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Step 12

Page 75: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Step 13

Page 76: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

End of Module

Page 77: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Conclusion ISA Server was designed to meet the needs of Internet-

enabled business by providing enterprise-class security, fast Web caching performance and powerful unified management tools built for Windows 2000 and 2003 Server.

ISA Server provides a multilayered firewall with built-in intrusion detection to keep internal networks safe.

ISA Server provides businesses with secure, fast Internet connectivity built on the powerful management features of Windows 2000 and 2003 Server.

ISA Server provides scalability for both small and enterprise class environments

Page 78: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Resources

[1] http://www.microsoft.com/isaserver/ [2] http://www.isaserver.org [3]

http://www.techiwarehouse.com/Articles/2002-12-23.html

[4] http://labmice.techtarget.com/BackOffice/ISAServer2000/default.htm

Page 79: Microsoft ISA Server 2000 Presented by Ricardo Diaz Ryan Fansa.

Glossary

Kerberos - a secure method for authenticating a request for a service in a computer network. Kerberos was developed in the Athena Project at the Massachusetts Institute of Technology (MIT).

NTLM - a Microsoft-Proprietary protocol that authenticates users and computers based on an authentication challenge and response.

Stateful Inspection - Stateful inspection is an advanced firewall architecture that was invented by Check Point Software Technologies in the early 1990s. Inspects the header of packets.

NAT - Network Address Translation (NAT) is the translation of an Internet Protocol address used within one network to a different IP address known within another network.