<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>ISA 2006 and Computer Sets....</title><link>http://blogs.technet.com/chrisavis/archive/2007/04/27/isa-2006-and-computer-sets.aspx</link><description>**Updated - Tom Shinder over at ISASERVER.ORG pointed out some legacy thinking I had in my post regarding ISA being in a Workgroup vs a Domain. He has an excellent article on this at this link . Microsoft also has an article regarding the pros and cons</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Thomas Shinder Blog  &amp;raquo; Blog Archive   &amp;raquo; Serious Error Regarding ISA Firewall Security Design Made at Microsoft TechNet Blog Site</title><link>http://blogs.technet.com/chrisavis/archive/2007/04/27/isa-2006-and-computer-sets.aspx#844743</link><pubDate>Sun, 29 Apr 2007 16:44:39 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:844743</guid><dc:creator>Thomas Shinder Blog  » Blog Archive   » Serious Error Regarding ISA Firewall Security Design Made at Microsoft TechNet Blog Site</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://blogs.isaserver.org/shinder/2007/04/29/serious-error-regarding-isa-firewall-security-design-made-at-microsoft-technet-blog-site/"&gt;http://blogs.isaserver.org/shinder/2007/04/29/serious-error-regarding-isa-firewall-security-design-made-at-microsoft-technet-blog-site/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: ISA 2006 and Computer Sets....</title><link>http://blogs.technet.com/chrisavis/archive/2007/04/27/isa-2006-and-computer-sets.aspx#847392</link><pubDate>Mon, 30 Apr 2007 04:40:38 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:847392</guid><dc:creator>Ray</dc:creator><description>&lt;P&gt;His desired methodology of&lt;/P&gt;
&lt;P&gt;"I will prefer to prevent users thru their machine names rather that the IP Addresses."&lt;/P&gt;
&lt;P&gt;is in contradiction to his desired results:&lt;/P&gt;
&lt;P&gt;"I want only 20 users to have unrestricted access to the Internet, while the remaining 180 users to be restricted to only 6 web sites."&lt;/P&gt;
&lt;P&gt;Restricting computers does not restrict users. He/she needs to require domain authentication for outbound access and create rules so that only the six users have unrestricted access while everyone else defaults to the six web sites.&lt;/P&gt;
&lt;P&gt;Doing it by computer name (actually by IP address) will fail as soon as DHCP gives someone a new address.&lt;/P&gt;
&lt;P&gt;Ray&lt;/P&gt;</description></item></channel></rss>