<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Introducing a New Era for ISA Server</title><link>http://blogs.technet.com/isablog/archive/2008/04/09/introducing-a-new-era-for-isa-server.aspx</link><description>As my first (of hopefully many) contributions to the ISA Server team blog, I want to first introduce myself to the community. My name is David B. Cross and I am the new Product Unit Manager for the ISA Server engineering organization. For many of the</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>! New ISA Server - Forefront Threat Management Gateway (TMG)</title><link>http://blogs.technet.com/isablog/archive/2008/04/09/introducing-a-new-era-for-isa-server.aspx#3033090</link><pubDate>Wed, 09 Apr 2008 13:37:27 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3033090</guid><dc:creator>Eduardo Petizme.com | MVP</dc:creator><description>&lt;p&gt;Hi all, As Forefront MVP I already know about it, but now (April 9th) it&amp;amp;#39;s public. &amp;amp;quot;... the&lt;/p&gt;
</description></item><item><title>NTLM-fallback please</title><link>http://blogs.technet.com/isablog/archive/2008/04/09/introducing-a-new-era-for-isa-server.aspx#3033251</link><pubDate>Wed, 09 Apr 2008 16:52:01 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3033251</guid><dc:creator>onovotny</dc:creator><description>&lt;p&gt;I'm not in the TAP and I didn't see any other place to provide ISA feedback --&lt;/p&gt;
&lt;p&gt;Please allow for Forms-based Auth to use both Basic and NTLM authentication in the fallback mechanism.&lt;/p&gt;
&lt;p&gt;The main reason for this is to support publishing both TS Gateway and OWA using the same listener. &amp;nbsp;TS Gateway's HTTP/RPC needs NTLM and Outlook's HTTP/RPC can use NTLM. &amp;nbsp;ActiveSync needs Basic. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Currently deploying all of these services requires two listeners on two IP addresses. &amp;nbsp;One for FBA/Basic -- everything except TS Gateway &amp;amp; Outlook Anywhere using NTLM, and the other using HTTP Auth / NTLM. &amp;nbsp;For a small business, or even a larger one, it would be far simpler if everything could be on a single listener on a single external IP. &amp;nbsp;The only thing standing in the way is that FBA can't fallback to NTLM.&lt;/p&gt;
&lt;p&gt;I ask you to please strongly consider adding this. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Oren&lt;/p&gt;
</description></item><item><title>re: Introducing a New Era for ISA Server</title><link>http://blogs.technet.com/isablog/archive/2008/04/09/introducing-a-new-era-for-isa-server.aspx#3033308</link><pubDate>Wed, 09 Apr 2008 18:11:35 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3033308</guid><dc:creator>gazanga</dc:creator><description>&lt;p&gt;It requires some hacking, but you can make ISA do that. &amp;nbsp;I'm rolling out TS GW like that now.&lt;/p&gt;
&lt;p&gt;I'm excited and nervous about the change. &amp;nbsp;I would like to see ISA be able to dive further inside of the packet to do more intelligent application filtering, but I'm worried the product will begin to slide away from it's original purpose. &amp;nbsp;Of course upon writing that, I realize original purpose was proxy so I guess I have to withdraw my argument hehe.&lt;/p&gt;
&lt;p&gt;Does MS ever hire Consultants for ISA only? &amp;nbsp;I've tried finding an opportunity as a MS consultant position and yet to find one. &amp;nbsp;&lt;/p&gt;
</description></item><item><title>Infos zur naechsten ISA Server Generation</title><link>http://blogs.technet.com/isablog/archive/2008/04/09/introducing-a-new-era-for-isa-server.aspx#3033367</link><pubDate>Wed, 09 Apr 2008 19:07:14 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3033367</guid><dc:creator>Forefront &amp; Security Blogs</dc:creator><description>&lt;p&gt;Seit heute sind nun einige Informationen rund um die neu Forefront-Generation (Codename &amp;amp;quot;Stirling&amp;amp;quot;&lt;/p&gt;
</description></item><item><title>What will happen with IAG?</title><link>http://blogs.technet.com/isablog/archive/2008/04/09/introducing-a-new-era-for-isa-server.aspx#3033383</link><pubDate>Wed, 09 Apr 2008 19:56:07 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3033383</guid><dc:creator>rhelmer</dc:creator><description>&lt;p&gt;It seems nothing was announced regarding how the recent changes around the Forefront brand affects IAG. &amp;nbsp;Will it be merged into TMG? &amp;nbsp;Is it being spun off? &amp;nbsp;Some guidance on the IAG product roadmap would be much appreciated.&lt;/p&gt;
&lt;p&gt;Thanks for the info on TMG! &amp;nbsp;Looks exciting. :)&lt;/p&gt;
</description></item><item><title>re: Introducing a New Era for ISA Server</title><link>http://blogs.technet.com/isablog/archive/2008/04/09/introducing-a-new-era-for-isa-server.aspx#3033428</link><pubDate>Wed, 09 Apr 2008 20:49:02 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3033428</guid><dc:creator>onovotny</dc:creator><description>&lt;p&gt;Gazanga,&lt;/p&gt;
&lt;p&gt;Could you please share the details of how you got Forms-Based Auth to fallback to NTLM (or how you got TS GW deployed)?&lt;/p&gt;
&lt;p&gt;I have looked and haven't seen much on that topic yet.&lt;/p&gt;
</description></item><item><title>Объявлен ISA vNext - Forefront Threat Management Gateway</title><link>http://blogs.technet.com/isablog/archive/2008/04/09/introducing-a-new-era-for-isa-server.aspx#3033457</link><pubDate>Wed, 09 Apr 2008 21:31:55 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3033457</guid><dc:creator>Sergey Simakov</dc:creator><description>&lt;p&gt;На проходящей конференции RSA Security официально объявлено имя продукта, приходящего на смену межсетевому&lt;/p&gt;
</description></item><item><title>re: Introducing a New Era for ISA Server</title><link>http://blogs.technet.com/isablog/archive/2008/04/09/introducing-a-new-era-for-isa-server.aspx#3033471</link><pubDate>Wed, 09 Apr 2008 21:44:58 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3033471</guid><dc:creator>someone</dc:creator><description>&lt;p&gt;Just to be sure, this will still run on Server 2003 32-bit hosts right?&lt;/p&gt;
</description></item><item><title>re: Introducing a New Era for ISA Server</title><link>http://blogs.technet.com/isablog/archive/2008/04/09/introducing-a-new-era-for-isa-server.aspx#3033959</link><pubDate>Thu, 10 Apr 2008 14:59:27 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3033959</guid><dc:creator>isablog</dc:creator><description>&lt;p&gt;someone:&lt;/p&gt;
&lt;p&gt;Server 2003 - no. Unfortunately, the differences in the networking/firewall integration hooks between Server 2003 and 2008 are too great for TMG to support both.&lt;/p&gt;
&lt;p&gt;32-bit - We may provide a 32-bit for evaluation and demo purposes, but it will not be supported for production. This is the same like Exchange2007.&lt;/p&gt;
</description></item><item><title>Объявлен "наследник" ISA - Forefront Threat Management Gateway</title><link>http://blogs.technet.com/isablog/archive/2008/04/09/introducing-a-new-era-for-isa-server.aspx#3034005</link><pubDate>Thu, 10 Apr 2008 16:19:03 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3034005</guid><dc:creator>External News</dc:creator><description>&lt;p&gt;Как сказано в статье- &lt;a rel="nofollow" target="_new" href="http://blogs.technet.com/ssimakov/archive/2008/04/09/isa-vnext-forefront-threat-management-gateway.aspx"&gt;http://blogs.technet.com/ssimakov/archive/2008/04/09/isa-vnext-forefront-threat-management-gateway.aspx&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: Introducing a New Era for ISA Server</title><link>http://blogs.technet.com/isablog/archive/2008/04/09/introducing-a-new-era-for-isa-server.aspx#3034791</link><pubDate>Fri, 11 Apr 2008 09:08:49 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3034791</guid><dc:creator>verypsb</dc:creator><description>&lt;p&gt;I really hope that the funtionality of IAG (Internet Access Gateway) will be included in Forefront TMG (Threat Management Gateway)...&lt;/p&gt;
</description></item><item><title>re: Introducing a New Era for ISA Server</title><link>http://blogs.technet.com/isablog/archive/2008/04/09/introducing-a-new-era-for-isa-server.aspx#3034909</link><pubDate>Fri, 11 Apr 2008 14:06:53 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3034909</guid><dc:creator>IanC</dc:creator><description>&lt;p&gt;Regarding Whale IAG. &amp;nbsp;My understanding is that this will now be integrated in to the new TMG product.&lt;/p&gt;
&lt;p&gt;My question... Will Microsoft be showcasing TMG at the forthcoming Infosec Europe event in London?&lt;/p&gt;
&lt;p&gt;Ian Currie&lt;/p&gt;
</description></item><item><title>May 2008 - Technical Rollup Mail - Internet</title><link>http://blogs.technet.com/isablog/archive/2008/04/09/introducing-a-new-era-for-isa-server.aspx#3048081</link><pubDate>Thu, 01 May 2008 10:32:25 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3048081</guid><dc:creator>Technical RollUp</dc:creator><description>&lt;p&gt;News Microsoft Internet Security and Acceleration Server Forefront Threat Management Gateway, the Next&lt;/p&gt;
</description></item><item><title>re: Introducing a New Era for ISA Server</title><link>http://blogs.technet.com/isablog/archive/2008/04/09/introducing-a-new-era-for-isa-server.aspx#3053701</link><pubDate>Sun, 11 May 2008 17:58:10 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3053701</guid><dc:creator>isablog</dc:creator><description>&lt;p&gt;Regarding NTLM-fallback ...&lt;/p&gt;
&lt;p&gt;This is more complex than it sounds, since the delegation auth options are somewhat dependent on the initial authenticaiton method.&lt;/p&gt;
&lt;p&gt;If FBA fallback includes NTLM, then the only delegation method available to you would be KCD.&lt;/p&gt;
&lt;p&gt;What you can do is use FBA/Basic auth at the listener and delegate using KCD or Negotiate/NTLM.&lt;/p&gt;
&lt;p&gt;I realize this doesn't answer you request, but it should get you past the auth disparity between aqpplications.&lt;/p&gt;
</description></item><item><title>ISA / IIS / Biztalk / WSPS / MOSS Info for the Month of April</title><link>http://blogs.technet.com/isablog/archive/2008/04/09/introducing-a-new-era-for-isa-server.aspx#3060568</link><pubDate>Sat, 24 May 2008 21:03:20 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3060568</guid><dc:creator>Heavy on the Technical</dc:creator><description>&lt;p&gt;News Microsoft Internet Security and Acceleration Server Forefront Threat Management Gateway, the Next&lt;/p&gt;
</description></item><item><title>They say it better than I can...</title><link>http://blogs.technet.com/isablog/archive/2008/04/09/introducing-a-new-era-for-isa-server.aspx#3064739</link><pubDate>Mon, 02 Jun 2008 11:23:05 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3064739</guid><dc:creator>Dougs Blog &gt;&gt; Exchange Server in the field</dc:creator><description>&lt;p&gt;Just want to point you to a few blog articles I have read recently just in case your search doesn't reveal&lt;/p&gt;
</description></item></channel></rss>