Tutorials

Specify Alternate Text

How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3

Firewall Client for ISA Server can be optionally installed on client computers protected by Microsoft ISA Server. Firewall Client for ISA Server provides enhanced security, application support, and access control for client computers. It provides authentication for Winsock applications that use TCP and UDP, supports complex secondary protocols, and supplies user and application information to the ISA Server logs.

When a client computer running Firewall Client for ISA Server makes a request, the destination is evaluated by the Firewall Client software, and external requests are directed to the ISA Server computer for handling. No specific routing infrastructure is required. Firewall Client sends user information transparently with each request, enabling you to create a firewall policy on the ISA Server computer with rules that use the authentication credentials presented by the client. ISA Server allows you to configure automatic discovery for Firewall client computers, using a WPAD entry in DNS or DHCP to obtain correct Web proxy settings for clients, depending on their location. This article covers the automatic deployment of the ISA Server 2006 Firewall client in a SBS 2008 network.


Download the latest ISA Server 2006 Firewall client

The latest version of the ISA Firewall client software can downloaded from here: http://www.microsoft.com/downloads/details.aspx?FamilyID=05c2c932-b15a-4990-b525-66380743da89&DisplayLang=en.


Create a software distribution share on your SBS 2008

On your SBS 2008 server we need to create a 'software distribution share' that will be used for automatic deployment of the ISA 2006 Firewall client.

  1. From the SBS 2008 Management console choose Shared Folders and Web sites. From the left choose 'Add a new shared folder'.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  2. Click browse to choose a location. You should choose a location that has a lot of free space because the share may be used for other purposes like automatic deployment of Office etc.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  3. Choose 'Make new folder'.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  4. I named this new folder 'SoftwareDistribution'. Click OK.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  5. We are back in the main screen. Click Next.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  6. Accept the defaults and click Next.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  7. Accept the default name and click next.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  8. Accept the defaults and click Next.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  9. Make sure that Administrators have Full Control.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  10. We don't really need quota on this share. Click Next.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  11. We do not need file screening either. Click Next.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  12. We don't need DFS Namespace Publishing either. Click next.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  13. Review your choices and click 'Create'.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  14. Click Close.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3

Add the Firewall client software to your software distribution share

  1. Copy the file you just downloaded to the Folder called 'SoftwareDistribution'.
  2. Open a command prompt and make sure you run it as Administrator.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  3. Change the command to the SoftwareDistribution folder.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  4. Extract the ISAClient file to the software distribution folder.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  5. You will see that MS_FWC.MSI is listed the software distribution folder. That is the file we need for our automatic deployment.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3

Create the GPO for automatic distribution of the ISA Firewall client software

  1. From the start menu choose Administrative Tools -> Group Policy Management.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  2. Choose the hive Group Policy Objects -> right click and choose New.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  3. Name the new GPO Windows SBS Client Software Distribution.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  4. Our new GPO is listed and choose Edit.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  5. In Computer Configuration choose Software installation. In the right part right click and choose New -> Package.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  6. A browser window will open. Point to your Firewall client software and click Open. Easiest way is to type in browse box \\yourservername. As soon as you do that a list of shares will appear and as you see our SoftwareDistribution share is also available.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  7. With the software highlighted click Open
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  8. Click Assigned and click OK.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  9. Close the GPO so that you return to the Group Policy Manager.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  10. Choose the SBSComputers OU and right click -> choose 'Link an Existing GPO'.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  11. Choose the 'Windows SBS Client Software Distribution' GPO and click OK.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  12. There is our new GPO. Click to close the Group Policy Manager.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3

Configure auto discovery on the ISA 2006 server

  1. Start the ISA Server Management tool.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  2. Expand ServerName, where ServerName is the name of your ISA Server computer. Expand Configuration, and then click Networks.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  3. Right-click the network that you want ISA Server to publish auto discovery information about, and then click Properties. For example, right-click Internal, and then click Properties.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  4. Click the Auto Discovery tab, click to select the Publish automatic discovery information check box, and then click OK.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  5. Click Apply to update the firewall policy, and then click OK.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3

On the SBS 2008 you need to add entries to the DHCP server scope.

To configure the DHCP server to send the Autoconfiguration URL to the Web Proxy and Firewall client:

  1. Start the DHCP snap-in.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  2. Right-click the DHCP name, and then click Set Predefined Options.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  3. Click Add.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  4. Type wpad in the Name box. Click String in the Data Type box. Type 252 in the Code box. Click OK.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  5. Type http://isaservername or IP address/wpad.dat in the String box in the Predefined Option and Values dialog box. Click OK.
  6. In the right pane of Scope Options click Configure Options.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  7. Put a check in '252 wpad' and click OK.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3

Test the installation of the Firewall client software on a Vista 32 bit workstation

  1. Logon to one of your workstations and open a command prompt. Run gpupdate /force and if your are asked to reboot please do that.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  2. The Firewall client has been installed after first login.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  3. Because we added the wpad entry to our DHCP options the Firewall client is successful in the auto discovery of the ISA server on our network.
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3
  4. And Internet Explorer has been configured to the ISA server as Proxy. That is the way it should be!
    How to publish SBS 2008 using a Server 2003 with ISA 2006 SE - part 3

About www.server-essentials.com 

www.server-essentials.com is founded by Mariette Knap, a Dutch Microsoft MVP. www.server-essentials.com is a community for IT Consultants and Business Owners who, themselves, take care of the IT infrastructure and Employees who do that little extra in the company to keep things running. Our forum is for discussing all things ‘IT’ and more.  Our documentation is top notch and written by and for the community.

Change your cookie settings


 
Contact Us

Concentrix BV

C. de Rijcklaan 1

3723 PM Bilthoven

The Netherlands

KvK 30202318

VAT Id 814036739B01

The layout of this page is made to be viewed online.