Implementing Microsoft Internet Security and Acceleration (ISA) Server 2004
MOC2824; 4 Days
Note: You are viewing a Preliminary Course Syllabus. Please call for
availability (615) 223-6789. We anticipate this course will be available in
early October. Because some parts of the course are currently in
development, some elements of this syllabus are subject to change.
Introduction
This four-day instructor-led course provides students with the knowledge and
skills to deploy and manage ISA Server 2004 as part of a larger security
infrastructure. The course introduces security concepts unique to ISA Server
2004 and provides best practices for their implementation.
Audience
The audience will be IT Professionals who are responsible for implementing
network and perimeter security measures, including Internet firewalls,
application layer filters, and screened networks. They will also implement
caching servers and additional mechanisms to protect public-facing Web servers.
These individuals will have a need to simplify ongoing management, reduce
support costs and prevent security breaches.
This course will also help to prepare individuals pursuing the MCSA: Security or
MCSE: Security certification specializations.
After completing this course, students will gain the skills to:
- Install ISA Server
- Configure ISA Server
- Manage ISA Server
- Troubleshoot ISA Server Configuration and Performance
- Configure Caching to Improve Performance
- Plan Access for Remote Clients and Networks
- Configure Access for Remote Clients and Networks
- Manage Remote Clients and Networks
- Plan for Firewall deployment
- Configure the Firewall
- Plan Access to Internal Resources
- Configure Access to Internal Resources
- Configure Monitoring and Reporting
- Monitor ISA Server
- Plan and Configure Application Layer Filtering
- Integrate ISA Server 2004 and Exchange Server
Prerequisites
This course requires that students meet the following prerequisites:
- Successful completion of Course 2152: Implementing Microsoft Windows 2000
Professional and Server, or equivalent knowledge of Windows 2000 Server
- Successful completion of Course 2153: Implementing a Microsoft Windows 2000
Network Infrastructure, or equivalent knowledge
Or
- Successful completion of Course 2273: Managing and Maintaining a Microsoft
Windows Server 2003 Environment, or equivalent knowledge of Windows Server 2003
operating system and network concepts
And
Microsoft Certified Professional Exams
This course will help the student prepare for the following Microsoft Certified
Professional exam:
Exam 70-350: Implementing Microsoft Internet Security and Acceleration (ISA)
Server 2004
Course Materials
The student kit includes a comprehensive workbook and other necessary materials
for this class.
The following software is provided in the student kit:
Evaluation copy of ISA Server 2004 for classroom use only.
Course Outline
Module 1: Overview of Microsoft ISA Server 2004
This module provides an introduction to ISA Server 2004. It introduces the core
functionality provided by ISA Server 2004 and presents an overview of how ISA
Server 2004 integrates with other security practices to form a defense-in-depth
approach to network security. The module also describes the most common
deployment scenarios for ISA Server 2004.
Lessons
- Introducing ISA Server 2004
- ISA Server and Network Security
- Deployment Scenarios for ISA Server 2004
Lab A: Introducing ISA Server 2004
- Designing an ISA Deployment for Contoso Pharmaceuticals
- Designing an ISA Deployment for Blue Yonder Airlines
After completing this module, students will be able to:
- Describe the features and functionality in ISA Server 2004 Standard Edition and
Enterprise Edition.
- Describe how to integrate ISA Server 2004 with a defense-in-depth security
strategy.
- List common deployment scenarios for ISA Server.
Module 2: Installing and Maintaining ISA Server 2004
This module describes how to install ISA Server 2004, how to install and
configure the ISA Server client software, and how to maintain ISA Server 2004
after installation.
Lessons
- Installing ISA Server 2004
- Choosing ISA Server Clients
- Installing and Configuring ISA Server Clients
- Advanced Firewall Client Configuration
- Securing ISA Server 2004
- Maintaining ISA Server
Lab A: Installing and Maintaining ISA Server 2004
- Performing an Unattended Installation of ISA Server 2004
- Migrating an ISA Server Configuration
- Securing ISA Server 2004
After completing this module, students will be able to:
- Install ISA Server 2004.
- Install and configure ISA Server 2004 clients.
- Secure the ISA Server.
- Maintain ISA Server.
Module 3: Enabling Access to Internet Resources
This module explains how to provide access to Internet resources for internal
corporate clients while maintaining network security. The module discusses
different ways to implement this and also how to configure rules for access.
Lessons
- Enabling Access to Internet Resources
- ISA Server 2004 as a Proxy Server
- Configuring Multi-Networking on ISA Server 2004
- Configuring Access Rule Elements
- Configuring Access Rules for Internet Access
Lab A: Enabling Access to Internet Resources
- Configuring ISA Server Access Rule Elements
- Configuring ISA Server Access Rules
- Testing ISA Server Access Rules
After completing this module, students will be able to:
- Describe access to Internet resources and how ISA Server 2004 enables access.
- Describe how ISA Server 2004 works as a proxy server.
- Configure multiple networks on ISA Server.
- Configure access rule elements.
- Configure ISA Server to provide access to Internet resources.
Module 4: Configuring ISA Server as a Firewall
This module explains how to configure ISA Server 2004 to provide firewall
capabilities and restrict traffic into and out of the network. The module
describes how to configure firewall policies and rules to provide specific
functionality.
Lessons
- Using ISA Server 2004 as a Firewall
- Examining Perimeter Networks and Templates
- Configuring System Policies
- Configuring Intrusion Detection and IP Preferences
Lab A: Configuring ISA Server as a Firewall
- Restoring Firewall Access Rules
- Modifying the ISA Server System Policy
- Testing the Access Rights and System Policy Modifications
After completing this module, students will be able to:
- Describe the core functionality provided by firewalls and how this functionality
is implemented in ISA Server 2004.
- Describe the different types of perimeter network types and use ISA Server
network templates to deploy perimeter networks.
- Configure system policies.
- Configure intrusion detection and IP preferences on ISA Server 2004.
Module 5: Configuring Access to Internal Resources
This module explains how to configure Web and server publishing rules to publish
internal network resources to the Internet without compromising internal network
security.
Lessons
- Introduction to Publishing
- Configuring Web Publishing
- Configuring Secure Web Publishing
- Configuring Server Publishing
- Configuring ISA Server Authentication
- Configuring Publishing for Additional Services
Lab A: Configuring Access to Internal Resources
- Configuring ISA Server Security Configuration
- Configuring a Windows Media Services Server Publishing Rule
- Testing the ISA Server Configuration
After completing this module, students will be able to:
- Describe how ISA Server 2004 can be used to configure access to internal
resources.
- Configure Web publishing.
- Configure secure Web publishing.
- Configure server publishing.
- Configure ISA Server authentication.
- Configure publishing for additional services.
Module 6: Integrating ISA Server 2004 and Microsoft Exchange Server
This module explains how Microsoft Exchange Server is a critical network service
that is virtually always accessible from the Internet and how ISA Server 2004
can be used to provide security for Exchange Server and for securing client
connections to Exchange.
Lessons
- Issues in E-Mail Security
- Configuring ISA Server to Secure SMTP Traffic
- Configuring ISA to Secure Client Connections
- Configuring ISA Server to Secure Web Client Connections
Lab A: Integrating ISA Server 2004 and Microsoft Exchange Server
- Configuring ISA Server for RPC over HTTP
- Configuring a Forms-Based Authentication for Microsoft Outlook Web Access
After completing this module, students will be able to:
- Describe the issues in e-mail security.
- Configure ISA Server to secure Simple Message Transfer Protocol (SMTP) traffic.
- Configure ISA Server to secure client connections.
- Configure ISA Server to secure Web client connections.
Module 7: Advanced Application and Web Filtering
This module explains how application and Web filtering can be used for very
specific filtering of traffic that flows through the ISA Server. The module
shows how to configure application and Web filtering to provide advanced
protection for the internal network.
Lessons
- Overview of Advanced Application and Web Filtering
- Configuring HTTP Filtering
- Configuring Application and Web Filters
Lab A: Advanced Application and Web Filtering
- Identifying an Application Method and Signature
- Modifying the ISA Server System Policy
After completing this module, students will be able to:
- Describe how application filtering and Web filtering work.
- Configure HTTP Web filters.
- Configure other application and Web filters.
Module 8: Configuring Virtual Private Network Access for Remote Clients and
Networks
This module explains how to provide access to the internal network for remote
users while maintaining network security by implementing a virtual private
network (VPN). The module shows how to configure ISA Server 2004 to provide a
VPN solution.
Lessons
- Virtual Private Networking Overview
- Configuring Virtual Private Networking for Remote Clients
- Configuring Virtual Private Networking for Remote Sites
- Configuring ISA Server 2004 for VPN Quarantine
After completing this module, students will be able to:
- Describe how virtual private networks (VPNs) work and the components required to
configure VPNs.
- Configure ISA Server to enable VPNs for remote clients.
- Configure ISA Server to enable VPNs for remote sites.
- Configure ISA Server to enable VPN quarantine service.
Module 9: Implementing Caching to Improve Browsing Performance
This module explains how ISA Server can cache content that clients request from
the Internet to provide a quicker response to the client. This module discusses
how to configure caching for maximum efficiency.
Lessons
- Overview of Caching
- Configuring General Cache Properties
- Configuring Cache Rules
- Configuring Content Download Jobs
Lab A: Configuring Caching on ISA Server 2004
- Testing and Monitoring ISA Server Caching
- Modifying ISA Server Caching
After completing this module, students will be able to:
- Describe how caching is implemented on ISA Server 2004.
- Configure caching properties on ISA Server 2004.
- Configure cache rules on ISA Server 2004.
- Configure content download jobs on ISA Server 2004.
|