I'm not an ISA expert by a long shot, but I managed to get ISA 2006 working 
here and we've been running it for some time.

I just discovered, though, that something may not be right. We caught some kids 
using a proxy server to bypass the State of Florida's content filter. The 
content filter blocks proxy sites, but only if they run on port 80. These kids 
were using sites on alternate ports.

However, this shouldn't be possible because our local ISA server shouldn't be 
allowing traffic on those ports. I just ran a test while running a live log 
query, and sure enough I was able to access http://air-proxy.com:82/?p=submit. 
The log said that this traffic was allowed under a rule I have called "Allow 
outbound Web and FTP traffic."

I double-checked that rule, though, and it's definitely configured to only 
allow FTP, HTTP, and HTTPS traffic over ports 21, 80, and 443, respectively.

What could I be missing here?



John Hornbuckle
MIS Department
Taylor County School District
318 North Clark Street
Perry, FL 32347

www.taylor.k12.fl.us




~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

Reply via email to