<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Augusto Alvarez &#187; ISA Server</title>
	<atom:link href="http://blog.augustoalvarez.com.ar/category/isa-server/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.augustoalvarez.com.ar</link>
	<description></description>
	<lastBuildDate>Mon, 06 Feb 2012 02:32:39 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.augustoalvarez.com.ar' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Augusto Alvarez &#187; ISA Server</title>
		<link>http://blog.augustoalvarez.com.ar</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.augustoalvarez.com.ar/osd.xml" title="Augusto Alvarez" />
	<atom:link rel='hub' href='http://blog.augustoalvarez.com.ar/?pushpress=hub'/>
		<item>
		<title>GFI WebMonitor 2009: Review and Common Configurations</title>
		<link>http://blog.augustoalvarez.com.ar/2009/05/11/gfi-webmonitor-2009-review-and-common-configurations/</link>
		<comments>http://blog.augustoalvarez.com.ar/2009/05/11/gfi-webmonitor-2009-review-and-common-configurations/#comments</comments>
		<pubDate>Mon, 11 May 2009 13:09:24 +0000</pubDate>
		<dc:creator>Augusto Alvarez</dc:creator>
				<category><![CDATA[GFI WebMonitor]]></category>
		<category><![CDATA[ISA Server]]></category>
		<category><![CDATA[Traffic Monitoring]]></category>

		<guid isPermaLink="false">http://augustoalvarez.wordpress.com/2009/05/11/gfi-webmonitor-2009-review-and-common-configurations/</guid>
		<description><![CDATA[&#160; For those that never heard about GFI WebMonitor; it’s an ISA Server (2004 or 2006) “add-on” that helps you monitor in real time the network traffic inside your organization, it also complements with ISA Server giving you the chance to directly configure white/black lists, set some access rules to the internet and scan all [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.augustoalvarez.com.ar&amp;blog=5820778&amp;post=223&amp;subd=augustoalvarez&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>&#160;</p>
<p>For those that never heard about <a href="http://www.gfi.com/webmon">GFI WebMonitor</a>; it’s an <strong>ISA Server (2004 or 2006) “add-on” that helps you monitor in real time the network traffic inside your organization</strong>, it also complements with ISA Server giving you the chance to directly <strong>configure white/black lists, set some access rules to the internet and scan all the traffic for virus and malware. </strong></p>
<p>In this post I’ll try to review the functionality, pros and cons, as well as the process of installing and configuring.</p>
<h3><font size="3"><strong>GFI WebMonitor 2009 Requirements </strong></font></h3>
<p>I’m evaluating the <strong>GFI UnifiedProtection Edition</strong> (that combines <strong>WebFilter</strong> and <strong>WebSecurity</strong>) in one package.</p>
<p><strong>Hardware</strong></p>
<ul>
<li><strong>Processor</strong>: 1.8ghz </li>
<li><strong>Memory</strong>: 2GB RAM </li>
<li><strong>Hard Disk</strong>: 10/15 GB free </li>
</ul>
<p><strong>Operating System and Software</strong></p>
<ul>
<li>Windows Server 2000 SP4 / Windows Server 2003 </li>
<li>ISA Server 2004 SP3 / ISA Server 2006 </li>
<li>Internet Explorer 6 or later </li>
<li>.Net Framework 2.0 </li>
</ul>
<p>&#160;</p>
<h3><font size="3"><strong>GFI WebMonitor Installation</strong></font></h3>
<p>You can download the trial version for GFI WebMonitor from <a href="http://www.gfi.com/downloads/register.aspx?pid=webmon&amp;lid=EN">this link</a>.</p>
<p>The installation process it’s <strong>simple</strong>, you shouldn’t have any problem with this.</p>
<p><img src="http://farm4.static.flickr.com/3545/3498116029_db7de84cef.jpg?v=0" width="404" height="305" /></p>
<p><strong>Access Permissions</strong>. Here you can set from which of the IP address the GFI web configuration will be accessible. Take note that you can specify the users that can access it.</p>
<p><img src="http://farm4.static.flickr.com/3609/3498930704_617daf5e0b.jpg?v=0" width="406" height="305" /></p>
<p><strong>Mail Settings</strong>. Configure it to receive mail notifications about when, for example, a user is trying to infringe a configured policy in WebMonitor.</p>
<p><img src="http://farm4.static.flickr.com/3411/3498930270_5a27e7e1b0.jpg?v=0" width="410" height="309" /></p>
<p><strong>Testing mail notifications.</strong></p>
<p><img src="http://farm4.static.flickr.com/3629/3498930542_9101e84f70.jpg?v=0" width="442" height="152" /></p>
<p>Once the installation is complete, <strong>two new access rules</strong> are configured in your <strong>ISA Server</strong> <strong>Firewall Policy</strong>: One to allow access to the WebMonitor tool from a browser, and the other for updates.</p>
<p><img src="http://farm4.static.flickr.com/3360/3498932232_1a8615c16b.jpg?v=0" /></p>
<h3><font size="3"><strong>GFI WebMonitor Dashboard</strong></font></h3>
<p>You can access the main window from the Program Menu of from your web browser.</p>
<p>Always having a dashboard it’s a good idea, specially with this kind of tool. Making a quick look here you’ll get most of the necessary information that WebMonitor provides:<strong> Bandwidth consumed, active connections, blocked content, etc. </strong></p>
<p>Including also a <strong>graphical presentation of the data</strong>, that, of course, helps you a lot to discover any anomaly.</p>
<p><img src="http://farm4.static.flickr.com/3363/3498931290_5e5ec8b6bf.jpg?v=0" /></p>
<h3><strong><font size="3">Monitoring</font></strong></h3>
<p>Within this section you’ll find all of<strong> data parsed</strong> and sorted in a very user-friendly way. They are pretty much self-explained.</p>
<p><img src="http://farm4.static.flickr.com/3543/3498118865_a8c2780010.jpg?v=0" /></p>
<p>All of this information is sorted also from a calendar, so if you want to take a look from previous dates, just use the <strong>“&lt;” “&gt;”</strong> buttons from upper right corner.</p>
<p><strong>Active and Past Connections.</strong></p>
<p><img src="http://farm4.static.flickr.com/3604/3498119325_0835f18af4.jpg?v=0" /></p>
<p><strong>Bandwidth Consumption and Distribution.</strong></p>
<p><img src="http://farm4.static.flickr.com/3395/3498119137_87b7ea57d8.jpg?v=0" /></p>
<p><strong>Top Policy Breakers</strong>. Users marked that tried to access or download blocked content. In my case, only IPs are showing but remember this tool is highly integrated with ISA Client and ISA Server authentication that associates traffic with specific users.</p>
<p><img src="http://farm4.static.flickr.com/3332/3498118761_a64f316b7d.jpg?v=0" width="525" height="75" /></p>
<p>If that’s not enough for you, check the <strong>charts</strong> options for specific URLs:</p>
<p><img src="http://farm4.static.flickr.com/3384/3498932378_ddcf83b07e.jpg?v=0" /></p>
<h3><font size="3">White/Black Lists</font></h3>
<p>By default, there are a few sites configured already in the white list.</p>
<p><img src="http://farm4.static.flickr.com/3578/3498931946_fd684e2f73.jpg?v=0" /></p>
<p>As an interesting option, you also have a “<strong>temporary white list</strong>” to allow specific sites for a few hours.</p>
<p><img src="http://farm4.static.flickr.com/3386/3498118067_e17136c0bf.jpg?v=0" width="338" height="208" /></p>
<p>When a black listed site is trying to be browsed, the client will receive this <strong>message</strong>.</p>
<p><img src="http://farm4.static.flickr.com/3338/3498117767_8b2016b647.jpg?v=0" /></p>
<h3><font size="3"><strong>Web Filtering Policies</strong></font></h3>
<p>Here you can <strong>create rules and policies for your network traffic</strong>. You have a “<strong>Default Web Filtering Policy</strong>” that allows all contents from all categories; you can modify this one or create a new one for a specific user or IP.</p>
<p><img src="http://farm4.static.flickr.com/3593/3498933606_1e9b6e3d77.jpg?v=0" width="524" height="86" /></p>
<p><strong>Creating a new policy it’s quite simple and intuitive.</strong></p>
<p><strong>Policy name and schedule.</strong></p>
<p><img src="http://farm4.static.flickr.com/3552/3498120147_d9a8e91e5d.jpg?v=0" width="446" height="438" /></p>
<p><strong>Categories to be blocked and allowed by the policy.</strong></p>
<p><img src="http://farm4.static.flickr.com/3392/3498120569_95887ac6ba.jpg?v=0" width="462" height="337" /></p>
<p><strong>Applies to (users, groups or IPs).</strong></p>
<p><img src="http://farm4.static.flickr.com/3385/3498934306_478f95d50f.jpg?v=0" width="436" height="293" /></p>
<p><strong>Notification options when a user intents to access blocked content.</strong></p>
<p><img src="http://farm4.static.flickr.com/3648/3498934570_941012541c.jpg?v=0" width="356" height="415" /></p>
<p>To define a website category a query is run to the <strong>WebGrade Database</strong>, that also receives updates periodically.</p>
<p><img src="http://farm4.static.flickr.com/3600/3498121339_742ef05900.jpg?v=0" width="529" height="217" /></p>
<p>You can also <strong>run queries manually to the database</strong> and find out the <strong>category</strong> for a specific site.</p>
<p>&#160;</p>
<h3><font size="3"><strong>Web Security Policies</strong></font></h3>
<p>These policies have the same functionality that the filtering policies, but are defined for <strong>file downloads, IM access and virus scanning.</strong></p>
<h5>Download Policies</h5>
<p>By default, all content is allowed for download.</p>
<p><img src="http://farm4.static.flickr.com/3577/3498935058_46ea27f178.jpg?v=0" width="367" height="381" /></p>
<p>As an alternative policy to blocked downloads is the “<strong>quarantine</strong>” option.</p>
<p><img src="http://farm4.static.flickr.com/3609/3498935162_19b5309413.jpg?v=0" width="332" height="258" /></p>
<h5>IM Control Policies</h5>
<p>This an option that is constantly asked and requested by ISA Server administrators, how to block IM on their networks.</p>
<p>Unfortunately, using this tool, <strong>you can only block MSN and Live Messenger traffic using HTTP connections.</strong></p>
<h5>Virus Scanning Policies</h5>
<p>By default any suspicious download will be scanned by <strong>three different antivirus engines</strong>: <a href="http://www.bitdefender.com/"><strong>BitDefender</strong></a><strong>, </strong><a href="http://www.kaspersky.com/"><strong>Kaspersky</strong></a><strong> and </strong><a href="http://www.norman.com/"><strong>Norman</strong></a>; that, of course are updated constantly.</p>
<p>The default files that are scanned: <strong>Microsoft Office documents, PDFs, ZIP and RAR, executables and MSI. </strong></p>
<p>Whenever any of these files are downloaded, the client will open the <strong>GFI WebMonitor Secure Download</strong> window that validates the file it’s not infected. </p>
<p><img src="http://farm4.static.flickr.com/3374/3498119703_a1a5f87446.jpg?v=0" /></p>
<p><strong>Download and virus scan completed.</strong></p>
<p><img src="http://farm4.static.flickr.com/3603/3498119525_f2f9404688.jpg?v=0" /></p>
<h3><font size="3"><strong>Conclusions</strong></font></h3>
<h5><font color="#008000">Pros</font></h5>
<ul>
<li>It is one of the <strong>best monitoring tools</strong> for <strong>bandwidth consumption</strong> available in the market. With a <strong>nice data parsing</strong> as well. </li>
<li>It represents a <strong>great complement for ISA Server access and deny rules.</strong> </li>
<li>Rules and policies are <strong>very easy to add and configure. </strong></li>
<li><strong>Minimum overhead in network connectivity.</strong> </li>
<li><strong>Antivirus Integration</strong>: This is probably my favorite feature. Has almost the <strong>same</strong> <strong>functionality than an corporative antivirus solution</strong> that controls any suspicious packet in the network. </li>
</ul>
<h5><font color="#ff0000">Cons </font></h5>
<ul>
<li><strong>Hardware requirements</strong>. It is not recommendable to use GFI WebMonitor on a machine with <strong>less than 2gb of RAM.</strong> </li>
<li>Even though the data parsing is great, <strong>there’s no easy way to export those reports to a document or even a CSV file. </strong></li>
<li>There are <strong>no options available for</strong> <strong>export/import WebMonitor configurations</strong>. It is not possible to replicate the same configuration on another server or make a backup in a simple way. </li>
</ul>
<p>If you are an IT Administrator that continuously perceive that your <strong>network is slow or it does not has the performance that it should</strong>,<strong> this tool can give you a lot of help.</strong> As a bonus, it will <strong>simplify configuring access rules and provide you with an excellent protection with 3 antivirus engines scanning packets. </strong></p>
<p>But if you are using a <strong>small resources machine as your gateway, don’t bother installing it</strong>, it would give you a lot more problems than solutions.</p>
<p>Hope that you find this useful,</p>
<p>Cheers!</p>
<p>Download the <a href="http://www.test-king.com/exams/642-642.htm">testking 642-642</a> dumps and <a href="http://www.test-king.com/exams/350-029.htm">testking 350-029</a> tutorials prepared by certified experts at <a href="http://www.test-king.com">testking</a> to help you learn how to improve web access using gfi web monitor </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/augustoalvarez.wordpress.com/223/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/augustoalvarez.wordpress.com/223/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/augustoalvarez.wordpress.com/223/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/augustoalvarez.wordpress.com/223/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/augustoalvarez.wordpress.com/223/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/augustoalvarez.wordpress.com/223/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/augustoalvarez.wordpress.com/223/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/augustoalvarez.wordpress.com/223/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/augustoalvarez.wordpress.com/223/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/augustoalvarez.wordpress.com/223/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/augustoalvarez.wordpress.com/223/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/augustoalvarez.wordpress.com/223/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/augustoalvarez.wordpress.com/223/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/augustoalvarez.wordpress.com/223/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.augustoalvarez.com.ar&amp;blog=5820778&amp;post=223&amp;subd=augustoalvarez&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.augustoalvarez.com.ar/2009/05/11/gfi-webmonitor-2009-review-and-common-configurations/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1cec2d2550378b6bd686e5ae7e0523c5?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aalvarez82</media:title>
		</media:content>

		<media:content url="http://farm4.static.flickr.com/3545/3498116029_db7de84cef.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3609/3498930704_617daf5e0b.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3411/3498930270_5a27e7e1b0.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3629/3498930542_9101e84f70.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3360/3498932232_1a8615c16b.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3363/3498931290_5e5ec8b6bf.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3543/3498118865_a8c2780010.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3604/3498119325_0835f18af4.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3395/3498119137_87b7ea57d8.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3332/3498118761_a64f316b7d.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3384/3498932378_ddcf83b07e.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3578/3498931946_fd684e2f73.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3386/3498118067_e17136c0bf.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3338/3498117767_8b2016b647.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3593/3498933606_1e9b6e3d77.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3552/3498120147_d9a8e91e5d.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3392/3498120569_95887ac6ba.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3385/3498934306_478f95d50f.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3648/3498934570_941012541c.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3600/3498121339_742ef05900.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3577/3498935058_46ea27f178.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3609/3498935162_19b5309413.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3374/3498119703_a1a5f87446.jpg?v=0" medium="image" />

		<media:content url="http://farm4.static.flickr.com/3603/3498119525_f2f9404688.jpg?v=0" medium="image" />
	</item>
		<item>
		<title>Publishing Team Foundation Server 2005 (Single-Server Mode) with ISA Server 2006</title>
		<link>http://blog.augustoalvarez.com.ar/2008/12/12/publishing-team-foundation-server-2005-single-server-mode-with-isa-server-2006/</link>
		<comments>http://blog.augustoalvarez.com.ar/2008/12/12/publishing-team-foundation-server-2005-single-server-mode-with-isa-server-2006/#comments</comments>
		<pubDate>Fri, 12 Dec 2008 18:54:57 +0000</pubDate>
		<dc:creator>Augusto Alvarez</dc:creator>
				<category><![CDATA[ISA Server]]></category>
		<category><![CDATA[Team Foundation Sever]]></category>
		<category><![CDATA[ISA Server Publication]]></category>
		<category><![CDATA[Team Foundation Server]]></category>

		<guid isPermaLink="false">http://augustoalvarez.wordpress.com/2008/12/12/publishing-team-foundation-server-2005-single-server-mode-with-isa-server-2006/</guid>
		<description><![CDATA[Publishing a TFS within an ISA Server basically depends on creating three rules for web sites: One will use the TFS default port (8080), the second will use SharePoint (on port 17012) and the other one is for the common HTTP port (80). A small comment about this: The same configuration described here, can also [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.augustoalvarez.com.ar&amp;blog=5820778&amp;post=21&amp;subd=augustoalvarez&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Publishing a TFS within an ISA Server basically depends on <strong>creating three rules for web sites</strong>: One will use the <strong>TFS default port</strong> (8080), the second will use <strong>SharePoint </strong>(on port 17012) and the other one is for the <strong>common HTTP port</strong> (80).
<p>A small comment about this: The same configuration described here, can also <strong>work for Team Foundation Server 2008</strong>.
<p>It’s very <strong>important</strong> that you <strong>already have defined your public name for the TFS Server</strong> and even more important that <strong>this public name can be resolved by the ISA Server and over the Internet</strong>.
<p>Let’s start then:
<p><strong><font size="3">1 – Publish TFS Services</font></strong>
<p><strong>1.1 </strong>– Select “<strong>Publish Web Site</strong>” and use the proper name for that rule.
<p><img height="291" alt="" src="http://farm3.static.flickr.com/2177/2220032481_1107746bbb.jpg?v=0" width="304">
<p><strong>1.2 </strong>– Select “<strong>Publish a single Web Site or load balancer</strong>”.
<p><img height="298" alt="" src="http://farm3.static.flickr.com/2111/2220031983_87cf429e1d.jpg?v=0" width="310">
<p><strong>1.3 </strong>– If you are not going to use SSL the just select “<strong>Use non-secured connections…”</strong>
<p><img height="294" alt="" src="http://farm3.static.flickr.com/2050/2220032271_19c1bc7112.jpg?v=0" width="311">
<p><strong>1.4 </strong>– In this step you must indicate the <strong>FQDN that the clients will use to connect with the Team Foundation Server</strong>. Remember that this name should be already accessible for the ISA Server.
<p><img height="304" alt="" src="http://farm3.static.flickr.com/2256/2220827184_731fd75147.jpg?v=0" width="321">
<p><strong>1.5 </strong>– No selection on Path and select “<strong>Forward the original host header…”</strong>
<p><img height="308" alt="" src="http://farm3.static.flickr.com/2376/2220032073_f000a3b59c.jpg?v=0" width="321">
<p><strong>1.6 </strong>– Select “<strong>Accept Requests for: This domain name (type below)</strong>” and use the public TFS name again.
<p><img height="311" alt="" src="http://farm3.static.flickr.com/2268/2220826598_6a123ec9df.jpg?v=0" width="329">
<p><strong>1.7 </strong>– On the next window you will need to <strong>create a Web Listener</strong>, which will be accepting the incoming requests for TFS Services port.
<p><img height="308" alt="" src="http://farm3.static.flickr.com/2110/2220826134_949d6113e6.jpg?v=0" width="323">
<p><strong>1.8 </strong>– Select again what kind of <strong>HTTP connections will use</strong>, secure or not secure.<strong></strong>
<p><strong>1.9 </strong>– Select that the Listener will be getting the requests from the <strong>External</strong> network that you should already have on your ISA Server
<p><img height="294" alt="" src="http://farm3.static.flickr.com/2385/2220031483_1633896f6e.jpg?v=0" width="320">
<p><strong>1.10 </strong>Select that the Listener will <strong>not require authentication</strong>. This process will be done by the TFS itself.
<p><img height="298" alt="" src="http://farm3.static.flickr.com/2010/2220032373_b4e4abbc04.jpg?v=0" width="323">
<p><strong>1.11 </strong>Hit <strong>Next</strong> and <strong>Finish</strong> the new listener creation.
<p><strong>1.12 </strong>Once that the creation of the listener finishes, you’ll be back at the rule wizard.<br />Leave selection of “<strong>No delegation, and client cannot authenticate directly</strong>”
<p><img height="308" alt="" src="http://farm3.static.flickr.com/2172/2220031019_a194dd816f.jpg?v=0" width="324">
<p><strong>1.13 </strong>Leave the “<strong>All Users</strong>” option and hit <strong>Next.</strong>
<p><strong>1.14 </strong>The wizard will complete but that’s not all<strong>. The web listener and the rules that you just created it actually didn’t complete with their proper configuration</strong>, all the listeners are created to “listen” in the default port of HTTP. Like TFS use the port <strong>8080</strong> to receive incoming requests, we will need to change that default port.
<p>Access the rule properties and get to the “<strong>Bridging</strong>” and select the port <strong>8080</strong>.
<p><img height="371" alt="" src="http://farm3.static.flickr.com/2081/2220031631_3d8e9584e3.jpg?v=0" width="325">
<p>Now enter to the listener properties and select on “<strong>Connections</strong>” the correct port.
<p><img height="350" alt="" src="http://farm3.static.flickr.com/2063/2220031279_df3b6fdde8.jpg?v=0" width="317">
<p>On “<strong>Authentication</strong>” select “<strong>Advanced</strong>” and check the option “<strong>Allow client authentication over HTTP</strong>”
<p><img height="376" alt="" src="http://farm3.static.flickr.com/2277/2220826316_1cda10c32d.jpg?v=0" width="319">
<p><strong>1.15 </strong>Hit <strong>OK</strong> twice and the rule for <strong>TFS Services it’s ready</strong>.
<p><font size="3"><strong>2 </strong><strong>– Publish TFS SharePoint</strong></font>
<p><strong>This rule follows the same configuration that the TFS Services on the steps 1 to 13</strong>. As you can imagine the differences are made within the ports configuration, and we will <strong>replace the 8080 used on the first rule by the 17012 of our SharePoint Services</strong>.
<p><strong>2.1 </strong>Enter the properties of the rule you just created for the SharePoint services and Access to the “<strong>Bridging</strong>” options and select the <strong>17012</strong> port.<img height="389" alt="" src="http://farm3.static.flickr.com/2263/2220032853_a70a8a5dae.jpg?v=0" width="327">
<p>Access the <strong>Listener properties</strong> and select “<strong>Connections</strong>” with the proper port:
<p><img height="362" alt="" src="http://farm3.static.flickr.com/2053/2220032961_99c7d87d94.jpg?v=0" width="327">
<p>Again on “<strong>Authentication</strong>” select “<strong>Advanced</strong>” and mark “<strong>Allow client authentication over HTTP”</strong>
<p><img height="385" alt="" src="http://farm3.static.flickr.com/2277/2220826316_1cda10c32d.jpg?v=0" width="327">
<p><strong>2.2 </strong>Now the TFS SharePoint Rule it’s created.
<p><strong><font size="3">3 – Publish TFS www</font></strong>
<p>Like the other two rules, <strong>the steps from 1 to 13 are completely the same</strong>. <strong>Like this rule it’s representing an HTTP connection, neither ports on the Bridging option nor the Web Listener needs to be changed, they must keep as the default port 80 configured. </strong>The only thing that you must do is the authentication method, as we did on the first two.
<p><strong>3.1 </strong>“<strong>Authentication</strong>” select “<strong>Advanced</strong>” and “<strong>Allow client authentication over HTTP</strong>”
<p><img height="382" alt="" src="http://farm3.static.flickr.com/2277/2220826316_1cda10c32d.jpg?v=0" width="325">
<p><strong>3.2 </strong>Hit <strong>OK</strong> twice and you are set to go.
<p>That’s pretty much everything to do.
<p><strong>There’s a common issue within TFS public name</strong>. When you use this FQDN to connect over the Internet, it appears that the users have not the proper permissions, making the <strong>“Documents” and “Reports” items unavailable, for Team Explorer</strong>. You should check another <strong><a href="http://augustoalvarez.wordpress.com/2008/12/12/common-issue-using-team-foundation-server-with-an-external-connection-documents-and-reports-items-becomes-unavailable/">post</a></strong> of mine that has the workaround for that problem.
<p>Also here&#8217;s an interesting article about how ISA Server handles authentication:<br /><a title="http://technet.microsoft.com/en-us/library/bb794722.aspx" href="http://technet.microsoft.com/en-us/library/bb794722.aspx">http://technet.microsoft.com/en-us/library/bb794722.aspx</a>
<p>I hope you find it useful!
<p>Cheers!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/augustoalvarez.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/augustoalvarez.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/augustoalvarez.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/augustoalvarez.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/augustoalvarez.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/augustoalvarez.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/augustoalvarez.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/augustoalvarez.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/augustoalvarez.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/augustoalvarez.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/augustoalvarez.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/augustoalvarez.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/augustoalvarez.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/augustoalvarez.wordpress.com/21/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.augustoalvarez.com.ar&amp;blog=5820778&amp;post=21&amp;subd=augustoalvarez&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.augustoalvarez.com.ar/2008/12/12/publishing-team-foundation-server-2005-single-server-mode-with-isa-server-2006/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1cec2d2550378b6bd686e5ae7e0523c5?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aalvarez82</media:title>
		</media:content>

		<media:content url="http://farm3.static.flickr.com/2177/2220032481_1107746bbb.jpg?v=0" medium="image" />

		<media:content url="http://farm3.static.flickr.com/2111/2220031983_87cf429e1d.jpg?v=0" medium="image" />

		<media:content url="http://farm3.static.flickr.com/2050/2220032271_19c1bc7112.jpg?v=0" medium="image" />

		<media:content url="http://farm3.static.flickr.com/2256/2220827184_731fd75147.jpg?v=0" medium="image" />

		<media:content url="http://farm3.static.flickr.com/2376/2220032073_f000a3b59c.jpg?v=0" medium="image" />

		<media:content url="http://farm3.static.flickr.com/2268/2220826598_6a123ec9df.jpg?v=0" medium="image" />

		<media:content url="http://farm3.static.flickr.com/2110/2220826134_949d6113e6.jpg?v=0" medium="image" />

		<media:content url="http://farm3.static.flickr.com/2385/2220031483_1633896f6e.jpg?v=0" medium="image" />

		<media:content url="http://farm3.static.flickr.com/2010/2220032373_b4e4abbc04.jpg?v=0" medium="image" />

		<media:content url="http://farm3.static.flickr.com/2172/2220031019_a194dd816f.jpg?v=0" medium="image" />

		<media:content url="http://farm3.static.flickr.com/2081/2220031631_3d8e9584e3.jpg?v=0" medium="image" />

		<media:content url="http://farm3.static.flickr.com/2063/2220031279_df3b6fdde8.jpg?v=0" medium="image" />

		<media:content url="http://farm3.static.flickr.com/2277/2220826316_1cda10c32d.jpg?v=0" medium="image" />

		<media:content url="http://farm3.static.flickr.com/2263/2220032853_a70a8a5dae.jpg?v=0" medium="image" />

		<media:content url="http://farm3.static.flickr.com/2053/2220032961_99c7d87d94.jpg?v=0" medium="image" />

		<media:content url="http://farm3.static.flickr.com/2277/2220826316_1cda10c32d.jpg?v=0" medium="image" />

		<media:content url="http://farm3.static.flickr.com/2277/2220826316_1cda10c32d.jpg?v=0" medium="image" />
	</item>
	</channel>
</rss>
