Often, you will manage ISA Server from a remote computer. Carefully determine which remote computers are allowed to manage and monitor ISA Server. The following table shows the system policy rules that should be configured.
|
Configuration group
|
Rule name
|
Rule description
|
| Microsoft Management Console | Allow remote management from selected computers using MMC Allow MS Firewall Control communication to selected computers | Allows computers in the Remote Management Computers computer set to access the ISA Server computer using the MS Firewall Control and RPC (all interfaces) protocols. |
| Terminal server | Allow remote management from selected computers using Terminal Server | Allows computers in the Remote Management Computers computer set to access the ISA Server computer using the RDP (Terminal Services) protocol. |
| ICMP (Ping) | Allow ICMP (PING) requests from selected computers to ISA Server | Allows computers in the Remote Management Computers computer set to access the ISA Server computer using the Ping protocol, and vice versa. |
By default, the system policy rules allowing remote management of ISA Server are enabled. ISA Server can be managed by running a remote Microsoft Management Console (MMC) snap-in, or by using Terminal Services.
By default, these rules apply to the built-in Remote Management Computers computer set. When you install ISA Server, this empty computer set is created. Add to this empty computer set all computers that will remotely manage ISA Server. Until you do so, remote management is effectively not available from any computer.
Note: |
|---|
|
Limit remote management to specific computers by configuring the system policy rules to apply only to specific IP addresses.
|
To enable remote management, perform the following steps.
-
Click Start, point to All Programs, point to Microsoft ISA Server, and then click ISA Server Management.
-
In the console tree of ISA Server Management, click Microsoft ISA Server 2004, click the server_name, and then click Firewall Policy.
-
On the Toolbox tab, click Network Objects.
-
On the toolbar beneath Network Objects, under Computer Sets, right-click Remote Management Computers and then click Properties.
-
Click Add and then click Computer.
-
In Name, type the name of the computer.
-
In Computer IP address, type the IP address of the computer that can remotely manage ISA Server.
Remote Monitoring and Logging
By default, remote logging and monitoring is disabled. The following configuration groups are disabled by default:
-
Remote Logging (NetBIOS)
-
Remote Logging (SQL)
-
Remote Performance Monitoring
-
Microsoft Operations Manager
The following table provides a description of the configuration groups.
|
Configuration group
|
Rule name
|
Rule description
|
| Remote logging (NetBIOS) | Allow remote logging to trusted servers using NetBIOS | Allows the ISA Server computer to access the Internal network using various NetBIOS protocols. |
| Remote Logging (SQL) | Allow remote SQL logging from ISA Server to selected servers | Allows the ISA Server computer to use Microsoft (SQL) protocols to access the Internal network. |
| Remote Performance Monitoring | Allow remote performance monitoring of ISA Server from trusted servers | Allows computers in the Remote Management Computers computer set to access the ISA Server computer using various NetBIOS protocols. |
| Microsoft Operations Manager | Allow remote monitoring from ISA Server to trusted servers, using Microsoft Operations Manager (MOM) Agent | Allows the ISA Server computer to access the Internal network using the Microsoft Operations Manager agent. |
Enabling Remote Logging and Monitoring
To enable remote monitoring and logging, perform the following steps.
-
Click Start, point to All Programs, point to Microsoft ISA Server, and then click ISA Server Management.
-
In the console tree of ISA Server Management, click Microsoft ISA Server 2004, click the server_name, and then click Firewall Policy.
-
On the Tasks tab, click Edit System Policy.
-
In the System Policy Editor, in the Configuration Groups tree, select one or more of the following configuration groups:
-
Remote Logging (NetBIOS)
-
Remote Logging (SQL)
-
Remote Performance Monitoring
-
Microsoft Operations Manager
-
On the General tab, verify that Enable is selected.