Secure E-Mail Access to Employees Outside the Corporate Network
ISA Server 2006 provides a unique level of protection for Outlook Web Access Web sites. With the easy-to-use interface of ISA Server 2006, organizations can quickly set up Web publishing rules that enforce secure forms-based authentication. ISA Server 2006 also helps stop attacks against e-mail servers, both through Secure Sockets Layer (SSL) decryption (SSL bridging), which enables SSL traffic to be statefully inspected for malicious code, and through stateful HTTP filtering, which provides deep inspection of HTTP application content. In addition, ISA Server can authenticate users. Authentication prevents anonymous connections from reaching your mail server. Preventing anonymous connections prevents anonymous user logon attempts, which represent a key attack vector aimed at internal mail servers.
ISA Server leverages the existing multifactor authentication currently used in organizations and provides secure authentication and authorization, whether the remote mail scenarios use Remote Authentication Dial-In User Service (RADIUS), RSA SecurID, or Windows-based authentication methods. This enables ISA Server to prevent dangerous anonymous requests from reaching Exchange Server. Forms-based authentication provides further protection by performing attachment blocking and session time-out. Attachment blocking prevents users from accessing attachments using Outlook Web Access. Session time-out prevents user e-mail sessions from being left open indefinitely for others to use.
|