lol...the way people worshipped ISA, I thought EVERYONE used it and I was the IDIOT that didn't know about it
turns out, not that many people use ISA...maybe because of trust issue? afterall, it is M$ security
ya, we do the same as spyordie007 with the dedicated SMTP relay server. we do have FE for OWA though, but it is locked down just for OWA and not the typical FE setup.
as for ISA being the best FW...it's not. I checked it out last night on microsoft and looked at most of the documentation. It offers no where near the features my current fw offers...one being ssl vpn. at least not natively, you'd have to go through another 3rd party vendor or device to achieve that functionality....
ISA looking at vpn traffic, I couldn't find where it says ISA will do this. The most I will believe is that ISA will look at ISA to ISA vpn traffic. but what about ISA to another vendor (if isa supports this). I doubt ISA will know how to decrypt ALL VPN traffic. Even if it does, you shouldn't allow your internal users to establish VPN traffic with anyone outside of your network anyways. This is easily blocked with good fw policy.
ISA looking at ssl traffic, again I couldn't find good documentation about this. It does say ISA will do ssl-to-ssl bridging(which is really cool), but does not mention that it supports all types of SSL certs. Does it only support microsoft's certificate authorities, or does it work with vendors like verisign? If only microsoft's CA's, I'm not sure if too many people in the world trust microsoft CA

This is for incoming SSL traffic to your web servers that provide SSL. what about outgoing ssl traffic? does isa look at that as well and block malicious outgoing activity hidden behind ssl? (again which vendors?) I doubt it...
the other things I couldn't find about ISA are: does it protect from the REAL bad stuff like
cross site scripting
sql, command and LDAP injection
SPI for VOIP and SIP
will it route through VPN's? <--
I think I will stick with my FW's /pets them
I'm still learning about ISA, so if I'm wrong about any of this, please feel free to point out and provide link. I'm very interested in learning about ISA, and any FW's in general. thx
