Getting started with Microsoft ISA Server 2006, Part 8: Create Web Access Rule
ISA, Security, Windows November 17th, 2009This article is one of the series of Getting started with Microsoft ISA Server 2006. You can see the index of this series at Getting started with Microsoft ISA Server 2006, Part 1: Introduction.
Create Firewall Policy Rule
From Part 7: Create DNS Lookup Rule, you have create an access rule to allow DNS look up from the internal network to the external DNS addresses. But you do not have any web access rule for users. So now, I will show how to create an access rule on ISA Server 2006 to allow HTTP and HTTPS protocols for a user to access the Internet.
Step-by-step
- On ISA Server Management, open Firewall Policy by expand Arrays -> BKKISA001 -> Firewall Policy (BKKISA001).

- On Firewall Policy, select Tasks and click on Create Access Rule.

- On Welcome to the New Access Rule Wizard, type a name for the access rule. On this example, I type “Allow HTTP, HTTPS for Linglom” and click Next.

- On Rule Action, select Allow and click Next.

- On Protocols, you have to choose which protocols will be applied to this rule.
- On Access Rule Sources, select the source network for this rule.
- On Access Rule Destinations, do the same as the previous step but select External network as a destination.

- On User Sets, you have to select which users and groups are applied to this access rule. On this example, I want this rule apply to only a domain user account – linglom.
- Remove All Users by click on Remove and add a new User Sets by click Add.

- On Add Users, you see existing user sets available. There is no user set that I want so I will create a new one. Click New.

- On Welcome to the New User Set Wizard, type the name of a new user set that you want and click Next.

- On Users, click Add -> Windows users and groups.

- On Select Users or Groups, select the users or groups that you want to add to this new user set. On this example, I select the domain user – linglom. Then, click OK.

- You see that the user has been added to a new user set. Click Next.

- On Completing the New User Set Wizard, click Finish.

- A new user set is created. The, select on it and click Add to add the new user set to this rule.

- Now the user set is added to the rule. So this rule will be apply to only this user – Linglom. Click Next.

- Remove All Users by click on Remove and add a new User Sets by click Add.
- On Completing the New Access Rule Wizard, click Finish.

- Don’t forget to save the changes that you have made by click on Apply at the top.

- The changes have been saved. Click OK.

- Now you see the rule that you have created.

What’s Next
You have some access rules on ISA Server 2006. That’s it for the basic configuration on the sever. Next, I will start configure client to access the Internet through ISA Server 2006. See Part 9: Client Configuration.
Related post
- Getting started with Microsoft ISA Server 2006, Part III: Create Firewall Policy Rule Firewall Policy From part II, you have configured Network Topology. Now you need to create a policy rule to allow...
- Getting started with Microsoft ISA Server 2006, Part 7: Create DNS Lookup Rule This article is one of the series of Getting started with Microsoft ISA Server 2006. You can see the index...
- Getting started with Microsoft ISA Server 2006, Part 6: Configure Network Layout This article is one of the series of Getting started with Microsoft ISA Server 2006. You can see the index...
- Getting started with Microsoft ISA Server 2006, Part II: Configure Network Topology Network Topology From Part I, you have finished install ISA Server 2006. Before using the server, you need to do...
- Getting started with Microsoft ISA Server 2006, Part I: Installation Introduction Microsoft Internet Security & Acceleration Server 2006 is a firewall and proxy product from Microsoft. It can protects local...
Related posts:








November 17th, 2009 at 2:05 pm
Dear linglom you are great.your writing skills are best i love your style and all of your guides.
February 22nd, 2010 at 11:03 pm
I am using ISA and I am having a problem… Well I have set of Allow and Deny for different group, but I can’t seem to make it work.. Which one shoudl I put up and down? The allow or Deny ? I work in a school so I divided it in 4 group. Student, Teachers, Administration, and Heads…. So should I put 4 allow up then 4 deny, or each group with his allow and deny? Where does the ISA to DC1 goes? ISA to Internet? If I put one rule up first then the other rules won’t work? If I disable student group the other group work, but if I don’t disable it all the other group will take the student rule. The student rule is the most ristrictive (I am blocking youtube,hotmail,music,.exe,.mp3,etc) The other group are less ristrictive. Its a bet confiusing. Some help please… I do hope you get my point.
February 23rd, 2010 at 11:52 am
Hi, Meshari
You should not use both allow and deny rules at the same time if it is possible because they may confuse you. You should have only allow rule. The bottom rule will deny others traffic by default.
If you want to discuss more detail about your situation, you can send a message to me on Contact me tab.
March 26th, 2010 at 12:48 pm
Hi ling log ,thanks for your great presentation about ISA server,as per your blog i have configured my ISA proxy, but little confusion about my access rules. can you explain to “allow only specific website for particular users, i have created restricted group in my ads