Jump to content

Recommended Posts

Posted (edited)

Licence renewal time comes around and I submit my usual request (no change to hardware, software or FTE staff so an easy one) only to find out no licensing for TMG any more as it is EOL.

 

uh oh.

 

So with a couple of months to go I am not quite in full panic mode yet. Anyone ideas on alternatives? I use TMG for VPN, multiple website publishing (OWA, outlook anywhere, intranet, moodle) spread over 2 ips in reverse proxy. Internally it load balances 2 ISPs on an active failover (with a static route on TMG sending SMTP over the "backup" ISP line permanently). Quite a few rules for letting a guest VLAN use internet and route certain web servers (we dont have an L3 router).

 

Are there any alternatives that will leverage the above with (presumably) AD integration? Will MS UAG cover my existing TMG usage (since it installs TMG I believe). Will UAG cost me an arm and a leg?

 

Ta

Edited by KK20
Posted

The problem with the TMG part of UAG is that it's controlled by UAG and you aren't supposed to change anything with the config itself, it gets updated by the UAG side so they may get removed. It also needs CALs...

 

It's also vile.

Posted (edited)

oops :) OWA is forms based on TMG atm. can smoothwall pass the forms based auth back to exchange and let exchange reject as appropriate? I'll need to look at the security implications of that first (hence the reason you normally let TMG be a firewall and do the AUTH). That being said, it is no different from letting IIS auth my webdav etc. Tom, ive posted in teh smoothwall direct support with a few more smoothwall questions. In reality I will probably email smoothwall directly after monday (ICT practical iGCSEs on monday so i'm on call for those in case of issues....)

 

Chazzy, thats the point. I cannot GET a TMG licence any longer, you cant buy one since they have EOLd with no replacement (unlike when they EOLd ISA you could "downgrade" a TMG licence)

Edited by KK20
  • 2 weeks later...
Posted (edited)
In the end ive decided sonicwall for the firewall but keep my existing dansguardian filter. I'll decomission the TMG server and setup an MS VPN server on the network to handle VPN from clients. Edited by KK20
Posted
In the end ive decided sonicwall for the firewall but keep my existing dansguardian filter. I'll decomission the TMG server and setup an MS VPN server on the network to handle VPN from clients.

 

Or you could setup pfsense with squid and dansguardian port over your configs and then setup OpenVPN, you can have as many VPN's on there as the system will cope with. You get a nice Web GUI that way.

Posted
I had thought of pfsense or even a clearos installation (was thinking pound or just squid3 with dansguardian either bolted on or under a dual squid option). Unfortunately time is against me so for this one i'm going for an off-the-shelf option.
  • 4 months later...
Posted

Just an update, the sonicwall is probably expensive for what it does but it works for me. A few VLAN issues that ive had to work around but overall it has worked perfectly.

 

If I had to do it again then yes, pfsense will do the same (loaded up with NICs of course). I went for an NSA 2400 in the end. MS VPN using SSTP only as we only use windows devices. Stuff the ipads... (sonicwall wanted money for VPN clients, I dont think so.)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...