KK20 Posted April 19, 2013 Posted April 19, 2013 (edited) Licence renewal time comes around and I submit my usual request (no change to hardware, software or FTE staff so an easy one) only to find out no licensing for TMG any more as it is EOL. uh oh. So with a couple of months to go I am not quite in full panic mode yet. Anyone ideas on alternatives? I use TMG for VPN, multiple website publishing (OWA, outlook anywhere, intranet, moodle) spread over 2 ips in reverse proxy. Internally it load balances 2 ISPs on an active failover (with a static route on TMG sending SMTP over the "backup" ISP line permanently). Quite a few rules for letting a guest VLAN use internet and route certain web servers (we dont have an L3 router). Are there any alternatives that will leverage the above with (presumably) AD integration? Will MS UAG cover my existing TMG usage (since it installs TMG I believe). Will UAG cost me an arm and a leg? Ta Edited April 19, 2013 by KK20
DMcCoy Posted April 19, 2013 Posted April 19, 2013 The problem with the TMG part of UAG is that it's controlled by UAG and you aren't supposed to change anything with the config itself, it gets updated by the UAG side so they may get removed. It also needs CALs... It's also vile.
KK20 Posted April 19, 2013 Author Posted April 19, 2013 and I now see forefront CALS removed from EES. Great. so begins my migration from MS then.
chazzy2501 Posted April 19, 2013 Posted April 19, 2013 I'm still using isa 2006 I usually buy a TMG server licence. Don't think I need a cal for it though.
DMcCoy Posted April 19, 2013 Posted April 19, 2013 FYI Support boundaries info about how you can use TMG as part of UAG
tom_newton Posted April 19, 2013 Posted April 19, 2013 As long as you're not doing forms based auth the smoothie UTM should cover those bases...
KK20 Posted April 19, 2013 Author Posted April 19, 2013 (edited) oops OWA is forms based on TMG atm. can smoothwall pass the forms based auth back to exchange and let exchange reject as appropriate? I'll need to look at the security implications of that first (hence the reason you normally let TMG be a firewall and do the AUTH). That being said, it is no different from letting IIS auth my webdav etc. Tom, ive posted in teh smoothwall direct support with a few more smoothwall questions. In reality I will probably email smoothwall directly after monday (ICT practical iGCSEs on monday so i'm on call for those in case of issues....) Chazzy, thats the point. I cannot GET a TMG licence any longer, you cant buy one since they have EOLd with no replacement (unlike when they EOLd ISA you could "downgrade" a TMG licence) Edited April 19, 2013 by KK20
KK20 Posted April 29, 2013 Author Posted April 29, 2013 (edited) In the end ive decided sonicwall for the firewall but keep my existing dansguardian filter. I'll decomission the TMG server and setup an MS VPN server on the network to handle VPN from clients. Edited April 29, 2013 by KK20
cpjitservices Posted April 29, 2013 Posted April 29, 2013 In the end ive decided sonicwall for the firewall but keep my existing dansguardian filter. I'll decomission the TMG server and setup an MS VPN server on the network to handle VPN from clients. Or you could setup pfsense with squid and dansguardian port over your configs and then setup OpenVPN, you can have as many VPN's on there as the system will cope with. You get a nice Web GUI that way.
KK20 Posted April 29, 2013 Author Posted April 29, 2013 I had thought of pfsense or even a clearos installation (was thinking pound or just squid3 with dansguardian either bolted on or under a dual squid option). Unfortunately time is against me so for this one i'm going for an off-the-shelf option.
cpjitservices Posted April 29, 2013 Posted April 29, 2013 Time... Is what it all boils down to in the end. Good Luck!
KK20 Posted September 19, 2013 Author Posted September 19, 2013 Just an update, the sonicwall is probably expensive for what it does but it works for me. A few VLAN issues that ive had to work around but overall it has worked perfectly. If I had to do it again then yes, pfsense will do the same (loaded up with NICs of course). I went for an NSA 2400 in the end. MS VPN using SSTP only as we only use windows devices. Stuff the ipads... (sonicwall wanted money for VPN clients, I dont think so.)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now