Jump to content

Recommended Posts

Posted (edited)

Hi, everybody. I'm trying to test TMG as firewall/proxy server. I followed tutorial to install TMG Edge Firewall in home lab conditions, but my clients are unable to connect to Web. If you are willing to help me, this are my settings.

I have Virtual Box lab. My modem's internal network is 192.168.0.xxx. On Domain Controller Server (Server 2008 R2) I have internal network NIC with static ip address set to 192.168.2.4. On Domain controller I have set up DNS and DHCP roles which are both working properly. I made another 2008 R2 server, joined it in domain, and installed TMG on it, I installed both SP1 and SP2 on it, than configured it, following tutorial on web. I have two NICs, LAN (192.168.2.xxx)and WAN which is in bridged mode (192.168.0.xxx).

On LAN i have static IP with this settings:

ip 192.168.2.1

netmask 255.255.255.0

no gateway

DNS server 192.168.2.4 (my internal DNS on Domain Controller)

On WAN I have automatic settings (I have dynamic IP adress from ISP):

It is something like: ip 192.168.0.xxx

netmask 255.255.255.0

192.168.0.1

DNS - 192.168.0.1 (I tried with OpenDNS too, but it didn't help and i read that DNS should be set to internal)

I was hoping to use LAN static ip 192.168.2.1 as Default Gateway for my clients so they could use internet (Clients only have one NIC with internal network)

After I installed TMG, I have created access rules and enabled HTTP and HTTPS, and DNS, and web traffic so it goes from internal to external network.

Then, I have set my Windows 8.1 client to use static ip address with this settings:

ip: 192.168.2.40

subnet: 255.255.255.0

GW: 192.168.2.1 (static IP of internal NIC on TMG server)

DNS: 192.168.2.4 (internal DNS)

I have no internet on client, but also I have strange situation. Windows says I'm connected to network (i have normal network icon instead of yellow Limited connectivity icon), but I can't ping 8.8.8.8, nor google.com. What I'm doing wrong? Any help would be highly appreciated.

Edited by Fi011
Posted (edited)

Thank you for your reply. Actually, I didn't set anything in DNS in DC, but DNS is working fine. Anyway, I found the solution to the problem. Instead of access rule that forwards HTTP and HTTPS from internal network to external network (I don't know why, but it's not working that way for me), I made a rule that forwards all outbound traffic from internal and local host to external network and that was it. I have set up DHCP to use static IP address of LAN NIC as gateway for all clients, and it is working properly now. All internal network computers have internet now.

Now, next challenge is to setup TMG as proxy server and start molesting my "clients" denying them access to certain cites as Facebook or Youtube. Anyway, as for DNS, I just added DNS role on DC, and in DHCP settings I made it that all clients use that internal DNS. Should I point it to internet? Because it is working fine now, and all clients can resolve ip addresses.

Edited by Fi011
Posted
At the risk off sounding unhelpful, are you aware that Microsoft are no longer developing the forefront line, TMG included? While this doesn't mean that it's going to suddenly stop working, it does mean that there are going to be no new features and that it isn't supported on the latest operating systems. With all due respect, I would say that it's a mistake to put a new TMG firewall into production now and that you should be looking at another system.
Posted
The tmg was blocking dns traffic so although http and https were allowed there was no way for the clients to get dns info from outside. If you setup dns including dns forwarder info such as 8.8.8.8 on the dc then allow dns traffic for that server you can then point the clients to the internal dns and only allow http and https traffic for the clients. Everything should work then.
Posted
At the risk off sounding unhelpful, are you aware that Microsoft are no longer developing the forefront line, TMG included? While this doesn't mean that it's going to suddenly stop working, it does mean that there are going to be no new features and that it isn't supported on the latest operating systems. With all due respect, I would say that it's a mistake to put a new TMG firewall into production now and that you should be looking at another system.

 

I'm in process of learning, so this is not for professional usage. My teacher recommended this program for proxy server. I know TMG is not supported in Windows 2012, but I think majority of companies still use Server 2008, so I guess TMG can be still put into good use. But it is definitely a good way to see how things are working and to improve my knowledge.

 

The tmg was blocking dns traffic so although http and https were allowed there was no way for the clients to get dns info from outside. If you setup dns including dns forwarder info such as 8.8.8.8 on the dc then allow dns traffic for that server you can then point the clients to the internal dns and only allow http and https traffic for the clients. Everything should work then.

 

Ok, I will try your method, but one thing confuses me. If DNS is not set properly, with HTTP/HTTPS rule allowed, clients would still be able to ping 8.8.8.8, but not ping google.com? Or I'm wrong? For example, when I didn't set DNS properly on some other setups, I could browse with ip addresses, but not with names of internet sites.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...