Jump to content

Recommended Posts

Posted

Hello,

 

I have recently been asked to setup an MPLS link to our internal network. To this end, on our core switch, HP E5412zl, I have created a VLAN 20, assigned a static IP to it, and then added a port to the VLAN. This port plugs into the interface of MPLS switch. Additionally, I have added the relevant static routes to the HP switch knows how to reach our other MPLS subnets.

 

So far, from the HP switch, I can successfully ping our other MPLS subnets including the interface of our MPLS switch.

 

Here's the problem.

 

We have Microsoft Threat Management Gateway (TMG) 2010 server configured as our default and internet gateway server for all devices. Meanwhile, all our PCs and Servers are on VLAN 10. So, when I tried to see if I can ping our other subnets from a PC, I noticed that the packets were being routed to the TMG server instead of the MPLS interface. To this end, I have configured the same static route on the TMG server as I have on the HP switch, however I have used the IP address that I assigned to the VLAN 20, as its next-hop address. Additionally, I have added the IP range (containing the IP addresses assigned to the VLAN and MPLS switch) to the Internal IP address on the TMG (Under Networking). So in theory, TMG should route any traffic destined for the MPLS network to the MPLS interface on the HP switch. However, I am still unable to even ping the MPLS interface on the HP switch from the TMG server.

 

So, as a test, I changed the default gateway on a PC to the IP address of VLAN 1 interface and hooray I could ping the MPLS interfaces on the HP and MPLS switches, including our MPLS subnets. However, this isn't a practical solution for us, as it would have to done network-wide.

 

Therefore, I was just wondering if anyone can help with configuration on the TMG server; in case I have missed anything.

 

Any help would be appreciated.

 

Thank you in anticipation.

Posted

I would say...TMG ... surely that’s dead and gone and not supported...but actually we still keep ours in place in case smoothwall stops...it doesn’t carryany traffic, but it could if required...

I’ve read the description...which is probably clear to someone understands routing...but I’m afraid I couldn’t understand your issues...but I know my weakness is forgetting to include a return path for packets....

Posted

Hi AlanD,

 

Agree, TMG is old technology now. Thankfully, we have a Smoothwall box on-standy that would replace the TMG over the Christmas break.

 

With regards the issue I was having, TMG wasn't routing my traffic correctly even though I had specified the static routes and included the IP range for the new VLAN within its Internal network properties.

 

Reading through the TechNet forums earlier on, I found out that the supported configuration for routing VLANs through the TMG is for the clients to use the ip address of their respective VLANs as their default gateway address. This would explain the reason my test PC worked when I changed its default gateway address to VLAN 1's ip address.

 

For now, we will do that until we decommission the TMG in a few weeks time.

 

Thanks.

Posted

...interesting to hear of another - possibly like minded - who has decided to use smoothwall after TMG.....allows us to run a radius server...DNS...DHCP...tightly integrated for BYOD...

 

I miss the SSO capability that TMG offered...but everything else seems pretty much covered...although I had thought MS were on a winner with TMG....

 

Sophos UTM would have given us the SSO - but "prevent" reporting seemed much better on smoothwall...and ready to go out of the box.

 

..I do complain about Smoothwall with mobile devices though....think they should put some effort into making this much better....because its not enough to simply tick the box to allow social media for example- you will then find you also need to do a load of stuff to make it work with APPs - even though it works fine for desktops.

Posted

IMHO TMG was axed because it allowed on-prem services to be secured at almost zero cost, and Microsoft wanted to sell cloud services.

 

Also they needed the networking talent in the organisation to be working on the network security and capability of the Azure platform.

 

As to the original post, TMG is a packet filter/layer 567(ish) application gateway, and not really a router. Set things up to let the router route, and the filter filter.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...