ful56_uk Posted February 18, 2010 Posted February 18, 2010 Hi I have been trying to setup a edge firewall using tmg. When I try to publish a site the tmg box can resolove the dns name. The tmg box can ping internal servers. What haven't I done? Thanks mark
SYNACK Posted February 18, 2010 Posted February 18, 2010 Assuming you mean that it can't resolve internal servers I would be looking at the DNS settings for the firewalls NICs, is it set to the internal DNS server. If your internal DNS is setup correctly with the external DNS servers set as fowarders then the internal DNS will do both internal and external. 1
ful56_uk Posted February 18, 2010 Author Posted February 18, 2010 ill checked that my lan card and that has the dns setting of my internal dns servers. TMG is a memeber of the domain as well. On the lan card I have no dns settings set.
EduTech Posted February 18, 2010 Posted February 18, 2010 On your Internal Nic Have you made sure that you have an IP Address / Subnet Mask / DNS Servers ? Have you tried performing an nslookup from the TMG Server? and do you have a rule to allow traffic from all traffic internally James. 1
bio Posted February 18, 2010 Posted February 18, 2010 TMG is a member of the domain as well. I would never do this.. The edge FW should never be a member of the domain. I would recommend a back to back TMG solution. The internal server should be a mmeber of the domain. regards bio.. 1
FN-GM Posted February 18, 2010 Posted February 18, 2010 Just to check something Your internal Nic has no default gateway set? and your external does? Does your webserver default gateway point to your TMG server? If it isn't set it up to that and it should be ok. I would never do this.. The edge FW should never be a member of the domain. I would recommend a back to back TMG solution. The internal server should be a mmeber of the domain. I agree with this. Also your Web servers ideally shouldn't be in the same network as your clients. 1
ful56_uk Posted February 19, 2010 Author Posted February 19, 2010 do i have to setup a network for internal to external as nat or route. as my owa rule keeps begin denied, i can ping the local mail server. i also cant access the net on the tmg server i can ping the gateway. i have made sure my lan has the dns and no gw and my wan has no dns and a gw set.
FN-GM Posted February 19, 2010 Posted February 19, 2010 On your external you will need a DG and dns 1
ful56_uk Posted February 19, 2010 Author Posted February 19, 2010 (edited) On your external you will need a DG and dns as well as the lan connection? no dg gateway on the lan? Edited February 19, 2010 by ful56_uk
SYNACK Posted February 19, 2010 Posted February 19, 2010 (edited) as well as the lan connection? no dg gateway on the lan? No DG on the LAN interface otherwise it will get confused add DNS though Edited February 19, 2010 by SYNACK
EduTech Posted February 19, 2010 Posted February 19, 2010 As Synack Said, The Internal NIC only needs to have IP, Subnet Mask and you DNS Servers the gateway is left as blanc and your clients would use the TMG Server as there gateway so your clients/servers would have a gateway of your Internal NIC IP Address. On your external NIC you would put in IP, Subnet, Gateway and LEA DNS Servers. If you use an UpStream Proxy, You would create a Web Chaining Rule to forward all requests to an upstream proxy. ---- Make Sure when you configure TMG, you had the internal NIC as your Internal Network ---- Create your rules accordingly, Normally they woud be setup with the server info obviously... Forward Host Header majority of the time and also requests appear to be coming from client rather than TMG Server. ---- Thats roughly how ours is configured anyway, published services are SharePoint, OWA and Talmos via https listener with WildCard SSL / NTLM Forms Based Authentication and Website, 6th Form Website Published via http Listener with No Auth. James.
ful56_uk Posted February 19, 2010 Author Posted February 19, 2010 Cheers thanks. So do I need to create a network rule for nat or route for external to internal?
EduTech Posted February 19, 2010 Posted February 19, 2010 Cheers thanks. So do I need to create a network rule for nat or route for external to internal? You should not have to create a rule for that, but than again your network is going to be setup differently.. what is it your trying to do? just publish a site? James.
ful56_uk Posted February 19, 2010 Author Posted February 19, 2010 Trying to publish owa logs say access denied. I have my web listener setup right and is listerning on the external network. In the log it is say external host to local host is the denied error.
EduTech Posted February 19, 2010 Posted February 19, 2010 Trying to publish owa logs say access denied. I have my web listener setup right and is listerning on the external network. In the log it is say external host to local host is the denied error. How have you setup the published rule? James.
ful56_uk Posted February 19, 2010 Author Posted February 19, 2010 Yep copyed the setup from my ISA 06 box which works fine
EduTech Posted February 19, 2010 Posted February 19, 2010 Yep copyed the setup from my ISA 06 box which works fine Hmm, and i am guessing that the other config from ISA you have also transfered? *dont mean to keep asking questions, just trying to get a picture... ISA was a pain at the best of times*
ful56_uk Posted February 19, 2010 Author Posted February 19, 2010 i didnt import it i have them running side by side to get the config but the isa has no nics in it as there disabled and tmg is live so i can test rules out. it doesnt make any sense to me why this dont work my lan nic is wan 10.35.248.2 10.35.251.3 255.255.252.0 255.255.252.0 no G/W 10.35.248.1 dns 10.35.248.31 (both internal dns) no dns 10.35.248.32 that is how it was setup with isa 2006 our ips county counicl have nat and forwards to wan for for our web sites so isa 06 had web listners listening on that 10.35.251.3 for our sharepoint, owa etc... which worked fine
EduTech Posted February 19, 2010 Posted February 19, 2010 That's where my setup is slightly different, our LEA is on a 172.18.180.xxx address where as internally i have 10.0.8.xxx Address. As you have near enough the same ip for internal and wan then what i would say is check that on your internal network it has not added your wan ip address's to that range. The Internal Network may have put that range in there, which might be where it is getting confused, just check what range's it has allocated for your internal network.
ful56_uk Posted February 19, 2010 Author Posted February 19, 2010 All sorted thanks James and everyone else. It was a problem with making sure the windows firewall was off and the firewall service that kept stopping also me getting the right info in the right nics does help.
EduTech Posted February 19, 2010 Posted February 19, 2010 All sorted thanks James and everyone else. It was a problem with making sure the windows firewall was off and the firewall service that kept stopping also me getting the right info in the right nics does help. Glad to hear it, Appoligies about all the questions like i say ISA/TMG can be a pain to diagnose sometimes... just good to try and get a clear picture of what is going on. James.
ful56_uk Posted February 25, 2010 Author Posted February 25, 2010 Hi do you know if clients need to use the client firewall in order for the url filtering to work? I have added a new nic on the server for the guess wireless system and want to put url filtering on that.
Modey Posted March 2, 2010 Posted March 2, 2010 I would never do this.. The edge FW should never be a member of the domain. I would recommend a back to back TMG solution. The internal server should be a mmeber of the domain. regards bio.. Debunking the Myth that the ISA Firewall Should Not be a Domain Member For the last two years I’ve been trying to communicate to ISA firewall admins that a domain member machine is more secure and more flexible than a non-domain member machine and that they do themselves and their companies a disservice by not joining the ISA firewall to the domain. This is a significant issue and not something to be taken lightly because there is a serious security hit you take when you don’t join the ISA firewall to the domain.
Modey Posted March 2, 2010 Posted March 2, 2010 Hi do you know if clients need to use the client firewall in order for the url filtering to work? I have added a new nic on the server for the guess wireless system and want to put url filtering on that. No they don't need the client firewall in order for the url filtering to work.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now