Jump to content

Recommended Posts

Posted

Hi

 

I have been trying to setup a edge firewall using tmg. When I try to publish a site the tmg box can resolove the dns name. The tmg box can

ping internal servers.

 

What haven't I done?

 

Thanks

 

mark

Posted
Assuming you mean that it can't resolve internal servers I would be looking at the DNS settings for the firewalls NICs, is it set to the internal DNS server. If your internal DNS is setup correctly with the external DNS servers set as fowarders then the internal DNS will do both internal and external.
  • Thanks 1
Posted
ill checked that my lan card and that has the dns setting of my internal dns servers. TMG is a memeber of the domain as well. On the lan card I have no dns settings set.
Posted

On your Internal Nic Have you made sure that you have an IP Address / Subnet Mask / DNS Servers ?

 

Have you tried performing an nslookup from the TMG Server? and do you have a rule to allow traffic from all traffic internally :)

 

James.

  • Thanks 1
Posted
TMG is a member of the domain as well.

 

I would never do this.. The edge FW should never be a member of the domain. I would recommend a back to back TMG solution. The internal server should be a mmeber of the domain.

 

regards

bio..

  • Thanks 1
Posted

Just to check something

 

Your internal Nic has no default gateway set? and your external does?

 

Does your webserver default gateway point to your TMG server?

 

If it isn't set it up to that and it should be ok.

 

I would never do this.. The edge FW should never be a member of the domain. I would recommend a back to back TMG solution. The internal server should be a mmeber of the domain.

 

I agree with this. Also your Web servers ideally shouldn't be in the same network as your clients.

  • Thanks 1
Posted
do i have to setup a network for internal to external as nat or route. as my owa rule keeps begin denied, i can ping the local mail server. i also cant access the net on the tmg server i can ping the gateway. i have made sure my lan has the dns and no gw and my wan has no dns and a gw set.
Posted (edited)
On your external you will need a DG and dns

 

as well as the lan connection? no dg gateway on the lan?

Edited by ful56_uk
Posted (edited)
as well as the lan connection? no dg gateway on the lan?

 

No DG on the LAN interface otherwise it will get confused add DNS though

Edited by SYNACK
Posted

As Synack Said, The Internal NIC only needs to have IP, Subnet Mask and you DNS Servers the gateway is left as blanc and your clients would use the TMG Server as there gateway so your clients/servers would have a gateway of your Internal NIC IP Address.

 

On your external NIC you would put in IP, Subnet, Gateway and LEA DNS Servers.

 

If you use an UpStream Proxy, You would create a Web Chaining Rule to forward all requests to an upstream proxy.

 

----

 

Make Sure when you configure TMG, you had the internal NIC as your Internal Network

 

----

 

Create your rules accordingly, Normally they woud be setup with the server info obviously... Forward Host Header majority of the time and also requests appear to be coming from client rather than TMG Server.

 

----

 

Thats roughly how ours is configured anyway, published services are SharePoint, OWA and Talmos via https listener with WildCard SSL / NTLM Forms Based Authentication and Website, 6th Form Website Published via http Listener with No Auth.

 

James.

Posted
Cheers thanks. So do I need to create a network rule for nat or route for external to internal?

 

You should not have to create a rule for that, but than again your network is going to be setup differently.. what is it your trying to do? just publish a site?

 

James.

Posted
Trying to publish owa logs say access denied. I have my web listener setup right and is listerning on the external network. In the log it is say external host to local host is the denied error.
Posted
Trying to publish owa logs say access denied. I have my web listener setup right and is listerning on the external network. In the log it is say external host to local host is the denied error.

 

How have you setup the published rule?

 

James.

Posted
Yep copyed the setup from my ISA 06 box which works fine

 

Hmm, and i am guessing that the other config from ISA you have also transfered?

 

*dont mean to keep asking questions, just trying to get a picture... ISA was a pain at the best of times*

Posted

i didnt import it i have them running side by side to get the config but the isa has no nics in it as there disabled and tmg is live so i can test rules out.

 

it doesnt make any sense to me why this dont work

 

my lan nic is wan

 

10.35.248.2 10.35.251.3

255.255.252.0 255.255.252.0

no G/W 10.35.248.1

 

dns

10.35.248.31 (both internal dns) no dns

10.35.248.32

 

that is how it was setup with isa 2006 our ips county counicl have nat and forwards to wan for for our web sites so isa 06 had web listners listening on that 10.35.251.3 for our sharepoint, owa etc... which worked fine

Posted

That's where my setup is slightly different, our LEA is on a 172.18.180.xxx address where as internally i have 10.0.8.xxx Address.

 

As you have near enough the same ip for internal and wan then what i would say is check that on your internal network it has not added your wan ip address's to that range.

 

The Internal Network may have put that range in there, which might be where it is getting confused, just check what range's it has allocated for your internal network.

Posted
All sorted thanks James and everyone else. It was a problem with making sure the windows firewall was off and the firewall service that kept stopping also me getting the right info in the right nics does help.
Posted
All sorted thanks James and everyone else. It was a problem with making sure the windows firewall was off and the firewall service that kept stopping also me getting the right info in the right nics does help.

 

Glad to hear it, Appoligies about all the questions like i say ISA/TMG can be a pain to diagnose sometimes... just good to try and get a clear picture of what is going on. ;)

 

James.

Posted

Hi

 

do you know if clients need to use the client firewall in order for the url filtering to work?

 

I have added a new nic on the server for the guess wireless system and want to put url filtering on that.

Posted
I would never do this.. The edge FW should never be a member of the domain. I would recommend a back to back TMG solution. The internal server should be a mmeber of the domain.

 

regards

bio..

 

Debunking the Myth that the ISA Firewall Should Not be a Domain Member

 

For the last two years I’ve been trying to communicate to ISA firewall admins that a domain member machine is more secure and more flexible than a non-domain member machine and that they do themselves and their companies a disservice by not joining the ISA firewall to the domain. This is a significant issue and not something to be taken lightly because there is a serious security hit you take when you don’t join the ISA firewall to the domain.
Posted
Hi

 

do you know if clients need to use the client firewall in order for the url filtering to work?

 

I have added a new nic on the server for the guess wireless system and want to put url filtering on that.

 

No they don't need the client firewall in order for the url filtering to work.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...