Jump to content

Recommended Posts

Posted (edited)

Would you recommend give Microsoft Forefront Gateway a try?

 

I dont particularlly like e2bn (Protex) service

 

Would prefere just to use one system, at the momment we are using Protex and impero. Thats when impero works, we have some much trouble with that.

 

Would e2bn/LA stop this?

 

 

What would you say?

 

How easy is it to setup?

 

Does this require entering a proxy address into Internet Explorer?

That always causes a lot of problems for us, often staff forget to turn on the proxy when they get back to work.

 

Any information and your thoughts would be good!

Edited by pritchardavid
Posted
TMG is alright, its just a fancy ISA server though and I have not personally used the filtering. Keep it on a physical box though as it seems to have issues when virtualised.
Posted

TMG is a really good and solid firewall that has deep packet inspection that goes beyond the usual so called hardware firewall that open ports myth. It works well as did ISA server 2004, 2006 (prev. versions). Obviously with TMG the URL filtering can also be activated (extra subscription or included in the enterprise pack of EES).

 

I agree that it needs a dedicated box and with it being 64bit now you can addin more RAM. Its available as both appliance or as software you can install on your chosen server HW.

 

Latest addition to URL (this is being developed and re-vamped with every update they have done for TMG) is the enforcement of safe search on search engines, ability to override URL category etc.

 

The support for AD is also there to make the groups of URL categories easier to allocate to different users based on groups etc. I personally think its a good firewall and caching server although its main selling point is the firewall capability. The ability to easily publish Outlook web access, outlook anywhere, sharepoint to external users is brilliant and makes it worth while.

 

The server license only costs about £150 for education customers and there is no need for CALs. CALs are required for the URL subscription but this is only is you use this and the CALS are covered by as i mentioned the enterprise pack on EES.

 

Ash.

Posted

What problems are you finding with protx?

 

I don't see how the LA could _stop_ you putting in additional filtering, although double-bagging your filtering has the odd isssue (block once, unblock twice) it is not totally impractical.

Posted (edited)

@ tom

 

What I mean by stopping is this.

 

With our Internet you HAVE to connect to it with using their proxy, they will only give you unfliltered internert if you have a good filtering system. That way if we done that, we can control what to block/unblock, would prefere one system instead of two. Plus may be faster as its local.

 

 

@ Everyone

 

With the last build of impero, 54 I think it was, its like it got very very restricted, even we have not changed the policies, even typing some thing simple like in google images it blocks it. Cant remember extually what the problems are.

 

Did try redeploying it, but thats made quite a few computers with Impero not installed. Hopefully the new build that as been released is better, problery gonna have to reload the computer with a new windows 7 image. It doesnt like being installed on a windows 7 image through, so I will have to make a startup script to start the impero install when the computer starts the first time after windows installed. Im guessing it doesnt like being installed on a windows 7 image because I think it as drivers, which windows removes during System Preperation before the computer restart to create the image.

Edited by pritchardavid
Posted

If I remember right .54 was beta build. Have you got the default policies turned off and your own created.. Defaults are very restrictive we recommend disabling those and creating your own.

 

Russ

Posted
TMG is a really good and solid firewall that has deep packet inspection that goes beyond the usual so called hardware firewall that open ports myth. It works well as did ISA server 2004, 2006 (prev. versions). Obviously with TMG the URL filtering can also be activated (extra subscription or included in the enterprise pack of EES).

 

I agree that it needs a dedicated box and with it being 64bit now you can addin more RAM. Its available as both appliance or as software you can install on your chosen server HW.

 

Latest addition to URL (this is being developed and re-vamped with every update they have done for TMG) is the enforcement of safe search on search engines, ability to override URL category etc.

 

The support for AD is also there to make the groups of URL categories easier to allocate to different users based on groups etc. I personally think its a good firewall and caching server although its main selling point is the firewall capability. The ability to easily publish Outlook web access, outlook anywhere, sharepoint to external users is brilliant and makes it worth while.

 

The server license only costs about £150 for education customers and there is no need for CALs. CALs are required for the URL subscription but this is only is you use this and the CALS are covered by as i mentioned the enterprise pack on EES.

 

Ash.

 

 

Thats a good price I would say

 

What would we have to get? We have got the forefront suite (Microsoft Forefront Protection Suite Features) & Forefront Unified Application Gateway

Posted
If I remember right .54 was beta build. Have you got the default policies turned off and your own created.. Defaults are very restrictive we recommend disabling those and creating your own.

 

Russ

 

Sorry .54 wasn't a beta build that was me being silly at 10:30 at night :).

 

Also I should say that there are plans to change the way that the default policies work.

 

Russ

Posted
If anyone can give me some advice/help to correctly setup my routing tables for TMG so I do not keep getting spoofing messages I would greatly appreciate a PM :) I have read up about it but nothing I do seems to make any difference.
Posted
Thats a good price I would say

 

What would we have to get? We have got the forefront suite (Microsoft Forefront Protection Suite Features) & Forefront Unified Application Gateway

 

Hi,

 

The forefront protection suite will give you access to the URL filtering as well as the MS antivirus for various products such as exchange servers, sharepoint servers and normal desktops and servers. The unified application gateway is the SSL VPN offering from microsoft and should tie in nicely with TMG 2010. I think you will still need to buy the server copy (£150 ) for TMG 2010 the URL filtering will be covered by the forefront suite i believe.

 

Ash.

Posted
If anyone can give me some advice/help to correctly setup my routing tables for TMG so I do not keep getting spoofing messages I would greatly appreciate a PM :) I have read up about it but nothing I do seems to make any difference.

 

Hi,

 

Can you provide some info on your setup i.e. what your internal IP assigned to TMG and external or are you using it as a proxy server with one NIC?

 

Ash.

  • Thanks 1
Posted
Keep it on a physical box though as it seems to have issues when virtualised.

 

Hi SYNACK,

 

I was wondering what problems you have with TMG on a VM ? we have 2 overhere so i might learn something here :)

 

bio..

Posted
Hi SYNACK,

 

I was wondering what problems you have with TMG on a VM ? we have 2 overhere so i might learn something here :)

 

bio..

 

Not 100% sure that it is to do with the VM environment or a conflict with SEP, the issue that I am having under Hyper-V SP1 is that over time it looses its console connection for mouse clicks and every so often it starts dropping outbound packets for 30 seconds or so. Really weird and I will be reinstalling it from scratch to isolate it out. The BPA also flags using it in a VM as a warning event that it may not provide as much protection as it could do.

 

Usage wise appart from the little chop outs it is much better than the last solution and some of the new features like the safe search enforcer are quite good especially considering the rather rudementry filtering upstream.

Posted

You say you have Hyper-V working with TMG installed on to an image?

 

We have just purchased TMG and awaiting for it to turn up (Frog VLE Installation) and I did try and get it working on an image but strangely enough it caused a Loop on our network...

I since then have not tried to get it working. How did you get it working?

Posted
You say you have Hyper-V working with TMG installed on to an image?

 

We have just purchased TMG and awaiting for it to turn up (Frog VLE Installation) and I did try and get it working on an image but strangely enough it caused a Loop on our network...

I since then have not tried to get it working. How did you get it working?

 

Image? It is installed on a VHD and run as a Hyper-V VM, I did nothing special to get it going, just installed a fresh copy of 2k8r2 SP1 Enterprise on the VM, joined it to the domain and installed TMG. My initial setup was a little convaluded as I had to wait for an managed ISP to get off their collective sitting appendages and actually make the changes required but other than that getting it running was just a matter of installing it. Installing its updates does make it better though and adds a few features.

Posted

Did you have to create the network bridge on the VM? (Sorry far too used to saying images).

 

That is where I struggled, EIS have told me it needs to be setup as a network bridge.

Posted

Ffffff, Just looked this up propperly and it looks like there is a fix for the console glitch:

Hyper-V Update to Improve Network Stability - Forefront TMG (ISA Server) Product Team Blog - Site Home - TechNet Blogs

The network connection of a running Hyper-V virtual machine is lost under heavy outgoing network traffic on a Windows Server 2008 R2-based computer

 

So thats one down, just need to see if it is SEP causing the minor drops now. Sorry to the OP for derailing the thread.

Posted (edited)
Did you have to create the network bridge on the VM? (Sorry far too used to saying images).

 

That is where I struggled, EIS have told me it needs to be setup as a network bridge.

 

EIS?

 

That may be implementation specific, I have it setup as a gateway firewall/Cache/router that isolates the internal network from the external internet and makes sure we don't waste any of our limited and expencive bandwidth on things we don't need to.

 

If it is set up as a bridge with no routing then this could be causing some of the issues, I do question the idea of bridged traffic for a WAN though as it effectivly means spewing all your internal broadcast and possibly multicast traffic over your WAN link saturating it unnessisarily.

 

The way I have it set up is (for simplicity) a couple of physical NICs in the Hyper-V host, Each of these is assigned to its own Network in hyper-v manager and then there are two virtual adapters on the VM, one connected to each network. Then the internet router is physicly connected to one of the ports (which only goes to ISA) and the other is connected to the internal network.

 

This looks interesting: http://technet.microsoft.com/en-us/edge/Video/ff710552

Edited by SYNACK
Posted

Sorry EIS are our service provider.

 

Our TMG box is for linking through our service provider (Frog VLE onsite server) to access it all externally in replace for our current website (currently hosted by EIS).

I was told it just needed to be setup as a network bridge, not so sure about creating that when you need two network adapters on a virtual box. When I created two, thats when it seems to cause me issues and the moment I got it working was the moment a loop back occured.

Posted
Sounds like both adapters are on the same network, they need to be on seporate networks if you are running it as a gateway. It needs to sit between your internal network and your ISP. You can install it with a single adapter and just have it filtering and proxying stuff but you loose most of its compelling security features.
  • Thanks 1
Posted
Sounds like both adapters are on the same network, they need to be on seporate networks if you are running it as a gateway. It needs to sit between your internal network and your ISP. You can install it with a single adapter and just have it filtering and proxying stuff but you loose most of its compelling security features.

 

There we go that's it, I did actually create the network bridge before I even got the software and had both adapters on my network. Network bridges is some thing I have had little experience with and it sounds like that was the problem.

 

Thanks :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...