<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SharePoint George &#187; TMG</title>
	<atom:link href="http://sharepointgeorge.com/category/forefront/tmg/feed/" rel="self" type="application/rss+xml" />
	<link>http://sharepointgeorge.com</link>
	<description>Everyday experiences on SharePoint, Exchange and most things Microsoft</description>
	<lastBuildDate>Tue, 20 Dec 2011 23:01:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010</title>
		<link>http://sharepointgeorge.com/2010/publish-remote-desktop-web-access-gateway-forefront-tmg-2010/</link>
		<comments>http://sharepointgeorge.com/2010/publish-remote-desktop-web-access-gateway-forefront-tmg-2010/#comments</comments>
		<pubDate>Thu, 22 Apr 2010 12:30:37 +0000</pubDate>
		<dc:creator>George Khalil</dc:creator>
				<category><![CDATA[Forefront]]></category>
		<category><![CDATA[TMG]]></category>

		<guid isPermaLink="false">http://sharepointgeorge.com/?p=1515</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style" addthis:url='http://sharepointgeorge.com/2010/publish-remote-desktop-web-access-gateway-forefront-tmg-2010/' addthis:title='Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010 ' ><a class="addthis_button_google_plusone" g:plusone:size="medium" ></a><a class="addthis_counter addthis_pill_style"></a></div>Today I continue my series of articles on Microsoft’s latest Forefront Threat Management Gateway (TMG) and will focus our efforts in publishing Windows 2008 R2 Remote Desktop Web Access (RD Web) and Remote Desktop Gateway (RD Gateway) or previously referred to as Terminal Server Web Access (TS Web) and Terminal Server Gateway (TS Gateway).<div class="addthis_toolbox addthis_default_style " addthis:url='http://sharepointgeorge.com/2010/publish-remote-desktop-web-access-gateway-forefront-tmg-2010/' addthis:title='Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010 ' ><a href="//addthis.com/bookmark.php?v=250&#38;username=xa-4d2b47597ad291fb" class="addthis_button_compact">Share</a><span class="addthis_separator">&#124;</span><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style" addthis:url='http://sharepointgeorge.com/2010/publish-remote-desktop-web-access-gateway-forefront-tmg-2010/' addthis:title='Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010 ' ><a class="addthis_button_google_plusone" g:plusone:size="medium" ></a><a class="addthis_counter addthis_pill_style"></a></div><p><strong> </strong></p>
<p>Today I will continue my series of articles on Microsoft’s latest Forefront Threat Management Gateway (TMG) and will focus our efforts in publishing Windows 2008 R2 Remote Desktop Web Access (RD Web) and Remote Desktop Gateway (RD Gateway) to the world wide web via TMG.  If you missed my first article on installing Forefront TMG, you can access it <a href="http://sharepointgeorge.com/2010/installing-forefront-threat-management-gateway-2010/" target="_blank">here</a>.</p>
<p>This article is assuming that your Remote Desktop Services infrastructure is already in place and that your RD Gateway and RD Web Access are on the same server.   Refer to my <a href="http://sharepointgeorge.com/2009/remote-desktop-services-windows-2008-r2-part-1/" target="_blank">3 part series</a> on Remote Desktop Services in Windows 2008 R2 which outlines the configuration of RD Host, RD Gateway and RD Web Access.</p>
<p>So let’s begin!</p>
<p><strong>Export Certificate</strong></p>
<p>We are assuming a trusted 3rd party certificate has already been issued  for the Remote Desktop Services infrastructure.  From your RD Web Access/Gateway server where the certificate is installed, launch IIS Manager and navigate to Server Certificates.  Select the certificate in question and from the Actions navigation pane, select Export…</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image310.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image3_thumb.png" border="0" alt="image3 thumb Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="660" height="236" /></a></p>
<p>Specify the location and enter a password to protect the exportation of the certificate.</p>
<p><strong>Import Certificate<br />
</strong></p>
<p>We now need to take the exported certificate and import it directly into our personal certificate store located on the TMG server.</p>
<p>On the TMG server, launch the Microsoft Management Console (MMC) / Select File / Add or Remove Snap-ins / select Certificates from available snap-ins and select Add &gt;</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image47.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image_thumb27.png" border="0" alt="image thumb27 Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="660" height="283" /></a></p>
<p>Select Computer account / Next.</p>
<p>Select Local computer / Finish.  Then click OK.</p>
<p>Right click on Personal Folder under Certificates and select All Tasks / Import…</p>
<p>This will invoke the Certificate Import Wizard. Click Next.</p>
<p>Browse for the certificate that we exported earlier on.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image61.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image6_thumb.png" border="0" alt="image6 thumb Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="499" height="324" /></a></p>
<p>Click Next</p>
<p>Enter the certificate password.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image91.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image9_thumb.png" border="0" alt="image9 thumb Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="476" height="331" /></a></p>
<p>Click Next.</p>
<p>Ensure that the “Personal” Certificate store is selected to import into.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image121.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image12_thumb.png" border="0" alt="image12 thumb Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="511" height="295" /></a></p>
<p>Click Next and Finish.</p>
<p>To confirm that the certificate was successfully imported, browse to Certificates / Personal / Certificate and double click on the imported certificate.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image151.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image15_thumb.png" border="0" alt="image15 thumb Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="404" height="398" /></a></p>
<p>It’s important that the certificate states that a private key that corresponds to this certificate is present, otherwise it will not be visible in TMG when applying it against our Web Listener.</p>
<p>I would also navigate to the Certification Path tab for the certificate to also ensure that the Certificate status is OK, i.e. there isn’t a “break” in the certificate path and that all certificates in the chain are present.</p>
<p><strong>Create Web Listener</strong></p>
<p>Launch the TMG Management Console and click on Firewall Policy</p>
<p>Navigate to Toolbox / Network Objects and select New, Web Listener.  This will invoke the New Web Listener Wizard.</p>
<p>Enter a friendly name.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image211.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image21_thumb.png" border="0" alt="image21 thumb Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="475" height="349" /></a></p>
<p>Click Next.</p>
<p>Ensure that &#8220;Require SSL secured connections with clients&#8221; is selected.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image241.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image24_thumb.png" border="0" alt="image24 thumb Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="492" height="360" /></a></p>
<p>Click Next</p>
<p>For your Web Listener IP address, select Internal and then click on Select IP Addresses.</p>
<p>You will need to specify a unique IP address for each Web Listener/Certificate that you setup on your TMG server.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image271.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image27_thumb.png" border="0" alt="image27 thumb Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="511" height="379" /></a></p>
<p>Click Next</p>
<p>In the next window you will assign the recently imported certificate from your RD Web Access/Gateway server against the IP address that we added in the previous window.</p>
<p>Click on Select Certificate and click on the respective certificate that will be applied against your RD Web Access/Gateway Web Listener. Click on “Select” once done.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image301.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image30_thumb.png" border="0" alt="image30 thumb Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="515" height="392" /></a></p>
<p>Click Next.</p>
<p>Select “No Authentication” from the drop down menu.  This is important as we will not be utilising TMG’s Forms Based Authentication.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image331.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image33_thumb.png" border="0" alt="image33 thumb Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="472" height="354" /></a></p>
<p>Click next.</p>
<p>The next screen will state that SSO is only available with HTML form Authentication.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image361.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image36_thumb.png" border="0" alt="image36 thumb Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="506" height="226" /></a></p>
<p>Click Next.</p>
<p>Click Finish to complete the New Web Listener Wizard.</p>
<p>Finally, click Apply to save the changes.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image391.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image39_thumb.png" border="0" alt="image39 thumb Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="527" height="121" /></a></p>
<p><strong>TMG Web Publishing Rule</strong></p>
<p>We can now proceed and create our RD Web Access/Gateway rule by right clicking on Firewall Policy / New / Exchange Web Client Access Publishing Rule… Specify a name for your rule;</p>
<p><em>Now you might be wondering why I have specifically selected the Exchange Publishing Rule as opposed to a generic Web Publishing rule.  Firstly, I am still not sure why Microsoft have not created a specific template for Remote Desktop Services and secondly if you select the Generic Web Site Publishing Rule, you will receive the below warning when you come to test your rule later.</em></p>
<p><em>Category: General warning</em></p>
<p><em>Error details: The internal path of the URL was identified as part of a SharePoint or Exchange server publishing rule.</em></p>
<p><em>Action: Use the SharePoint Publishing Rule Wizard or the Exchange Publishing Rule Wizard.</em></p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image48.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image_thumb28.png" border="0" alt="image thumb28 Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="512" height="346" /></a></p>
<p>Click Next</p>
<p>Select “Exchange Server 2007” and only select the Outlook Anywhere option.  Leave “Publish additional folders on the Exchange Server for Outlook 2007 clients” unchecked</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image49.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image_thumb29.png" border="0" alt="image thumb29 Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="514" height="346" /></a></p>
<p>Click Next</p>
<p>Select Publish a single Web site or load balancer.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image50.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image_thumb30.png" border="0" alt="image thumb30 Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="515" height="353" /></a></p>
<p>Click Next.  Select Use SSL to connect to the published Web server or server farm.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image51.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image51_thumb.png" border="0" alt="image51 thumb Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="511" height="387" /></a></p>
<p>Click Next.  Specify the Internal site name.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image54.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image54_thumb.png" border="0" alt="image54 thumb Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="503" height="431" /></a></p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image57.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image57_thumb.png" border="0" alt="image57 thumb Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="509" height="339" /></a></p>
<p>Click Next.</p>
<p>Specify the Public FQDN which should be externally resolvable.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image52.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image_thumb31.png" border="0" alt="image thumb31 Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="512" height="265" /></a></p>
<p>Click Next.  Select the Web listener that we created earlier.  Click Next</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image66.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image66_thumb.png" border="0" alt="image66 thumb Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="512" height="337" /></a></p>
<p>Select “No delegation, but client may authenticate directly” from the Authentication Delegation drop down.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image69.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image69_thumb.png" border="0" alt="image69 thumb Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="505" height="287" /></a></p>
<p>Click Next.</p>
<p>Remove All Authenticated Users and Add All Users.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image72.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image72_thumb.png" border="0" alt="image72 thumb Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="506" height="291" /></a></p>
<p>Click Finish to complete…</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image53.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image_thumb32.png" border="0" alt="image thumb32 Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="516" height="487" /></a></p>
<p>There is only one more step and we are done.  Because there is no dedicated publishing rule template for RD Web Access/Gateway we need to add a couple of entries to the Paths area under RD Web Access/Gateway rule.</p>
<p>Right click on your designated rule and select properties, and navigate to the Paths tab.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image78.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image78_thumb.png" border="0" alt="image78 thumb Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="412" height="433" /></a></p>
<p>Click Add..</p>
<p>Enter /rdweb/* as the path.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image81.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image81_thumb.png" border="0" alt="image81 thumb Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="381" height="288" /></a></p>
<p>Now because we selected the Exchange Server 2007 publishing wizard and in particular the Outlook Anywhere service, the RPC path mapping should already be included under paths.  Do NOT remove this path.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image84.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image84_thumb.png" border="0" alt="image84 thumb Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010" width="385" height="291" /></a></p>
<p>Finally, remove /* if it exists.</p>
<p>Make sure you click on Test Rule which should provide you with a green tick beside each path entry!</p>
<p>That’s all that is to it.  In upcoming posts in this series, I will go through publishing other items such as Outlook Web App and SharePoint sites.</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://sharepointgeorge.com/2010/publish-remote-desktop-web-access-gateway-forefront-tmg-2010/' addthis:title='Publish Remote Desktop Web Access and Gateway with Forefront TMG 2010 ' ><a href="http://sharepointgeorge.com//addthis.com/bookmark.php?v=250&amp;username=xa-4d2b47597ad291fb" class="addthis_button_compact">Share</a><span class="addthis_separator">|</span><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a></div>]]></content:encoded>
			<wfw:commentRss>http://js-kit.com/rss/sharepointgeorge.com/p=1515</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Installing Forefront Threat Management Gateway 2010</title>
		<link>http://sharepointgeorge.com/2010/installing-forefront-threat-management-gateway-2010/</link>
		<comments>http://sharepointgeorge.com/2010/installing-forefront-threat-management-gateway-2010/#comments</comments>
		<pubDate>Tue, 13 Apr 2010 13:00:58 +0000</pubDate>
		<dc:creator>George Khalil</dc:creator>
				<category><![CDATA[Forefront]]></category>
		<category><![CDATA[TMG]]></category>

		<guid isPermaLink="false">http://sharepointgeorge.com/?p=1401</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style" addthis:url='http://sharepointgeorge.com/2010/installing-forefront-threat-management-gateway-2010/' addthis:title='Installing Forefront Threat Management Gateway 2010 ' ><a class="addthis_button_google_plusone" g:plusone:size="medium" ></a><a class="addthis_counter addthis_pill_style"></a></div>Forefront Threat Management Gateway 2010, or commonly referred to as TMG 2010, is the long awaited latest and greatest release of Microsoft’s Internet Security and Acceleration (ISA) server in which we have all come to love or hate over the years.   TMG builds on ISA’s ability to deliver a comprehensive application layer reverse proxy firewall and is usually deployed on the edge of your network or in between an existing edge such as a firewall provided by Cisco or Checkpoint. <div class="addthis_toolbox addthis_default_style " addthis:url='http://sharepointgeorge.com/2010/installing-forefront-threat-management-gateway-2010/' addthis:title='Installing Forefront Threat Management Gateway 2010 ' ><a href="//addthis.com/bookmark.php?v=250&#38;username=xa-4d2b47597ad291fb" class="addthis_button_compact">Share</a><span class="addthis_separator">&#124;</span><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style" addthis:url='http://sharepointgeorge.com/2010/installing-forefront-threat-management-gateway-2010/' addthis:title='Installing Forefront Threat Management Gateway 2010 ' ><a class="addthis_button_google_plusone" g:plusone:size="medium" ></a><a class="addthis_counter addthis_pill_style"></a></div><p>Forefront Threat Management Gateway 2010, or commonly referred to as TMG 2010, is the long awaited latest and greatest release of Microsoft’s Internet Security and Acceleration (ISA) server in which we have all come to love or hate over the years.   TMG builds on ISA’s ability to deliver a comprehensive application layer reverse proxy firewall and is usually deployed on the edge of your network or in between an existing edge such as a firewall provided by Cisco or Checkpoint.  Today, I will begin a series of articles on installing and configuring Forefront TMG 2010, discuss some of the new features that have been integrated into this release before providing a step by step guide in securely publishing web sites such as Outlook Web App (OWA) or internal SharePoint  web sites.</p>
<p>Let’s begin by outlining some of the key new features that TMG introduces over ISA.</p>
<ul>
<li><strong>URL Filtering:</strong> TMG now integrates a comprehensive web filtering subscription services that is tightly integrated into the TMG management console.  Organizations can creates rules to block or allow web sites based on category such pornography, violence, shopping etc.  This was usually only possible by using 3rd party services such as Websense/Surfcontrol or Symantec and usually required additional hardware requirements and extra servers on top of your ISA implementation.</li>
<li> <strong>Web anti-malware: </strong>Another subscription based service that provides protection over web sites/pages that may contain malware and viruses.</li>
<li> <strong>Email protection: </strong>Yup, you guessed it.. Another protection subscription service that utilises Forefront Protection for your Exchange servers and scans emails for viruses and spam content before they are delivered to your Exchange mailboxes.</li>
<li><strong>Network Inspection System: </strong>Commonly referred to as NIS, this out of the box feature scans traffic for any exploits based on any outstanding Microsoft Vulnerabilities.</li>
<li><strong>Other features: </strong>These include the long awaited 64 bit and Windows 2008 support for greater scalability, Enhanced NAT for 1-1 publishing, and Enhanced VOIP capabilities that should make for simpler voice deployments.</li>
</ul>
<p>Now that we have been introduced to some of the notable features within TMG, let’s begin the installation and initial configuration, but before doing so, ensure that you have met the minimum system requirements which are listed in the following TechNet article ;</p>
<p><a title="http://technet.microsoft.com/en-au/library/dd896981.aspx" href="http://technet.microsoft.com/en-au/library/dd896981.aspx">http://technet.microsoft.com/en-au/library/dd896981.aspx</a></p>
<p>After ensuring the minimum requirements are met, launch the autorun.hta and on the main setup splash page, begin by running the preparation tool.  Because my machine is joined to the network and is running WSUS, I have purposely skipped the Run Windows Update, however please do so in the event you are not running WSUS in your environment.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/03/image13.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/03/image_thumb13.png" border="0" alt="image thumb13 Installing Forefront Threat Management Gateway 2010" width="660" height="466" /></a></p>
<p>The following welcome screen is displayed.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image5.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image5_thumb.png" border="0" alt="image5 thumb Installing Forefront Threat Management Gateway 2010" width="474" height="253" /></a></p>
<p>Click Next</p>
<p>Accept the terms and conditions. Click on Next</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image8.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image8_thumb.png" border="0" alt="image8 thumb Installing Forefront Threat Management Gateway 2010" width="521" height="483" /></a></p>
<p>Select Forefront TMG services and Management.  Click Next.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image11.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image11_thumb.png" border="0" alt="image11 thumb Installing Forefront Threat Management Gateway 2010" width="625" height="484" /></a></p>
<p>The Installation proceeds and begins configuring the necessary Windows Roles and Features that are required by TMG.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image14.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image14_thumb.png" border="0" alt="image14 thumb Installing Forefront Threat Management Gateway 2010" width="535" height="336" /></a></p>
<p>Upon completion, you should receive the following Preparation Complete Window.  Click Finish to launch the TMG installation.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image17.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image17_thumb.png" border="0" alt="image17 thumb Installing Forefront Threat Management Gateway 2010" width="482" height="347" /></a></p>
<p>The installation begins and the wizard outlines the 3 core stages and estimated times.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image20.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image20_thumb.png" border="0" alt="image20 thumb Installing Forefront Threat Management Gateway 2010" width="414" height="232" /></a></p>
<p>Once the welcome screen appears, click Next.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image23.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image23_thumb.png" border="0" alt="image23 thumb Installing Forefront Threat Management Gateway 2010" width="512" height="388" /></a></p>
<p>Accept the Licence Agreement. Click Next</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image26.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image26_thumb.png" border="0" alt="image26 thumb Installing Forefront Threat Management Gateway 2010" width="483" height="340" /></a></p>
<p>Enter the customer information and Click Next.</p>
<p>Specify your installation path.  Click Next.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image29.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image29_thumb.png" border="0" alt="image29 thumb Installing Forefront Threat Management Gateway 2010" width="504" height="268" /></a></p>
<p>Add your Internal Network Address Ranges. Click Next.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image1.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image1_thumb.png" border="0" alt="image1 thumb Installing Forefront Threat Management Gateway 2010" width="504" height="271" /></a></p>
<p>You will receive the below warning message advising of services that will be restarted during the installation.  Click Next.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image4.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image4_thumb.png" border="0" alt="image4 thumb Installing Forefront Threat Management Gateway 2010" width="467" height="301" /></a></p>
<p>Click Install.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image71.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image71_thumb.png" border="0" alt="image71 thumb Installing Forefront Threat Management Gateway 2010" width="463" height="257" /></a></p>
<p>You should hopefully receive the below screen notifying that the installation was a success.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image10.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image10_thumb.png" border="0" alt="image10 thumb Installing Forefront Threat Management Gateway 2010" width="513" height="387" /></a></p>
<p>Upon launching Forefront TMG for the first time you will be presented with a Getting Started Wizard which will assist in getting you up and running in 3 easy steps.  Please note that if you are looking at importing your existing ISA 2006 Server configuration settings to the new TMG server then you much close the wizard and accomplish this task first.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image13.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image13_thumb.png" border="0" alt="image13 thumb Installing Forefront Threat Management Gateway 2010" width="517" height="486" /></a></p>
<p>Let’s begin by going through the 3 stages of the Getting Started Wizard.  The first stage is Configuring your network settings.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image161.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image161_thumb.png" border="0" alt="image161 thumb Installing Forefront Threat Management Gateway 2010" width="523" height="363" /></a></p>
<p>Click Next</p>
<p>The below screen capture similarly to ISA 2006 allows you to select a network template and in this instance will detect what different types of network setups are configurable based on the number of adapters installed on your TMG server.  In my instance, I only have one single adapter and this has been reflected in the below screen capture.  This TMG setup is purely acting as a second layer application firewall publishing our Web Applications such as SharePoint and Outlook Web App.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image19.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image19_thumb.png" border="0" alt="image19 thumb Installing Forefront Threat Management Gateway 2010" width="545" height="398" /></a></p>
<p>Click Next</p>
<p>Specify your IP address settings.  It is best practice that you specify a static IP address to your TMG server as opposed to utilising DHCP.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image22.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image22_thumb.png" border="0" alt="image22 thumb Installing Forefront Threat Management Gateway 2010" width="496" height="399" /></a></p>
<p>Click Next and Finish.</p>
<p>You will then be presented with Stage 2 of the Getting Started Wizard, Configure system settings.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image251.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image251_thumb.png" border="0" alt="image251 thumb Installing Forefront Threat Management Gateway 2010" width="518" height="229" /></a></p>
<p>The system will attempt to determine Host identification details such as Computer name, Windows domain and DNS suffix.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image281.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image281_thumb.png" border="0" alt="image281 thumb Installing Forefront Threat Management Gateway 2010" width="544" height="417" /></a></p>
<p>Click Next and Finish.</p>
<p>The third and final stage of the Getting Started Wizard is defining your deployment options.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image31.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image31_thumb.png" border="0" alt="image31 thumb Installing Forefront Threat Management Gateway 2010" width="523" height="190" /></a></p>
<p>Click Next</p>
<p>Specify whether Forefront TMG will use the Microsoft Update Service to check for updates.  Please note, that if your TMG server is configured to use WSUS then it will utilise this method first and use the Microsoft Update service as a fallback method.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image34.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image34_thumb.png" border="0" alt="image34 thumb Installing Forefront Threat Management Gateway 2010" width="540" height="366" /></a></p>
<p>The next screen allows us to configure TMG’s protection features such as Network Inspection System (NIS) and Web Protection.  As mentioned earlier in the post, these are paid subscription based services, however Microsoft do provide you with a 120 days complimentary evaluation of these 2 product offerings.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image37.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image37_thumb.png" border="0" alt="image37 thumb Installing Forefront Threat Management Gateway 2010" width="552" height="370" /></a></p>
<p>Click Next</p>
<p>Specify your NIS signature update settings and how often it will check for new updates.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image40.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image40_thumb.png" border="0" alt="image40 thumb Installing Forefront Threat Management Gateway 2010" width="540" height="436" /></a></p>
<p>Click Next.</p>
<p>In the next screen, specify whether you want to participate in the Customer Feedback Improvement Program.</p>
<p>Click Next</p>
<p>In the next screen you will be provided with the opportunity to participate in the Microsoft Telemetry Reporting Service where malware attacks etc are sent to Microsoft, assisting them with improving TMG and it’s signatures.</p>
<p>Click Next and then Finish.</p>
<p><a href="http://sharepointgeorge.com/wp-content/uploads/2010/04/image43.png"><img style="display: inline; border-width: 0px;" title="image" src="http://sharepointgeorge.com/wp-content/uploads/2010/04/image43_thumb.png" border="0" alt="image43 thumb Installing Forefront Threat Management Gateway 2010" width="508" height="489" /></a></p>
<p>Upon clicking close, TMG will provide you with the ability to Run the Web Access Wizard to create your first rule.  We will be discussing Access Rules and Publishing Rules in upcoming articles in this TMG series.</p>
<p>I&#8217;d be interested to know how many TMG deployments are out there and how many are considering replacing their existing ISA boxes with TMG 2010.</p>
<p><strong>References</strong></p>
<p>Forefront TMG Planning and Design; <a title="http://technet.microsoft.com/en-au/library/cc441674.aspx" href="http://technet.microsoft.com/en-au/library/cc441674.aspx">http://technet.microsoft.com/en-au/library/cc441674.aspx</a></p>
<p>Forefront TMG Deployment; <a title="http://technet.microsoft.com/en-au/library/cc441445.aspx" href="http://technet.microsoft.com/en-au/library/cc441445.aspx">http://technet.microsoft.com/en-au/library/cc441445.aspx</a></p>
<p>Installing Forefront TMG; <a title="http://technet.microsoft.com/en-au/library/cc441440.aspx" href="http://technet.microsoft.com/en-au/library/cc441440.aspx">http://technet.microsoft.com/en-au/library/cc441440.aspx</a></p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://sharepointgeorge.com/2010/installing-forefront-threat-management-gateway-2010/' addthis:title='Installing Forefront Threat Management Gateway 2010 ' ><a href="http://sharepointgeorge.com//addthis.com/bookmark.php?v=250&amp;username=xa-4d2b47597ad291fb" class="addthis_button_compact">Share</a><span class="addthis_separator">|</span><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a></div>]]></content:encoded>
			<wfw:commentRss>http://js-kit.com/rss/sharepointgeorge.com/p=1401</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

