<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>RO Windows Administrators Weblog &#187; TMG</title>
	<atom:link href="http://www.winadmin.ro/tag/tmg/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.winadmin.ro</link>
	<description>Weblogul adminilor de Windows din Romania.</description>
	<lastBuildDate>Fri, 03 Feb 2012 19:33:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>TMG&#8211;no network adapters could be identified.</title>
		<link>http://www.winadmin.ro/2012/01/21/tmgno-network-adapters-could-be-identified/</link>
		<comments>http://www.winadmin.ro/2012/01/21/tmgno-network-adapters-could-be-identified/#comments</comments>
		<pubDate>Sat, 21 Jan 2012 05:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[TMG]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2012/01/21/tmgno-network-adapters-could-be-identified/</guid>
		<description><![CDATA[Azi m-am impotmolit pentru cateva momente in eroarea descrisa aici: http://blogs.technet.com/b/isablog/archive/2010/11/19/no-network-adapters-could-be-identified-error-when-choosing-a-network-template-in-tmg.aspx Cum nu prea aveam chef sa fac nimic din recomandarile de acolo am verificat rapid configuratia sistemului meu. Si bine am facut ca nu m-am repezit. Am adaugat DNS Suffix in configuratia sistemului (lucru ce era necesar, nu stiu cum de nu a tipat [...]]]></description>
			<content:encoded><![CDATA[<p>Azi m-am impotmolit pentru cateva momente in eroarea descrisa aici:</p>
<p><a title="http://blogs.technet.com/b/isablog/archive/2010/11/19/no-network-adapters-could-be-identified-error-when-choosing-a-network-template-in-tmg.aspx" href="http://blogs.technet.com/b/isablog/archive/2010/11/19/no-network-adapters-could-be-identified-error-when-choosing-a-network-template-in-tmg.aspx">http://blogs.technet.com/b/isablog/archive/2010/11/19/no-network-adapters-could-be-identified-error-when-choosing-a-network-template-in-tmg.aspx</a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2012/01/image13.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2012/01/image_thumb13.png" width="583" height="473" /></a></p>
<p>Cum nu prea aveam chef sa fac nimic din recomandarile de acolo am verificat rapid configuratia sistemului meu. Si bine am facut ca nu m-am repezit. Am adaugat DNS Suffix in configuratia sistemului (lucru ce era necesar, nu stiu cum de nu a tipat la instalare), restart, si wizard-ul a mers fara probleme.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2012/01/21/tmgno-network-adapters-could-be-identified/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The end of TMG</title>
		<link>http://www.winadmin.ro/2011/06/04/the-end-of-tmg/</link>
		<comments>http://www.winadmin.ro/2011/06/04/the-end-of-tmg/#comments</comments>
		<pubDate>Sat, 04 Jun 2011 05:27:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Diverse]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ISA]]></category>
		<category><![CDATA[TMG]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2011/06/04/the-end-of-tmg/</guid>
		<description><![CDATA[Cam asa lasa impresia Microsoft, ca dupa mai bine de 10 ani de Proxy Server/ISA/TMG renunta la acest produs. Ce m-a dus la aceasta idee a fost lipsa de implicare a Microsoft in ultimii ani de a promova TMG, iar azi cand am cautat in lista de sesiuni de la Teched US o sesiune de [...]]]></description>
			<content:encoded><![CDATA[<p>Cam asa lasa impresia Microsoft, ca dupa mai bine de 10 ani de Proxy Server/ISA/TMG renunta la acest produs. Ce m-a dus la aceasta idee a fost lipsa de implicare a Microsoft in ultimii ani de a promova TMG, iar azi cand am cautat in lista de sesiuni de la Teched US o sesiune de TMG, surpriza … nu am gasit nici una.</p>
<p>Imediat am cautat pe net despre ceva zvonuri si se pare ca nu sunt singurul care gandeste asa:</p>
<p><a title="http://www.techrepublic.com/blog/window-on-windows/the-demise-of-threat-management-gateway-is-microsoft-backing-away-from-the-edge/4387" href="http://www.techrepublic.com/blog/window-on-windows/the-demise-of-threat-management-gateway-is-microsoft-backing-away-from-the-edge/4387">http://www.techrepublic.com/blog/window-on-windows/the-demise-of-threat-management-gateway-is-microsoft-backing-away-from-the-edge/4387</a></p>
<p>Totusi, sfarsitul TMG-ului ar insemna si sfarsitul UAG-ului. Despre UAG nu stiu ce sa zic, daca a fost adoptat de clienti, ce market share avea etc, insa TMG/ISA au fost si inca mai sunt unele dintre cele mai bune produse ale MS cu un numar foarte mare de utilizatori.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2011/06/04/the-end-of-tmg/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TMG, NLB &amp; Firewall Client</title>
		<link>http://www.winadmin.ro/2011/02/01/tmg-nlb-firewall-client/</link>
		<comments>http://www.winadmin.ro/2011/02/01/tmg-nlb-firewall-client/#comments</comments>
		<pubDate>Tue, 01 Feb 2011 05:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Firewall Client]]></category>
		<category><![CDATA[TMG]]></category>
		<category><![CDATA[TMG Client]]></category>
		<category><![CDATA[Trusted Management Gateway]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2011/02/01/tmg-nlb-firewall-client/</guid>
		<description><![CDATA[Stiu ca inca nu am ajuns cu articolele sa discutam despre NLB pe TMG insa mi-a fost atrasa atentia de o problema in configuratia TMG in NLB cu Firewall Clients in spate. Technet-ul spune CLAR: Load balancing is not supported with Forefront TMG Clients or ISA Firewall Clients http://technet.microsoft.com/en-us/library/ee796231.aspx#bnmjr5r58uhhh Man, this sucks!!! Cica ar fi [...]]]></description>
			<content:encoded><![CDATA[<p>Stiu ca inca nu am ajuns cu articolele sa discutam despre NLB pe TMG insa mi-a fost atrasa atentia de o problema in configuratia TMG in NLB cu Firewall Clients in spate.</p>
<p>Technet-ul spune CLAR: <strong>Load balancing is not supported with Forefront TMG Clients or ISA Firewall Clients</strong></p>
<p><a title="http://technet.microsoft.com/en-us/library/ee796231.aspx#bnmjr5r58uhhh" href="http://technet.microsoft.com/en-us/library/ee796231.aspx#bnmjr5r58uhhh">http://technet.microsoft.com/en-us/library/ee796231.aspx#bnmjr5r58uhhh</a></p>
<p>Man, this sucks!!! Cica ar fi nush ce chestie in arhitectura produsului si ca Firewall Client trebuie sa comunice direct cu Dedicated IP. In practica asta inseamna ca o sa vezi toate masinile cu Firewall Client ca stau conectate la un singur nod.</p>
<p>MS spune sa folosesti DNS round robin ca sa balansezi clientii pe nodurile din cluster insa cam toata lumea isi pune problema de High Availability in scenariul asta. Daca ma apuc sa folosesc un IP din lista care nu mai e online?</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/01/image70.png"><img style="margin: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; border: 0px;" src="http://www.winadmin.ro/wp-content/uploads/2011/01/image_thumb70.png" border="0" alt="image" width="392" height="484" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/01/image71.png"><img style="padding-left: 0px; padding-right: 0px; padding-top: 0px; border: 0px;" src="http://www.winadmin.ro/wp-content/uploads/2011/01/image_thumb71.png" border="0" alt="image" width="406" height="453" /></a></p>
<p>HA-ul e si nu e o problema in scenariul asta. Depinde de fapt pe ce client ruleaza TMG Firewall Client. Daca ruleaza pe Windows 7, e posibil ca Round Robin-ul sa-i furnizeze doar IP-urile care sunt online. Dar asta face subiectul unui alt post …</p>
<p>MS ar cam trebui sa gaseasca o solutie calumea, nu workaround-uri de felul asta. E ca si cum ai spune “nu merge ca l-am facut prost de la inceput”. Exagerez si eu, ca nu e un produs rau, dar vrem mai mult.</p>
<p>PS: ar merge sa prinzi un Sales care vrea sa-ti vanda TMG si sa-l intrebi daca face load balancing pt Firewall Clients. Eventual sa-ti dea si in scris <img class="wlEmoticon wlEmoticon-smile" style="border-style: none;" src="http://www.winadmin.ro/wp-content/uploads/2011/01/wlEmoticon-smile4.png" alt="Smile" />.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2011/02/01/tmg-nlb-firewall-client/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TMG 2010&#8211;Install Options</title>
		<link>http://www.winadmin.ro/2011/01/21/tmg-2010install-options/</link>
		<comments>http://www.winadmin.ro/2011/01/21/tmg-2010install-options/#comments</comments>
		<pubDate>Fri, 21 Jan 2011 05:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[TMG]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2011/01/21/tmg-2010install-options/</guid>
		<description><![CDATA[Intr-un articol precedent am discutat despre o varianta de instalare a TMG. Cea mai simpla de fapt. Standalone server, fara domeniu. Acum o sa recapitulam pe scurt si celelalte optiuni de instalare. Prima optiune se refera la instalarea serviciilor TMG, fara ea nu se instaleaza TMG. Forefront TMG Management &#8211; optiunea de instala doar consola [...]]]></description>
			<content:encoded><![CDATA[<p>Intr-un <a href="http://www.winadmin.ro/2010/06/22/installing-tmg-2010-workgroup-mode/">articol</a> precedent am discutat despre o varianta de instalare a TMG. Cea mai simpla de fapt. Standalone server, fara domeniu.</p>
<p>Acum o sa recapitulam pe scurt si celelalte optiuni de instalare.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/01/image17.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/01/image_thumb17.png" width="570" height="392" /></a></p>
<p>Prima optiune se refera la instalarea serviciilor TMG, fara ea nu se instaleaza TMG.</p>
<p>Forefront TMG Management &#8211; optiunea de instala doar consola de administrare, folosita bineinteles pentru a instala consola de administrare pe un alt sistem. </p>
<p>Enterprise Management Server (EMS) for centralized array management – EMS-ul reprezinta un server separat care stocheaza centralizat toate setarile serverelor din array-urile controlate de EMS. Folosind EMS puteti seta politici care se pot aplica peste toate firewall-urile (TMG) din enterprise (chiar si versiunea Standard). E de fapt fostul CSS din ISA 2006 EE.</p>
<p>Nota: EMS are nevoie de AD si foloseste o instanta de AD LDS pentru stocarea setarilor. </p>
<p>De mentionat ca EMS nu este necesar in majoritatea cazurilor – doar atunci cand aveti mai mult de un array si doriti sa le administrati centralizat.</p>
<p>Ok, si acum cam am tot pomenit de array, de ce nu vedem nici o optiune de instalara e pentru un simplu array. Lucrurile s-au schimbat mult in bine la TMG iar instalarea si configurarea este mult mai flexibila. Adaugarea la array si scoatearea din array se poate face foarte simplu fara a mai modifica intr-un fel configuratia serverului sau a reinstala TMG. Pur si simplu dupa ce ai instalat TMG, dai join sau unjoin.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/01/image18.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/01/image_thumb18.png" width="504" height="408" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/01/image19.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/01/image_thumb19.png" width="248" height="301" /></a></p>
<p>&#160;</p>
<p>Nota: Array se refera la un grup de sisteme care sunt administrate ca fiind unul singur si peste care se aplica acelasi set de reguli. Un soi de cluster.</p>
<p>Primul membru din array se instaleaza normal fara a specifica vreo optiune legata de array. Abia dupa ce instalam am doilea server, folosim optiunea join to array si specificam numele primului server. In acest fel obtinem un standalone array in care unul dintre noduri devine Array Manager.</p>
<p>Mai exista si optiunea de a seta un array fara ca serverele sa faca parte dintr-un domeniu. Optiunea e suportata insa necesita ceva mai multe setari manuale pentru a face array-ul functional.</p>
<p>&#160;</p>
<p>TMG vine cu optiuni de instalare si configurare MULT mai flexibile decat versiunile precedente, facand ca toate operatiunile de instalare si reconfigurare sa fie extraordinar de usoare (atunci cand nu dai de bug-uri).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2011/01/21/tmg-2010install-options/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TMG 2010 Recap</title>
		<link>http://www.winadmin.ro/2011/01/20/tmg-2010-recap/</link>
		<comments>http://www.winadmin.ro/2011/01/20/tmg-2010-recap/#comments</comments>
		<pubDate>Thu, 20 Jan 2011 05:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[TMG]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2011/01/20/tmg-2010-recap/</guid>
		<description><![CDATA[Stateam in cumpana daca sa mai scriu de TMG sau nu si pana la urma m-am hotarat sa scriu, ca e totusi un produs foarte ok. Informatii as avea destule de ar trebui sa transform site-ul intr-unul dedicat de TMG, insa si informatiile astea trebuie structurate cumva altfel cei ce vor sa invete de la [...]]]></description>
			<content:encoded><![CDATA[<p>Stateam in cumpana daca sa mai scriu de TMG sau nu si pana la urma m-am hotarat sa scriu, ca e totusi un produs foarte ok. Informatii as avea destule de ar trebui sa transform site-ul intr-unul dedicat de TMG, insa si informatiile astea trebuie structurate cumva altfel cei ce vor sa invete de la zero nu ar intelege nimic. O sa incerc sa o iau cat mai de jos insa ajuta daca te-ai lovit cat de cat de versiunile precendente.</p>
<p>TMG sau Trusted Management Gateway este urmasul ISA Server pe care multi dintre noi l-am folosit sau poate ca il mai folosim in continuare.</p>
<p>Diferenta majora intre TMG si versiunile precedente este ca ruleaza numai pe platforma pe 64 de biti si are inclus un engine antivirus care scaneaza traficul. Ar mai fi si SSL inspection, URL Filtering si NIS.</p>
<p>Anul trecut am postat un articol introductiv despre TMG <a title="http://www.winadmin.ro/2010/06/22/installing-tmg-2010-workgroup-mode/" href="http://www.winadmin.ro/2010/06/22/installing-tmg-2010-workgroup-mode/">http://www.winadmin.ro/2010/06/22/installing-tmg-2010-workgroup-mode/</a> si o sa continui.</p>
<p>Intre timp au aparut si cateva update-uri pentru TMG si anume SP1 si cateva rollup-uri.</p>
<p>SP1 il gasiti la download aici: <a title="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=f0fd5770-7360-4916-a5be-a88a0fd76c7c&amp;displaylang=en" href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=f0fd5770-7360-4916-a5be-a88a0fd76c7c&amp;displaylang=en">http://www.microsoft.com/downloads/en/details.aspx?FamilyID=f0fd5770-7360-4916-a5be-a88a0fd76c7c&amp;displaylang=en</a></p>
<p>Iar rollup-urile aici:</p>
<p><a title="http://support.microsoft.com/kb/2433623/" href="http://support.microsoft.com/kb/2433623/">http://support.microsoft.com/kb/2433623/</a></p>
<p><a title="http://support.microsoft.com/kb/2475183" href="http://support.microsoft.com/kb/2475183">http://support.microsoft.com/kb/2475183</a></p>
<p>Rollup-urile sunt post SP1, deci aveti nevoie de SP1 sa le instalati. Puteti vedea lista (destul de scurta) cu problemele rezolvate pentru a decide daca aveti nevoie de ele sau nu.</p>
<p>SP1 vine si cu functionalitati noi nu numai cu hotfixuri, cum ar fi URL Override, colocare cu rolul de RODC si BranchCache si publicare de Sharepoint 2010.</p>
<p>Acum sper doar sa-mi fac timp sa termin seria de TMG pana nu apare SP2 (programat anul acesta) care o sa vina si el cu elemente noi. <img style="border-bottom-style: none;border-right-style: none;border-top-style: none;border-left-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://www.winadmin.ro/wp-content/uploads/2011/01/wlEmoticon-smile2.png" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2011/01/20/tmg-2010-recap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ISA/TMG one to one NAT</title>
		<link>http://www.winadmin.ro/2010/07/08/isatmg-one-to-one-nat/</link>
		<comments>http://www.winadmin.ro/2010/07/08/isatmg-one-to-one-nat/#comments</comments>
		<pubDate>Thu, 08 Jul 2010 20:00:11 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[ISA]]></category>
		<category><![CDATA[TMG]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/?p=1889</guid>
		<description><![CDATA[Pentru ca de curand am fost intrebat de multe ori despre one to one NAT in ISA sau TMG m-am gandit sa clarific putin lucrurile. Termenul de NAT one to one (sau Full Cone NAT) se refera la posibilitatea ca device-ul care face NAT sa mapeze in tabela lui de translatare o adresa dedicata si [...]]]></description>
			<content:encoded><![CDATA[<p>Pentru ca de curand am fost intrebat de multe ori despre one to one NAT in ISA sau TMG m-am gandit sa clarific putin lucrurile.</p>
<p>Termenul de NAT one to one (sau Full Cone NAT) se refera la posibilitatea ca device-ul care face NAT sa mapeze in tabela lui de translatare o adresa dedicata si permanenta pentru IP-ul translatat.</p>
<p>Imi este cam greu sa explic principiile de baza asa ca doritorii pot citi mai multe aici: <a title="http://www.cisco.com/web/about/ac123/ac147/archived_issues/ipj_7-3/anatomy.html" href="http://www.cisco.com/web/about/ac123/ac147/archived_issues/ipj_7-3/anatomy.html">http://www.cisco.com/web/about/ac123/ac147/archived_issues/ipj_7-3/anatomy.html</a></p>
<p>In mare as putea sa spun ca ISA/TMG nu o sa faca niciodata Full Cone NAT asa cum este descris la Cisco. Asta si pentru ca este un firewall, iar principiul descris de Cisco este mult prea permisiv. In schimb anumite parti din acest model pot fi implementate cu ISA/TMG.</p>
<p>O sa incerc sa descriu doua din scenariile in care este nevoie de acest model de NAT, si cum pot fi ele realizate cu ISA/TMG.</p>
<p>Ca exemplu am luat o infrastructura care are 3 servere aflate in spatele unui firewall tip ISA/TMG.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image99.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb93.png" width="644" height="298" /></a></p>
<p>In primul scenariu, se cere ca fiecare dintre serverele din reteaua interna sa poata fi accesat din exterior prin RDP pe portul default TCP 3389.</p>
<p>Hmm, pai cu un singur IP pe interfata externa normal ca nu se poate. Solutia trebuie sa arate cam asa:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image100.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb94.png" width="644" height="298" /></a></p>
<p>Observati ca de data asta firewall-ul are mai multe IP-uri externe. Publicand portul 3389 pe fiecare IP in parte putem sa realizam foarte usor ceea ce s-a cerut. Server1 va putea fi accesat prin 193.68.17.1:3389, Server2 prin 193.68.17.2:3389 si asa mai departe. Acest scenariu poate fi realizat cu ISA2004/2006/TMG fara nici un fel de problema (prin Server Publishing). Multi “specialisti” cauta sa faca asa ceva cu ISA, insa auzind din diverse locuri ca ISA nu stie de NAT one-to-one renunta.</p>
<p>Acum sa luam un alt caz, foarte discutat si pentru care chiar era nevoie de o imbunatatire.&#160; Cazul “outbound” in care un server din spatele lui ISA comunica cu un server din extern iar traficul trebuie sa iasa pe un IP dedicat. Cam toate discutiile de pe Internet se refera la scenariul cu serverul de email (care bineinteles ca are IP-ul lui dedicat si diferit de cel primar al lui ISA) care trebuie sa iasa in extern pe un anumit IP (de regula acelasi cu MX-ul, sau ca se se potriveasca cu nu stiu ce inregistrare PTR). Ei, cazul asta nu merge pe ISA 2004/2006. Toate conexiunile outbound ies prin IP-ul primar de pe interfata externa a lui ISA.</p>
<p>Cu toate ca e un inconvenient, nu e un capat de lume, dar multi se impotmolesc in asta.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image101.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb95.png" width="644" height="246" /></a></p>
<p>Incepand cu TMG (probabil datorita valurilor de comentarii si sugestii de pe Internet) a fost introdusa si posibilitatea de a mapa traficul outbound pe un anumit IP (adica exact de ziceam mai sus), functionalitatea numindu-se Enhanced NAT. Nu e ceva foarte visibil in interfata TMG si din acest motiv o sa arat cum se face.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/07/image1.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/07/image_thumb1.png" width="506" height="390" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/07/image2.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/07/image_thumb2.png" width="644" height="441" /></a></p>
<p>Obiectul de tip Computer de mai sus, contine IP-ul serverului de email.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/07/image3.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/07/image_thumb3.png" width="508" height="390" /></a></p>
<p>External se refera la tot ce nu e cuprins in alta retea definita in TMG (adica tot ce e extern).</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/07/image4.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/07/image_thumb4.png" width="509" height="389" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/07/image5.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/07/image_thumb5.png" width="506" height="389" /></a></p>
<p>IP-urile respective trebuie sa fie adaugate pe interfata de retea externa.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/07/image6.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/07/image_thumb6.png" width="406" height="484" /></a></p>
<p>Nota: cu 4 IP-uri pe placa externa, interfata TMG nu imi afisa nici un IP in lista. Probabil ca e un bug sau ceva specific setup-ului meu. Cu 2 a mers fara probleme.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/07/image7.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/07/image_thumb7.png" width="644" height="456" /></a></p>
<p>In momentul acesta mai este inca un pas de facut. Sa mutam regula nou facuta inaintea celei generale de NAT (numita Internet Access).</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/07/image8.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/07/image_thumb8.png" width="644" height="455" /></a></p>
<p>Dupa aplicarea setarilor, traficul outbound de la serverul de mail va iesi prin IP-ul dedicat, restul prin IP-ul default de pe interfata externa.</p>
<p>Sper sa mai fi clarificat cate ceva si sa va fie de folos articolul,</p>
<p>Andrei.</p>
<p>UPDATE: Pe ISA 2004/2006 acest lucru poate fi facut cu <a href="http://www.collectivesoftware.com/Products/IPbinder">IPBinder</a> de la Collective Software. Atentie ca mesajul lor de marketing spune ca TMG nu stie sa faca asa ceva. WRONG. Mai sus aveti dovada ca poate. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/07/08/isatmg-one-to-one-nat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Installing TMG 2010 (Workgroup mode)</title>
		<link>http://www.winadmin.ro/2010/06/22/installing-tmg-2010-workgroup-mode/</link>
		<comments>http://www.winadmin.ro/2010/06/22/installing-tmg-2010-workgroup-mode/#comments</comments>
		<pubDate>Tue, 22 Jun 2010 04:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[TMG]]></category>
		<category><![CDATA[Trusted Management Gateway]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/?p=1771</guid>
		<description><![CDATA[TMG sau Forefront Trusted Management Gateway este inlocuitorul lui ISA Server, Enterprise Firewall-ul produs de Microsoft.&#160; Incepand cu aceasta versiune, TMG vine doar in versiunea pe 64 de biti spre deosebire de ISA care rula doar pe Windows x86. OS-urile suportate sunt Windows Server 2008 &#38; R2 (numai x64). Anumite componente ale produsului sunt schimbate [...]]]></description>
			<content:encoded><![CDATA[<p>TMG sau Forefront Trusted Management Gateway este inlocuitorul lui ISA Server, Enterprise Firewall-ul produs de Microsoft.&#160; Incepand cu aceasta versiune, TMG vine doar in versiunea pe 64 de biti spre deosebire de ISA care rula doar pe Windows x86. OS-urile suportate sunt Windows Server 2008 &amp; R2 (numai x64).</p>
<p>Anumite componente ale produsului sunt schimbate semnificativ fata de vechile versiuni, insa acestea fiind destul de low level, nu vor fi observate de un administrator obisnuit. Si ma refer in special la integrarea cu <a href="http://www.microsoft.com/whdc/device/network/WFP.mspx">Windows Filtering Platform</a>.</p>
<p>Cate ceva despre system requirements:</p>
<p>- 64bit processor – dual core</p>
<p>- 2Gb RAM</p>
<p>Nota: merge si cu un core si doar 1Gb RAM, insa performantele lasa de dorit (de folosit in configuratia asta numai in mediu de test)</p>
<p>- 2.5Gb spatiu pe disk</p>
<p>- 2 placi de retea (pentru operarea in firewall mode)</p>
<p>- Windows 2008 SP2 sau R2 (x64)</p>
<p>- .Net Framework 3.5 SP1</p>
<p>- Windows Installer 4.5</p>
<p>- nu este suportata instalarea pe domain controller <img src='http://www.winadmin.ro/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>- este suportata instalarea in VM</p>
<p>&#160;</p>
<p>Astea sunt cerintele asa in mare. Restul de componente (roluri &amp; features) sunt instalate de catre TMG Preparation Tool.</p>
<p>Mai multe detalii puteti gasi aici:</p>
<p><a title="http://technet.microsoft.com/en-us/library/dd896981.aspx" href="http://technet.microsoft.com/en-us/library/dd896981.aspx">http://technet.microsoft.com/en-us/library/dd896981.aspx</a></p>
<p>Scenariu pentru care m-am decis sa fac acest tutorial arata cam asa:</p>
<p>&#160;</p>
<p>&#160;</p>
<p>&#160;</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image32.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb26.png" width="644" height="340" /></a></p>
<p>Un server cu 2 placi de retea, una conectata la Internet si una in LAN, pe care ruleaza Windows 2008R2 + TMG 2010. In LAN am sisteme stand alone fara domain controller. Sau daca am, in acest scenariu nu doresc integrarea TMG cu Active Directory.</p>
<p>Inainte de a incepe instalarea este bine sa configurati partea de networking si sa va asigurati ca aveti conectivitata in retelele conectate, altfel dupa instalarea TMG lucrurile se complica, filtrarile de pe TMG facand diagnosticul mai dificil.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image92.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb86.png" width="644" height="172" /></a></p>
<p>Tip:denumiti adapatoarele de retea cu nume sugestive.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image93.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb87.png" width="407" height="451" /></a></p>
<p>Gateway se seteaza numai pe placa externa. In scenariul fara AD, setam DNS doar pe placa externa a serverului.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image94.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb88.png" width="407" height="449" /></a></p>
<p>Inainte de pornirea setup-ului e bine sa actualizam sistemul de operare cu ultimele update-uri pentru a evita urmatoarele reboot-uri.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image33.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb27.png" width="644" height="481" /></a></p>
<p>Preparation tool-ul imi instaleaza toate componentele necesare pentru ca TMG sa se poate instala. Cei care s-au jucat cu versiunea beta cunosc chinul de a instala manual aceste componente.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image34.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb28.png" width="644" height="448" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image35.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb29.png" width="644" height="447" /></a></p>
<p>Normal ca vom dori sa instalam si serviciile TMG si consola de administrare.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image36.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb30.png" width="644" height="448" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image37.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb31.png" width="644" height="449" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image38.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb32.png" width="644" height="446" /></a></p>
<p>Si abia in clipa asta incepe instalarea propriu zisa a TMG-ului.</p>
<p>Nota: Instalarea nu mai este la fel de rapida ca la versiunile ISA2000/2004/2006.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image39.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb33.png" width="490" height="238" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image40.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb34.png" width="507" height="384" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image41.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb35.png" width="506" height="382" /></a></p>
<p>Acum urmeaza pasul cel mai important. Definirea zonei de adrese <strong>interne</strong>. Atentie! Aici trebuie sa puneti doar range-urile de adrese interne. Wizard-ul o poate face pentru voi selectand placa de retea interna (o sa adauge subnetul la care este atasata placa).</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image42.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb36.png" width="506" height="383" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image43.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb37.png" width="389" height="416" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image44.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb38.png" width="440" height="417" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image45.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb39.png" width="508" height="382" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image46.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb40.png" width="508" height="383" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image47.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb41.png" width="508" height="385" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image48.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb42.png" width="508" height="383" /></a></p>
<p>Instalaea este completa, acum urmeaza setup-ul initial care mi se pare enervant. As fi preferat sa ma lase sa imi fac eu regulile asa cum vreau fara nici o interventie din partea lui. Oricum este folositor pentru cei fara prea mare experienta cu acest produs.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image49.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb43.png" width="644" height="414" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image50.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb44.png" width="556" height="482" /></a></p>
<p>Aici selectati modelul retelei voastre. Ceea ce am selectat eu mai jos se refera la un server cu 2 placi de retea care face legatura intre extern si intern. In lista se mai afla, modelul cu TMG in spatele altui firewall, si modelul cu TMG doar cu o placa de retea, folosit doar pentru webp proxy, caching si publishing.</p>
<p>Network template-urile iti definesc relatiile dintre retelele conectatae la TMG.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image51.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb45.png" width="556" height="481" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image52.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb46.png" width="556" height="481" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image53.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb47.png" width="555" height="482" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image54.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb48.png" width="555" height="481" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image55.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb49.png" width="542" height="482" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image56.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb50.png" width="556" height="481" /></a></p>
<p>Avem si optiunea sa joinam serverul la domeniu insa nu o sa o facem pentru ca am spus ca mergem pe scenariul cu server standalone.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image57.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb51.png" width="556" height="481" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image58.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb52.png" width="553" height="479" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image59.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb53.png" width="540" height="484" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image60.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb54.png" width="554" height="484" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image61.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb55.png" width="552" height="484" /></a></p>
<p>Web Protection se licentiaza separat ca subscriptie, insa din clipa in care instalati TMG aveti acces la acest feature cat trial 120 de zile.</p>
<p>Recomand sa bifati si Enable URL Filtering pentru ca este un feature foarte util.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image62.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb56.png" width="552" height="484" /></a></p>
<p>NIS aka Network Inspection System este modulul de IPS si inspecteaza traficul pe baza unor semnaturi publicate de catre MS. Foarte util atunci cand nu a aparut fix pentru anumite vulnerabilitati, insa exista un model pentru traficul facut de exploit.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image63.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb57.png" width="552" height="484" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image64.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb58.png" width="552" height="484" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image65.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb59.png" width="549" height="484" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image66.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb60.png" width="553" height="484" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image67.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb61.png" width="541" height="484" /></a></p>
<p>Acum instalarea si configurarea initiala a produsului fiind completa, rulam acest Web Access wizard, care ne poate ajuta sa definim primele reguli de acces.</p>
<p>Nota: by default dupa instalare, TMG blocheaza tot traficul (aproape) in &amp; out, asa ca fara sa definiti reguli de acces, nu o sa functioneze nimic.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image68.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb62.png" width="572" height="448" /></a></p>
<p>Urmatoarea optine va crea o regula care va bloca tot traficul ce se incadreaza in anumite categorii predefinite in TMG.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image69.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb63.png" width="571" height="449" /></a></p>
<p>Categoriile le vedeti in fereastra urmatoare iar in spate sta serviciul Microsoft Reputation Service (o imensa baza de date folosita pentru a clasificata site-urile de pe Internet).</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image70.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb64.png" width="572" height="451" /></a></p>
<p>Urmatoarea optiune se refera la scanarea malware a traficului web ce trece prin TMG.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image71.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb65.png" width="573" height="448" /></a></p>
<p>Nou in TMG exista optiunea de a face inspectie pe conexiuni HTTPS. Cu toate ca wizard-ul sugereaza activarea optiunii de inspectie HTTPS, recomand ca in aceasta etapa sa nu o activati si sa selectati Allow all HTTPS traffic. Activarea acestei optiuni fara sa intelegi foarte bine ce face si fara sa anunti end user-ul despre cum se poate schimba experienta lui de navigare pe web, poate crea probleme.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image72.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb66.png" width="572" height="450" /></a></p>
<p>Urmeaza partea de web caching, unde e bine sa specificam dimensiunea cache-ului (in functie de spatiul pe care il avem la dispozitie si de traficul la care este supus serverul).</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image73.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb67.png" width="573" height="451" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image74.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb68.png" width="451" height="450" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image75.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb69.png" width="572" height="449" /></a></p>
<p>Si acum sa inspectam putin consola de administrare. Primul lucru observat sunt cele doua butoane Apply &amp; Discard. Pentru a salva regula nou creata si setarile din Wizardul de configurare e nevoie sa aplicam modificarile cu Apply.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image76.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb70.png" width="644" height="456" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image77.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb71.png" width="368" height="350" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image78.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb72.png" width="536" height="266" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image79.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb73.png" width="531" height="348" /></a></p>
<p>Mai jos am pus cateva imagini din consola:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image80.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb74.png" width="644" height="455" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image81.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb75.png" width="644" height="456" /></a></p>
<p>Cam aici in Firewall Policy se desfasoara majoritatea activitatii de administrare.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image82.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb76.png" width="644" height="458" /></a></p>
<p>Web access policy este de fapt un alt view al regulilor, dar doar pentru cele care contin protocoalele HTTP si FTP.</p>
<p>Putem observa aici ca prima regula blocheaza accesul la anumite categorii, iar ce trece mai departe este permis de urmatoarea regula.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image83.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb77.png" width="644" height="458" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image84.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb78.png" width="644" height="458" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image85.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb79.png" width="644" height="458" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image86.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb80.png" width="644" height="458" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image87.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb81.png" width="644" height="458" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image88.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb82.png" width="644" height="458" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image89.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb83.png" width="644" height="457" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image90.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb84.png" width="644" height="456" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image91.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb85.png" width="644" height="456" /></a></p>
<p>Mai departe, m-am conectat pe un sistem din reteaua interna si am incercat sa accesez o pagina de pe internet. Inainte de asta am configurat in Internet Explorer adresa TMG-ului ca si web proxy. Este necesar sa configurez IE-ul asa pentru ca in regulile de acces nu am si regula pentru traficul DNS, iar clientul neputand sa interogheze servere DNS externe trebuie sa apeleze la TMG pentru rezolutia de nume.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image98.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb92.png" width="389" height="336" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image95.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb89.png" width="644" height="482" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image96.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb90.png" width="644" height="382" /></a></p>
<p>Sesiunea web proxy poate fi vazuta in interfata de administrare si pot afla detalii mai amanuntite despre modul in care s-a efectuat conexiunea.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/06/image97.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/06/image_thumb91.png" width="644" height="455" /></a></p>
<p>Si iata ca TMG functioneaza si este gata pentru a imbunatati performantele conexiunii la internet si pentru a bloca traficul de tip malware sau cel catre destinatii riscante pentru utilizatorii din reteaua mea.</p>
<p>Atat de aceasta data, insa voi mai reveni si cu alte scenarii si detalii de configurare mai avansate despre acest produs.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/06/22/installing-tmg-2010-workgroup-mode/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Microsoft Reputation Service portal</title>
		<link>http://www.winadmin.ro/2009/10/14/microsoft-reputation-service-portal/</link>
		<comments>http://www.winadmin.ro/2009/10/14/microsoft-reputation-service-portal/#comments</comments>
		<pubDate>Wed, 14 Oct 2009 16:42:18 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[TMG]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2009/10/14/microsoft-reputation-service-portal/</guid>
		<description><![CDATA[Serviciul pentru catalogarea site-urilor care este folosit in momentul actual de TMG a primit si o interfata pentru public. https://www.microsoft.com/security/portal/mrs/default.aspx Pana acum pentru a vedea in ce categorie se afla un site trebuia sa folosim consola TMG. Acum putem vizualiza informatiile folosind linkul de mai sus si putem recomanda introducerea site-ului in una sau mai [...]]]></description>
			<content:encoded><![CDATA[<p>Serviciul pentru catalogarea site-urilor care este folosit in momentul actual de TMG a primit si o interfata pentru public.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/10/image24.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2009/10/image_thumb23.png" width="244" height="195" /></a> </p>
<p><a title="https://www.microsoft.com/security/portal/mrs/default.aspx" href="https://www.microsoft.com/security/portal/mrs/default.aspx">https://www.microsoft.com/security/portal/mrs/default.aspx</a></p>
<p>Pana acum pentru a vedea in ce categorie se afla un site trebuia sa folosim consola TMG. Acum putem vizualiza informatiile folosind linkul de mai sus si putem recomanda introducerea site-ului in una sau mai multe categorii.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2009/10/14/microsoft-reputation-service-portal/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

