Publishing Exchange, etc, without TMG/ISA


Recommended Posts

Hi guys, I've always used ISA and now TMG as a firewall in more complex scenarios with multiple servers hosting sites/services. This allows me to examine specific web requests all on port 80 and 443 and direct them to the appropriate server such as the Exchange server for OWA, or to a web server for other sites. With TMG now possibly being phased out or it's future up in the air, what other firewall products do you guys suggest with similar capabilities?

Perhaps another way to answer my concern is, is there a better way publish Exchange OWA so that I don't have sites using the same ports on different servers?

I have always done one outside ip for a specific service. I have never done a single outside to host multiple services utilizing the same port(s).

Owa, VPN, and web on different external ip's using one to one nat.

So for your Exchange server you have all the roles on the one box and you're using what for your firewall? Windows firewall?

We use TMG (and ISA in the past) and have very close ties with Microsoft and haven't heard that Microsoft are phasing out their firewall solutions. I know they are pushing UAG as a solution but I'm sure they'll have a product similar to ISA/TMG when they phase that particular product out.

We use TMG (and ISA in the past) and have very close ties with Microsoft and haven't heard that Microsoft are phasing out their firewall solutions. I know they are pushing UAG as a solution but I'm sure they'll have a product similar to ISA/TMG when they phase that particular product out.

Just do a Google search for "future of TMG" and it's clear that there is serious noise around what's to become of TMG. It could be just a consolidation of the Forefront line. I'm just curious what people are doing without TMG/ISA. It seems to me that there is really no other product that comes close. What gets me right now is that TMG does not work at all on Server 2012 and there aren't plans to make work.

http://www.techrepublic.com/blog/window-on-windows/the-demise-of-threat-management-gateway-is-microsoft-backing-away-from-the-edge/4387

So for your Exchange server you have all the roles on the one box and you're using what for your firewall? Windows firewall?

That depends on the site. 80 and 443 would go to the cas and 25 would go to the spam filter. The db can be separate. Web services can be seperated as well.

Just do a Google search for "future of TMG" and it's clear that there is serious noise around what's to become of TMG. It could be just a consolidation of the Forefront line. I'm just curious what people are doing without TMG/ISA. It seems to me that there is really no other product that comes close. What gets me right now is that TMG does not work at all on Server 2012 and there aren't plans to make work.

http://www.techrepub...m-the-edge/4387

Ah yes, for 2012 Msft is currently pushing UAG (which is more expensive and may be too much for what you are looking for). We're just starting our migration to 2012 servers so haven't come across the TMG/2012 problem yet.

Sorry I didn't realize you were asking about the firewall. No no windows firewall other than for internal traffic. I consider it a security breach to use windows firewall as your routing firewall, this is due to the simple fact that they are on the forefront of being compromised all of the time, more than any other company. How was it put, windows is like having a house in the bad neighborhood in town that has barred up windows and a heavy steal door. I choose to live in a better part of town where people aren't always trying to break in. The Windows house has been robbed too many times.

Cisco, sonic wall, fortinet, juniper, or even pfsense, monowall, or smoothwall distros.

As someone who's used ISA and TMG since ISA2000, and also uses and deals with Cisco, Checkpoint, and Juniper solutions as well, nothing really comes close to ISA and TMG, and no, running on Windows hasn't been the (usually overblown) security risk people think it is. Sadly, Microsoft has no roadmap for TMG, but considering it and 2008R2 underneath it should be supported for many years, you have time either to wait and see what the forefront line becomes over the next 5-6 years, or to move to something else that will do parts of each job.

As to publishing, you have to go back to opening ports and services on other equipment. As sc302 mentions, it's simply opening external ports on external IPs on the external interface, and routing them to the appropriate ports on the internal IP address(es) of the internal servers.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • XBOX is at the end of its generational life cycle and wasn't selling much anyway. They need to figure out the pricing for XBOX Helios. However, I'm not buying the DRAM shortage with AI preferring HBM. I think it's industry gouging.
    • Amazon Prime Day 2026: Best Dolby soundbar deals from Sony, Samsung, JBL, Polk, and more by Sayan Sen Yesterday we covered the JBL BAR 800 which is a 5.1.2 Dolby Atmos/Vision soundbar. The unit is on sale for its lowest ever price of just $800 making it a solid offer. However, there are many more options to choose from and in this article, we have made a compilation of the best deals including from Sony, Polk, Yamaha, Denon, Samsung and more. Sony's BAR models are currently at their lowest prices which makes them solid offerings. The company's BRAVIA Theatre Bar lineup is designed to suit different home cinema needs. The Bar 5 is an entry-level 3.1-channel soundbar with a wireless subwoofer, supporting Dolby Atmos®, DTS:X, S-Force PRO Front Surround, and Vertical Surround Engine for immersive audio with clear dialogue. The Bar 6 upgrades to a 3.1.2-channel configuration by adding dedicated up-firing speakers for more convincing overhead Atmos effects while retaining the wireless subwoofer. At the premium end, the Bar 7, Bar 8, and flagship Bar 9 are single-soundbar solutions featuring Sony’s 360 Spatial Sound Mapping technology, which creates phantom speakers for a wider surround field. Bar 7 includes nine speaker units, Bar 8 increases this to eleven, and Bar 9 offers thirteen speaker driver units promising the most expansive soundstage and acoustic performance. All models should integrate seamlessly with compatible BRAVIA TVs and support the BRAVIA Connect app for setup and control. Get them at the links below: Sony BRAVIA Theater Bar 9 Soundbar (HT-A9000): $998.00 (Amazon US) (Was: $1498) Sony BRAVIA Theater Bar 8 Soundbar (HT-A9000): $798.00 (Amazon US) (Was: $998) Sony BRAVIA Theater Bar 7 Soundbar (HT-A7100): $618.00 (Amazon US) (Was: $768) Sony BRAVIA Theater System 6: $548.00 | Sony BRAVIA Theater Bar 6: $448.00 Sony BRAVIA Theater Bar 5 (HT-B500): $278.00 (Amazon US) (Was: $348) Sony HT-S400 2.1 soundbar: $198.00 (Amazon US) (Was: $248) Aside from those, we also have more discounts including from Samsung, Polk Audio, and more: Samsung Q-Series Soundbar HW-QS90H 7.1.2: $797.99 (Amazon US) (Was: $998) Polk Audio Signa S4: $336.00 (Amazon US) (Was: $449) Hisense AX3120Q: $229.00 (Amazon US) (Was: $259) Check out more soundbar deals that you may like at this link. Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • Stellarium 26.2 by Razvan Serea Stellarium is a free open source planetarium for your computer. It shows a realistic sky in 3D, just like what you see with the naked eye, binoculars or a telescope. It is being used in planetarium projectors. Just set your coordinates and go. Stellarium key features: Realistic simulation of the sky, sunrise and sunset Default catalogue of over 600,000 stars Downloadable additional catalogues for up to 210 million stars Catalog data for all New General Catalogue (NGC) objects Images of almost all Messier objects and the Milky Way Artistic illustrations for all 88 modern constellations More than a dozen different cultures with their constellations Solar and lunar eclipse simulation Photorealistic landscapes (more are available on the website) Scripting support with ECMAScript (a few demo scripts are included) Extendable with plug-ins: 8 plug-ins installed by default, including: artificial satellites plug-in (updated from an on-line TLE database) ocular simulation plug-in (shows how objects look like in a given ocular) Solar System editor plug-in (imports comet and asteroid data from the MPC) telescope control plug-in (Meade LX200 and Celestron NexStar compatible) The major changes of this version: Added new sky culture Added new plugin: Planes Many improvements in plugins Many improvements in Core and GUI Many updates in sky cultures. [full release notes] Download: Stellarium 26.2 (64-bit) | 456.0 MB (Open Source) View: Stellarium Home Page | Other Operating Systems | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Conversation Starter
      Admir earned a badge
      Conversation Starter
    • First Post
      The_Focal_Point earned a badge
      First Post
    • Apprentice
      daryld went up a rank
      Apprentice
    • Contributor
      Carltonbar went up a rank
      Contributor
    • One Month Later
      The_Focal_Point earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      418
    2. 2
      +Edouard
      170
    3. 3
      PsYcHoKiLLa
      130
    4. 4
      Xenon
      69
    5. 5
      neufuse
      69
  • Tell a friend

    Love Neowin? Tell a friend!