Publishing Exchange, etc, without TMG/ISA


Recommended Posts

Hi guys, I've always used ISA and now TMG as a firewall in more complex scenarios with multiple servers hosting sites/services. This allows me to examine specific web requests all on port 80 and 443 and direct them to the appropriate server such as the Exchange server for OWA, or to a web server for other sites. With TMG now possibly being phased out or it's future up in the air, what other firewall products do you guys suggest with similar capabilities?

Perhaps another way to answer my concern is, is there a better way publish Exchange OWA so that I don't have sites using the same ports on different servers?

I have always done one outside ip for a specific service. I have never done a single outside to host multiple services utilizing the same port(s).

Owa, VPN, and web on different external ip's using one to one nat.

So for your Exchange server you have all the roles on the one box and you're using what for your firewall? Windows firewall?

We use TMG (and ISA in the past) and have very close ties with Microsoft and haven't heard that Microsoft are phasing out their firewall solutions. I know they are pushing UAG as a solution but I'm sure they'll have a product similar to ISA/TMG when they phase that particular product out.

We use TMG (and ISA in the past) and have very close ties with Microsoft and haven't heard that Microsoft are phasing out their firewall solutions. I know they are pushing UAG as a solution but I'm sure they'll have a product similar to ISA/TMG when they phase that particular product out.

Just do a Google search for "future of TMG" and it's clear that there is serious noise around what's to become of TMG. It could be just a consolidation of the Forefront line. I'm just curious what people are doing without TMG/ISA. It seems to me that there is really no other product that comes close. What gets me right now is that TMG does not work at all on Server 2012 and there aren't plans to make work.

http://www.techrepublic.com/blog/window-on-windows/the-demise-of-threat-management-gateway-is-microsoft-backing-away-from-the-edge/4387

So for your Exchange server you have all the roles on the one box and you're using what for your firewall? Windows firewall?

That depends on the site. 80 and 443 would go to the cas and 25 would go to the spam filter. The db can be separate. Web services can be seperated as well.

Just do a Google search for "future of TMG" and it's clear that there is serious noise around what's to become of TMG. It could be just a consolidation of the Forefront line. I'm just curious what people are doing without TMG/ISA. It seems to me that there is really no other product that comes close. What gets me right now is that TMG does not work at all on Server 2012 and there aren't plans to make work.

http://www.techrepub...m-the-edge/4387

Ah yes, for 2012 Msft is currently pushing UAG (which is more expensive and may be too much for what you are looking for). We're just starting our migration to 2012 servers so haven't come across the TMG/2012 problem yet.

Sorry I didn't realize you were asking about the firewall. No no windows firewall other than for internal traffic. I consider it a security breach to use windows firewall as your routing firewall, this is due to the simple fact that they are on the forefront of being compromised all of the time, more than any other company. How was it put, windows is like having a house in the bad neighborhood in town that has barred up windows and a heavy steal door. I choose to live in a better part of town where people aren't always trying to break in. The Windows house has been robbed too many times.

Cisco, sonic wall, fortinet, juniper, or even pfsense, monowall, or smoothwall distros.

As someone who's used ISA and TMG since ISA2000, and also uses and deals with Cisco, Checkpoint, and Juniper solutions as well, nothing really comes close to ISA and TMG, and no, running on Windows hasn't been the (usually overblown) security risk people think it is. Sadly, Microsoft has no roadmap for TMG, but considering it and 2008R2 underneath it should be supported for many years, you have time either to wait and see what the forefront line becomes over the next 5-6 years, or to move to something else that will do parts of each job.

As to publishing, you have to go back to opening ports and services on other equipment. As sc302 mentions, it's simply opening external ports on external IPs on the external interface, and routing them to the appropriate ports on the internal IP address(es) of the internal servers.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Zoom Workplace 7.1.0.41345 by Razvan Serea Zoom Workplace for Windows is a reliable video conferencing tool that makes it easy to connect and collaborate. With features like messaging, file sharing, and app integrations, it’s designed to streamline teamwork. You’ll get high-quality audio and video, strong security with end-to-end encryption, and an intuitive interface—all of which help remote teams and businesses stay productive and connected. Zoom Workplace key features: High-Definition Video & Audio: Provides clear, reliable communication for virtual meetings. End-to-End Encryption: Ensures secure communication with strong data protection. Multi-Factor Authentication: Adds an extra layer of security for user accounts. Integration with Productivity Apps: Supports seamless integration with Microsoft Office, Google Workspace, and more. File Sharing: Easily share files during meetings for efficient collaboration. Real-Time Messaging: Enables team chat for ongoing communication. Collaborative Whiteboarding: Allows teams to brainstorm and collaborate visually. Webinar Support: Host large webinars with interactive features. Administrative Controls: Manage user permissions, meeting settings, and security features. Cloud Storage: Automatically stores meetings and files in the cloud for easy access. Cross-Platform Support: Available on Windows, macOS, and mobile devices. Meeting features: Virtual Backgrounds: Customize your background for meetings to maintain privacy or enhance professionalism. Touch Up My Appearance: Automatically smoothens skin tone for a more polished video appearance. Breakout Rooms: Divide meetings into smaller sessions for group discussions or workshops. Live Transcription: Automatically generate real-time captions during meetings for accessibility. Zoom Apps: Integrate third-party applications directly into Zoom for enhanced functionality. Meeting Reactions: Participants can use emojis for quick, non-verbal feedback during meetings. Polling: Conduct live polls during meetings to gather instant feedback from participants. Attention Tracking: Monitors participant attention during meetings to ensure engagement. Closed Captioning: Enable manual or automatic captions for a more inclusive experience. Webinar Replay: Record and share webinars with analytics for audience engagement. Download: Zoom 64-bit | 145.0 MB (Free, paid upgrade available) Links: Zoom Website | Zoom ARM64 | Zoom Installers | Release Notes Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • UK funds £60M AI labs to challenge US tech dominance with open-source models by Paul Hill The UK government has awarded £60 million to Oxford University and University College London to help keep the country in the AI race by focusing on open-source, low-hardware alternatives. This is in stark contrast to the expensive, closed-source, and high-hardware-requirement models being created in the United States and elsewhere. The money will be shared among two new academic research labs over six years to help them redesign the fundamental mathematics and architectures of AI to help the UK reduce its reliance on a handful of US tech firms. Commenting on the development, AI Minister Kanishka Narayan said: Initially, the government planned to fund just one lab with a £40 million investment, but with this update, two labs will now get access to a larger pool of funds. The labs are expected to invest in the top AI researchers at every career stage, with £2 million per lab being set aside for hiring at least ten doctoral students. The government hopes that this will grow the UK’s talent in the field of AI. The labs are also expected to work closely with the leaders in British AI research, such as the Alan Turing Institute and UKRI’s AI research hubs. This will allow the various teams to collaborate and create new solutions faster than they could alone. This development is pretty interesting for a number of reasons, chiefly that it could create a long-term challenge for US tech firms if these labs successfully scale these open-source architectures that bypass the proprietary ecosystems. It could also give British businesses and public sector organizations access to AI features without paying high licensing fees to foreign providers or needing to invest in specialized server infrastructure.
    • If I were them, I'm gonna hold out until the prices of these semiconductor parts normalize. $1,049 for a ~5 year old hardware is DoA, more so for gamers. On a deeper note, if Steam Machine is priced like this, we are soo effed up for the next gen Xbox console and PS6. With great AAA titles releasing at the end of the year, this just creates more demand...and more tears for me. Lol.
    • I suspect one reason its hard to justify subsidising is that it's not a locked down device like a traditional console is. In this climate sadly if it was a "good deal" you'd get people hoarding them for anything but gaming. The Lenovo Legion Go 2 with the Ryzen Z2 Extreme is £1300 here ($1720) for some context on how other SteamOS like devices are now priced. I got the older Z1 Extreme model for £300 with a dock, just shows how insane prices have got recently.
  • Recent Achievements

    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
    • Rookie
      dorf went up a rank
      Rookie
    • First Post
      mike_rumble earned a badge
      First Post
    • Dedicated
      tuben earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      465
    2. 2
      +Edouard
      183
    3. 3
      PsYcHoKiLLa
      94
    4. 4
      Michael Scrip
      88
    5. 5
      neufuse
      70
  • Tell a friend

    Love Neowin? Tell a friend!