Publishing Exchange, etc, without TMG/ISA


Recommended Posts

Hi guys, I've always used ISA and now TMG as a firewall in more complex scenarios with multiple servers hosting sites/services. This allows me to examine specific web requests all on port 80 and 443 and direct them to the appropriate server such as the Exchange server for OWA, or to a web server for other sites. With TMG now possibly being phased out or it's future up in the air, what other firewall products do you guys suggest with similar capabilities?

Perhaps another way to answer my concern is, is there a better way publish Exchange OWA so that I don't have sites using the same ports on different servers?

I have always done one outside ip for a specific service. I have never done a single outside to host multiple services utilizing the same port(s).

Owa, VPN, and web on different external ip's using one to one nat.

So for your Exchange server you have all the roles on the one box and you're using what for your firewall? Windows firewall?

We use TMG (and ISA in the past) and have very close ties with Microsoft and haven't heard that Microsoft are phasing out their firewall solutions. I know they are pushing UAG as a solution but I'm sure they'll have a product similar to ISA/TMG when they phase that particular product out.

We use TMG (and ISA in the past) and have very close ties with Microsoft and haven't heard that Microsoft are phasing out their firewall solutions. I know they are pushing UAG as a solution but I'm sure they'll have a product similar to ISA/TMG when they phase that particular product out.

Just do a Google search for "future of TMG" and it's clear that there is serious noise around what's to become of TMG. It could be just a consolidation of the Forefront line. I'm just curious what people are doing without TMG/ISA. It seems to me that there is really no other product that comes close. What gets me right now is that TMG does not work at all on Server 2012 and there aren't plans to make work.

http://www.techrepublic.com/blog/window-on-windows/the-demise-of-threat-management-gateway-is-microsoft-backing-away-from-the-edge/4387

So for your Exchange server you have all the roles on the one box and you're using what for your firewall? Windows firewall?

That depends on the site. 80 and 443 would go to the cas and 25 would go to the spam filter. The db can be separate. Web services can be seperated as well.

Just do a Google search for "future of TMG" and it's clear that there is serious noise around what's to become of TMG. It could be just a consolidation of the Forefront line. I'm just curious what people are doing without TMG/ISA. It seems to me that there is really no other product that comes close. What gets me right now is that TMG does not work at all on Server 2012 and there aren't plans to make work.

http://www.techrepub...m-the-edge/4387

Ah yes, for 2012 Msft is currently pushing UAG (which is more expensive and may be too much for what you are looking for). We're just starting our migration to 2012 servers so haven't come across the TMG/2012 problem yet.

Sorry I didn't realize you were asking about the firewall. No no windows firewall other than for internal traffic. I consider it a security breach to use windows firewall as your routing firewall, this is due to the simple fact that they are on the forefront of being compromised all of the time, more than any other company. How was it put, windows is like having a house in the bad neighborhood in town that has barred up windows and a heavy steal door. I choose to live in a better part of town where people aren't always trying to break in. The Windows house has been robbed too many times.

Cisco, sonic wall, fortinet, juniper, or even pfsense, monowall, or smoothwall distros.

As someone who's used ISA and TMG since ISA2000, and also uses and deals with Cisco, Checkpoint, and Juniper solutions as well, nothing really comes close to ISA and TMG, and no, running on Windows hasn't been the (usually overblown) security risk people think it is. Sadly, Microsoft has no roadmap for TMG, but considering it and 2008R2 underneath it should be supported for many years, you have time either to wait and see what the forefront line becomes over the next 5-6 years, or to move to something else that will do parts of each job.

As to publishing, you have to go back to opening ports and services on other equipment. As sc302 mentions, it's simply opening external ports on external IPs on the external interface, and routing them to the appropriate ports on the internal IP address(es) of the internal servers.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • The concern of this article is not getting "hacked". No one is taking over my Google account and anyone that was is far away from self-hosting their passwords. It was about your big tech account of choice deciding to reduce features or getting out of the password manager business altogether. Bitwarden (or say Proton) is professional security company offering opensource solutions. They are going no where and one can easily download or export their passwords to another password manager service regardless. They again also offer self-hosted option. I doubt many people were sold on this solution based on the write up. The author had a number of warnings and caveats themselves. A local, self-managed solution is not for 99% of users.
    • I've owned nothing but ATi/AMD GPUs since 2002, after my last nVidia GPU in 2001 (3dfx before that), IIRC, and in all of that time I recall getting this error maybe once, certainly no more than twice. Despite all the scuttlebutt as to how poor AMD drivers are supposed to be that has certainly not been my experience at all... Usually it has been a configuration problem of some kind. Then again, since we're dealing with OS versions that are EOL, it could easily be an OS version discrepancy. It's still weird to think that Win11 has been officially out for more than five years!
    • AI will never be the jobs panacea some companies fantasize about today. Oracle is likely using it as an excuse, which we will see a lot of companies doing, I'm certain. They love their "plausible" excuses for their downturns. A couple of weeks ago my wife asked me to call Krogers about some discrepancy in a online grocery order, and it will be the last time either of us does that. I'll just do emails with humans from now on... The AI experience was horrible--the obviously recorded voice started asking a bunch of questions about our orders six months prior(!) and saying, "Is this in reference to your order on January 6, for $****?" You say "No!" and immediately the next question is "Is this in reference to your order on January 29th, for $****?" again, I answered "No!"--and it was incredible--on and on it went like that for fully 20 minutes until we finally got to the present, and only then was I put through to a human with authentic intelligence... I wondered why on Earth the idiot AI didn't start with the most recent orders and work back from there, as it was something anyone with a functioning brain would have done. And why didn't the AI have enough sense to ask me what the problem was in the first place? It didn't take too much deduction to understand that the goal of this "AI" was to cause the person on the phone to hang up in disgust, with no resolution of the problem. That begs another question: why pay for a tool-free problem line if the goal is to avoid solving your customer's problems?... Fortunately, Krogers does have real humans capable of reading an email and understanding it, and if she sees another situation in the future that's route she or I will take. The online grocery delivery service from Krogers has been great, over all, but their AI truly sucks.
    • AI is the justification that company administrators use to lay people off; it is not the end all, be all touted in the media (many of whom can't tell a microchip from a potato chip). Greed is main driving factor behind its adoption; the other is remaining relevant in the face of competition from other entities.
  • Recent Achievements

    • One Month Later
      timbobit earned a badge
      One Month Later
    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
    • Rookie
      dorf went up a rank
      Rookie
    • First Post
      mike_rumble earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      479
    2. 2
      +Edouard
      172
    3. 3
      PsYcHoKiLLa
      103
    4. 4
      Michael Scrip
      88
    5. 5
      neufuse
      70
  • Tell a friend

    Love Neowin? Tell a friend!