Monday, December 10, 2012 9:16 PMI just setup a TMG firewall, and all is well with Internet access. I am not able to access devices on the perimeter network, however. I copied the routing and firewall policy for the perimeter that was successfully used on our ISA 2004, but this does not work. Here are the rules I have setup: 1.) A network rule is setup as a route with the Source being "Internal" and Destination being the perimeter. 2.) A firewall policy is setup for all outbound traffic with Source and Destination both setup with Internal, Local Host, and the perimeter network.
Tuesday, December 11, 2012 5:15 AM
please check the TMG live Logging to see if a Firewall policy rule is blocking the traffic. If you do not see the Firewall policy rule which blocks the traffic in the Live logging there may be a Routing problem.
The internal clients ad the devices in the DMZ (Perimeter network) are Secure NAT clients?
regards Marc Grote aka Jens Baier - www.it-training-grote.de - www.forefront-tmg.de - www.nt-faq.de
Tuesday, December 11, 2012 5:35 PMThanks. What I found from the log is that the source IP is the IP address of the outside interface rather than the inside interface. I would not want to have a route from the outside to the perimieter network, and there is a route setup from the inside to the perimeter network. Any idea how to force the source IP to be the inside interface?
Wednesday, December 12, 2012 2:44 PMModerator
Thank you for the post.
You may launch getting started wizard to reconfigure network template as per: http://www.isaserver.org/tutorials/Microsoft-Forefront-TMG-How-use-TMG-network-templates.html, and then configure NIC refer to: http://social.technet.microsoft.com/wiki/contents/articles/recommended-network-adapter-configuration-for-forefront-tmg-enterprise-edition-servers.aspx
Nick Gu - MSFT
- Proposed As Answer by Nick Gu - MSFTMicrosoft Contingent Staff, Moderator Friday, December 14, 2012 4:47 PM
- Marked As Answer by Nick Gu - MSFTMicrosoft Contingent Staff, Moderator Monday, December 17, 2012 2:32 AM