Con risposta How to create vlan on Forefront TMG

  • Thursday, February 07, 2013 3:02 PM
     
     

    In our company we have a Forefront TMG server with 3 NIC.

    Internal
    Permiter
    External

    The internal adapter should need to get different IP adresses for each vlan 10.1.1.200, 10.2.1.200, 10.3.1.200. The internal card is an intel 82567LM and the drivers are installed. How can I create seperate nic's for each vlan on the internal adapter? And how I can route all this stuff?

    Thanks in advance.

All Replies

  • Thursday, February 07, 2013 7:17 PM
     
     Answered

    Hi,

    TMG is not VLAN aware. You must use the Network Adapter card configuration software to build VLAN and Virtual Interfaces. After you create the Virtual Interfaces, TMG can see this interfaces:
    http://blogs.technet.com/b/isablog/archive/2006/10/04/802.1q-and-isa-server.aspx


    regards Marc Grote aka Jens Baier - www.it-training-grote.de - www.forefront-tmg.de - www.nt-faq.de

  • Monday, February 11, 2013 9:42 AM
     
     
    Thanks for the answer, I guess I also need to configure a trunk to the interface of the server?
  • Monday, February 11, 2013 1:14 PM
     
     
    Hi,

    ACK

    regards Marc Grote aka Jens Baier - www.it-training-grote.de - www.forefront-tmg.de - www.nt-faq.de

  • Tuesday, February 12, 2013 9:45 AM
     
     

    Hi,

    I checked a couple of websites how to enable vlan in forefront TMG, but it is not working. I'm searching for 2 weeks and I'm getting frustated of it.
    In my forefront tmg I have one Intel network adapter for my internal network. I created on this NIC two virtual NIC with vlan 10 and vlan 70.
    Each one has its own IP address:

    VLAN 10: 10.1.1.200
    VLAN 70: 10.2.1.200

    In the layer 3 switch I created this vlan also with for each vlan a default gateway.
    VLAN 10: 10.1.1.1
    VLAN 70: 10.2.1.1
    From this switch (Dell connect 6224) is a trunk configured to this one interface

    There are two PC in each vlan
    PC 1: 10.1.1.25, default gateway 10.1.1.200
    PC 2: 10.2.1.25, default gateway 10.2.1.200

    There is a firewall rule configured with the following:
    Allow all traffic between VLAN 10 to VLAN 70
    Allow all trafiic between VLAN 70 to VLAN 10
    Allow all traffic from VLAN 10 and VLAN 70 to EXTERN

    None of the vlan's can ping each other, but they can ping there dfault gateway. Only VLAN 10 can access the internet.

    The configuration physical is: Users -> L3 -> TMG

    Can someone please explain me what I need todo? 

    • Edited by StijnS Tuesday, February 12, 2013 9:47 AM
    • Edited by StijnS Tuesday, February 12, 2013 10:29 AM
    •  
  • Wednesday, February 13, 2013 8:36 AM
     
     Answered
    I fixed the problem. I reinstalled the whole server and defined every network adapter in the internal network. If I define each adapter as a different internal network it doesn't work.
    • Marked As Answer by StijnS Wednesday, February 13, 2013 8:36 AM
    •