• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

TMG or UAG? or both.

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [Threat Management Gateway (TMG) 2010] >> General >> TMG or UAG? or both. Page: [1]
Login
Message << Older Topic   Newer Topic >>
TMG or UAG? or both. - 19.Nov.2010 11:36:02 AM   
FudNut

 

Posts: 7
Joined: 3.Jun.2008
Status: offline
Hello,

I have been given the following scenario: Deploy a gateway and publish a SharePoint site and file server access through it. Initially it will be to connect client sites to us and allow them access to our intranet etc. However it may need to be opened to home workers (IE I cannot tie down all in coming connection from home workers, I could if it was only a site to site incoming public IP from business A, B and C)

The severs used here are sitting in a DMZ with the forward edge device being a CheckPoint firewall.

My question here is I have been looking at the TMG and UAG for this task. My understanding the TMG is a true firewall and can publish the SharePoint but not the file server? The UAG is a gateway to proxy connections and publish apps but not a true firewall??

So if I have to publish SharePoint and files I could use a UAG and tie down the incoming connection with my CheckPoint, however if home workers have to hit the services I would need a TMG to proxy connections with a UAG behind to publish the file shares?

Let me know if this does not make sense, it makes sense in my head !!

Thanks.

< Message edited by FudNut -- 19.Nov.2010 11:37:05 AM >
Post #: 1
RE: TMG or UAG? or both. - 19.Nov.2010 3:35:32 PM   
Jason Jones

 

Posts: 4663
Joined: 30.Jul.2002
From: United Kingdom
Status: offline
As you already have an edge firewall, you can accomplish what you need with UAG.

You would only need to go with TMG (in addition to UAG) if you need another firewall or need some form of outbound secure web gateway.

In terms of publishing, UAG will have the upper hand over TMG and is much better suited to your needs IMHO.

This is worth a read too to understand the TMG instance that runs under UAG: http://technet.microsoft.com/en-us/library/ee522953.aspx 

Cheers

JJ

< Message edited by Jason Jones -- 19.Nov.2010 3:38:39 PM >


_____________________________

Jason Jones | Forefront MVP | Silversands Ltd
My Blogs: http://blog.msedge.org.uk/ and http://blog.msfirewall.org.uk/

(in reply to FudNut)
Post #: 2
RE: TMG or UAG? or both. - 19.Nov.2010 5:45:03 PM   
sketchy00

 

Posts: 66
Joined: 8.Aug.2008
From: Bellevue, WA
Status: offline
Richard Hicks also has a nice post on TMG versus UAG. This can be found here:

http://tmgblog.richardhicks.com/2010/10/10/what-are-the-differences-between-tmg-and-uag/

(in reply to Jason Jones)
Post #: 3
RE: TMG or UAG? or both. - 19.Nov.2010 7:44:32 PM   
Jason Jones

 

Posts: 4663
Joined: 30.Jul.2002
From: United Kingdom
Status: offline
Indeed he does!

_____________________________

Jason Jones | Forefront MVP | Silversands Ltd
My Blogs: http://blog.msedge.org.uk/ and http://blog.msfirewall.org.uk/

(in reply to sketchy00)
Post #: 4
RE: TMG or UAG? or both. - 22.Nov.2010 6:55:40 AM   
FudNut

 

Posts: 7
Joined: 3.Jun.2008
Status: offline
The links are what I needed, good stuff guys.

No out bound connections from the LAN segment bar windows and AV updates (no users) so the TMG is not required.

So I use my current firewall with an inbound HTTP/S rule only for defence to hit UAG EXT INT to publish SharePoint and File server. This will cover off my tasks, the one answer I still cannot find is does TMG support the file access? Or is this done via UAG only?

(in reply to Jason Jones)
Post #: 5
RE: TMG or UAG? or both. - 22.Nov.2010 8:03:17 AM   
Jason Jones

 

Posts: 4663
Joined: 30.Jul.2002
From: United Kingdom
Status: offline
You can configure file access using WebDav. Have a look here:

http://www.carbonwind.net/ISA/WebDav/WebDav1.htm

It's a bit messy, but does work...

Cheers

JJ

_____________________________

Jason Jones | Forefront MVP | Silversands Ltd
My Blogs: http://blog.msedge.org.uk/ and http://blog.msfirewall.org.uk/

(in reply to FudNut)
Post #: 6
RE: TMG or UAG? or both. - 22.Nov.2010 9:20:21 AM   
FudNut

 

Posts: 7
Joined: 3.Jun.2008
Status: offline
Ok, got it. I tested this before on a different project, from what I remember it ran like a bag of bolts.......

So UAG it is then!

(in reply to Jason Jones)
Post #: 7
RE: TMG or UAG? or both. - 22.Nov.2010 9:44:01 AM   
Jason Jones

 

Posts: 4663
Joined: 30.Jul.2002
From: United Kingdom
Status: offline
LOL...I was being polite with "messy"

_____________________________

Jason Jones | Forefront MVP | Silversands Ltd
My Blogs: http://blog.msedge.org.uk/ and http://blog.msfirewall.org.uk/

(in reply to FudNut)
Post #: 8

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [Threat Management Gateway (TMG) 2010] >> General >> TMG or UAG? or both. Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts