Figure 1
Also note that you can get help in the Getting Started Wizard by clicking the Help about the Getting Started Wizard link at the bottom of the page.
Click Next in the Welcome to the Network Setup Wizard page.
On the Network Template Selection page, you have four options to choose from:
In this example, we select the Edge firewall option and click Next .
In the Local Area Network (LAN) Settings page , configure the IP address of the internal interface. If you have configured the interface, you will see the settings here and can change the settings on this page. In the Specify additional network topology routes section , you can click the Add button and add routing tables.
After configuring the internal interface settings, click Next .
On the Internet Settings page, configure the IP address settings on the external interface. Note that you have the option to set static entries or use DHCP. Select the appropriate NIC and then select the settings to work. Click Next .
That's all in the Network Setup Wizard . Review your settings on the Completing the Network Setup Wizard page and click Finish .
The next step is the Configure system settings wizard. Click the Configure system settings link to start executing.
Click Next on the Welcome to the System Configuration Wizard page.
Some configuration options are available on the Host Identification page:
At the bottom of the page, you will see the full hostname of the TMG firewall after making the changes here. In general, we should understand these configuration tasks before starting to install the TMG firewall. However, if you forget, you can still retake these tasks using the System Configuration Wizard.
Click Next .
It was a fairly short wizard. Read the information on the Completing the System Configuration Wizard page to confirm that it is correct, then click Finish . Note that if you change the domain, workgroup or hostname, the computer will restart before you move on to the next steps.
The third step of the Getting Started Wizard is to define deployment options. Click the link to Define deployment options.
Click Next on the Welcome to the Deployment Wizard link.
The first thing that the Deployment Wizard wants you to do is to select the Microsoft Update Setup options . Here you have three choices:
Note that if the computer is not connected to the Internet, this step may take longer, as the firewall will try many attempts to connect to the Internet Microsoft Update Services. This may sound redundant because your firewall can connect to the Internet, but if you don't configure the TMG firewall to use an external DNS server, the TMG firewall has no way of identifying the names of the Microsoft Update Internet server.
You can configure the internal interface to use the internal DNS server, but the TMG firewall will still be unable to use the DNS server because you do not have the appropriate Access Rule to allow access from DNS servers. inside to external DNS servers. You need to resolve the Internet host name, but you will still not be able to get the configuration interface to make those DNS servers available.
Maybe in the future, in an additional service pack, we will create a temporary DNS rule during the installation process to allow internal DNS servers to resolve the public host name problem. Until then, we'll just have to wait a bit at this stage of installation.
On the Forefront TMG Protection Features Settings page you have several options:
Notice how the URL Filtering service works. The TMG firewall does not download the entire database, but instead sends the URL string to the Microsoft Reputation Service via an SSL connection to receive the category results and uses that result to evaluate the connection request.
On the NIS Signature Update Settings page , you also have several options:
Click Next .
On the Customer Feedback page, you have an option to join the Microsoft Customer Experience Improvement Program. You should practice in this program. It allows Microsoft to find out how you use the TMG firewall and help them focus on making their products better based on how users use them. In this example, we select the option Yes, I am willing to participate in anonymously in the Customer Experience Improvement Program and click Next .
In the Microsoft Telemetry Reporting Service page , you can help Microsoft and other TMG firewall manufacturers by providing information about malware and other attacks on your network with Microsoft. Unless you have a reason for not doing this, you should choose the Advanced option. This will make the anti-malware component more effective and as a result, the network will be more secure. However, when selecting the advanced option, in addition to adding basic information being sent to Microsoft, information about malicious attacks will be sent in more detail, such as saved templates. full amount and string of URLs. This additional information can give Microsoft lots of help in analyzing and eliminating attacks.
In this example we will select the Advanced option and click Next .
It is a fairly long wizard! On the Completing the Deployment Wizard page, read the information about the options that you made to confirm that they are correct, and then click Finish .
Here, everything seemed to end. As mentioned earlier, we suspect the problem is that the TMG firewall cannot resolve the host names it needs to download anti-malware and NIS services updates. This is a matter of fact that you do not want to address an external DNS server on any TMG firewall NIC - but during installation, this issue may be required. However, it can also cause problems with Active Directory communications. The problem can be solved later by creating an Access Rule to allow internal DNS servers to access the Internet, the type of access depends on how you configure the internal DNS servers to identify host names - yes can be through recursion or transducer.
Here we have done with the Getting Started Wizard . You will receive a message at the end of the page that You have successfully completed all the steps of the Getting Started Wizard. Bạn đang hiện thời để xác định Web Access policy cho bạn organization . For ISA firewall administrators, the Web Access Policy feature may be a bit confusing - because this policy creates Access Rules and groups them into a Web Access Policy.
So how did we do it? We expect that after installing the firewall, the Alerts tab will notify us that the services have been started - there is plenty of time for us to do with the following configuration. What is the result?
What shows up? There is no endpoint mapper, and we have not tried to map an endpoint and what will happen if we do, we will not know which endpoint will be delivered. I see things sometimes related to name resolution issues, so maybe the DNS release I mentioned above may be related to this. The malware inspection issue is mostly due to DNS issues, so don't worry about that. Let's restart the firewall and see if anything happens.
The results are a little better. The WFP Filter Conflict Detected warning is a 'normal' warning, which is a false warning that you can ignore. Not sure why the Malware Inspection Currently Unavailable alert is here, but it may be because the computer is not running long enough to download updates.
Conclude
In this series of two articles, I showed you the experience of installing the TMG firewall. In Part 1 we saw what appeared during the installation process that is very similar to the ISA firewall installation. However, in Part 2, I showed you the Getting Started Wizard , which is all new to the TMG firewall, which includes three small wizards inside the Getting Started Wizard. and successfully installed the TMG firewall.