Installing Forefront Threat Management Gateway on SBS 2008 domain controller

Hi.
I am trying to install Forefront Threat Management Gateway on SBS 2008 domain controller. I have read that you cant install TMG on an domain controller but only on a domain member.

Obviously if i am installing it on SBS, the server will be my domain controller. I am installing it only on the one box and it is 64bit along with SBS 2008 64bit.

My question is, does anyone know if there is a way to install TMG (beta) on SBS 2008 running as a domain controller, or will there be a later version released that will be able to do this. I cant use hyper V as the bios do not support it.

thanks.
technolutionsAsked:
Who is Participating?
 
Keith AlabasterConnect With a Mentor Enterprise ArchitectCommented:
I am not anticipating it, no. The only way i would do this would be on a seperate box for the tmg
0
 
Keith AlabasterEnterprise ArchitectCommented:
Sorry, don't believe you can do this.

Keith
0
 
technolutionsAuthor Commented:
ok thanks. any idea if there will be an version in the not so distant future that you can run on a DC?
or what i can do for an solution?
0
Simple Misconfiguration =Network Vulnerability

In this technical webinar, AlgoSec will present several examples of common misconfigurations; including a basic device change, business application connectivity changes, and data center migrations. Learn best practices to protect your business from attack.

 
technolutionsAuthor Commented:
wow that really sucks. I really cant believe they will do it like that. will wait for the final version.
thanks for the help anyway.
0
 
kurian2z5Commented:
Install TMG first and then promote it to a domain controller. Haven't encountered any problems yet.
0
 
Keith AlabasterEnterprise ArchitectCommented:
Please do not be ridiculous. Ftmg is not supported on a domain controller.
0
 
kurian2z5Commented:
Its not officially supported obviously. I'm only doing this on my home network and I don't expect anyone to do this in a production environment. If your company is too cheap to allot another server for TMG, its probably not the product for you anyway.

You can run dcpromo after installing TMG and it works.
0
 
Keith AlabasterEnterprise ArchitectCommented:
Nothing to do with my company, instead I am speaking as a Microsoft Certified Trainer for FTMG as well as being an MVP for both the ISA and FTMG products. Second, the question asker has SBS 2008 which is the only domain controller (at least to start with) - it can hardly be dcpromo'ed up at a later stage. if it was a supportable scenario, MS would have kept the option open. However, it is not supported in any situation therefore if you purchase FTMG you need to install on a separate server that is not a DC.

 
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.