?
Solved

ForeFront TMG Multiple Gateways

Posted on 2010-09-08
6
Medium Priority
?
1,588 Views
Last Modified: 2013-11-16
Hi Guys,

Is it possible to configure 2 x gateways in Forefront TMG,
We have two routers onsite to the internet.
We want to allocate some users to the one gateway and a group of more users to use the second gateway.

Could this be configured in ForeFront TMG?  I realize that the box will require 3 x network cards;
(1 x internal, 2 x external)
0
Comment
Question by:Rupert Eghardt
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
6 Comments
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 33629225
No - it can't. ISA and FTMG have no concept of protocol or user based routing in this context. You can route to different external gateways based on the destination IP address but this is more on the OS routing table rather than anything clever in ISA/FTMG.

Even using the ISP Failover/load-balancing options that now come with FTMG, the balancing is by traffic, not by source user or protocol.

Keith
0
 
LVL 10

Expert Comment

by:simonlimon
ID: 33635543
Maybe you could try using Networking rules, but you will have to filter by Source IPs and not by Usernames.
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 33635868
I say again, it will not work. Period.
0
WatchGuard's M Series Appliances - Miecom Approved

WatchGuard's newest M series appliances were put to the test by Miercom.  We had great results and outperformed all of our competitors in both stateless and stateful traffic throghput scenarios! Ready to see how your UTM appliance stacked up? Download the Miercom Report!

 
LVL 10

Expert Comment

by:simonlimon
ID: 33635901
You can also try using ISP redundancy mode as explained, I know the question was different and this will be done dynamically.

http://www.isaserver.org/tutorials/Microsoft-Forefront-TMG-ISP-Redundancy-Mode.html
0
 
LVL 51

Accepted Solution

by:
Keith Alabaster earned 2000 total points
ID: 33640740
ISP redundancy only uses the alternative route if the primnary fails. ISP load-balancing allows the two connections to be used concurrently but splits the traffic either 50-50 or on a percentage basis selectable by the operator. It will not make decisions based upon protocol, source ip address, or other criteria.

Not trying to rain on anyone's parade but neither ISA or FTMG is geared to do what is being asked.
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 33689365
Are we done here?
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
Suggested Courses

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question