Solved

Forefront TMG 2010 DR between two physical sites and two DMZs

Posted on 2011-03-01
7
775 Views
Last Modified: 2012-06-27
Hi All

Looking at implemneting DR for Forefront TMG 2010 Enterprise. This needs to be between two physical sites (same domain) both of which the TMG will be located inside a separate DMZ - theat is 2 x sites, 1 x domain, 2 x DMZ.
I believe using EMS (1 at each site for DR purposes), can set up an Enterprise EMS with two separate arrays ? But how is the synchronization managed between the TMGs in different DMZs ?

Other option is use DNS round-robin. If so, would it be best to use two separate stand-alone TMGs and sync manually the policies/rules, or again, set up an EMS or stand-alone array ?

Confused and any help welcomed - especially if any articles on best practice in this scenario.

0
Comment
Question by:TheGeezer2010
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 2
7 Comments
 
LVL 29

Expert Comment

by:pwindell
ID: 35014787
If done with an Array that would require 5 nics in each TMG.  That can become a lot of complexity to try to deal with,...and Arryas can be a "handful" already to begin with.  I'm not saying it can't be done,...I'm saying that you need to consider the complexity of what monster you may create.
0
 
LVL 11

Author Comment

by:TheGeezer2010
ID: 35025058
Turns out cannot do an array as only have Standard version of TMG. I have manually exported/imported the rules, listeners and farms - these will not change at all due to the nature of the solution so manual process is acceptable. Will now test Round Robin DNS to see the effect on the iPhones. Will advise outcome.
0
 
LVL 11

Author Comment

by:TheGeezer2010
ID: 35096411
Testing round-robin tomorrow.
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 11

Accepted Solution

by:
TheGeezer2010 earned 0 total points
ID: 35181480
Round robin works pretty much flawlessly. Some considerations if you DON'T join domain and install/configure TMG OUTSIDE of the DMZ.
When you join domain inside DMZ, it may appear to have joined the domain correctly, but the SPNs will not be registered in AD and therefore KERBEROS authentication will not work (and therefore neither will anything such as OWA publishing which requires authentication). This is because a random set of ports will be used for the RPC connections between the TMG box and the DC/GC (on W2008 these are restricted to 49152-65535 TCP). You will therefore need to reboot the TMG box with these ports OPENED on the external FW, then, once the SPNs are correctly registered (you will no longer get events 5788/9), re-close the ports on the external FW.
I am going to close this with no points awarded as worked this out myself.

Thank you to those who did respond.
0
 
LVL 11

Author Comment

by:TheGeezer2010
ID: 35190629
Final issue was that users with iPhones IOS between 4.21 and 4.24 were getting prompted for cert when connecting to other TMG. This is because Apple changed to using per host authentication instead of per cert. Resolved this by upgrading to latest version of IOS which uses per cert.
0
 
LVL 29

Expert Comment

by:pwindell
ID: 35191631
Ok.
Very good.
0
 
LVL 11

Author Closing Comment

by:TheGeezer2010
ID: 35221163
Self-resolved
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have been asked to explain on many, many occasions the correct way to setup network cards and DNS settings on ISA Server 2004, 2006 and forefront Threat management gateway (FTMG) and have willing done so. I have also promised my self everytime tha…
So the following errors occurs in 2 ways that I am aware of at this stage, and you receive one of the following error messages: ERROR 1. When trying to save a rule: No Web listener is specified for the Web publishing rule Autodiscovery Publishin…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…
I've attached the XLSM Excel spreadsheet I used in the video and also text files containing the macros used below. https://filedb.experts-exchange.com/incoming/2017/03_w12/1151775/Permutations.txt https://filedb.experts-exchange.com/incoming/201…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question