forefront TMG, default gateway & Proxy server

Posted on 2011-09-27
Last Modified: 2012-05-12

I Installed Forefront Threat Management Gateway 2010
First Connected to External Internet router at
Second to Lacal Network at -
Local Gateway address (The Machine I installed on)
Gateway (forefront TMG)  is in Workgroup Mode

My questions:

1. I understand that only one DNS must be set in the Gateway (forefront TMG) in the external LAN in My case  the First Connection, is that correct ?

2. What should I set for each computer inside my Local Lan for:
    The Default Gateway ?
    The DNS ?
    Should I need to set Proxy server in each computer to Port 8080 ?

Question by:DoronAviad
LVL 51

Accepted Solution

Keith Alabaster earned 500 total points
ID: 36714660
1. No - dns mus ONLY be set on the INTERNAL nic and must point to the INTERNAL dns server. Nothing should ever know about the external DNS except the DNS forwarders in the YOUR DNS server service.
2. default gateway on internal PC's/Servers will be the TMG internal IP adrress.
3. As above, the Internal DNS
4. Yes

5. These are absolute basics not only for TMG but for Windows generally. I would suggest you read one of the good admin books or get yourself on a course else TMG will trip you up significantly. It is not forgiving when you get it wrong - if you do not know the detail of how it operates then to make it work people often have tp put in entries that also open big holes in their security without realising it.


Author Closing Comment

ID: 36715750
Thank you

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
checking for updates 11 71
How VPC help preventing STP Loops 4 102
URL question:  WWW versus WWW1 in address line 4 61
2 routers and 1 public IP Address. 10 42
So the following errors occurs in 2 ways that I am aware of at this stage, and you receive one of the following error messages: ERROR 1. When trying to save a rule: No Web listener is specified for the Web publishing rule Autodiscovery Publishin…
There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question