Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1187
  • Last Modified:

Microsoft forefront TMZ 2010 in a bridgemode

Hi,
Can Microsoft forefront TMZ 2010 be installed in a bridged mode behind a cisco 2911 router? i.e In this scenario the TMZ 2010 has 2 NICs one external (no IP) and one internal (with internal IP)
Router cisco 2911.....to....>>>External NIC of TMZ2010 with no IP......to...>>>Internal NIC of TMZ with IP...........to.........>>>>>the LAN switch......>>>>>USERS.
My purpose is to test TMZ 2010 with minimal configuration on my network while TMZ sees all the traffic.
Help, please correct the above physical layout if required.
Thanks
0
amanzoor
Asked:
amanzoor
  • 4
  • 3
1 Solution
 
Keith AlabasterCommented:
No - not supported, sorry.
0
 
amanzoorNetwork infrastructure AdminAuthor Commented:
Keith,
Then please let me know if I have to put both NICs coming out of TMZ 2010 into the switch? or what will be the physical layout in the above mentioned scenario?
Thanks
0
 
Keith AlabasterCommented:
The TMG is a firewall so one nic will go the the internal switch and be given an internal IP address. The other nic will be the external one and will need to be on a different subnet to the internal network which will require you to change the internal IP of the Cisco.
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
amanzoorNetwork infrastructure AdminAuthor Commented:
Keith:
At the moment I have 2 subnets '10.10.10.0/24 and '10.10.2.0/24', on my cisco 2911 router I have already assigned two internal IPs for it i.e 10.10.10.254 and 10.10.2.254' I will assign the internal IP to the internal NIC of the TMZ server say '10.10.10.6', for its External NIC I will assign '10.10.2.6' Is this good?
0
 
Keith AlabasterCommented:
Internet ASA NIC 1.1.1.1
           ASA
Internal ASA Nic 10.10.2.x /24
         |
    DMZ Area using 10.10.2.abc subnet
         |
 TMG external NIC 10.10.2.z  /24
           TMG
  TMG internal NIC 10.10.10.y  /24
         |
         |
   Internal LAN using 10.10.10.def subnet

This is the way it has to be.
0
 
amanzoorNetwork infrastructure AdminAuthor Commented:
keith,
Let me clarify the scenario, I do not have any permiter network (all the eggs in one basket).  Basically Cisco 2911 is an IOS firewall, and its internal interface has two IP addresses (10.10.10.0/24 and 10.10.2.0/24) and all of my servers and clients run from within these 2 subnets, these two subnets are internal subnets.  Now please guide if I still have to assign 10.10.2.z/24 to the external interface of the TMZ?  appreciate.
0
 
Keith AlabasterCommented:
Understood - I have been Cisco qualified on their switching and routing track plus their security track for over 10 years.

Obviously we are not communicating too well or I am not guiding appropriately - not sure which.

The bottom line here is that you MUST have a different subnet on both of TMG's network cards. You are suggesting placing a 10.10.2.x address on one nic and a 10.10.10.x address on the other - at least that is what I am understanding from your posts. This cannot be done because both of these subnets are already connected to the Cisco unit - you state that the Cisco has two ip's on its internal nic.

There must be a total seperation between the subnets that are on the outside of TMG and ANY subnets which will form the internal network.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

  • 4
  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now