Solved

Single NIC for http web publish rule - TMG

Posted on 2015-01-13
2
262 Views
Last Modified: 2015-02-11
Hi discussion at work.

I suggest just 1 NIC for TMG  in DMZ is the most secure - We have an ASA firewall

Im been told that its more secure with 2 x NICs  - 1 dmz and 1 internal (im presuming internal means that (internal LAN) - then a NAT on the TMG

How is this more secure - is not "MORE" secure with just 1 NIC in the DMZ? - then publishing rule proxies the connection to inside LAN?
0
Comment
Question by:philb19
2 Comments
 
LVL 28

Assisted Solution

by:asavener
asavener earned 250 total points
ID: 40547290
I'm not sure exactly what your setup is, or how you're trying to leverage the TMG server.  Can you provide a diagram?

Is the "DMZ" just an interface off of the ASA, and you also have an inside and an outside interface?

Internet
   |
ASA--DMZ
   |
Inside


Traditionally, I had the ISA/TMG server as a second firewall:

Internet
   |
ASA
   |
DMZ  (Considered the "inside" interface on the ASA)
   |
TMG
   |
Inside

IMO, the second topology provides additional security, because any internet traffic has to traverse two different firewall platforms to reach the inside network.  You also get to use the TMG as a proxy server for your internal clients.
0
 
LVL 23

Accepted Solution

by:
Suliman Abu Kharroub earned 250 total points
ID: 40580918
You can't use TMG as a firewall with a single NIC, only proxy server.... so 2 NICs is more secure.
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Setting up a VPN 60 144
Cisco ASA and Watchguard firewall 2 40
Cisco 5508 WLC software upgrade 2 38
Need a "SonicWall" Replacement 12 22
If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

832 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question