We have decided to test and then deploy a Forefront TMG server on our network of 50 - 75 users (Windows 7, XP Clients, Windows Server 2008R2 Servers and a few Linux Boxes)
Our Network Topology is :
4 Floors (4 Lan Switches) > Connected to a Core Switch in our Server Room > Core Switch Connected to our Cisco Router on FA 0/1 > Cisco Router FA 0/0 Connected to our ISP (WAN).
At this moment our DHCP is running on our cisco router and it is also the default gateway for our LAN : Default Gateway : 192.168.1.1
My Question is :
TMG Server has 2 NICs (One is Connected to our LAN Switch - TMG NIC IP : 192.168.1.200)
During Forefront TMG Installation, I added the range 192.168.1.1 - 192.168.1.254 on Adapter Selection during installation,
Once the install completes, how shall I redirect my clients, so that all network and internet traffic goes via TMG NIC 192.168.1.200
What IP Shall I assign to the 2nd NIC on the TMG Server ?
Where shall that 2nd NIC be connected ?
Shall I place TMG Server with DUAL NICS between our Core LAN Switch and Router or Behind the Core Switch ?
Will be grateful for your assistance on this, we would use this for content filtering and web blocking and other features.
Thanks for reading !
Thank you for your reply : I have more then 3 questions now :-)
Q.1 : If I have 3 ISP Connections and 4NICS on our TMG Server, Can I connect all of them and have TMG Load-Balance / Failover them ?
Q.2 : Can TMG Dial a PPPOE Connection ? say All 3 ISPs require us to dial a pppoe - is it possible to configure that for each nic ?
Q.3 : We also have a Cisco router acting as our WAN Router at the moment, only plugged into 1 ISP, When I configure TMG to loadbalance all 3 WANs, shall I just remove cisco out of the topology or how would I connect TMG and Cisco? A bit confused here - will be grateful if you could assist on this - if this is possible.
Q.4 : If I had ONLY 1 (ONE) Nic on our TMG Server, would it connect to our LAN Switch and then we would specify its address on our W7 / XP Clients so it acts as a caching server / web filter ?
Q.5 : How do we route all internal internet traffic so that it only goes through our TMG server - if we were to use this for caching and web filtering only ?
Once again thanks for your reply - I am just testing this at the moment, I have setup an AD 2008R2 Box, TMG is joined to the domain and has 4 Network Cards installed and configured. TMG is currently plugged into our LAN Switch