forefront threat management gateway 2010

85
Implementing Microsoft ® Forefront Threat Management Gateway 2010 Member Online Training

Upload: theintin

Post on 22-Feb-2015

494 views

Category:

Documents


3 download

TRANSCRIPT

Page 1: Forefront Threat Management Gateway 2010

Implementing Microsoft ®

Forefront Threat Management Gateway 2010

Member Online Training

Page 2: Forefront Threat Management Gateway 2010

Introduction

Name

Company affiliation

Title/function

Job responsibility

Systems administration experience

Microsoft Windows Server operating systems experience

Expectations for the course

Page 3: Forefront Threat Management Gateway 2010

Trainer Expectations for the course

ท าใหผอบรมเขาใจการตดตง Forefront Threat Management Gateway 2010 รวมถงการบรหารจดการ TMG จ ากดสทธในการใชงาน Internet ของ Users ในบรษท และการเปดใหผทอยภายนอกสามารถตดตอกบ คอมพวเตอรภายในบรษทผานทาง TMG ไดดวย

Page 4: Forefront Threat Management Gateway 2010

Course Outline

ตรวจสอบ Configure ของเครอง Server, Client และ Network Infrastructure ของระบบคอมพวเตอรจ าลอง

ตดตง TMG 2010 ตงแตเรมตนพรอมกบเรยนรประโยชนทจะไดรบจาก TMG 2010 ระหวางรอการตดตงเสรจ

ตรวจสอบ TMG หลงจากตดตงเสรจ พรอมกบเรยนรเมนตางๆ รวมถงการใชงาน Logs and Reports

ท าความรจกเมนตางๆทเพอขนมาใหมทแตกตางจาก ISA เชน Update Center, Intrusion Prevention

ท าความรจก ก าหนดใหเครอง Client ตดตอกบ TMG 2010 คอ Secure NAT และ Web Proxy

สราง Policy ส าหรบให User ภายในบรษทใชงาน (Internet HTTP, HTTPS,PING เครองภายนอกได)

เรยนตอในรอบทสอง

Page 5: Forefront Threat Management Gateway 2010

Course Outline (continued)

สราง Policy ส าหรบให User ภายในบรษทใชงาน (ใชงาน POP3 โหลดเมลจากภายนอก, Remote Desktop ไปทภายนอกได)

สราง Policy ส าหรบให User ภายในบรษทใชงาน (ใชงาน VPN ไปทภายนอกได, FTP ไปทภายนอกได)

เรยนรการใชงาน URL Category Site และ Category Query พรอมกบสราง Policy Block Category Site

สราง Policy ใหคนภายนอกสามารถเปดเวบของบรษททอยหลง TMG 2010 ดวยการท า Publish Web Sites

สราง Policy ใหคนภายนอกสามารถ Connect VPN เขามาทบรษทโดยผาน TMG 2010

สราง Policy ใหคนภายนอกสามารถ FTP และ Remote Desktop เขามาทเครองคอมพวเตอรในบรษท

เรยนรการ Backup และ Restore Policy ตางๆทสรางขนดวย TMG 2010

Page 6: Forefront Threat Management Gateway 2010

Setup

ทกเครองในหองเรยนตดตง Windows Server 2003 R2 Enterprise Edition Evaluation (Service Pack 1)

Internet Connection to ADSL router

Microsoft Virtual Server 2005 R2

Image Server (AD01,FOREFRONT)

Image Client XP (XP01)

Page 7: Forefront Threat Management Gateway 2010

Network Infrastructure of today.

Page 8: Forefront Threat Management Gateway 2010

Sun VirtualBox

Page 9: Forefront Threat Management Gateway 2010

Check before install Forefront TMG.

Internal computer open all web site (Internet)

Internal computer VPN to customer (PPTP,L2TP)

Internal computer PING external computer

Internal computer open MSN Messenger

Internal computer send mail to external

Internal computer Remote Desktop to external computer

Page 10: Forefront Threat Management Gateway 2010

Join computer to domain (itksdemo.local)

Page 11: Forefront Threat Management Gateway 2010

Setup Microsoft Forefront TMG

Page 12: Forefront Threat Management Gateway 2010

Run Windows Update

Page 13: Forefront Threat Management Gateway 2010

Run Preparation Tool

Page 14: Forefront Threat Management Gateway 2010

Run Installation Wizard

Page 15: Forefront Threat Management Gateway 2010

Windows Server is not 64bit.

Page 16: Forefront Threat Management Gateway 2010

Forefront computer information

Page 17: Forefront Threat Management Gateway 2010

Installation Forefront TMG Step by Step

Page 18: Forefront Threat Management Gateway 2010

Installation Forefront TMG Step by Step

Page 19: Forefront Threat Management Gateway 2010

Installation Forefront TMG Step by Step

Page 20: Forefront Threat Management Gateway 2010

Installation Forefront TMG Step by Step

Page 21: Forefront Threat Management Gateway 2010

Installation Forefront TMG Step by Step

Page 22: Forefront Threat Management Gateway 2010

Installation Forefront TMG Step by Step

Page 23: Forefront Threat Management Gateway 2010

Installation Forefront TMG Step by Step

Page 24: Forefront Threat Management Gateway 2010

Installation Forefront TMG Step by Step

Page 25: Forefront Threat Management Gateway 2010

Installation Forefront TMG Step by Step

Page 26: Forefront Threat Management Gateway 2010

Installation Forefront TMG Step by Step

Page 27: Forefront Threat Management Gateway 2010

Installation Forefront TMG Step by Step

Page 28: Forefront Threat Management Gateway 2010

Installation Forefront TMG Step by Step

Page 29: Forefront Threat Management Gateway 2010

Installation Forefront TMG Step by Step

Page 30: Forefront Threat Management Gateway 2010

Installation Forefront TMG Step by Step

Page 31: Forefront Threat Management Gateway 2010

Installation Forefront TMG Step by Step

Page 32: Forefront Threat Management Gateway 2010

Installation Forefront TMG Step by Step

Page 33: Forefront Threat Management Gateway 2010

Forefront Threat Management Gateway (Main Menu)

Page 34: Forefront Threat Management Gateway 2010

Dashboard

Page 35: Forefront Threat Management Gateway 2010

Firewall Policy

Page 36: Forefront Threat Management Gateway 2010

Web Access Policy

Page 37: Forefront Threat Management Gateway 2010

Remote access Policy (VPN)

Page 38: Forefront Threat Management Gateway 2010

Networking

Page 39: Forefront Threat Management Gateway 2010

Logs & Reports

Page 40: Forefront Threat Management Gateway 2010

Check after install Forefront TMG.

Internal computer open all web site (Internet)

Internal computer VPN to customer (PPTP,L2TP)

Internal computer PING external computer

Internal computer open MSN Messenger

Internal computer send mail to external

Internal computer Remote Desktop to external computer

Page 41: Forefront Threat Management Gateway 2010

Logging

Page 42: Forefront Threat Management Gateway 2010

Types of Clients

Improves the performance of Web requests for internal clients

Allows internet access only for authenticated users

Does not require you to deploy client software

ISA Server

Internet

Web Proxy Client Firewall Client

SecureNAT Client

Page 43: Forefront Threat Management Gateway 2010

SecureNAT Client

Page 44: Forefront Threat Management Gateway 2010

Web Proxy Client

Page 45: Forefront Threat Management Gateway 2010

Forefront TMG Client

Page 46: Forefront Threat Management Gateway 2010

Create Firewall Policy

Page 47: Forefront Threat Management Gateway 2010

Set user condition for connect to internet

Page 48: Forefront Threat Management Gateway 2010

Proxy Network Access Message

Page 49: Forefront Threat Management Gateway 2010

Group Policy for setup proxy settings

Page 50: Forefront Threat Management Gateway 2010

Create policy PING external IP

Page 51: Forefront Threat Management Gateway 2010

Create policy Remote Desktop to external

Page 52: Forefront Threat Management Gateway 2010

Create policy VPN to external

Page 53: Forefront Threat Management Gateway 2010

to be continued

on day 2

Page 54: Forefront Threat Management Gateway 2010

Create Policy for NO-IP

Page 55: Forefront Threat Management Gateway 2010

Create Policy for NO-IP

Page 56: Forefront Threat Management Gateway 2010

How to block all news web site.

Page 57: Forefront Threat Management Gateway 2010

Block all news web site.

Page 58: Forefront Threat Management Gateway 2010

Enable URL Filtering

Page 59: Forefront Threat Management Gateway 2010

Block all web mail site (Hotmail , Yahoo…)

Page 60: Forefront Threat Management Gateway 2010

Block only MSN Messenger

Page 61: Forefront Threat Management Gateway 2010

MSN on web. http://www.thaihotweb.com/hotweb/msn.html

http://webmessenger.msn.com/

http://webmessenger.msn.com/

http://www.ebuddy.com/

http://www.koolim.com/

http://www.snimmer.com/

http://www.iloveim.com/

http://express.instan-t.com/myim/start.htm

http://www.msn2go.com/

Page 62: Forefront Threat Management Gateway 2010

Setup VPN Access Policy

Page 63: Forefront Threat Management Gateway 2010

Setup VPN Access Policy

Page 64: Forefront Threat Management Gateway 2010

Setup VPN Access Policy

Page 65: Forefront Threat Management Gateway 2010

Setup VPN Access Policy

Page 66: Forefront Threat Management Gateway 2010

Setup VPN Access Policy

Page 67: Forefront Threat Management Gateway 2010

Setup VPN Access Policy

Page 68: Forefront Threat Management Gateway 2010

Setup VPN Access Policy

Page 69: Forefront Threat Management Gateway 2010

Setup VPN Access Policy

Page 70: Forefront Threat Management Gateway 2010

Web Publishing (www.itksdemo.com)

Page 71: Forefront Threat Management Gateway 2010

Web Publishing (www.itksdemo.com)

Page 72: Forefront Threat Management Gateway 2010

Web Publishing (www.itksdemo.com)

Page 73: Forefront Threat Management Gateway 2010

Web Publishing (www.itksdemo.com)

Page 74: Forefront Threat Management Gateway 2010

Web Publishing (www.itksdemo.com)

Page 75: Forefront Threat Management Gateway 2010

Web Publishing (www.itksdemo.com)

Page 76: Forefront Threat Management Gateway 2010

Publishing Remote Desktop

Page 77: Forefront Threat Management Gateway 2010

Publishing Remote Desktop

Page 78: Forefront Threat Management Gateway 2010

Router Port Forwarding

Page 79: Forefront Threat Management Gateway 2010

Export (Backup)…

Page 80: Forefront Threat Management Gateway 2010

Import (Restore)…

Page 81: Forefront Threat Management Gateway 2010

Apply Policy After Restore.

Page 82: Forefront Threat Management Gateway 2010

One-Time Report

Page 83: Forefront Threat Management Gateway 2010

One-Time Report

Page 84: Forefront Threat Management Gateway 2010

One-Time Report

Page 85: Forefront Threat Management Gateway 2010

One-Time Report