Показаны сообщения с ярлыком TMG. Показать все сообщения
Показаны сообщения с ярлыком TMG. Показать все сообщения

четверг, 18 сентября 2025 г.

Как сконвертировать сертификат из pem в pfx Windows 2008 R2, Windows Server 2012 R2

Импорт pfx в windows server 2008r2 через mmc и через консоль (CERTUTIL -f -importpfx "domain2.pfx"выдает incorrect password или The specified network password is not correct.

Я столкнулся с той же проблемой с OpenSSL 3 и Windows Server 2008R2/2012 R2. Однако в конечном итоге я собрал правильную комбинацию параметров для конвертации сертификата:

openssl pkcs12 -export -certpbe PBE-SHA1-3DES -keypbe PBE-SHA1-3DES -nomac -inkey contoso.com.key -in contoso.com.crt -out contoso.com-legacy.pfx

Источник: https://stackoverflow.com/questions/69343254/the-password-you-entered-is-incorrect-when-importing-pfx-files-to-windows-cer

понедельник, 6 июня 2016 г.

Повреждена конфигурация TMG

How To Recover Forefront TMG From a Corrupt Configuration Database

We all know it is good practice to keep regular Forefront TMG configuration backups as they help you recover your deployment quickly and accurately in case of a failure or miss configuration.  There is however a scenario where these backups cannot be restored to bail you out.  When Forefront TMG has a corrupt configuration database, the backup and restore mechanism itself is broken and as such you need to fix this first before you can recover from backup.

четверг, 5 ноября 2015 г.

четверг, 30 июля 2015 г.

Exchange 2013 OWA logoff via TMG

OWA Forms Based Auth Logoff Changes in Exchange 2013 Cumulative Update 9 – And Good News for TMG Customers
Update - 2/9/15: Since publishing this blog we made a decision to push one aspect of this change to CU9 to allow some partners a little more time to adapt to this new behavior. The new signout.aspx code is still shipping in CU8, but we are not changing to the new logoff behavior, that is sending the user logging off to signout.aspx until CU9. To be clear, CU8 will actually contain the new signout.aspx page, but the code will continue to send users logging off to logon.aspx.
So all references to CU8 in the post below have been changed to CU9. All references to CU9 changed to CU10, and so on. Hopefully that’s not too confusing.
Now just between us, if you really want to take advantage of this new code in CU8 you can! As the code snippet below indicates (in which we have also corrected a small mistake), you can remark the line in web.config to ‘LegacyLogOff’ (or indeed set it to any value except “LegacyLogOff”, even removing the line completely has the same effect) and you will send users logging off to signout.aspx. Just be careful when you make these changes, and remember the upgrade order comments further down, they all still apply. Here’s a small table to make this all a little easier to grasp:

понедельник, 20 июля 2015 г.

TMG OWA logoff


On any TMG publishing rules, on the Application Settings tab, modify the "Published server logoff URL" to be "owa/auth/signout.aspx".
Then, on any CAS servers, navigate to and open
%ExchangeInstallPath%\Frontend\HttpProxy\OWA\web.config
and delete this line:
<add key="LogonSettings.SignOutKind" value="LegacyLogOff" />
Thirdly, on any mailbox servers, navigate to these files
%ExchangeInstallPath%\ClientAccess\OWA\web.config
%ExchangeInstallPath%\ClientAccess\ECP\web.config
and delete the same line from both files.
Lastly, do an IISreset on each affected server.

пятница, 17 октября 2014 г.

How to use Kerberos Constrained Delegation with Forefront TMG

Using TMG, one-time passwords and Kerberos Constrained Delegation

How to configure TMG for SSL Client Certificate Authentication

Right click on the listener that you created before and select the “Authentication” tab.
SSL Client Certificate Authentication
Select “SSL Client Certificate Authentication” from the dropdown menu. You can only choose “Windows Active Directory” to validate the credentials.

Fortigate — достойная замена уходящему Microsoft Forefront TMG

Kerberos Constrained Delegation in ISA Server 2006

Публикация web-сайтов через ISA с использованием KDC

Configuring Exchange Server for Kerberos constrained delegation

In this scenario, to use Kerberos constrained delegation, the virtual directory used for Outlook Web Access on all the Exchange servers in your deployment (the /Exchange virtual directory in this solution) must be configured to accept Kerberos authentication, and Kerberos constrained delegation must be enabled on your Exchange servers. If your deployment includes both Exchange front-end and back-end servers, your Exchange front-end servers must be configured as front-end servers that support Kerberos constrained delegation.

пятница, 8 августа 2014 г.

Публикация приложений Exchange 2013 через Web Application Proxy в Server 2012 R2

Релиз Windows Server 2012 R2 принес много вкусностей, в том числе и средство публикации Web Application Proxy. Когда я узнал, что сначала Forefront TMG а потом и UAG выводят из разработки, мне не было понятно какими продуктами Microsoft закроет дырку в продуктах. Выход WAP расставил все по местам, и сей час я вижу платформу готовую к использованию в корпоративной среде. Конечно же, если сей час сравнивать WAP и TMG в вопросах более тонкой публикации, TMG будет превосходить, но в будущем, скорее всего, стоит ожидать исправления этой ситуации.

Источник: здесь

TMG - редирект HTTP запросов на HTTPS/OWA

Данный метод я использую для перенаправления HTTP запросов к моему TMG серверу на 443 порт. В основном это будет нашим заблудшим пользователям, забывшим написать букву S в протоколе доступа.

среда, 18 июня 2014 г.

https://technet.microsoft.com/en-us/library/cc995178.aspx

Publishing multiple Web sites over HTTPS

To publish multiple Web sites over HTTPS

  1. In the Forefront TMG Management console tree, click Firewall Policy.
  2. In the task pane, click the Toolbox tab.
  3. On the Toolbox tab, click Network Objects, click New, and then select Web Listener to open the New Web Listener Wizard.
  4. Complete the New Web Listener Wizard as outlined in the following table.

четверг, 31 января 2013 г.

Миграция с ISA 2004/2006 на Forefront TMG


На смену Internet Security & Acceleration (ISA) Server пришел Forefront Threat Management Gateway (TMG).

В данном переводе мы рассмотрим процесс перехода с ISA 2004/2006 на Forefront TMG.

ISA Server 2004/2006 не предусматривает перехода на TMG обычным обновлением — FF TMG работает только на 64-битных ОС семейства Windows, тогда как ISA — только на 32-битных.

среда, 13 июня 2012 г.

Настройка уведомлений о событиях по электронной в TMG 2010


В данной статье мы рассмотрим как настроить уведомления по электронной почты для определенных событий Microsoft Threat Management Gateway 2010 (TMG 2010).

Для создания уведомления откройте консоль управления TMG и перейдите в узел Monitoring. Далее в правой панели нажмите на ссылку Configure Alert Definitions

Очистка DNS кэша Forefront TMG


В случае если вы измените А запись для определенного DNS хоста на вашем локальном DNS сервере, Forefront TMG не будет сразу использовать обновленную DNS запись, даже в том случае, если вы выполните команду ipconfig /flushdns .  Данная команда работает только для локально залогиненного пользователя. DNS запись будет обновлена только после истечению TTL записи (которую можно посмотреть и изменить на вашем локальном DNS сервере, который использует TMG). Если вы хотите ускорить процесс, выполните следующие инструкции:

пятница, 1 июня 2012 г.

TMG 2010 зависание при загрузке


TMG is taking more than 16 minutes to start on Windows 2008 R2

Yeah, ok today is not an OpsMgr post but about “Microsoft Forefront Threat Management Gateway server” (TMG).
Because there is almost nothing known about this strange issue I described the steps which I did to solve the case.
I had 6 Windows 2008 R2 server (for TMG) deployed in a ESX environment in which I have installed TMG with a single adapter. I was successful in installing TMG, defining the internal network etc, however when I restart the server for the first time after initial configuration, it takes approx. 16 minutes at the “Applying Computer Settings” which is very slow. After these 16 minutes I can login but the TMG Services are stopped.