openssl pkcs12 -export -certpbe PBE-SHA1-3DES -keypbe PBE-SHA1-3DES -nomac -inkey contoso.com.key -in contoso.com.crt -out contoso.com-legacy.pfx
"Есть люди, которым труднее других. И на них обязанность быть лучше. Другим сходит с рук, а им нет… Это вроде бы каждый обязан. Но если человек решился жить по мечте, то он обязан вдвойне. Потому что большинство по мечте жить трусит… Или благоразумие мешает. А те, кто живет по мечте, — они вроде примера. Или укора". Олег Куваев.
Показаны сообщения с ярлыком TMG. Показать все сообщения
Показаны сообщения с ярлыком TMG. Показать все сообщения
четверг, 18 сентября 2025 г.
Как сконвертировать сертификат из pem в pfx Windows 2008 R2, Windows Server 2012 R2
понедельник, 6 июня 2016 г.
Повреждена конфигурация TMG
How To Recover Forefront TMG From a Corrupt Configuration Database
We all know it is good practice to keep regular Forefront TMG configuration backups as they help you recover your deployment quickly and accurately in case of a failure or miss configuration. There is however a scenario where these backups cannot be restored to bail you out. When Forefront TMG has a corrupt configuration database, the backup and restore mechanism itself is broken and as such you need to fix this first before you can recover from backup.
четверг, 26 ноября 2015 г.
Публикация RDWEB через TMG с использованием HTTP аутентификации
Вот
статьи по которым я публикацию вчера делал (с авторизацией по HTTP)
http://www.isaserver.org/articles-tutorials/configuration-general/Microsoft-Forefront-TMG-Publishing-RD-Web-Access-RD-Gateway-Part2.html
четверг, 5 ноября 2015 г.
не пингуется TMG из ipsec
При этом остальные хосты пингует
Выполнить:
netsh tmg set global
name=DontDropIPSECDetunneledTrafficToLocalhost value=1 persistent
Источник: https://support.microsoft.com/en-us/kb/2502685
Источник: https://support.microsoft.com/en-us/kb/2502685
четверг, 30 июля 2015 г.
Exchange 2013 OWA logoff via TMG
Update - 2/9/15: Since publishing this blog we made a
decision to push one aspect of this change to CU9 to allow some partners a
little more time to adapt to this new behavior. The new signout.aspx code is
still shipping in CU8, but we are not changing to the new logoff behavior, that
is sending the user logging off to signout.aspx until CU9. To be clear, CU8
will actually contain the new signout.aspx page, but the code will continue to
send users logging off to logon.aspx.
So all references to CU8 in the post
below have been changed to CU9. All references to CU9 changed to CU10, and so
on. Hopefully that’s not too confusing.
Now just between us, if you really want
to take advantage of this new code in CU8 you can! As the code snippet below
indicates (in which we have also corrected a small mistake), you can remark the
line in web.config to ‘LegacyLogOff’ (or indeed set it to any value except
“LegacyLogOff”, even removing the line completely has the same effect) and you
will send users logging off to signout.aspx. Just be careful when you make
these changes, and remember the upgrade order comments further down, they all
still apply. Here’s a small table to make this all a little easier to grasp:
понедельник, 20 июля 2015 г.
TMG OWA logoff
On any TMG publishing rules, on the Application Settings tab, modify the "Published server logoff URL" to be "owa/auth/signout.aspx".
Then, on any CAS servers, navigate to and open
%ExchangeInstallPath%\Frontend\HttpProxy\OWA\web.config
and delete this line:
<add key="LogonSettings.SignOutKind" value="LegacyLogOff" />
Thirdly, on any mailbox servers, navigate to these files
%ExchangeInstallPath%\ClientAccess\OWA\web.config
%ExchangeInstallPath%\ClientAccess\ECP\web.config
and delete the same line from both files.
Lastly, do an IISreset on each affected server.
пятница, 17 октября 2014 г.
How to configure TMG for SSL Client Certificate Authentication
Right click on the listener that you created before and select the “Authentication” tab.
SSL Client Certificate Authentication
Select “SSL Client Certificate Authentication” from the dropdown menu. You can only choose “Windows Active Directory” to validate the credentials.
Kerberos Constrained Delegation in ISA Server 2006
Публикация web-сайтов через ISA с использованием KDC
Configuring Exchange Server for Kerberos constrained delegation
In this scenario, to use Kerberos constrained delegation, the virtual directory used for Outlook Web Access on all the Exchange servers in your deployment (the /Exchange virtual directory in this solution) must be configured to accept Kerberos authentication, and Kerberos constrained delegation must be enabled on your Exchange servers. If your deployment includes both Exchange front-end and back-end servers, your Exchange front-end servers must be configured as front-end servers that support Kerberos constrained delegation.
вторник, 12 августа 2014 г.
пятница, 8 августа 2014 г.
Публикация приложений Exchange 2013 через Web Application Proxy в Server 2012 R2
Релиз Windows Server 2012 R2 принес много вкусностей, в том числе и средство публикации Web Application Proxy. Когда я узнал, что сначала Forefront TMG а потом и UAG выводят из разработки, мне не было понятно какими продуктами Microsoft закроет дырку в продуктах. Выход WAP расставил все по местам, и сей час я вижу платформу готовую к использованию в корпоративной среде. Конечно же, если сей час сравнивать WAP и TMG в вопросах более тонкой публикации, TMG будет превосходить, но в будущем, скорее всего, стоит ожидать исправления этой ситуации.
Источник: здесь
Источник: здесь
TMG - редирект HTTP запросов на HTTPS/OWA
Данный метод я использую для перенаправления HTTP запросов к моему TMG серверу на 443 порт. В основном это будет нашим заблудшим пользователям, забывшим написать букву S в протоколе доступа.
среда, 18 июня 2014 г.
https://technet.microsoft.com/en-us/library/cc995178.aspx
Publishing multiple Web sites over HTTPS
To publish multiple Web sites over HTTPS
- In the Forefront TMG Management console tree, click Firewall Policy.
- In the task pane, click the Toolbox tab.
- On the Toolbox tab, click Network Objects, click New, and then select Web Listener to open the New Web Listener Wizard.
- Complete the New Web Listener Wizard as outlined in the following table.
пятница, 1 февраля 2013 г.
HTML-формы ISA 2006
Источник: http://blog.msfirewall.org.uk/2008/11/customising-isa-server-2006-html-forms.html
Источник: http://www.exchange-genie.com/2009/01/creating-custom-isa-logon-page/
У меня сделаны красивые формы в стиле OWA 2010. Если нужно, обращайтесь.
Источник: http://www.exchange-genie.com/2009/01/creating-custom-isa-logon-page/
У меня сделаны красивые формы в стиле OWA 2010. Если нужно, обращайтесь.
четверг, 31 января 2013 г.
Миграция с ISA 2004/2006 на Forefront TMG
В данном переводе мы рассмотрим процесс перехода с ISA 2004/2006 на Forefront TMG.
ISA Server 2004/2006 не предусматривает перехода на TMG обычным обновлением — FF TMG работает только на 64-битных ОС семейства Windows, тогда как ISA — только на 32-битных.
среда, 13 июня 2012 г.
Настройка уведомлений о событиях по электронной в TMG 2010
В данной статье мы рассмотрим как настроить уведомления по электронной почты для определенных событий Microsoft Threat Management Gateway 2010 (TMG 2010).
Для создания уведомления откройте консоль управления TMG и перейдите в узел Monitoring. Далее в правой панели нажмите на ссылку Configure Alert Definitions
Очистка DNS кэша Forefront TMG
В случае если вы измените А запись для определенного DNS хоста на вашем локальном DNS сервере, Forefront TMG не будет сразу использовать обновленную DNS запись, даже в том случае, если вы выполните команду ipconfig /flushdns . Данная команда работает только для локально залогиненного пользователя. DNS запись будет обновлена только после истечению TTL записи (которую можно посмотреть и изменить на вашем локальном DNS сервере, который использует TMG). Если вы хотите ускорить процесс, выполните следующие инструкции:
пятница, 1 июня 2012 г.
TMG 2010 зависание при загрузке
TMG is taking more than 16 minutes to start on Windows 2008 R2
Yeah, ok today is not an OpsMgr post but about “Microsoft Forefront Threat Management Gateway server” (TMG).
Because there is almost nothing known about this strange issue I described the steps which I did to solve the case.
Because there is almost nothing known about this strange issue I described the steps which I did to solve the case.
I had 6 Windows 2008 R2 server (for TMG) deployed in a ESX environment in which I have installed TMG with a single adapter. I was successful in installing TMG, defining the internal network etc, however when I restart the server for the first time after initial configuration, it takes approx. 16 minutes at the “Applying Computer Settings” which is very slow. After these 16 minutes I can login but the TMG Services are stopped.
Подписаться на:
Сообщения (Atom)