TMG has three clients: Web Proxy, firewall client, and ScureNAT. The Web proxy and firewall client support identity authentication.
Note: whether it is Web proxy client or fireproof client identity authentication, the user uses the account and password when logging on to connect to TMG and then perform identity verification, after the local database (SAM) of TMG or the Active Directory database is verified, you can access the Internet normally.
The following figure shows the network topology. the TMG has been added to the domain to facilitate user authentication.
Objective: To test the identity authentication of the domain client bob and the workgroup client Peter for accessing the Internet, respectively.
In the previous blog, win701 is a domain client that can access the Internet. We can directly modify the firewall policy and adjust the user.
Create a local user peter on TMG
Locate the user in the TMG toolbox and select "new"
Give a user Set Name: Web
Add windows users and groups
Add domain user bob and workgroup user peter
For example
After creating a user set, we directly modify the default Web Access Policy (this policy is automatically created after the TMG wizard is completed), delete all users, and add the web user set.
View the authentication method of the Web proxy client
Test Client Authentication
After logging on to the win701 domain client as the domain administrator, you cannot access the Internet.
If the domain user bob is successfully logged on to Sina
Successfully accessed the MSN homepage using workgroup peter.