The company has multiple internal websites that provide external services at the same time, such as Web1 and Web2, and users who want the public network to access them through port 80, generally, the vro can only map 80 to Web1, while Web2 cannot use port 80 for access. However, the TMG is powerful and can use port 80 to access multiple sites within the enterprise, that is, an 80 listener corresponds to multiple websites.
The network topology, for example, Web1 and Web2, has been added to the domain abc.com.
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/1603014I3-0.png "" 700 "height =" 305 "/>
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/1603012450-1.png "" 732 "height =" 154 "/>
Tutorial ideas:
1. Set up the most basic website points for Web1 and Web2
2. TMG released multiple sites
3. Use a PC with the same network segment as the TMG external Nic to simulate a public network client, use the hosts file for domain name resolution, and test whether a port 80 can be used to access multiple Web sites on the Intranet.
Build a Web site
Since this part is very simple, I will not demonstrate it. I will directly access the two sites I set up to see if they are successful, such as accessing Web1.
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/1603014157-2.png "" 654 "height =" 491 "/>
Access Web2
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/160301H21-3.png "" 654 "height =" 490 "/>
As shown in, add two A records to the dc dns.
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/16030160S-4.png "" 654 "height =" 489 "/>
TMG released multiple site sites: Web1 and Web2
For example, select "Publish Website" in the task"
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/160301H03-5.png "" 654 "height =" 487 "/>
The name of the Web Publishing rule: Publish Web1 and Web2.
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/1603015M6-6.png "" 654 "height =" 489 "/>
Allow
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/1603015294-7.png "" 634 "height =" 472 "/>
Select "Publish multiple websites"
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/160301MD-8.png "" 654 "height =" 490 "/>
Select "add"
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/1603015M2-9.png "" 654 "height =" 492 "/>
For example, add Web1 and Web2
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/1603013b1-10.png "" 654 "height =" 491 "/>
After adding the image, select "Next" as follows"
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/1603011253-11.png "" 654 "height =" 488 "/>
Public name suffix, enter the Domain Name: abc.com, and select "Next"
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/1603012557-12.png "" 654 "height =" 491 "/>
Because we do not have a listener, select "new"
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/160301G58-13.png "" 654 "height =" 488 "/>
Random name
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/16030111E-14.png "" 654 "height =" 493 "/>
Select the type of connection that the Web listener will establish with the client. We select "No SSL secure connection needs to be established with the client"
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/1603011118-15.png "" 654 "height =" 489 "/>
Select the external address for the Web Listener listener"
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/160301DM-16.png "" 654 "height =" 490 "/>
Select how the client authenticates Forefront TMG and how Forefront TMG authenticates its creden, and select "no authentication"
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/1603016152-17.png "" 654 "height =" 491 "/>
Select next by default.
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/160301L32-18.png "" 654 "height =" 492 "/>
Create a listener
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/1603016107-19.png "" 654 "height =" 488 "/>
Select "Next"
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/16030142S-20.png "" 654 "height =" 488 "/>
Select Forefront as the method used to connect to the published Web server for authentication, and select "No delegates, the client cannot perform direct authentication", because our Web site does not require authentication, in my experiment, both Web1 and Web2 enable Anonymous Authentication.
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/1603016224-21.png "" 639 "height =" 478 "/>
User set, which defaults to all users
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/1603012Z5-22.png "" 654 "height =" 488 "/>
If the selection is complete, we can test the rules.
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/1603012641-23.png "" 654 "height =" 489 "/>
For example, neither Web1 nor Web2 can be tested. Why? In fact, this is the case. Our tmg dns points to the public network DNS server. Gu cannot resolve the IP address corresponding to the internal website domain name. How can this problem be solved?
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/1603014195-24.png "" 654 "height =" 491 "/>
Don't worry. Let's take a look at the rules that appear after we finished the wizard. If there are two rules
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/160301M56-25.png "" 654 "height =" 489 "/>
Next, I will solve the problem that the rule test just failed. For example, right-click "attribute" on the rule"
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/1603014R0-26.png "" 654 "height =" 492 "/>
In "to", enter the IP address of Web1, apply, OK, and test the rule.
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/1603011142-27.png "" 654 "height =" 492 "/>
For example, after entering the IP address, Web1 will be tested successfully, and the same Web2 will also be filled in with the IP address, and I will not be able
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/160301J13-28.png "" 654 "height =" 493 "/>
Above, we have completed a TMG listener 80 and released two sites.
Client Test
For example, modify the following in the XP hosts file:
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/1603015218-29.png "" 654 "height =" 489 "/>
For example, XP successfully accesses Web1 after entering the domain name web1.abc.com.
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/1603014503-30.png "" 654 "height =" 492 "/>
For example, xp successfully accesses Web2 after entering Web2.abc.com.
650) this. width = 650; "title =" image "style =" border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; border-left: 0px; padding-right: 0px "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/16030113T-31.png "" 654 "height =" 495 "/>