A high-level overview of network adapter configuration best practice is provided below:
Based upon these best practices, the configuration shown below is a tried and tested approach that can be used as part of a TMG Enterprise Edition deployment.
For deployments with a single network adapter, the following actions are recommended:
Rename all network adapters to descriptive names that ideally match the TMG network names. With TMG Enterprise Edition, it is recommended to add a dedicated Intra-Array network adapter. Therefore, we need to consider this additional adapter in the configuration steps, but TMG is still considered as a unihomed deployment. For example:
Internal Network Intra-Array Network
Internal Network Adapter
Please Note: By disabling the 'File and Print Sharing for Microsoft Networks' binding on the TMG internal adapter it will prevent you from connecting to shares on the TMG computer, irrespective of TMG system policy or other custom rules that may allow it. This approach is recommended for better security, as TMG should not be accessible as a file server, but this is an optional step.
Please Note: In the event that you are not using a dedicated Intra-Array network adapter, it is recommended to leave the 'File and Print Sharing for Microsoft Networks' binding at the default setting of Enabled on the Internal Network adapter.
Intra-Array Network Adapter
Edit the network adapter bind order to place the Internal Network adapter at the top (highest) position and the Intra-Array Network adapter should be placed directly below it. For example:
Internal Network (Highest) Intra-Array Network (Next Highest)
For deployments with multiple network adapters, the following actions are recommended:
Rename all network adapters to descriptive names that ideally match the TMG network names. For example:
Internal Network Intra-Array Network Anonymous Access Perimeter/DMZ Network Authenticated Access Perimeter/DMZ Network External Network
Perimeter/DMZ Network Adapters
External Network Adapter
Edit the network adapter bind order to place the Internal Network adapter at the top (highest) position, the Intra-Array Network adapter next, the Perimeter/DMZ Network adapters next and the External Network at the bottom (lowest) position. For example:
Internal Network (Highest) Intra-Array Network (Next Highest) Perimeter/DMZ Network(s) …others… External Network (Lowest)
This article was originally written by:
Jason Jones, Forefront MVP Principal Security Consultant Silversands Limited -------- My Forefront Edge Blog: http://blog.msedge.org.uk/ My TMG Blog: http://blog.msfirewall.org.uk/ MVP Profile: https://mvp.support.microsoft.com/profile/Jason.Jones Twitter: http://twitter.com/jjatsilversands
Maheshkumar S Tiwari edited Revision 1. Comment: Added tags and minor formatting
Maheshkumar S Tiwari edited Original. Comment: Added TOC