Wednesday, February 24, 2010

 

Increase DirectAccess Deployablility

 

 

Feed: Forefront Experts
Posted on: Monday, February 15, 2010 11:39 AM
Author: Hal Berenson
Subject: Increasing DirectAccess Deployability
 

Andrew Garcia over at eWeek has written an excellent article describing his experience testing Microsoft Forefront UAG 2010's capabilities for assisting deployment of Microsoft Windows' DirectAccess.  I thought I'd add a little color commentary to the deployment topic..

A little over a year before the release of Windows 7 and Windows Server 2008 R2 the UAG team looked at what it could do to incorporate DirectAccess as a technology in its overall "access" mission.  Later, a Microsoft-wide virtual team looked into what we could do to accelerate DirectAccess deployment.  These two activities have already born fruit, both in new features in UAG 2010 and the new DirectAccess Connectivity Assistant.

As an example, one of the key features UAG brings to the DirectAccess deployment story is support for the DNS64 and NAT64 IPv6 transition technologies.  The "64" refers to "6-to-4", as in IPv6 to IPv4 (as oppsed to the common usage implying something to do with 64-bits).  DNS64 and NAT64 are the latest technologies for allowing IPv6 clients to communicate with IPv4 servers.  They are in the process of replacing the earlier DNS-ALG and NAT-PT technologies that were found to be flawed and moved to historical status by the Internet Engineering Task Force (IETF).  As a result of DNS-ALG/NAT-PT's status customers may not be willing to deploy them and vendors (some of whom already support these technologies in shipping products) may not want to advocate their use.  That left a big gap for customers considering deployment of DirectAccess, how to enable communications with servers that only support IPv4?  UAG 2010 stepped in to help and is the first product to bring the newer DNS64 and NAT64 to market.  Others will certainly follow as the need to enable transition to IPv6 becomes more urgent

Although not part of UAG, the Microsoft DirectAccess Connectivity Assistant (DCA) is another important part of our efforts to accelerate DirectAccess deployment.    One piece of feedback we received from early adopters of DirectAccess was that their end-users loved DirectAccess so much that when it didn't work they were quite vocal about their frustration.  Perhaps it worked just fine from their home or hotel, but not when they were in their favorite coffee shop.  The lack of an indicator that DirectAccess was "on" and working properly added to end-user frustration.  The lack of an easy way to gather and deliver diagnostic information to IT, so they could help solve the problem, raised support costs.  DCA displays the status of DirectAccess connections in the Windows 7 notification area, gives the end-user assistance in solving connectivity problems, and provides diagnostic information should IT need to get involved in resolving connectivity problems.  DCA is now available for download on TechNet.

Making products easily deployable is a major focus for the Identity and Security Division and customers should start to see the result as we roll out new products.  For DirectAccess we continue to drive a Microsoft-wide effort to accelerate deployment.  In the short run you'll notice an increasing amount of deployment guidance becoming available.  I urge you to keep an eye on the Forefront UAG Product Team Blog for announcements as well as for hints and deep dives to help with your UAG deployments (DirectAccess and otherwise).


View article...

Wednesday, February 24, 2010 3:51:33 PM (Eastern Standard Time, UTC-05:00)  #    Comments [0]  | 
Tuesday, February 23, 2010

Installing and Configuring the Email Hygiene Solution on the TMG 2010 Firewall

There is a pretty good 3 part tutorial over on ISA Server.org by Deb Shinder on setting up an Email Hygiene solution on the new TMG Firewall.  This is a powerful solution but care must be taken to install things in the right order.  The tutorial provides step by step instructions with screen shots.

Installing and Configuring the Email Hygiene Solution on the TMG 2010 Firewall – Part 1: Installation.

Installing and Configuring the E-mail Hygiene Solution on the TMG 2010 Firewall – Part 2: E-Mail Policy.

Installing and Configuring the Email Hygiene Solution on the TMG 2010 Firewall – Part 3: Configuring AntiSpam Policy.

Tuesday, February 23, 2010 10:04:07 AM (Eastern Standard Time, UTC-05:00)  #    Comments [0]  | 
Friday, February 19, 2010

 

Snowstorms Pummel Worker Productivity, Citrix Survey Finds

 

Published Friday, February 12, 2010 5:27 PM by David Marshall 

 

Behind the traffic pile-ups, cancelled flights and power outages caused by recent record storms in the Middle Atlantic States, there’s another sobering story – the enormous cumulative loss of business productivity caused by employees’ inability to work from home when commuting became impossible. A survey of 500 people in four states and the District of Columbia, commissioned by Citrix Online, found that 52% of respondents have lost six or more hours of work due to this winter’s severe storms; this represents a potential loss of nearly 50 million total man hours of productivity in these states. Half have been forced to cancel or delay a meeting in the last year due to inclement weather. Further, 47% stated they have no technology tools, flex time, telework provisions or alternate assignments to assist when commuting is a problem.

“Enabling your employees to work from anywhere is simple,” said Chuck Wilsker, President and CEO of the Telework Coalition and a member of Citrix Online’s Worldwide Workplace Council. “The keys are to plan ahead, determine the specific needs of your organization, identify best practices for managing your virtual workplace, and using technologies, which are both suited to productivity and can address your benchmarks for success. The first application I ever used that allowed me to work remotely was GoToMyPC and it’s still a wonderful solution. Citrix Online’s Worldwide Workplace Council has authored a paper outlining the five steps to a virtual workplace program.”

For example, Ira H. Siegal, CPA, of Bala Cynwyd, Pennsylvania, an affiliate of 123College.com, inc., turned to GoToMeeting     when he saw that snow threatened to prevent attendees from coming to a seminar last week. He recalled, “As I watched the snow get deeper, some of the people who had registered to attend my seminar started to question whether it would occur. I polled them, and they said they would have trouble shoveling out their cars and navigating the roads to make it to my event. I realized I needed a back-up plan, and decided to conduct an online seminar instead. GoToMeeting     saved the day for me, and allowed me to conduct business from the safety of my home.”

The Citrix Online survey, which covered New York, New Jersey, Pennsylvania, Virginia/D.C., and Maryland, found that 38% of respondents were unable to commute to work at least once during the storms in December 2009 and January and February 2010. For many, this meant a lost day of productivity; results revealed 50% of those surveyed had no work situation away from their office.

For more information about Citrix Online, a division of Citrix Systems, Inc. (NASDAQ: CTXS), or Work Shifting, visit http://www.citrixonline.com/ or http://www.workshifting.com/.

 

Filed under: Survey

Friday, February 19, 2010 8:54:11 AM (Eastern Standard Time, UTC-05:00)  #    Comments [0]  | 

 

Microsoft DirectAccess Connectivity Assistant

 

Feed: Bink.nu
Posted on: Saturday, February 13, 2010 4:48 PM
Author: Steven Bink
Subject: Microsoft DirectAccess Connectivity Assistant

 

Check out the Microsoft DirectAccess Connectivity Assistant, the newest edition to the Windows® Optimized Desktop Toolkit 2010 to help reduce costs and improve the experience of DirectAccess. 

The Microsoft DirectAccess Connectivity Assistant (DCA) helps organizations reduce the cost of supporting DirectAccess users and significantly improve their connectivity experience. This Solution Accelerator is part of the Windows® Optimized Desktop Toolkit 2010 (WODT 2010).

 The Microsoft DirectAccess Connectivity Assistant (DCA) helps organizations reduce the cost of supporting DirectAccess users and significantly improve their connectivity experience.

DCA informs mobile users of their connectivity status at all times; provides tools to help them reconnect on their own if problems arise; and creates diagnostics to help mobile users provide IT staff with key information if necessary—all to help customers operate with more efficiency, and at a lower cost.

DCA is the newest addition to the Windows® Optimized Desktop Toolkit 2010, which is designed to help IT pros plan, deliver, and operate the right desktop technologies for users across their organization.

The download includes the following components:

  • Microsoft_DirectAccess_Connectivity_Assistant.zip
  • Microsoft_DirectAccess_Connectivity_Assistant_x32.msi
  • Microsoft_DirectAccess_Connectivity_Assistant_x64.msi
  • Microsoft_DirectAccess_Connectivity_Assistant_DeploymentGuide.docx
  • Microsoft_DirectAccess_Connectivity_Assistant_Release_Notes.en.htm
  • DirectAccess Connectivity Assistant GP.admx
  • DirectAccess Connectivity Assistant GP.adml

Download details DirectAccess Connectivity Assistant

Send via e-mail | Submit to Digg | Add to Live Favorites

View article...

Friday, February 19, 2010 8:34:40 AM (Eastern Standard Time, UTC-05:00)  #    Comments [0]  | 
Friday, February 12, 2010

Forefront TMG 2010 Email Protection Updates

This recent article was published at Tales from the Edge, that explains how to configure Exchange Sync with Forefront TMG 2010, here it is the link for it: http://technet.microsoft.com/en-us/library/ee513174.aspx. Also, here is a reminder about the supported scenarios with Forefront TMG 2010 and Exchange 2007 Edge role, for the support matrix click here.

From: http://blogs.technet.com/isablog/archive/2009/11/10/email-protection-in-forefront-tmg-2010-release-candidate.aspx

The * on this table says:

Recently a blog post was published by the Exchange team saying that they reconsidered and are planning to support Windows Server 2008 (SP2). To read more about it please follow this link: http://msexchangeteam.com/archive/2009/11/04/453026.aspx

There is a newer update on that, which is the one below:

“…we will be adding support for Exchange 2007 on the Windows Server 2008 R2 platform.   While we had hoped to add this application/operating system combination quickly, unfortunately adding this support requires code changes to setup in Exchange 2007.  Therefore, our vehicle for adding this support will be via a third Service Pack for Exchange 2007 in the second half of calendar year 2010.”

From: http://msexchangeteam.com/archive/2009/11/30/453327.aspx

In other words: If you want to deploy Exchange 2007 Edge role on Forefront TMG 2010 you will need to:

  • Windows Server 2008 SP2
  • Exchange 2007 SP2

If you already installed Forefront TMG 2010 on Windows Server 2008 R2 and want to install Exchange Edge role to enable EMail Protection feature your current supported options are:

  • Install Exchange 2010 Edge Role
  • Wait for Exchange 2007 SP3 to come out so you can install Exchange 2003 Edge Role on Windows Server 2008 R2

Author

Yuri Diogenes
Sr Security Support Escalation Engineer
Microsoft CSS Forefront Edge Team

Technical Review

Noam Ilovich
Program Manager
Microsoft Forefront Edge Team

View article...

Friday, February 12, 2010 1:34:33 PM (Eastern Standard Time, UTC-05:00)  #    Comments [0]  | 

Forefront TMG 2010 Web Protection Services Licensing

Introduction

Forefront TMG 2010 adds two new subscription-based features, known collectively as Forefront TMG Web Protection Services (WPS). These features include URL Filtering (URLF) and Anti-Malware or Enhanced Malware Protection (AM or EMP). One thing that makes these features unique within Forefront TMG is that they are licensed separately from Forefront TMG itself. This blog will discuss the various licensing and purchasing options available for URLF and EMP subscriptions and guide you through managing the license details in Forefront TMG management.

WPS Purchasing and Pricing

The first thing most people want to know is “How do I get a Forefront TMG WPS license and how much does it cost?”

Forefront TMG WPS is subscription product licensed per user or per device.  This subscription is only offered through Microsoft Volume Licensing programs, and must be purchased separately from Forefront TMG 2010. Forefront TMG WPS is included in Forefront Protection Suite and ECAL.  You can find information on purchasing Forefront TMG WPS through Microsoft or a Microsoft partner at http://www.microsoft.com/forefront/threat-management-gateway/en/us/purchase.aspx.

The Forefront TMG WPS pricing structure is outlined in http://www.microsoft.com/forefront/threat-management-gateway/en/us/pricing-licensing.aspx.

Verifying the Evaluation License

You may want to take advantage of Forefront TMG WPS while you wait for your license to arrive; or perhaps you want to give WPS a test drive before you decide whether you want to purchase a license. Regardless, TMG provides a free 120-day trial subscription that goes into effect as soon as you deploy Forefront TMG 2010.

Using the Getting Started Wizard (GSW)

The Getting Started Wizard (GSW) provides one way to configure these options. During this process, you can choose to enable HTTPS Inspection, URLF and EMP as well as whether to use the evaluation license (selected by default). The following steps show you where you make these choices in the GSW.

Note: if the TMG computer is a member of an array, the GSW is not available. In this case, you must use the Without the GSW steps

View article...

Friday, February 12, 2010 1:13:38 PM (Eastern Standard Time, UTC-05:00)  #    Comments [0]  | 
Thursday, February 04, 2010

Still confused about what Direct Access really is and what it can mean for your business?  Bookmark the DirectAccess FAQ for answers to many of your DirectAccess questions.  Learn how your users can be seamlessly and securely connected to your network any time they have an internet connection.  Keep your users up to date with security and system health policies using DirectAccess. 

General | ISA | Microsoft | TMG
Thursday, February 04, 2010 11:04:26 AM (Eastern Standard Time, UTC-05:00)  #    Comments [0]  | 

Announcing the Forefront TMG Best Practices Analyzer Version 8!  This announcement discusses new features and functions found in the latest release of the Best Practices Analyzer tool, including URL Filtering, ISP Redundancy, HTTPS Inspection, Anti-Malware protection and much more!   

Thursday, February 04, 2010 11:02:17 AM (Eastern Standard Time, UTC-05:00)  #    Comments [0]  | 

Forefront TMG Case Studies – Many of our customers will wait a while and look to see how a software product performs in the real world before making the decision to adopt a new technology.  The same goes for the Microsoft Forefront TMG product, the successor to the popular and proven Microsoft ISA technology.  Customers want to know why TMG is being adopted, why they should change from their current ISA platform, and what benefits they will realize when they decide to make the move.  A great way to answer those questions is through real world case studies such as those found here where customer testimonials can help illustrate some of the benefits found in Microsoft TMG. 

Forefront | ISA | Microsoft | TMG
Thursday, February 04, 2010 10:46:46 AM (Eastern Standard Time, UTC-05:00)  #    Comments [0]  | 

Theme design by Jelle Druyts

Pick a theme: