Quantcast
Viewing all articles
Browse latest Browse all 3822

Problem Setting Load Balanced FFTMG 2010 as a gateway

Please help me.

 I have successfully implemented two Microsoft Forefront TMG 2010 servers in a load balanced environment as a reverse proxy for several web servers. The TMG1 IP:xxx.xxx.xxx.43, TMG2 IP: xxx.xxx.xxx.44 and the shared TMG IP:xxx.xxx.xxx.45. The web server is configured with internal IP WEB1:xxx.xxx.xxx.183 and WEB2:xxx.xxx.xxx.187. All TMG servers and web servers are configured with gateway IP:xxx.xxx.xxx.254. Both web servers are clustered Domino Servers. At TMG, both web servers are configured as Web Farm. Everything is working fine and both LAN and internet users are able to access the web server via http and https to url myfinance.domain.com.

<image removed>

The problem came when the web server needs to see the client IP. For this to happen, i have to configure the following:

 1. Both web servers need to reconfigure the gateway IP from xxx.xxx.xxx.254 to xxx.xxx.xxx.45 - now the web servers are pointing to TMG as a gateway.

 2. Subsequently,at the main Firewall/Gateway (xxx.xxx.xxx.254) i am creating two static routes to both web servers to use xxx.xxx.xxx.45 as gateway.

 3. Finally, I am setting the TMG to forward the original client ip to the web servers as shown below.

<image removed>

The above setting makes client IP visible to WEB1 and WEB2. However, it is not functioning well and the following are the diagnosis and symptom:

 1.  At any point of time, one of the TMG server does not function. For example, if TMG1 is working then TMG2 is not working. Therefore if a client requesting to access myfinance.domain.com and being processed by TMG1 the client will not experience any problem whereas if it is processed by TMG2, then the client will experience request timeout.

 2. Further to this, if the TMG1 is drained, TGM2 will work fine. Subsequent to that, if TMG2 is drained, TMG1 will work fine.

 3. A simple ping from WEB1 (linux) and WEB2 (linux) to external IP will produce duplicate IP.

 Am I doing something wrong? Is the intended outcome not supported by FFTMG 2010? Is there any workaround? Please help.

 Thanks.


Viewing all articles
Browse latest Browse all 3822

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>