- Set up alternate access mappings for this URL in the SharePoint Central Admin
- Create internal and external DNS for the SharePoint URL
- Internal DNS points to the IP of the SharePoint Server
- External DNS points to the IP of the TMG
- Create the SSL certificate (if not created), and export it to a .PFX
- Import SSL Certificate onto the TMG Server
- Local Computer > Personal Certificates store
- Create New TMG Web Listener
- Launch the Web Listener Wizard
- Create a name identifying the SharePoint site URL in it
- Use SSL
- Choose: Internal
- Select IP Addresses
- Click New
- Click Add IP
- Add the internal IP address of the SharePoint server, click OK
- choose the IP you added, and click the Add button
- Ok
- Next
- Choose the certificate you imported into the server for this site >Next
- HTML Form Authentication > Windows (Active Directory) > Next
- Enable SSO > Type in root domain name > Next
- Finish
- Go into the properties of the Web Listener
- Go to the Connections Tab
- Make sure it's set up for HTTP (80) and HTTPS (443)
- Redirect all traffic from HTTP to HTTPS
- Set up the TMG Firewall Rule
- Right Click on Firewall Rules > New > SharePoint site Publishing Rule
- Type in the URL of your SharePoint site set up in internal DNS
- Pick either single server, or balanced, depending how your SharePoint architecture is built. I will pick single for these directions.
- Do Not use SSL
- Type in the internal DNS name to get to the site
- Type in the internal DNS name to get to the site
- Choose the listener you set up > Next
- Authentication Delegation: Keep default > Next
- Choose: SharePoint AAM is already configured on the server > Next
- Keep All Authenticated Users > Next
- Finish
Set up TMG for SharePoint on-prem
These are the step you should use to set up your SharePoint site in your Threat Management Gateway (TMG)
0 comments:
Post a Comment
Note: Only a member of this blog may post a comment.