■
The ISA/TMG server retrieves new pages or files from the internet , and passes them
back to the Web Appliance
.
■
The Web Appliance
receives the allowed pages or files, caches them, and passes them on
to the users .
■
The users receive only safe and allowed pages and files or a notification page.
Configuration
Follow the configuration instructions for the basic network deployment scenario that you want to
use—Explicit Deployment, Transparent Deployment, or Bridged Deployment—but locate your
Web Appliance between the ISA/TMG server and your users.
Note: Even if you have an upstream proxy (a proxy between the Web Appliance and the internet)
configured, you still need to configure the Web Appliance with access to your organization’s DNS
server, which is set on the Configuration > Network > Network Interface page.
Note: A simple way to set up load balancing amongst multiple Web Appliances is to set up a
DNS round robin scheme. If you do this, you should disable DNS caching because Windows DNS
caching can mask the round robin effect. Also, you must ensure that you have a firewall with
network address translation (NAT), but not an ISA/TMG server in firewall mode, between the Web
Appliances and the internet. This firewall must be configured to present a single IP for the Web
Appliances to external sites. The NAT, or IP masquerading, prevents sites that check and record
the IP address of visitors in cookies from encountering multiple IP addresses. To disable Windows
DNS caching, see the Microsoft support article
http://support.microsoft.com/kb/318803
.
Note: Explaining how to configure an ISA/TMG server is beyond the scope of this documentation.
For details on ISA/TMG server configuration, see Microsoft’s
Microsoft Forefront TMG Deployment
page.
Related tasks
on page 35
on page 25
Related information
Disabling Client-Side DNS Caching
Microsoft ISA Server Deployment
Microsoft Forefront TMG Deployment
2.3.7 Integrating with Sophos Email Products
The appliance can be configured to work with Sophos’s email products, such as the Sophos Email
Appliances or PureMessage for UNIX. The instructions for doing so are listed below.
■
To configure your Sophos Web or Management Appliance to route email via your Sophos
Email Appliance:
a) On your Sophos Web or Management Appliance, on the Configuration > Network >
Hostname page, enter the IP address of your Email Appliance in the Outgoing SMTP
mail server text box.
b) On your Sophos Email Appliance, on the Configuration > Routing > Internal Mail Hosts
page, enter the IP address of your Web or Management Appliance in the Internal hosts
and networks text box, and click Add.
Sophos Web Appliance | Getting Started | 37