Microsoft Forefront Threat Management Gateway (Forefront TMG), formerly known as Microsoft Internet Security and Acceleration Server (ISA Server), is a discontinued network
router,
firewall,
antivirus program
Antivirus software (abbreviated to AV software), also known as anti-malware, is a computer program used to prevent, detect, and remove malware.
Antivirus software was originally developed to detect and remove computer viruses, hence the name. ...
,
VPN server and
web cache from
Microsoft Corporation. It ran on
Windows Server and works by inspecting all network traffic that passes through it.
Features
Microsoft Forefront TMG offers a set of features which include:
# Routing and remote access features: Microsoft Forefront TMG can act as a
router, an Internet
gateway, a
virtual private network
A virtual private network (VPN) extends a private network across a public network and enables users to send and receive data across shared or public networks as if their computing devices were directly connected to the private network. The be ...
(VPN) server, a
network address translation (NAT) server and a
proxy server.
# Security features: Microsoft Forefront TMG is a
firewall which can inspect network traffic (including web content,
secure web content and emails) and filter out
malware
Malware (a portmanteau for ''malicious software'') is any software intentionally designed to cause disruption to a computer, server, client, or computer network, leak private information, gain unauthorized access to information or systems, depri ...
, attempts to exploit security
vulnerabilities and content that does not match a predefined security policy. In technical sense, Microsoft Forefront TMG offers
application layer protection,
stateful filtering,
content filtering
An Internet filter is software that restricts or controls the content an Internet user is capable to access, especially when utilized to restrict material delivered over the Internet via the Web, Email, or other means. Content-control software dete ...
and
anti-malware protection.
# Network performance features: Microsoft Forefront TMG can also improve network performance: It can compress web traffic to improve communication speed. It also offers
web caching: It can cache frequently-accessed web content so that users can access them faster from the local network cache. Microsoft Forefront TMG 2010 can also cache data received through
Background Intelligent Transfer Service, such as updates of software published on
Microsoft Update website.
History
Microsoft Proxy Server
The Microsoft Forefront Threat Management Gateway product line originated with Microsoft Proxy Server. Developed under the
code-name "Catapult", Microsoft Proxy Server v1.0 was first launched in January 1997,
and was designed to run on
Windows NT 4.0. Microsoft Proxy Server v1.0 was a basic product designed to provide Internet Access for clients in a LAN Environment via
TCP/IP. Support was also provided for IPX/SPX networks (primarily used in legacy
Novell NetWare environments), through a
WinSock translation/tunnelling client which allowed TCP/IP applications, such as web browsers, to operate transparently without any TCP/IP on the wire. Although well-integrated into Windows NT4,
Microsoft Proxy Server v1.0 only had basic functionality, and came in only one edition. Extended support for Microsoft Proxy Server v1.0 ended on 31 March 2002.
Microsoft Proxy Server v2.0 was launched in December 1997,
and included better NT Account Integration, improved
packet filtering
In computing, a firewall is a network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules. A firewall typically establishes a barrier between a trusted network and an untrusted ne ...
support, and support for a wider range of
network protocols. Microsoft Proxy Server v2.0 exited the extended support phase and reached
end of life End-of-life may refer to:
* End-of-life (product), a term used with respect to terminating the sale or support of goods and services
* End-of-life care, medical care for patients with terminal illnesses or conditions that have become advanced, prog ...
on 31 December 2004.
ISA Server 2000
On 18 March 2001, Microsoft launched Microsoft Internet Security and Acceleration Server 2000 (ISA Server 2000).
ISA Server 2000 introduced the ''Standard'' and ''Enterprise'' editions, with Enterprise-grade functionality such as High-Availability
Cluster
may refer to:
Science and technology Astronomy
* Cluster (spacecraft), constellation of four European Space Agency spacecraft
* Asteroid cluster, a small asteroid family
* Cluster II (spacecraft), a European Space Agency mission to study th ...
ing not included in the Standard Edition. ISA Server 2000 required
Windows 2000 (any edition), and will also run on
Windows Server 2003. In accordance with Microsoft's Support Lifecycle Policy, ISA Server 2000 was the first ISA Server product to use the 10-year support lifecycle with 5 years of ''Mainstream'' support and five years of ''Extended'' support. ISA Server 2000 reached End of Life on 12 April 2011.
ISA Server 2004
Microsoft Internet Security and Acceleration Server 2004 (ISA Server 2004) was released on 8 September 2004.
ISA Server 2004 introduced multi-networking support, integrated virtual private networking configuration, extensible user and authentication models,
application layer firewall support,
Active Directory integration,
SecureNAT, and improved reporting and management features. The rules based configuration was also considerably simplified over ISA Server 2000 version.
ISA Server 2004 Enterprise Edition included array support, integrated
Network Load Balancing (NLB), and
Cache Array Routing Protocol (CARP). One of the core capabilities of ISA Server 2004, dubbed Secure Server Publishing, was its ability to securely expose their internal servers to Internet. For example, some organizations use ISA Server 2004 to publish their
Microsoft Exchange Server services such as
Outlook Web Access
Outlook on the web (previously known as Exchange Web Connect, Outlook Web Access, and Outlook Web App) is a personal information manager web app from Microsoft. It includes a web-based email client, a calendar tool, a contact manager, and a ta ...
(OWA),
Outlook Mobile Access (OMA) or
ActiveSync
ActiveSync is a mobile data synchronization app developed by Microsoft, originally released in 1996. It synchronizes data with handheld devices and desktop computers. In the Windows Task Manager, the associated process is called wcescomm.exe.
O ...
. Using the ''Forms-based Authentication'' (''FBA'') authentication type, ISA Server can be used to pre-authenticate web clients so that traffic from unauthenticated clients to published servers is not allowed.
ISA Server 2004 is available in two editions, Standard and Enterprise. Enterprise Edition contains features enabling policies to be configured on an array level, rather than on individual ISA Servers, and load-balancing across multiple ISA Servers. Each edition of ISA Server is licensed per processor. (The version included in Windows Small Business Server 2000/2003 Premium includes licensing for 2 processors.)
ISA Server 2004 runs on
Windows Server 2003 Standard or Enterprise Edition. Appliance hardware containing Windows Server 2003 Appliance Edition and ISA Server Standard Edition is available from a variety of Microsoft Partners.
ISA Server 2006
Microsoft Internet Security and Acceleration Server 2006 (ISA Server 2006) was released on 17 October 2006.
It is an updated version of ISA Server 2004, and retains all features from ISA Server 2004 except Message Screener.
ISA Server 2006 introduced new features including:
* Support for
Exchange Server 2007 (referred to as "Exchange 12" in the Microsoft ISA Server 2006 Evaluation Guide)
* New configuration wizards for various tasks such as setting up a "site-to-site VPN connection", publishing SharePoint services, publishing websites, creating firewall rules.
* Introduction of
single sign-on for groups of published web sites.
* Improvements to user authentication including the addition of
LDAP Authentication support
* Resistance to
flood attack
In computing, a denial-of-service attack (DoS attack) is a cyber-attack in which the perpetrator seeks to make a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host con ...
s, to protect the ISA server from being "unavailable, compromised, or unmanageable during a flooding attack."
* Performance features such as
BITS Caching, Web Publishing Load Balancing and
HTTP compression.
ISA Server Appliance Edition
Microsoft also offered ISA Server 2006 Appliance Edition. It was designed to be pre-installed onto OEM hardware (
server appliances) that are sold by hardware manufacturers as a stand-alone firewall type device. Along with Appliance Edition, ISA server 2006 Standard Edition and Enterprise Edition were available in preconfigured hardware.
Microsoft Forefront TMG MBE
Microsoft Forefront Threat Management Gateway Medium Business Edition (Forefront TMG MBE) is the next version of ISA Server which is also included with
Windows Essential Business Server. This version only runs on the 64-bit edition of
Windows Server 2008 and does not support Enterprise edition features such as array support or Enterprise policy. Mainstream support for Forefront TMG MBE ended on 12 November 2013.
Microsoft Forefront TMG 2010
Microsoft Forefront Threat Management Gateway 2010 (Forefront TMG 2010) was released on 17 November 2009.
It is built on the foundation of ISA Server 2006 and provides enhanced web protection, native 64-bit support, support for
Windows Server 2008 and
Windows Server 2008 R2, malware protection and BITS caching.
Service Pack
In computing, a service pack comprises a collection of updates, fixes, or enhancements to a software program delivered in the form of a single installable package. Companies often release a service pack when the number of individual patches to a ...
1 for this product was released on 23 June 2010.
It includes several new features to support
Windows Server 2008 R2 and
SharePoint 2010 lines of products.
Service Pack 2 for this product was released on 10 October 2011.
On 9 September 2012 Microsoft announced no further development will take place on Forefront Threat Management Gateway 2010 and the product will no longer be available for purchase as of 1 December 2012. Mainstream support ceased on 14 April 2015 and extended support has ended on 14 April 2020.
See also
*
Microsoft Servers
*
Microsoft Forefront
Microsoft Forefront is a discontinued family of line-of-business security software by Microsoft Corporation. Microsoft Forefront products are designed to help protect computer networks, network servers (such as Microsoft Exchange Server and ...
*
Microsoft Forefront Unified Access Gateway
Microsoft Forefront Unified Access Gateway (UAG) is a discontinued software suite that provides secure remote access to corporate networks for remote employees and business partners. Its services include reverse proxy, virtual private network (VPN ...
References
External links
*
TMG TechCenterForefront TMG (ISA Server) Product Team BlogRichard Hicks' Forefront TMG Blog
{{Firewall software
Forefront Threat Management Gateway
Firewall software
Computer security software
Proxy servers
1997 software
Content-control software