Published by: Indrajit Banerjee on May 20, 2008
Installing the Forefront Threat Management Gateway(Forefront TMG)
If you haven’t heard yet, the ISA Firewall is going away. The last version of the ISAFirewall is going to be ISA 2006. However, that doesn’t mean that the ISA software thatwe’ve come to love over the year is going away. While the ISA brand will fall into thedustbin of history, we’ll see the next version of the ISA Firewall come in with a newname: the Forefront Threat Management Gateway.There are a number of reasons why the ISA name is going away. But probably the primary reason is that the general public never seemed to be able to figure out what theISA Firewall was all about. Some people thought it was just a Web proxy server (a laProxy 2.0), some people thought it was just a firewall, some people thought it was a VPNserver, some people thought it was a VPN gateway, and some people thought it was somekind of Frankenstein and couldn’t make any sense out of it. By renaming the product, theForefront TMG should be able to get some newfound attention, and hopefully the nameitself will provide a clearer focus on the primary design goal of the product.In this article I’m going to give you a look at the installation process. However, beforeinstalling the TMG, you need to know the following:
TMG will only run on 64-bit Windows Server 2008. There will be a 32-bit demoversion after the TMG goes RTM, but there won’t be any beta versions that run on32-bit Windows
TMG requires at least 1 GB of memory (it will probably run on less, but not veryquickly)
150 MB of disk space
At least one NIC (although I always recommend two or more NICs to providetrue security)
You must install to the default folder on the C: drive
TMG will install IIS 7 on your machine in order to support SQL reportingservices. If you remove TMG from the machine, II7 will not be removed for youand you will need to do that manually
Services and driver files for the TMG are installed in the TMG installation folder 
For the beta 1 version of the TMG, the TMG machine must be a domain member.In future betas, non-domain membership will be supported.In this article series (should end up being two parts), I am installing the TMG on aWindows Server 2008 Enterprise edition machine that is running as a VM on VMwareVirtual Server 1.0. The VM has two interfaces: one interface is bridged to the externalnetwork and will act as the external interface and the second interface is placed onVMNet2, which will be the interface on the default Internal Network. Note that thenetworking model for the TMG has not changed from that used by the ISA Firewall.Download your TMG software.The TMG is one of the several pieces of software that comprise the Forefront Stirlingcollection of products. You can download all of the them, or just the TMG. The TMG willwork fine without Stirling, but Stirling is something that you definitely want to get toknow about in the future.
Double click the file you downloaded. You’ll see the Welcome to the
Welcome to theInstallShield Wizard for the Forefront Threat Management Gateway
page. Click 
Figure 1
Install the files to the default location, which is
C:\Program Files (x86)\Microsoft ISAServer
. Click 
Figure 2
The files will be extracted to that location.
Figure 3
when the extraction finishes.
Figure 4
Go to the
C:\Program Files (x86)\Microsoft ISA Server
folder and double click the

