<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://technetvietnam.net/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><title type="html">FOREFRONT TMG &amp;amp; ISA&amp;#39;S BLOG</title><subtitle type="html">AUTHOR : DAO DUY HIEU - FREE SUPPORT : +84.919513471</subtitle><id>http://technetvietnam.net/blogs/hieudd/atom.aspx</id><link rel="alternate" type="text/html" href="http://technetvietnam.net/blogs/hieudd/default.aspx" /><link rel="self" type="application/atom+xml" href="http://technetvietnam.net/blogs/hieudd/atom.aspx" /><generator uri="http://communityserver.org" version="4.1.31106.3070">Community Server</generator><updated>2010-12-07T10:52:09Z</updated><entry><title>Migrating from ISA Server 2006 to Forefront TMG 2010</title><link rel="alternate" type="text/html" href="/blogs/hieudd/archive/2011/12/09/migrating-from-isa-server-2006-to-forefront-tmg.aspx" /><id>/blogs/hieudd/archive/2011/12/09/migrating-from-isa-server-2006-to-forefront-tmg.aspx</id><published>2011-12-09T08:45:53Z</published><updated>2011-12-09T08:45:53Z</updated><content type="html">&lt;p&gt;Forefront Threat Management Gateway (TMG) là phiên bản nâng cấp kế tiếp của&amp;#160; Internet Security and Acceleration (ISA) Server được Microsoft ra mắt vào cuối năm 2009. Về cơ bản TMG Server thừa hưởng nhiều tính năng giống ISA Server nhưng mạnh mẽ hơn, hoàn thiện hơn và bổ sung nhiều tính năng mới. Bài viết này sẽ hướng dẫn bạn chuyển đổi từ ISA 2006 sang TMG 2010.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/mohinhTMG_5F00_796398BE.jpg"&gt;&lt;img title="mohinhTMG" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="240" alt="mohinhTMG" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/mohinhTMG_5F00_thumb_5F00_19150338.jpg" width="640" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Trước khi tiến hành chuyển đổi ISA lên TMG, các bạn cần hiểu rõ các vấn đề sau :&lt;/p&gt;  &lt;p&gt;- ISA chỉ hoạt động trên nền tảng Windows 2003 về trước, TMG chỉ hoạt động dưới nền tảng Windows 2008 về sau.&lt;/p&gt;  &lt;p&gt;- Không thể Upgrade trực tiếp từ ISA Server lên TMG Server.&lt;/p&gt;  &lt;p&gt;- TMG không hỗ trợ chuyển đổi phiên bản ISA Enterprise&lt;/p&gt;  &lt;p&gt;- TMG không hỗ trợ chuyển đổi phiên bản ISA Server 2000/2004, để chuyển đổi lên TMG thì trước tiên bạn phải nâng cấp ISA Server 2000/2004 lên ISA 2006.&lt;/p&gt;  &lt;p&gt;- ISA Server 2006 phải là một member domain. TMG không hỗ trợ chuyển đổi từ một ISA ở chế độ workgroup (stand alone pc).&lt;/p&gt;  &lt;p&gt;- Chức năng Web Proxy Client trên ISA Server (Local Host Network) sẽ không được di chuyển sang TMG Server&lt;/p&gt;  &lt;p&gt;- Những cấu hình Report cũng sẽ không được di chuyển.&lt;/p&gt;  &lt;p&gt;- Những Features trên ISA Server 2006 sẽ không hoạt động trên Forefront TMG, tuy nhiên ta có thể cấu hình lại vì TMG có hỗ trợ.&lt;/p&gt;  &lt;p&gt;- Kiểm tra tính tương thích các phần mềm của hãng thứ 3 trên ISA Server 2006 có hoạt động trên TMG Server không.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;1/ Backup config trên ISA Server 2006&lt;/p&gt;  &lt;p&gt;- Truy cập vào cửa sổ quản lý của ISA Server, trên ISA Server click chuột phải chọn &lt;strong&gt;Export (Back Up)&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture001_5F00_31A4A088.png"&gt;&lt;img title="picture001" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="461" alt="picture001" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture001_5F00_thumb_5F00_13C61C87.png" width="640" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Cửa sổ &lt;strong&gt;Export Wizard&lt;/strong&gt; chọn &lt;strong&gt;Next&lt;/strong&gt;.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture002_5F00_2EFE7588.png"&gt;&lt;img title="picture002" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="386" alt="picture002" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture002_5F00_thumb_5F00_4A36CE89.png" width="503" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong khung &lt;strong&gt;Export Preferences&lt;/strong&gt; :&lt;/p&gt;  &lt;p&gt;+ Đánh dấu check vào &lt;strong&gt;Export confidential infomation&lt;/strong&gt; và nhập mật khẩu bảo vệ file backup&lt;/p&gt;  &lt;p&gt;+ Đánh dấu check vào &lt;strong&gt;Export user permission settings&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture003_5F00_1A7BB6BB.png"&gt;&lt;img title="picture003" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="386" alt="picture003" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture003_5F00_thumb_5F00_1A0F83C6.png" width="503" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Chọn đường dẫn lưu file backup&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture004_5F00_2E94D344.png"&gt;&lt;img title="picture004" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="386" alt="picture004" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture004_5F00_thumb_5F00_2A1E527D.png" width="503" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Kiểm tra và hoàn tất tiến trình backup.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture005_5F00_62C8FC8A.png"&gt;&lt;img title="picture005" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="386" alt="picture005" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture005_5F00_thumb_5F00_702F0F90.png" width="503" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Tiến trình backup tiến hành.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture006_5F00_4073F7C2.png"&gt;&lt;img title="picture006" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="140" alt="picture006" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture006_5F00_thumb_5F00_6022D18A.png" width="527" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;2/ Chép file backup ra USB hoặc một phân vùng khác, Formart phân vùng chứa hệ điều hành Windows Server 2003 và tiến hành cài đặt Windows Server 2008 x64 (khuyến khích sử dụng Windows Server 2008 R2). Sau khi cài đặt xong Windows và đặt 02 IP card mạng giống như cũ thì ta tiếp tục cài đặt Forefront Threat Management Gateway (TMG) 2010. &lt;a href="http://hieu.info/2010/12/06/ci-d%e1%ba%b7t-forefront-threat-management-gateway-tmg-2010-ph%e1%ba%a7n-ii-ci-d%e1%ba%b7t-forefront-tmg-server/"&gt;(Xem bài viết cài đặt TMG tại đây)&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;3/ Restore config trên Forefront TMG&lt;/p&gt;  &lt;p&gt;- Truy cập cửa sổ quản lý Forefront TMG, trên &lt;strong&gt;Forefront TMG&lt;/strong&gt; click phải chọn &lt;strong&gt;Import (Restore)&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture007_5F00_14C32DC6.png"&gt;&lt;img title="picture007" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="448" alt="picture007" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture007_5F00_thumb_5F00_2FFB86C7.png" width="640" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Cửa sổ &lt;strong&gt;Import Wizzard&lt;/strong&gt; chọn &lt;strong&gt;Next&lt;/strong&gt;.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture008_5F00_565D6A12.png"&gt;&lt;img title="picture008" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="386" alt="picture008" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture008_5F00_thumb_5F00_06874587.png" width="503" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Chọn file backup của ISA Server 2006, chọn &lt;strong&gt;Next&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture009_5F00_21BF9E88.png"&gt;&lt;img title="picture009" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="386" alt="picture009" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture009_5F00_thumb_5F00_3A4F3BD8.png" width="503" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Forefront TMG cảnh báo là file backup config ta đang sử dụng của một phiên bản cũ. Click OK&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture010_5F00_4ED48B56.png"&gt;&lt;img title="picture010" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="165" alt="picture010" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture010_5F00_thumb_5F00_4A5E0A8F.png" width="416" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Nhập password bảo vệ của file backup.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture011_5F00_45E789C8.png"&gt;&lt;img title="picture011" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="386" alt="picture011" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture011_5F00_thumb_5F00_457B56D3.png" width="503" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Kiểm tra và hoàn tất tiến trình restore. Chọn &lt;strong&gt;Finish&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture012_5F00_07EDF90A.png"&gt;&lt;img title="picture012" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="386" alt="picture012" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture012_5F00_thumb_5F00_2E4FDC55.png" width="503" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Tiến trình Restore bắt đầu.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture013_5F00_308C6511.png"&gt;&lt;img title="picture013" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="140" alt="picture013" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture013_5F00_thumb_5F00_7E289191.png" width="527" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Sau khi Restore thành công, Forefront TMG có những cảnh báo mà ta đã biết từ phần giới thiệu ở trên.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture014_5F00_32C8EDCD.png"&gt;&lt;img title="picture014" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="373" alt="picture014" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture014_5F00_thumb_5F00_4B588B1D.png" width="372" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Nhấn kiểm tra các Rules và các thiết lập đã được restore, chọn &lt;strong&gt;Apply&lt;/strong&gt; để thực thi.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture015_5F00_54B45051.png"&gt;&lt;img title="picture015" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="448" alt="picture015" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture015_5F00_thumb_5F00_5AFB26DF.png" width="640" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://technetvietnam.net/aggbug.aspx?PostID=450" width="1" height="1"&gt;</content><author><name>DaoDuyHieu</name><uri>http://technetvietnam.net/members/DaoDuyHieu/default.aspx</uri></author><category term="TMG 2010" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/TMG+2010/default.aspx" /><category term="FIREWALL" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/FIREWALL/default.aspx" /><category term="ISA" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/ISA/default.aspx" /><category term="FOREFRONT TMG 2010" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/FOREFRONT+TMG+2010/default.aspx" /><category term="TMG" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/TMG/default.aspx" /></entry><entry><title>Upgrading TMG Server 2010 Standard Edition To Enterprise Edition</title><link rel="alternate" type="text/html" href="/blogs/hieudd/archive/2011/12/06/upgrading-tmg-server-2010-standard-edition-to-enterprise-edition.aspx" /><id>/blogs/hieudd/archive/2011/12/06/upgrading-tmg-server-2010-standard-edition-to-enterprise-edition.aspx</id><published>2011-12-06T03:30:25Z</published><updated>2011-12-06T03:30:25Z</updated><content type="html">&lt;p&gt;Bạn đã từng sử dụng ISA Server 2004/2006, việc nâng cấp từ phiển bản Standard lên phiên bản Enterprise gặp rất nhiều khó khăn. Trước tiên bạn phải backup rules và remove phiên bản ISA Standard hiện tại, sau đó cài phiên bản ISA Enterprise và restore các rules. Với TMG Server 2010 thì việc này hết sức dễ dàng, bạn chỉ cần nhập product key của phiên bản TMG Server 2010 Enterprise vào giao diện quản lý của TMG hiện là quá trình upgrade thành công.&lt;/p&gt;  &lt;p&gt;1/ Mở &lt;strong&gt;TMG Server 2010 management console&lt;/strong&gt;, click vào &lt;strong&gt;System&lt;/strong&gt; bên trái.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture001_5F00_54B134F4.png"&gt;&lt;img title="picture001" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="445" alt="picture001" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture001_5F00_thumb_5F00_7B15A8F0.png" width="640" border="0" /&gt;&lt;/a&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;2/ Trong mục &lt;strong&gt;System&lt;/strong&gt;, nhìn mục &lt;strong&gt;Task&lt;/strong&gt; bên phải, click vào &lt;strong&gt;Upgrade to Enterprise Edition&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture002_5F00_2F49D237.png"&gt;&lt;img title="picture002" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="445" alt="picture002" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture002_5F00_thumb_5F00_2A671E7B.png" width="640" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;3/ Chọn sang tab &lt;strong&gt;Product ID&lt;/strong&gt;, chọn &lt;strong&gt;Upgrade To Enterprise Edition ..&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture003_5F00_3356B0BA.png"&gt;&lt;img title="picture003" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture003" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture003_5F00_thumb_5F00_60D7D07D.png" width="433" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Nhập vào &lt;strong&gt;product key&lt;/strong&gt; phiên bản &lt;strong&gt;TMG Server 2010 Enterprise Edition&lt;/strong&gt;, chọn &lt;strong&gt;OK&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture004_5F00_29FD7C37.png"&gt;&lt;img title="picture004" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="125" alt="picture004" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture004_5F00_thumb_5F00_2586FB70.png" width="240" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Trở lại tab &lt;strong&gt;Product ID&lt;/strong&gt;, bạn sẽ thấy phiên bản hiện tại là &lt;strong&gt;Enterprise&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture005_5F00_3A0C4AEE.png"&gt;&lt;img title="picture005" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture005" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture005_5F00_thumb_5F00_47725DF4.png" width="433" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;4/ Nhấp &lt;strong&gt;Apply&lt;/strong&gt; để quá trình upgrade hoàn tất, lúc này phiên bản TMG Server 2010 của bạn đã nâng cấp từ Standard lên Enterprise.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture006_5F00_3B706DC0.png"&gt;&lt;img title="picture006" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="445" alt="picture006" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture006_5F00_thumb_5F00_7D76DD01.png" width="640" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://technetvietnam.net/aggbug.aspx?PostID=449" width="1" height="1"&gt;</content><author><name>DaoDuyHieu</name><uri>http://technetvietnam.net/members/DaoDuyHieu/default.aspx</uri></author><category term="TMG 2010" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/TMG+2010/default.aspx" /><category term="FOREFRONT TMG 2010" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/FOREFRONT+TMG+2010/default.aspx" /></entry><entry><title>Quản trị TMG 2010 : Access Rules (3)</title><link rel="alternate" type="text/html" href="/blogs/hieudd/archive/2010/12/17/qua-n-tri-tmg-2010-access-rules-3.aspx" /><id>/blogs/hieudd/archive/2010/12/17/qua-n-tri-tmg-2010-access-rules-3.aspx</id><published>2010-12-17T01:24:44Z</published><updated>2010-12-17T01:24:44Z</updated><content type="html">&lt;p&gt;&lt;font face="Arial"&gt;Sau khi các bạn đã cài đặt thành công TMG 2010, các bạn cần phải tạo ra các Access Rule để quản lý mọi gói tin ra vào hệ thống. Trong bài viết này hướng dẫn cách tạo các Access Rule phù hợp với nhu cầu của các doanh nghiệp hiện nay.&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font face="Arial" color="#ff0000"&gt;I. Giới thiệu :&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font face="Arial"&gt;Bài lab bao gồm các bước:&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;1. Kiểm tra Default Rule &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;2. Tạo rule truy vấn DNS để phân giải tên miền&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;3. Tạo rule cho phép các user thuộc nhóm Manager truy cập Internet không hạn chế&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;4. Tạo rule cho phép các user thuộc nhóm Staff chỉ được phép truy cập 1 số trang web trong giờ hành chánh&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;5. Tạo rule cho phép các user thuộc nhóm Staff được truy cập web trong giờ giải lao, ngoại trừ trang linux.org&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;6. Tạo rule cho phép user có thể kết nối mail ngoài internet bằng Windows Live Mail với giao thức POP3/SMTP.&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;7. Không cho nghe nhạc trực tuyến, cấm chat Yahoo Messenger, cấm download file có đuôi .exe&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;8. Cấm truy cập một số trang web, nếu truy cập sẽ tự động chuyển đến trang web cảnh cáo của công ty&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font face="Arial" color="#ff0000"&gt;II. Thực hiện: (Tiếp theo)&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font face="Arial"&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font face="Arial"&gt;6. Tạo rule cho phép user có thể kết nối mail ngoài internet bằng Windows Live Mail với giao thức POP3/SMTP&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font face="Arial"&gt;a. Tạo access rules trên TMG Server&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Trong cửa sổ &lt;b&gt;Forefront TMG&lt;/b&gt;, chuột phải &lt;b&gt;Firewall Policy&lt;/b&gt;, chọn &lt;b&gt;New,&lt;/b&gt; chọn &lt;b&gt;Access Rule &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Hộp thoại &lt;b&gt;Access Rule Names&lt;/b&gt;, đặt tên rule là: &lt;b&gt;Allow Manager – Full Access &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image031" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image031" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image031_5F00_44892BC6.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Hộp thoại &lt;b&gt;Rule Action&lt;/b&gt;, chọn &lt;b&gt;Allow &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image032" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image032" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image032_5F00_3D004D0A.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Hộp thoại &lt;b&gt;Protocols&lt;/b&gt;, chọn &lt;b&gt;Selected Protocol, &lt;/b&gt;nhấn&lt;b&gt; Add &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Trong hộp thoại &lt;b&gt;Add Protocols&lt;/b&gt;, bung mục &lt;b&gt;Common Protocols&lt;/b&gt;, chọn &lt;b&gt;SMTP và POP3&lt;/b&gt;, nhấn &lt;b&gt;Add&lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;-&amp;#160; Nhấn &lt;b&gt;Next &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image033" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image033" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image033_5F00_10E35019.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Hộp thoại &lt;b&gt;Access Rule Sources&lt;/b&gt;, Aad &lt;b&gt;Internal&lt;/b&gt;, nhấn &lt;b&gt;Next &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image034" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image034" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image034_5F00_078A1B96.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Hộp thoại &lt;b&gt;Access Rule Destinaton&lt;/b&gt;, add &lt;b&gt;External, &lt;/b&gt;nhấn&lt;b&gt; Next &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image035" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image035" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image035_5F00_312598DC.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Hộp thoại &lt;b&gt;User Sets&lt;/b&gt;, bạn chọn &lt;b&gt;All Users &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image036" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image036" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image036_5F00_32F5EEA3.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Hộp thoại &lt;b&gt;Completing the New Access Rule Wizard&lt;/b&gt;, &lt;b&gt;Finish &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image037" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image037" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image037_5F00_49B7C6DD.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Nhấn chọn &lt;b&gt;Apply, &lt;/b&gt;nhấn&lt;b&gt; OK &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font face="Arial"&gt;b. Cấu hình Windows Live Mail và check mail : (trong vd này tôi có sử dụng email &lt;/font&gt;&lt;a href="mailto:daoduyhieu@technetvietnam.com"&gt;&lt;font face="Arial"&gt;daoduyhieu@technetvietnam.com&lt;/font&gt;&lt;/a&gt;&lt;font face="Arial"&gt; nằm ngoài internet)        &lt;br /&gt;&lt;/font&gt;&lt;/b&gt;&lt;font face="Arial"&gt;- Log on &lt;b&gt;Staff1 &lt;/b&gt;trên máy Client&lt;b&gt;,&lt;/b&gt; khởi động Windows Live Mail&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;-&amp;#160; Sử dụng các thông số của email để cấu hình Windows Live Mail:&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;Email : &lt;/font&gt;&lt;a href="mailto:daoduyhieu@technetvietnam.caom"&gt;&lt;font face="Arial"&gt;daoduyhieu@technetvietnam.caom&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;SMTP/POP : mail.technetvietnam.com&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;     &lt;br /&gt;&lt;/b&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image038" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image038" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image038_5F00_393F55E2.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image039" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image039" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image039_5F00_2213DB64.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image040" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image040" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image040_5F00_03C9246E.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Sau đó, nhấn vào biểu tượng&lt;b&gt; Send/Receive,&lt;/b&gt; bạn sẽ nhận được mail tải về từ ngoài internet qua giao thức POP3/SMTP&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image041" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image041" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image041_5F00_05997A35.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font face="Arial"&gt;7. Không cho nhân viên nghe nhạc trực tuyến, cấm chat Yahoo Messenger, cấm download file có đuôi .exe&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font face="Arial"&gt;a. Cấm trong giờ hành chánh&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Tại máy &lt;b&gt;TMG Server&lt;/b&gt;, trong cửa sổ &lt;b&gt;Forefront TMG &lt;/b&gt;, chuột phải lên rule &lt;b&gt;Allow Staff on Work Time&lt;/b&gt;, chọn&lt;b&gt; Configure HTTP &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image042" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image042" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image042_5F00_0A128BAD.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Qua tab&lt;b&gt; Signatures, &lt;/b&gt;nhấn&lt;b&gt; Add &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image043" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image043" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image043_5F00_52CC0471.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Ở khung&lt;b&gt; Name&lt;/b&gt;, nhập tên:&lt;/font&gt;&lt;font face="Arial"&gt;&lt;b&gt; Deny Yahoo Messenger        &lt;br /&gt;&lt;/b&gt;Khung &lt;b&gt;Search in, &lt;/b&gt;chọn tùy chọn&lt;/font&gt;&lt;font face="Arial"&gt;&lt;b&gt;: Request headers&amp;#160; &lt;br /&gt;&lt;/b&gt;Khung&lt;b&gt; HTTP Header, &lt;/b&gt;nhập:&lt;/font&gt;&lt;font face="Arial"&gt;&lt;b&gt; Host:        &lt;br /&gt;&lt;/b&gt;Khung&lt;b&gt; Signature, &lt;/b&gt;nhập:&lt;/font&gt;&lt;font face="Arial"&gt;&lt;b&gt; msg.yahoo.com        &lt;br /&gt;&lt;/b&gt;chọn&lt;b&gt; OK &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image044" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image044" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image044_5F00_698DDCAB.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Nhấn&lt;b&gt; Apply, &lt;/b&gt;chọn&lt;b&gt; OK &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image045" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image045" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image045_5F00_4B4325B5.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Qua tab&lt;b&gt; Methods, &lt;/b&gt;trong khung&lt;b&gt; Specify the action taken for HTTP methods, &lt;/b&gt;chọn&lt;b&gt; Block specified methods (allow all others) &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image046" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image046" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image046_5F00_7B00CE34.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Nhập vào những định dạng file mà bạn muốn cấm&lt;b&gt;, &lt;/b&gt;ví dụ:&lt;b&gt; .exe&amp;#160; &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image047" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image047" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image047_5F00_71A799B1.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Chuột phải vào&lt;b&gt; Allow Staff on Work Time, &lt;/b&gt;chọn&lt;b&gt; Properties &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image048" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image048" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image048_5F00_3A611276.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Qua tab&lt;b&gt; Content Types, &lt;/b&gt;khung&lt;b&gt; This rule applies to, &lt;/b&gt;chọn &lt;b&gt;Selected content types&lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Trong khung&lt;b&gt; Content Types &lt;/b&gt;bỏ dấu chọn ô &lt;b&gt;Audio &lt;/b&gt;và&lt;b&gt; Video (để user không nghe nhạc trực tuyến). &lt;/b&gt;Nhấn&lt;b&gt; Apply, &lt;/b&gt;chọn&lt;b&gt; OK &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image049" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image049" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image049_5F00_031A8B3B.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;&lt;b&gt;b. Cấm trong giờ giải lao:&lt;/b&gt; Làm tương tự bước a trên rule &lt;b&gt;Allow Staff on Rest Time&lt;/b&gt;       &lt;br /&gt;&lt;b&gt;c. Kiểm tra: &lt;/b&gt;      &lt;br /&gt;- Log on &lt;b&gt;Administrator&lt;/b&gt; trên máy &lt;b&gt;Client, &lt;/b&gt;thử&lt;b&gt; Sign in &lt;/b&gt;vào&lt;b&gt; Yahoo Messenger, &lt;/b&gt;bạn sẽ &lt;b&gt;không thể đăng nhập Yahoo&lt;/b&gt; được&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image050" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image050" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image050_5F00_4BD403FF.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Bạn thử &lt;b&gt;download 1 file.exe&lt;/b&gt; bất kỳ từ trang web nào đó. (&lt;b&gt;VD&lt;/b&gt;: &lt;/font&gt;&lt;a href="http://rarlab.com"&gt;&lt;font face="Arial"&gt;http://&lt;/font&gt;&lt;/a&gt;&lt;font face="Arial"&gt;rarlab.com) &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Kiểm tra sẽ thấy &lt;b&gt;download&lt;/b&gt; thất bại &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image051" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image051" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image051_5F00_5B0A6CCC.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Thử truy cập vào trang&lt;b&gt; &lt;a href="http://nhacso.net/"&gt;http://nhacso.net&lt;/a&gt;, &lt;/b&gt;kiểm tra không được nghe nhạc trực tuyến &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image052" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image052" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image052_5F00_7F9E8B01.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;&lt;b&gt;8. Cấm truy cập một số trang web, nếu truy cập sẽ tự động chuyển đến trang web cảnh báo của công ty&lt;/b&gt;       &lt;br /&gt;&lt;b&gt;a. Tạo Access Rule cho truy cập từ Internal tới Internal với All Protocol &lt;/b&gt;(tương tự như các bước trên)&amp;#160; &lt;br /&gt;&lt;b&gt;b. Tạo URL Sets : (xem lại phần 4b)&lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Add những trang web mà bạn muốn cấm vào Deny Web (Ở đây tôi sử dụng lại Retrict Web)&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;&lt;b&gt;c. Tạo Access Rule&lt;/b&gt;       &lt;br /&gt;- Chuột phải &lt;b&gt;Firewall Policy&lt;/b&gt;, chọn &lt;b&gt;New,&lt;/b&gt; chọn &lt;b&gt;Access Rule &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image053" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image053" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image053_5F00_1D136CBF.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Hộp thoại &lt;b&gt;Access Rule Names&lt;/b&gt;, đặt tên rule là: &lt;b&gt;Deny and Redirect Web &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image054" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image054" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image054_5F00_17C4860E.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Hộp thoại &lt;b&gt;Rule Action&lt;/b&gt;, chọn &lt;b&gt;Deny &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image055" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image055" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image055_5F00_353967CB.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Trong hộp thoại &lt;b&gt;Protocols&lt;/b&gt;, chọn &lt;b&gt;Selected protocols&lt;/b&gt;, nhấn &lt;b&gt;Add &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Trong hộp thoại &lt;b&gt;Add Protocols&lt;/b&gt;, bung mục &lt;b&gt;Common Protocols&lt;/b&gt;, chọn &lt;b&gt;HTTP và HTTPS&lt;/b&gt;, nhấn &lt;b&gt;Add &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image056" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image056" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image056_5F00_4BFB4005.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Hộp thoại &lt;b&gt;Access Rule Sources&lt;/b&gt;, Add Rule: &lt;b&gt;Internal, &lt;/b&gt;nhấn&lt;b&gt; Next &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image057" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image057" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image057_5F00_38DA1359.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Hộp thoại &lt;b&gt;Access Rule Destinaton&lt;/b&gt;, nhấn &lt;b&gt;Add.&lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Bung mục &lt;b&gt;URL Sets&lt;/b&gt;, add &lt;b&gt;Deny Web &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Nhấn &lt;b&gt;Next &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image058" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image058" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image058_5F00_4F9BEB93.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Hộp thoại &lt;b&gt;User Sets&lt;/b&gt;, chọn &lt;b&gt;All Users &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image059" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image059" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image059_5F00_18556458.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Hộp thoại &lt;b&gt;Completing the New Access Rule Wizard&lt;/b&gt;, nhấn &lt;b&gt;Finish &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image060" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image060" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image060_5F00_48130CD7.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Move up rule &lt;b&gt;Deny and Redirect Web &lt;/b&gt;làm rule số 2,&amp;#160; chọn &lt;b&gt;Apply,&lt;/b&gt; nhấn&lt;b&gt; OK &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Chuột phải vào rule&lt;b&gt; Deny and Redirect Web, &lt;/b&gt;chọn&lt;b&gt; Properties &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image061" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image061" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image061_5F00_379A9BDC.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;b&gt;&lt;font face="Arial"&gt; &lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;&lt;b&gt;- &lt;/b&gt;Trong hộp thoại&lt;b&gt; Deny and&amp;#160; Redirect Web Properties, &lt;/b&gt;qua tab&lt;b&gt; Action, chọn Advanced&lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image062" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image062" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image062_5F00_15459714.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Đánh dấu check vào mục&lt;b&gt; Redirect HTTP requests to this Web Page, &lt;/b&gt;khung bên dưới nhập vào trang web mà bạn muốn redirect về &lt;/font&gt;&lt;a href="http://technetvietnam.local/canhbao.htm"&gt;&lt;font face="Arial"&gt;http://technetvietnam.local/canhbao.htm&lt;/font&gt;&lt;/a&gt;&lt;font face="Arial"&gt; (Trong bài viết có hosting sẳn trang web này tại máy DC)&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image063" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image063" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image063_5F00_24E832D6.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Log on user&lt;b&gt; TechNetVietnam\Man2 &lt;/b&gt;trên máy&lt;b&gt; DC, &lt;/b&gt;truy cập vào trang web bị cấm&lt;b&gt;. VD: &lt;a href="http://linux.org"&gt;http://linux.org&lt;/a&gt; &lt;/b&gt;sẽ tự động redirect về trang cảnh báo của công ty&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a&gt;&lt;font face="Arial"&gt;&lt;img title="clip_image064" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="clip_image064" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/clip_5F00_image064_5F00_4D869EDD.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://technetvietnam.net/aggbug.aspx?PostID=393" width="1" height="1"&gt;</content><author><name>DaoDuyHieu</name><uri>http://technetvietnam.net/members/DaoDuyHieu/default.aspx</uri></author><category term="TMG 2010" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/TMG+2010/default.aspx" /><category term="FIREWALL" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/FIREWALL/default.aspx" /><category term="ISA" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/ISA/default.aspx" /><category term="FOREFRONT TMG 2010" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/FOREFRONT+TMG+2010/default.aspx" /><category term="TMG" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/TMG/default.aspx" /></entry><entry><title>Quản trị TMG 2010 : Access Rules (2)</title><link rel="alternate" type="text/html" href="/blogs/hieudd/archive/2010/12/14/qua-n-tri-tmg-2010-access-rules-2.aspx" /><id>/blogs/hieudd/archive/2010/12/14/qua-n-tri-tmg-2010-access-rules-2.aspx</id><published>2010-12-14T00:42:43Z</published><updated>2010-12-14T00:42:43Z</updated><content type="html">&lt;p&gt;&lt;font face="Arial"&gt;Sau khi các bạn đã cài đặt thành công TMG 2010, các bạn cần phải tạo ra các Access Rule để quản lý mọi gói tin ra vào hệ thống. Trong bài viết này hướng dẫn cách tạo các Access Rule phù hợp với nhu cầu của các doanh nghiệp hiện nay.&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font face="Arial" color="#ff0000"&gt;I. Giới thiệu :&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font face="Arial"&gt;Bài lab bao gồm các bước:&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;1. Kiểm tra Default Rule &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;2. Tạo rule truy vấn DNS để phân giải tên miền&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;3. Tạo rule cho phép các user thuộc nhóm Manager truy cập Internet không hạn chế&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;4. Tạo rule cho phép các user thuộc nhóm Staff chỉ được phép truy cập 1 số trang web trong giờ hành chánh&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;5. Tạo rule cho phép các user thuộc nhóm Staff được truy cập web trong giờ giải lao, ngoại trừ trang linux.org&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;6. Tạo rule cho phép user có thể kết nối mail ngoài internet bằng Windows Live Mail với giao thức POP3/SMTP.&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;7. Không cho nghe nhạc trực tuyến, cấm chat Yahoo Messenger, cấm download file có đuôi .exe&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;8. Cấm truy cập một số trang web, nếu truy cập sẽ tự động chuyển đến trang web cảnh cáo của công ty&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font face="Arial" color="#ff0000"&gt;II. Thực hiện: (Tiếp theo)&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;4. Tạo rule cho phép các user thuộc nhóm Staff chỉ được phép truy cập 1 số trang web trong giờ hành chánh&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;a. Tạo Schedule Element&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Trong cửa sổ TMG, chọn Firewall Policy, qua cửa sổ thứ 3, tại tab&lt;b&gt; Toolbox, &lt;/b&gt;bung mục&lt;b&gt; Schedules, &lt;/b&gt;chọn&lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt; New        &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture026_5F00_392B5AE2.png"&gt;&lt;img title="picture026" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture026" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture026_5F00_thumb_5F00_5AAA8A71.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Trong ô &lt;b&gt;Name&lt;/b&gt;, nhập tên &lt;b&gt;Work Time&lt;/b&gt;. Bên dưới chọn từ &lt;b&gt;(7h - 11h)&lt;/b&gt; và từ &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;(1h – 5h)&amp;#160; &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture027_5F00_111B3C74.png"&gt;&lt;img title="picture027" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture027" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture027_5F00_thumb_5F00_2E901E31.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Tương tự, tạo thêm 1 schedule là &lt;b&gt;Rest Time&lt;/b&gt;, với thời gian là từ &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;11h – 1h        &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture028_5F00_12EE22EC.png"&gt;&lt;img title="picture028" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture028" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture028_5F00_thumb_5F00_06829074.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;b&gt;     &lt;br /&gt;&lt;span style="font-family:arial;"&gt;b. Tạo Element URL Sets&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Trong cửa sổ TMG, chọn Firewall Policy, qua cửa sổ thứ 3, tại tab&lt;b&gt; Toolbox, &lt;/b&gt;bung mục&lt;b&gt; Network Objects, &lt;/b&gt;nhấn &lt;b&gt;New&lt;/b&gt;, chọn &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;URL Set        &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture029_5F00_0F05EFBE.png"&gt;&lt;img title="picture029" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture029" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture029_5F00_thumb_5F00_3A4D1776.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Trong hộp thoại&lt;b&gt; New URL Set. &lt;/b&gt;Ô &lt;b&gt;Name , &lt;/b&gt;nhập tên:&lt;b&gt; Restrict Web,&lt;/b&gt; add các trang web mà bạn muốn cấm (Vd:&lt;b&gt;http://linux.org ) &lt;/b&gt;chọn&lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt; OK        &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture031_5F00_5BCC4705.png"&gt;&lt;img title="picture031" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture031" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture031_5F00_thumb_5F00_123CF908.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;-&amp;#160; Tương tự, bạn tạo thêm URL Set là: &lt;b&gt;Allow Web&lt;/b&gt; và add những trang web được phép truy cập vào       &lt;br /&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture030_5F00_28929E4D.png"&gt;&lt;img title="picture030" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture030" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture030_5F00_thumb_5F00_1AC2E903.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;/b&gt;    &lt;p&gt;     &lt;br /&gt;&lt;span style="font-family:arial;"&gt;c. Tạo Access Rule:&lt;/span&gt;&lt;/p&gt;    &lt;br /&gt;&lt;span style="font-family:arial;"&gt;- Chuột phải &lt;b&gt;Firewall Policy&lt;/b&gt;, chọn &lt;b&gt;New,&lt;/b&gt; chọn &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;Access Rule&lt;/span&gt;&lt;/b&gt;&lt;/p&gt; &lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;Access Rule Names&lt;/b&gt;, đặt tên rule là: &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;Allow Staff on Work Time      &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture032_5F00_31188E48.png"&gt;&lt;img title="picture032" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture032" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture032_5F00_thumb_5F00_275326D0.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;Rule Action&lt;/b&gt;, chọn &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;Allow        &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture033_5F00_529A4E88.png"&gt;&lt;img title="picture033" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture033" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture033_5F00_thumb_5F00_14348AD5.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;Protocols&lt;/b&gt;, chọn &lt;b&gt;Selected Protocols&lt;/b&gt; và nhấn &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;Add&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Trong hộp thoại &lt;b&gt;Add Protocols&lt;/b&gt;, bung mục &lt;b&gt;Common Protocols&lt;/b&gt;, chọn &lt;b&gt;HTTP và HTTPS&lt;/b&gt;, nhấn &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;Add&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Nhấn&lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt; Next        &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture044_5F00_51C4794F.png"&gt;&lt;img title="picture044" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture044" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture044_5F00_thumb_5F00_5A47D899.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;Mailware Inspection&lt;/b&gt; chọn &lt;b&gt;Enable mailware inspection for this rule, &lt;/b&gt;chọn&lt;b&gt; Next&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture035_5F00_5EC0EA11.png"&gt;&lt;img title="picture035" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture035" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture035_5F00_thumb_5F00_3956F6A3.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;b&gt;     &lt;br /&gt;&lt;span style="font-family:arial;"&gt;- &lt;/span&gt;&lt;/b&gt;&lt;span style="font-family:arial;"&gt;Hộp thoại &lt;b&gt;Access Rule Sources&lt;/b&gt;, add&amp;#160; &lt;b&gt;Internal&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture036_5F00_3DD0081B.png"&gt;&lt;img title="picture036" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture036" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture036_5F00_thumb_5F00_3883B21B.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;Access Rule Destinaton&lt;/b&gt;, nhấn&lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt; Add        &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Bung &lt;b&gt;URL Sets&lt;/b&gt;, chọn &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;Allow Web&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Nhấn &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;Next&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;       &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture037_5F00_280B4120.png"&gt;&lt;img title="picture037" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture037" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture037_5F00_thumb_5F00_6C4E391D.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;User Sets&lt;/b&gt;, remove group &lt;b&gt;All Users&lt;/b&gt;, add group &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;Staff        &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture038_5F00_3BBABB65.png"&gt;&lt;img title="picture038" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture038" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture038_5F00_thumb_5F00_12467A25.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;Completing the New Access Rule Wizard&lt;/b&gt;, nhấn &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;Finish        &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture039_5F00_6CDC86B6.png"&gt;&lt;img title="picture039" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture039" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture039_5F00_thumb_5F00_7808A1B1.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Chuột phải lên &lt;b&gt;Rule Allow Staff on Work Time&lt;/b&gt;, chọn &lt;/span&gt;&lt;span style="font-family:arial;"&gt;&lt;b&gt;Properties        &lt;br /&gt;&lt;/b&gt;      &lt;br /&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture040_5F00_6E433A39.png"&gt;&lt;img title="picture040" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture040" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture040_5F00_thumb_5F00_39A56EAF.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Qua Tab &lt;b&gt;Schedule,&lt;/b&gt; trong khung &lt;b&gt;schedule&lt;/b&gt;, chọn là &lt;b&gt;Work Time , &lt;/b&gt;Nhấn &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;OK        &lt;br /&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture041_5F00_5B249E3E.png"&gt;&lt;img title="picture041" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture041" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture041_5F00_thumb_5F00_3F82A2F9.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Trên máy Client, log on &lt;b&gt;TechNetVietnam\Staff1&lt;/b&gt;, truy cập trang web&lt;b&gt; &lt;a href="http://technetvietnam.net"&gt;http://technetvietnam.net&lt;/a&gt; &lt;/b&gt;trong giờ làm việc, kiểm tra truy cập thành công&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture0411_5F00_75F354FB.png"&gt;&lt;img title="picture041-1" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture041-1" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture0411_5F00_thumb_5F00_734D29FB.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;       &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family:arial;"&gt;- Truy cập những trang web khác trong giờ làm việc&lt;b&gt;,&lt;/b&gt; ví dụ:&lt;b&gt;&amp;#160;&lt;a href="http://isaserver.org"&gt;http://isaserver.org&lt;/a&gt; &lt;/b&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt;kiểm tra không truy cập được&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture0412_5F00_229E9F86.png"&gt;&lt;img title="picture041-2" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture041-2" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture0412_5F00_thumb_5F00_1FF87486.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font face="Arial"&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font face="Arial"&gt;5. Tạo rule cho phép các user thuộc nhóm Staff được truy cập web trong giờ giải lao, ngoại trừ trang linux.org&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;&lt;font face="Arial"&gt;- Trong cửa sổ Forefront TMG, chuột phải &lt;b&gt;Firewall Policy&lt;/b&gt;, chọn &lt;b&gt;New,&lt;/b&gt; chọn &lt;b&gt;Access Rule &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Hộp thoại &lt;b&gt;Access Rule Names&lt;/b&gt;, đặt tên rule là: &lt;b&gt;Allow Staff on Rest Time &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture042_5F00_625AA2D5.png"&gt;&lt;/a&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture042_5F00_286DF09A.png"&gt;&lt;font face="Arial"&gt;&lt;img title="picture042" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture042" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture042_5F00_thumb_5F00_753C9A0E.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/a&gt;&lt;font face="Arial"&gt;&amp;#160;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Hộp thoại &lt;b&gt;Rule Action&lt;/b&gt;, chọn &lt;b&gt;Allow&lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture043_5F00_25C7C59A.png"&gt;&lt;/a&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture043_5F00_6357B414.png"&gt;&lt;font face="Arial"&gt;&lt;img title="picture043" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture043" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture043_5F00_thumb_5F00_0ABC6A1B.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/a&gt;&lt;font face="Arial"&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Hộp thoại &lt;b&gt;Protocols&lt;/b&gt;, chọn &lt;b&gt;Selected Protocols&lt;/b&gt; và nhấn &lt;b&gt;Add&lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;-&amp;#160; Trong hộp thoại &lt;b&gt;Add Protocols&lt;/b&gt;, bung mục &lt;b&gt;Common Protocols&lt;/b&gt;, chọn &lt;b&gt;HTTP và HTTPS&lt;/b&gt;, nhấn &lt;/font&gt;&lt;b&gt;&lt;font face="Arial"&gt;Add        &lt;br /&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Nhấn &lt;b&gt;Next&lt;/b&gt;&lt;/font&gt;&lt;/p&gt; &lt;b&gt;   &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture044_5F00_52DF4319.png"&gt;&lt;/a&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture044_5F00_5B62A263.png"&gt;&lt;font face="Arial"&gt;&lt;img title="picture044" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture044" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture044_5F00_thumb_5F00_39A43D61.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/a&gt;&lt;font face="Arial"&gt; &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Arial"&gt;- Hộp thoại Mailware Inspection chọn Enable mailware inspection for this rule, chọn Next&lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Arial"&gt;&lt;/font&gt;&lt;/p&gt;   &lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture045_5F00_63E601AD.png"&gt;&lt;/a&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture045_5F00_164C65DE.png"&gt;&lt;font face="Arial"&gt;&lt;img title="picture045" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture045" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture045_5F00_thumb_5F00_564349E5.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/a&gt;&lt;font face="Arial"&gt; &lt;/font&gt;&lt;/b&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Hộp thoại &lt;b&gt;Access Rule Sources&lt;/b&gt;, add &lt;b&gt;Internal, &lt;/b&gt;nhấn&lt;b&gt; Next&lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture046_5F00_70E2726F.png"&gt;&lt;/a&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture046_5F00_00850E32.png"&gt;&lt;font face="Arial"&gt;&lt;img title="picture046" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture046" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture046_5F00_thumb_5F00_12FD6327.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/a&gt;&lt;font face="Arial"&gt; &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Hộp thoại &lt;b&gt;Access Rule Destinaton&lt;/b&gt;, add &lt;b&gt;External, &lt;/b&gt;nhấn&lt;/font&gt;&lt;b&gt;&lt;font face="Arial"&gt; Next        &lt;br /&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture047_5F00_6C024F64.png"&gt;&lt;/a&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture047_5F00_2D9C8BB1.png"&gt;&lt;font face="Arial"&gt;&lt;img title="picture047" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture047" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture047_5F00_thumb_5F00_0CD8A73D.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/a&gt;&lt;font face="Arial"&gt; &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Hộp thoại &lt;b&gt;User Sets&lt;/b&gt;, remove group &lt;b&gt;All Users&lt;/b&gt;, add group &lt;b&gt;Staff&lt;/b&gt; vào, chọn Next &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture048_5F00_3D3F2773.png"&gt;&lt;/a&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture048_5F00_7ACF15ED.png"&gt;&lt;font face="Arial"&gt;&lt;img title="picture048" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture048" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture048_5F00_thumb_5F00_3E693634.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/a&gt;&lt;font face="Arial"&gt; &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Hộp thoại &lt;b&gt;Completing the New Access Rule Wizard&lt;/b&gt;, nhấn &lt;/font&gt;&lt;b&gt;&lt;font face="Arial"&gt;Finish &lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture049_5F00_5565227F.png"&gt;&lt;/a&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture049_5F00_24D43578.png"&gt;&lt;font face="Arial"&gt;&lt;img title="picture049" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture049" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture049_5F00_thumb_5F00_4CC9C9C8.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/a&gt;&lt;font face="Arial"&gt; &lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Chuột phải lên rule &lt;b&gt;Allow Staff on Rest Time&lt;/b&gt;, chọn &lt;/font&gt;&lt;b&gt;&lt;font face="Arial"&gt;Properties        &lt;br /&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture050_5F00_69172D75.png"&gt;&lt;/a&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture050_5F00_43AD3A07.png"&gt;&lt;font face="Arial"&gt;&lt;img title="picture050" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture050" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture050_5F00_thumb_5F00_2BDB7883.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/a&gt;&lt;font face="Arial"&gt; &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Qua Tab &lt;b&gt;Schedule,&lt;/b&gt; trong mục &lt;b&gt;Schedule,&lt;/b&gt; chọn &lt;/font&gt;&lt;b&gt;&lt;font face="Arial"&gt;Rest Time        &lt;br /&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture051_5F00_7A1DEC09.png"&gt;&lt;/a&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture051_5F00_69A57B0E.png"&gt;&lt;font face="Arial"&gt;&lt;img title="picture051" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture051" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture051_5F00_thumb_5F00_415B488F.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/a&gt;&lt;font face="Arial"&gt; &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Qua tab &lt;b&gt;To, &lt;/b&gt;khung&lt;b&gt; Exceptions, &lt;/b&gt;nhấn&lt;/font&gt;&lt;b&gt;&lt;font face="Arial"&gt; Add        &lt;br /&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Bung mục&lt;b&gt; URL Sets, &lt;/b&gt;chọn&lt;/font&gt;&lt;font face="Arial"&gt;&lt;b&gt; Restrict Web        &lt;br /&gt;&lt;/b&gt;-&amp;#160; Nhấn&lt;b&gt; Apply, &lt;/b&gt;chọn &lt;/font&gt;&lt;b&gt;&lt;font face="Arial"&gt;OK &lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture052_5F00_1C0BDF3F.png"&gt;&lt;/a&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture052_5F00_5DA61B8B.png"&gt;&lt;font face="Arial"&gt;&lt;img title="picture052" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture052" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture052_5F00_thumb_5F00_3DDF4856.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/a&gt;&lt;font face="Arial"&gt; &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Trên máy DC, log on user &lt;b&gt;TechNetVietnam\Staff2&lt;/b&gt;, truy cập trang&lt;b&gt;: &lt;a href="http://linux.org"&gt;http://linux.org&lt;/a&gt;&amp;#160; &lt;/b&gt;kiểm tra nhận thông báo lỗi.&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture054_5F00_4D2DAA90.png"&gt;&lt;/a&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture054_5F00_039E5C93.png"&gt;&lt;font face="Arial"&gt;&lt;img title="picture054" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture054" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture054_5F00_thumb_5F00_281A815B.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/a&gt;&lt;font face="Arial"&gt; &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Arial"&gt;- Truy cập những trang web khác &lt;b&gt;(ví dụ: &lt;/b&gt;&lt;b&gt;&lt;a href="http://windowsecurity.com"&gt;http://windowsecurity.com&lt;/a&gt;&amp;#160; ) &lt;/b&gt;kiểm tra truy cập thành công&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture053_5F00_4F009108.png"&gt;&lt;/a&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture053_5F00_530D6F8B.png"&gt;&lt;font face="Arial"&gt;&lt;img title="picture053" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture053" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture053_5F00_thumb_5F00_71CE7AAD.png" width="557" border="0" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/a&gt;&lt;font face="Arial"&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://technetvietnam.net/aggbug.aspx?PostID=392" width="1" height="1"&gt;</content><author><name>DaoDuyHieu</name><uri>http://technetvietnam.net/members/DaoDuyHieu/default.aspx</uri></author><category term="TMG 2010" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/TMG+2010/default.aspx" /><category term="FIREWALL" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/FIREWALL/default.aspx" /><category term="ISA" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/ISA/default.aspx" /><category term="FOREFRONT TMG 2010" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/FOREFRONT+TMG+2010/default.aspx" /><category term="TMG" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/TMG/default.aspx" /></entry><entry><title>Quản trị TMG 2010 : Access Rules (1)</title><link rel="alternate" type="text/html" href="/blogs/hieudd/archive/2010/12/13/qua-n-tri-tmg-2010-access-rules-1.aspx" /><id>/blogs/hieudd/archive/2010/12/13/qua-n-tri-tmg-2010-access-rules-1.aspx</id><published>2010-12-13T07:20:00Z</published><updated>2010-12-13T07:20:00Z</updated><content type="html">&lt;p&gt;&lt;span style="font-family:arial;"&gt;Sau khi các bạn đã cài đặt thành công TMG 2010, các bạn cần phải tạo ra các Access Rule để quản lý mọi gói tin ra vào hệ thống. Trong bài viết này hướng dẫn cách tạo các Access Rule phù hợp với nhu cầu của các doanh nghiệp hiện nay.&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;span style="color:#ff0000;font-family:arial;"&gt;I. Giới thiệu :&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;span&gt;Bài lab bao gồm các bước:&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;1. Kiểm tra Default Rule &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;2. Tạo rule truy vấn DNS để phân giải tên miền&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;3. Tạo rule cho phép các user thuộc nhóm Manager truy cập Internet không hạn chế&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;4. Tạo rule cho phép các user thuộc nhóm Staff chỉ được phép truy cập 1 số trang web trong giờ hành chánh&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;5. Tạo rule cho phép các user thuộc nhóm Staff được truy cập web trong giờ giải lao, ngoại trừ trang linux.org&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;6. Tạo rule cho phép user có thể kết nối mail ngoài internet bằng Windows Live Mail với giao thức POP3/SMTP.&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;7. Không cho nghe nhạc trực tuyến, cấm chat Yahoo Messenger, cấm download file có đuôi .exe&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;8. Cấm truy cập một số trang web, nếu truy cập sẽ tự động chuyển đến trang web cảnh cáo của công ty&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;     &lt;br /&gt;&lt;span style="color:#ff0000;font-family:arial;"&gt;II. Chuẩn bị :&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;Mô hình bài lab :&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/TMG_5F00_7BBB2089.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;img title="TMG" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="267" alt="TMG" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/TMG_5F00_thumb_5F00_28666B14.png" width="640" border="0" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;Bài lab bao gồm 3 máy :&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - Máy DC: Windows Server&amp;#160; 2008 R2&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + Tạo OU &lt;b&gt;HCM&lt;/b&gt;. Trong OU &lt;b&gt;HCM&lt;/b&gt;, tạo 2 group &lt;b&gt;Manager&lt;/b&gt;, &lt;b&gt;Staff&lt;/b&gt;.&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + Trong OU &lt;b&gt;HCM&lt;/b&gt;, tạo 2 user &lt;b&gt;Man1&lt;/b&gt;, &lt;b&gt;Man2&lt;/b&gt; làm thành viên của group &lt;b&gt;Manager&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + Trong OU &lt;b&gt;HCM&lt;/b&gt;, tạo 2 user &lt;b&gt;Staff1&lt;/b&gt;, &lt;b&gt;Staff2&lt;/b&gt; làm thành viên của group &lt;b&gt;Staff&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - Máy TMG Server: Windows Server&amp;#160; 2008 R2, TMG 2010&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - Máy Client : Windows 7&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;III. Thực hiện:&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;1. Kiểm tra Default Rule&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Mặc định sau khi cài TMG 2010, chỉ có 1 access rule tên &lt;b&gt;Default Rule&lt;/b&gt; cấm tất cả mọi traffic ra vào&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Tại máy Client, log on &lt;b&gt;TechNetVietnam\Administrator&lt;/b&gt;, truy cập vào trang web bất kỳ, kiểm tra nhận được thông báo lỗi của TMG Server&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture001_5F00_21400B5F.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture001_5F00_4EC3BBD3.png"&gt;&lt;img title="picture001" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture001" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture001_5F00_thumb_5F00_0FF8E868.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Tại máy DC, Vào &lt;b&gt;cmd&lt;/b&gt; gõ lệnh &lt;b&gt;nslookup&lt;/b&gt;, phân giải lần lượt tên 2 trang web sau: &lt;/span&gt;&lt;a href="http://www.technetvietnam.net"&gt;&lt;span style="font-family:arial;"&gt;www.technetvietnam.net&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt; và &lt;/span&gt;&lt;a href="http://www.vnexpress.net"&gt;&lt;span style="font-family:arial;"&gt;www.vnexpress.net&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&amp;#160; , kiểm tra phân giải thất bại&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture002_5F00_300CD1E8.png"&gt;&lt;/a&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture002_5F00_4D81B3A5.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;img title="picture002" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture002" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture002_5F00_thumb_5F00_4CB301A9.png" width="557" border="0" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;     &lt;br /&gt;&lt;span style="font-family:arial;"&gt;2. Tạo rule truy vấn DNS để phân giải tên miền&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Tại máy TMG Server, log on &lt;b&gt;TechNetVietnam\Administrator&lt;/b&gt;, mở &lt;b&gt;TMG Server&lt;/b&gt;, chuột phải&lt;b&gt; Firewall Policy&lt;/b&gt;, chọn &lt;b&gt;New&lt;/b&gt;, chọn &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;Access Rule        &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture003_5F00_48355DA5.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture003_5F00_6C5D48E5.png"&gt;&lt;img title="picture003" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture003" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture003_5F00_thumb_5F00_3B674C26.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;Access Rule Names&lt;/b&gt;, đặt tên rule là: &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;DNS Query        &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture004_5F00_7817B179.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture004_5F00_6AD8DA79.png"&gt;&lt;img title="picture004" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture004" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture004_5F00_thumb_5F00_33089831.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;Rule Action&lt;/b&gt;, chọn &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;Allow        &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture005_5F00_012E7FBF.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture005_5F00_09B1DF09.png"&gt;&lt;img title="picture005" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture005" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture005_5F00_thumb_5F00_036F9B07.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;Protocols&lt;/b&gt;, chọn &lt;b&gt;Selected Protocols&lt;/b&gt; và nhấn &lt;b&gt;Add&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Trong hộp thoại &lt;b&gt;Add Protocols&lt;/b&gt;, bung mục &lt;b&gt;Common Protocols&lt;/b&gt;, chọn &lt;b&gt;DNS&lt;/b&gt;, nhấn &lt;b&gt;Add&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture006_5F00_603D9DC8.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture006_5F00_7DB27F85.png"&gt;&lt;img title="picture006" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture006" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture006_5F00_thumb_5F00_296A6CBF.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Nhấn &lt;b&gt;Next&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture007_5F00_1B276143.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture007_5F00_75BD6DD4.png"&gt;&lt;img title="picture007" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture007" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture007_5F00_thumb_5F00_4A13C715.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;Access Rule Sources&lt;/b&gt;, Add 2 Rule : &lt;b&gt;Internal&lt;/b&gt; và &lt;b&gt;Local Host&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture008_5F00_13324F92.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture008_5F00_30A7314F.png"&gt;&lt;img title="picture008" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture008" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture008_5F00_thumb_5F00_14A02652.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;Access Rule Destinaton&lt;/b&gt;, Add Rule: &lt;b&gt;External, &lt;/b&gt;nhấn&lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt; Next        &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture009_5F00_202EC054.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture009_5F00_0FB64F59.png"&gt;&lt;img title="picture009" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture009" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture009_5F00_thumb_5F00_7109195B.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;User Sets&lt;/b&gt;, chọn &lt;b&gt;All Users, &lt;/b&gt;nhấn&lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt; Next        &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture010_5F00_3854BB60.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture010_5F00_75E4A9DA.png"&gt;&lt;img title="picture010" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture010" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture010_5F00_thumb_5F00_03E2BE68.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;Completing the New Access Rule Wizard&lt;/b&gt;,&amp;#160; kiểm tra lại thông tin về Rule lần cuối, sau đó nhấn &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;Finish        &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture011_5F00_377EE627.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture011_5F00_10B36098.png"&gt;&lt;img title="picture011" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture011" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture011_5F00_thumb_5F00_715500B6.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Nhấn chọn &lt;b&gt;Apply,&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt; Ok&amp;#160; &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&amp;#160; &lt;br /&gt;&lt;i&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Lưu ý:&lt;/b&gt;&lt;/span&gt; Sau mỗi lần tạo rule, phải chọn &lt;b&gt;Apply&lt;/b&gt; để rule có hiệu lực&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;     &lt;br /&gt;&lt;span style="font-family:arial;"&gt;3. Tạo rule cho phép các user thuộc nhóm Manager truy cập Internet không hạn chế&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;b&gt;a.&lt;/b&gt; &lt;b&gt;Tạo Element để định nghĩa nhóm Manager và Staff&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Trong cửa sổ TMG, tại cửa sổ thứ 3, chọn tab&lt;b&gt; Toolbox, &lt;/b&gt;bung mục&lt;b&gt; Users, &lt;/b&gt;chọn&lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt; New        &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;User set name&lt;/b&gt;, đặt tên là &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;Manager        &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture012_5F00_38E599AA.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture012_5F00_4F3B3EEF.png"&gt;&lt;img title="picture012" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture012" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture012_5F00_thumb_5F00_5B2406C6.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;Users&lt;/b&gt;, nhấn &lt;b&gt;Add&lt;/b&gt;, chọn &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;Windows users and groups…        &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture013_5F00_0854ACA3.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture013_5F00_30F318AA.png"&gt;&lt;img title="picture013" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture013" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture013_5F00_thumb_5F00_7BCFF1CD.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Add 2 users &lt;b&gt;Man1&lt;/b&gt; và &lt;b&gt;Man2&lt;/b&gt;&amp;#160; vào hộp thoại &lt;b&gt;Users&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture014_5F00_599184B1.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture014_5F00_54452EB1.png"&gt;&lt;img title="picture014" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture014" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture014_5F00_thumb_5F00_7F732E0C.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Trong hộp thoại &lt;b&gt;Completing&lt;/b&gt;, chọn &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;Finish&amp;#160;&amp;#160; &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture015_5F00_2AD0ED71.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture015_5F00_731E3340.png"&gt;&lt;img title="picture015" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture015" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture015_5F00_thumb_5F00_54BCE49E.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;-&amp;#160; Tương tự, bạn tạo thêm nhóm là &lt;/span&gt;&lt;span style="font-family:arial;"&gt;&lt;b&gt;Staff        &lt;br /&gt;&lt;/b&gt;      &lt;br /&gt;-&amp;#160; Hộp thoại Users, Add 2 user &lt;b&gt;Staff1&lt;/b&gt; và &lt;b&gt;Staff2, &lt;/b&gt;chọn&lt;/span&gt;&lt;span style="font-family:arial;"&gt;&lt;b&gt; Next        &lt;br /&gt;&lt;/b&gt;      &lt;br /&gt;-&amp;#160;&amp;#160; Hộp thoại &lt;b&gt;Completing the New User Set Wizard&lt;/b&gt;, chọn &lt;b&gt;Finish&lt;/b&gt;       &lt;br /&gt;&lt;/span&gt;&lt;b&gt;     &lt;br /&gt;&lt;/b&gt;&lt;span style="font-family:arial;"&gt;- Nhấn &lt;b&gt;Apply&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture016_5F00_2C37A0F4.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture016_5F00_2272397C.png"&gt;&lt;img title="picture016" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture016" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture016_5F00_thumb_5F00_376F3EE7.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;b Tạo Access Rule:&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Chuột phải &lt;b&gt;Firewall Policy&lt;/b&gt;, chọn &lt;b&gt;New,&lt;/b&gt; chọn &lt;b&gt;Access Rule&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;Access Rule Names&lt;/b&gt;, đặt tên rule là: &lt;b&gt;Allow Manager – Full Access&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture017_5F00_58E2EB7E.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture017_5F00_2F027749.png"&gt;&lt;img title="picture017" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture017" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture017_5F00_thumb_5F00_1D33F725.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt;&amp;#160;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;Rule Action&lt;/b&gt;, chọn &lt;b&gt;Allow&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;     &lt;br /&gt;&lt;/b&gt;&lt;b&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture018_5F00_0C413F8C.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture018_5F00_29B62149.png"&gt;&lt;img title="picture018" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture018" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture018_5F00_thumb_5F00_216580FD.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;Protocols&lt;/b&gt;, chọn &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;All outbound traffic        &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture019_5F00_270FF649.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture019_5F00_68AA3295.png"&gt;&lt;img title="picture019" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture019" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture019_5F00_thumb_5F00_57005DC6.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;Mailware Inspection&lt;/b&gt; chọn &lt;b&gt;Enable mailware inspection for this rule, &lt;/b&gt;chọn&lt;b&gt; Next&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture020_5F00_6D23440D.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture020_5F00_35731A8E.png"&gt;&lt;img title="picture020" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture020" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture020_5F00_thumb_5F00_7A5273CD.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;Access Rule Sources&lt;/b&gt;, add &lt;b&gt;Internal, &lt;/b&gt;chọn&lt;b&gt; Next&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture021_5F00_10092720.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture021_5F00_78E03D52.png"&gt;&lt;img title="picture021" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture021" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture021_5F00_thumb_5F00_144B5552.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;Access Rule Destinaton&lt;/b&gt;, add &lt;b&gt;External, c&lt;/b&gt;họn &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;Next        &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture022_5F00_3CE9C159.png"&gt;&lt;img title="picture022" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture022" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture022_5F00_thumb_5F00_084BF5CF.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;User Sets&lt;/b&gt;, remove group &lt;b&gt;All Users&lt;/b&gt;, và add group &lt;b&gt;Manager&lt;/b&gt; vào, chọn Next&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture023_5F00_5ED7B48E.png"&gt;&lt;img title="picture023" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture023" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture023_5F00_thumb_5F00_396DC120.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Hộp thoại &lt;b&gt;Completing the New Access Rule Wizard&lt;/b&gt;, chọn &lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt;Finish        &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture024_5F00_247ECF5E.png"&gt;&lt;img title="picture024" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture024" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture024_5F00_thumb_5F00_2C988C64.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;- Nhấn chọn &lt;b&gt;Apply, &lt;/b&gt;chọn&lt;/span&gt;&lt;b&gt;&lt;span style="font-family:arial;"&gt; OK&amp;#160; &lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;    &lt;p&gt;     &lt;br /&gt;-&amp;#160; Trên máy Client, log on&lt;b&gt; TechNetVietnam\Man1&lt;/b&gt;, truy cập trang web: &lt;a href="http://technetvietnam.net"&gt;http://technetvietnam.net&lt;/a&gt; &lt;/p&gt;   &lt;span style="font-family:arial;"&gt;kiểm tra truy cập thành công      &lt;br /&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture025_5F00_37C4A75F.png"&gt;&lt;img title="picture025" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture025" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture025_5F00_thumb_5F00_15036FA2.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://technetvietnam.net/aggbug.aspx?PostID=390" width="1" height="1"&gt;</content><author><name>DaoDuyHieu</name><uri>http://technetvietnam.net/members/DaoDuyHieu/default.aspx</uri></author><category term="TMG 2010" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/TMG+2010/default.aspx" /><category term="FIREWALL" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/FIREWALL/default.aspx" /><category term="ISA" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/ISA/default.aspx" /><category term="FOREFRONT TMG 2010" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/FOREFRONT+TMG+2010/default.aspx" /><category term="TMG" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/TMG/default.aspx" /></entry><entry><title>Cài đặt Forefront Threat Management Gateway (TMG) 2010 - Phần III: Cấu hình Auto Discovery &amp; triển khai Forefront TMG Client</title><link rel="alternate" type="text/html" href="/blogs/hieudd/archive/2010/12/09/c-224-i-t-forefront-threat-management-gateway-tmg-2010-ph-n-iii-c-u-h-236-nh-auto-discovery-amp-tri-n-khai-forefront-tmg-client.aspx" /><id>/blogs/hieudd/archive/2010/12/09/c-224-i-t-forefront-threat-management-gateway-tmg-2010-ph-n-iii-c-u-h-236-nh-auto-discovery-amp-tri-n-khai-forefront-tmg-client.aspx</id><published>2010-12-09T03:44:11Z</published><updated>2010-12-09T03:44:11Z</updated><content type="html">&lt;h3&gt;&lt;font color="#ff0000"&gt;Phần III: Cấu hình Auto Discovery &amp;amp; triển khai Forefront TMG Client &lt;/font&gt;&lt;/h3&gt;  &lt;p&gt;Có 3 cơ chế để các Clients trong nội bộ truy cập internet thông qua Forefront TMG Server là &lt;b&gt;Secure NAT Client&lt;/b&gt;, &lt;b&gt;Web Proxy Client&lt;/b&gt; &amp;amp; &lt;b&gt;Forefront TMG Client&lt;/b&gt; với các đặc điểm được so sánh trong bảng sau:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/TMGClient_5F00_3EA9AAAF.jpg"&gt;&lt;img title="TMGClient" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="385" alt="TMGClient" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/TMGClient_5F00_thumb_5F00_30D9F565.jpg" width="640" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Với các đặc điểm trong bảng so sánh trên, chúng ta thấy rõ ưu điểm của Forefront TMG Client là vừa hỗ trợ được tất cả protocols vừa hỗ trợ kiểm soát truy cập theo User account, vì vậy trong hệ thống Forefront TMG 2010 chúng ta nên cấu hình cho các máy Clients truy cập Internet bằng cơ chế Forefront TMG Client. Và để TMG Client tự động dò &amp;amp; kết nối đến TMG Server, trong phần III chúng tôi sẽ trình bày cách thức cấu hình chức năng Auto Discovery trên Forefront TMG 2010&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;u&gt;Lưu ý&lt;/u&gt;: Để thực hiện Phần III các bạn phải hoàn tất các bước ở &lt;a href="http://technetvietnam.net/blogs/hieudd/archive/2010/12/07/c-224-i-t-forefront-threat-management-gateway-tmg-2010-ph-n-i-t-ng-quan-forefront-tmg-2010.aspx"&gt;Phần I: Tổng quan Forefront TMG 2010&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;1&lt;/b&gt;&lt;b&gt;. Bật chức năng Auto Discovery trên Forefront TMG Server&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;- Trên TMG Server, logon TECHNETVIETNAM\Administrator, mở Forefront TMG Management, vào Networking&lt;/p&gt;  &lt;p&gt;- Trong cửa sổ giữa, qua tab Network, chuột phải Internal chọn Properties &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture001_5F00_4BA61B71.png"&gt;&lt;img title="picture001" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture001" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture001_5F00_thumb_5F00_0216CD74.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong hộp thoại Internal Properties, qua tab Auto Discovery, đánh dấu chọn vào ô Publish automatic discovery information for this network, chọn OK &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture002_5F00_7F70A273.png"&gt;&lt;img title="picture002" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture002" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture002_5F00_thumb_5F00_0A9CBD6F.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong cửa sổ Forefront TMG, chọn Apply&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture003_5F00_0C00E041.png"&gt;&lt;img title="picture003" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture003" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture003_5F00_thumb_5F00_5043D83E.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-Trong hộp thoại Saving Configuration Changes, chọn OK&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;5. Cấu hình Auto Discovery&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Có 3 cách cấu hình Auto Discovery: &lt;/p&gt;  &lt;p&gt;- Cấu hình Auto Discovery bằng Alias record trên DNS Server&lt;/p&gt;  &lt;p&gt;- Cấu hình Auto Discovery bằng DHCP Option&lt;/p&gt;  &lt;p&gt;- Cấu hình Auto Discovery bằng Active Directory&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Cách 1:&amp;#160; Cấu hình Auto Discovery bằng Alias record trên DNS Server&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;- Trên DNS Server (Server02), mở DNS Management, bung Forward Lookup Zones, chuột phải trên zone technetvietnam.local chọn New Alias (CNAME)&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture004_5F00_66997D83.png"&gt;&lt;img title="picture004" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture004" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture004_5F00_thumb_5F00_56210C88.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-Trong hộp thoại New Resource Record, khai báo các thông tin như trong hình bên dưới, chọn OK (TMG.technetvietnam.local là tên của máy TMG Server) &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture005_5F00_2CACCB48.png"&gt;&lt;img title="picture005" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture005" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture005_5F00_thumb_5F00_3EF822BB.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;b&gt;Vì trên Windows Server 2008 R2, trong danh sách Global Query Block List cấm phân giải tên WPAD nên chúng ta phải làm hành động xóa danh sách Global Query Block List hiện thời.&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;- Để kiểm tra danh sách Global Query Block List hiện thời các bạn sử dụng lệnh: &lt;b&gt;dnscmd /info /globalqueryblocklist &lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture006_5F00_6077524A.png"&gt;&lt;img title="picture006" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture006" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture006_5F00_thumb_5F00_77392A84.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Để xóa&amp;#160; danh sách Global Query Block List hiện thời các bạn sử dụng lệnh: &lt;b&gt;dnscmd /config /globalqueryblocklist &lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture007_5F00_7909804B.png"&gt;&lt;img title="picture007" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture007" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture007_5F00_thumb_5F00_6A616517.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Sử dụng lệnh nslookup kiểm tra phân giải thành công alias &lt;strong&gt;WPAD.technetvietnam.local&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture008_5F00_2F10900A.png"&gt;&lt;img title="picture008" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture008" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture008_5F00_thumb_5F00_29C1A959.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Cách 2: Cấu hình Auto Discovery bằng DHCP Option&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Thực hiện tại DHCP Server &lt;/p&gt;  &lt;p&gt;- Mở công cụ quản lý DHCP, chuột phải IPv4 chọn Set Predefined Options &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture009_5F00_597F51D8.png"&gt;&lt;img title="picture009" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture009" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture009_5F00_thumb_5F00_6921ED9A.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-Trong hộp thoại Predefined Options and Values, chọn Add để tạo 1 DHCP Option mới&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture010_5F00_0DB60BD0.png"&gt;&lt;img title="picture010" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture010" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture010_5F00_thumb_5F00_684C1861.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-Trong hộp thoại Option Type, khai báo các giá trị như trong hình bên dưới, chọn OK &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture011_5F00_25DC06DC.png"&gt;&lt;img title="picture011" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture011" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture011_5F00_thumb_5F00_357EA29E.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-Trong hộp thoại Predefined Options and Values, nhập &lt;a href="http://TMG.technetvietnam.local:8080/wpad.dat"&gt;http://TMG.technetvietnam.local:8080/wpad.dat&lt;/a&gt; vào ô String, chọn OK&lt;/p&gt;  &lt;p&gt;(TMG.technetvietnam.local là tên của máy TMG Server) &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture012_5F00_45213E60.png"&gt;&lt;img title="picture012" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture012" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture012_5F00_thumb_5F00_6DBFAA67.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-Trong cửa sổ DHCP,bung Scope Internal, chuột phải Server Options chọn Configure Options &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture013_5F00_2B4F98E2.png"&gt;&lt;img title="picture013" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture013" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture013_5F00_thumb_5F00_461BBEEE.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-Trong hộp thoại Server Option, đánh dấu chọn ô 252 WPAD, chọn OK&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture014_5F00_3CC28A6B.png"&gt;&lt;img title="picture014" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture014" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture014_5F00_thumb_5F00_79E645F0.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong Server Option, kiểm tra có option 252 WPAD &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture015_5F00_2284B1F8.png"&gt;&lt;img title="picture015" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture015" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture015_5F00_thumb_5F00_32274DBA.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Cách 3: Cấu hình Auto Discovery bằng Active Directory&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Thực hiện tại TMG Server &lt;/p&gt;  &lt;p&gt;- Download &lt;b&gt;&lt;a href="http://download.microsoft.com/download/D/A/4/DA48B499-D681-4493-AB83-0EDA4789F412/AdConfigPack.exe"&gt;AdConfigPack.exe&lt;/a&gt;&lt;/b&gt; , chạy file &lt;b&gt;AdConfigPack.exe&lt;/b&gt; để cài đặt &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture016_5F00_28CE1937.png"&gt;&lt;img title="picture016" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture016" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture016_5F00_thumb_5F00_665E07B1.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-Trong hộp thoại Welcome, chọn Next&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture017_5F00_610F2100.png"&gt;&lt;img title="picture017" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture017" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture017_5F00_thumb_5F00_05A33F36.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-Trong hộp thoại License Agreement, chọn I accept the terms in the license agreement, chọn Next&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture018_5F00_3560E7B5.png"&gt;&lt;img title="picture018" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture018" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture018_5F00_thumb_5F00_0BECA675.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Hộp thoại Location to Save Files, để đường dẫn mặc định, chọn Next, chọn Finish&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture019_5F00_1F999009.png"&gt;&lt;img title="picture019" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture019" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture019_5F00_thumb_5F00_4F573888.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Mở Command Line, chuyển qua đường dẫn C:\Program Files (x86)\Microsoft TMG\AdConfig, gõ lệnh&lt;/p&gt;  &lt;p&gt;&lt;b&gt;TMGAdConfig.exe add -default -type winsock -url &lt;a href="http://TMG.technetvietnam.local:8080/wspad.dat"&gt;http://TMG.technetvietnam.local:8080/wspad.dat&lt;/a&gt; -f &lt;/b&gt;&lt;/p&gt;  &lt;p&gt;(TMG.technetvietnam.local là tên của máy TMG Server) &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture021_5F00_2D0233C0.png"&gt;&lt;img title="picture021" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture021" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture021_5F00_thumb_5F00_00E536CF.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;6. Cài đặt Forefront TMG Client&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Đề triển khai cài đặt Forefront TMG Client cùng lúc cho tất cả các máy Clients, trong hệ thống thực tế các bạn có thể sử dụng chức năng Deploy Software của GPO hoặc SCCM. Trong bài viết này, để hiểu rõ vấn đề cài đặt Forefront TMG Client nên chúng tôi sẽ cài bằng tay.&lt;/p&gt;  &lt;p&gt;- Trên các máy Client, mở source cài đặt Forefront TMG 2010, vào thư mục client, chạy file &lt;b&gt;MS_FWC.msi&lt;/b&gt; để cài đặt&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture022_5F00_69B9BC50.png"&gt;&lt;img title="picture022" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture022" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture022_5F00_thumb_5F00_795C5812.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-&amp;#160; Trong hộp thoại Welcome, chọn Next &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture023_5F00_4FE816D2.png"&gt;&lt;img title="picture023" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture023" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture023_5F00_thumb_5F00_28B05E4E.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong hộp thoại License Agreement, chọn I accept the terms in the license agreement, chọn Next&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture024_5F00_0CA23014.png"&gt;&lt;img title="picture024" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture024" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture024_5F00_thumb_5F00_57983194.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Hộp thoại Destination Folder, giữ nguyên đường dẫn mặc định, chọn Next&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture025_5F00_099262D0.png"&gt;&lt;img title="picture025" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture025" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture025_5F00_thumb_5F00_269B1198.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong hộp thoại, Forefront TMG Computer Selection chọn:&lt;/p&gt;  &lt;p&gt;&amp;#160; + Connect to this Forefront TMG computer để khai báo TMG Server bằng tay&lt;/p&gt;  &lt;p&gt;&amp;#160; + Automatically detect the appropriate Forefront TMG computer để TMG Client tự động dò và kết nối TMG Server&lt;/p&gt;  &lt;p&gt;Vì chúng ta đã cấu hình Auto Discovery nên lúc này chúng ta chọn chế độ Automatically detect the appropriate Forefront TMG computer&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture026_5F00_63BECD1D.png"&gt;&lt;img title="picture026" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture026" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture026_5F00_thumb_5F00_1DD02AAE.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Hộp thoại Ready to Install the Program, chọn Install&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture027_5F00_21DD0931.png"&gt;&lt;img title="picture027" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture027" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture027_5F00_thumb_5F00_7F1BD173.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Hộp thoại Install Wizard Completed, chọn Finish&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture028_5F00_51310F6C.png"&gt;&lt;img title="picture028" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture028" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture028_5F00_thumb_5F00_6E39BE34.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Mở Forefront TMG Client, qua tab Setting, kiểm traTMG Client kết nối đến TMG Server thành công, chọn Advanced&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture029_5F00_392FBFB5.png"&gt;&lt;img title="picture029" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture029" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture029_5F00_thumb_5F00_56386E7D.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-Trong hộp thoại Advanced Automatic Detection, kiểm tra chúng ta đang sử dụng cả 3 cơ chế Auto Discovery&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture030_5F00_08329FB9.png"&gt;&lt;img title="picture030" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture030" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture030_5F00_thumb_5F00_3A2CD0F4.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;7. Kiểm tra truy cập Internet&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;- Trên máy TMG Server, mở Forefront TMG Management, chuột phải Firewall Policy bung New, chọn Access Rule &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture031_5F00_1E1EA2BA.png"&gt;&lt;img title="picture031" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture031" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture031_5F00_thumb_5F00_78B4AF4B.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-Trong hộp thoại Welcome, đặt tên cho rule là Test : Internet outgoing , chọn Next&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture032_5F00_16299109.png"&gt;&lt;img title="picture032" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture032" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture032_5F00_thumb_5F00_0859DBBF.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Hộp thoại, Rule Action. chọn Allow, chọn Next&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture033_5F00_42D4DB93.png"&gt;&lt;img title="picture033" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture033" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture033_5F00_thumb_5F00_0E371009.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-Hộp thoại Protocol, chọn All outbound traffic, chọn Next &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture034_5F00_4FD14C55.png"&gt;&lt;img title="picture034" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture034" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture034_5F00_thumb_5F00_5F73E817.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-Hộp thoại malware Inspection, chọn Do not enable malware inspection for this rule, chọn Next &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture035_5F00_1D03D692.png"&gt;&lt;img title="picture035" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture035" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture035_5F00_thumb_5F00_53748894.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Hộp thoại Access Rule Source, add Internal &amp;amp; Local Host vào, chọn Next &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture036_5F00_70E96A51.png"&gt;&lt;img title="picture036" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture036" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture036_5F00_thumb_5F00_1987D659.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Hộp thoại Access Rule Destinations, add External vào, chọn Next &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture037_5F00_292A721B.png"&gt;&lt;img title="picture037" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture037" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture037_5F00_thumb_5F00_66BA6095.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-Hộp thoại User Sets, để mặc định, chọn Next&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture038_5F00_08399025.png"&gt;&lt;img title="picture038" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture038" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture038_5F00_thumb_5F00_77C11F29.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-Hộp thoại Completing, chọn Finish&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture039_5F00_35510DA4.png"&gt;&lt;img title="picture039" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture039" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture039_5F00_thumb_5F00_4BA6B2E9.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong cửa sổ Forefront TMG chọn Apply, chọn OK&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture040_5F00_28E57B2C.png"&gt;&lt;img title="picture040" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture040" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture040_5F00_thumb_5F00_63CF3EA6.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Kiểm tra tất cả các máy truy cập Internet thành công &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture041_5F00_777C283A.png"&gt;&lt;img title="picture041" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture041" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture041_5F00_thumb_5F00_22C34FF3.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://technetvietnam.net/aggbug.aspx?PostID=386" width="1" height="1"&gt;</content><author><name>DaoDuyHieu</name><uri>http://technetvietnam.net/members/DaoDuyHieu/default.aspx</uri></author><category term="FIREWALL" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/FIREWALL/default.aspx" /><category term="ISA" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/ISA/default.aspx" /><category term="FOREFRONT TMG 2010" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/FOREFRONT+TMG+2010/default.aspx" /><category term="TMG" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/TMG/default.aspx" /></entry><entry><title>Cài đặt Forefront Threat Management Gateway (TMG) 2010 - Phần II: Cài đặt Forefront TMG Server</title><link rel="alternate" type="text/html" href="/blogs/hieudd/archive/2010/12/08/c-224-i-t-forefront-threat-management-gateway-tmg-2010-ph-n-ii-c-224-i-t-forefront-tmg-server.aspx" /><id>/blogs/hieudd/archive/2010/12/08/c-224-i-t-forefront-threat-management-gateway-tmg-2010-ph-n-ii-c-224-i-t-forefront-tmg-server.aspx</id><published>2010-12-08T00:50:39Z</published><updated>2010-12-08T00:50:39Z</updated><content type="html">&lt;h3&gt;&lt;font color="#ff0000"&gt;Phần II: Cài đặt Forefront TMG Server&lt;/font&gt; &lt;/h3&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font color="#0000ff"&gt;I. Mô hình:&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/TMG_5F00_7E6FF44C.png"&gt;&lt;img title="TMG" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="267" alt="TMG" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/TMG_5F00_thumb_5F00_70340C0D.png" width="640" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font color="#0000ff"&gt;II. Chuẩn bị:&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Trong mô hình lab sử dụng 02 máy Windows Server 2008 R2 và 01 máy Windows 7&lt;/p&gt;  &lt;p&gt;- TMG làm chức năng TMG Server (TMG.technetvietnam.local)&lt;/p&gt;  &lt;p&gt;- PDC làm chức năng DC, DNS Server (PDC.technetvietnam.local) &lt;/p&gt;  &lt;p&gt;- WIN7 làm chứng năng client (WIN7.technetvietnam.local)&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Thiết lập TCP/IP cho 2 máy như trong bảng sau:&lt;/p&gt;  &lt;table cellspacing="0" cellpadding="2" width="619" border="1"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="118"&gt;         &lt;p align="center"&gt;&lt;strong&gt;Interface\Server&lt;/strong&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="127"&gt;         &lt;p align="center"&gt;&lt;strong&gt;PDC&lt;/strong&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="233"&gt;         &lt;p align="center"&gt;&lt;strong&gt;TMG Server&lt;/strong&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="139"&gt;         &lt;p align="center"&gt;&lt;strong&gt;WIN7&lt;/strong&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="118"&gt;         &lt;p align="center"&gt;&lt;strong&gt;LAN&lt;/strong&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="127"&gt;IP : 172.16.1.2          &lt;br /&gt;GW : 172.16.1.1           &lt;br /&gt;DNS : 172.16.1.2&lt;/td&gt;        &lt;td valign="top" width="233"&gt;IP : 172.16.1.1          &lt;br /&gt;GW :           &lt;br /&gt;DNS : 172.16.1.2&lt;/td&gt;        &lt;td valign="top" width="139"&gt;IP : 172.16.1.11          &lt;br /&gt;GW : 172.16.1.1           &lt;br /&gt;DNS : 172.16.1.2&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="118"&gt;         &lt;p align="center"&gt;&lt;strong&gt;WAN&lt;/strong&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="127"&gt;&amp;#160;&lt;/td&gt;        &lt;td valign="top" width="233"&gt;IP : 192.168.1.2          &lt;br /&gt;GW : 192.168.1.1 (DSL Router)           &lt;br /&gt;DNS : &lt;/td&gt;        &lt;td valign="top" width="139"&gt;&amp;#160;&lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;- Cấu hình PDC làm Domain Controller &amp;amp; DNS Server của domain TECHNETVIETNAM.LOCAL&lt;/p&gt;  &lt;p&gt;- Join TMG &amp;amp; WIN7 vào domain TECHNETVIETNAM.LOCAL&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font color="#0000ff"&gt;III. Thực hiện:&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;1. Thực hiện Windows Update&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Chạy Windows Update để cài đặt các bản cập nhật &amp;amp; bản vá lỗi cần thiết trước khi cài đặt Forefront TMG Server &lt;/p&gt;  &lt;p&gt;- Trên TMG Server, logon TECHNETVIETNAM\Administrator, chay file autorun.hta trong source cài đặt Forefront TMG 2010&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture001_5F00_7D2DEC1E.png"&gt;&lt;img title="picture001" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture001" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture001_5F00_thumb_5F00_21C20A54.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong&amp;#160; cửa sổ cài đặt Forefront TMG 2010, chọn Run Windows Update&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture002_5F00_3164A616.png"&gt;&lt;img title="picture002" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture002" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture002_5F00_thumb_5F00_67692523.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Sau khi update thành công, chọn Install updates &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture003_5F00_6B7603A6.png"&gt;&lt;img title="picture003" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture003" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture003_5F00_thumb_5F00_621CCF23.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong hộp thoại Windows Update, chọn I accept the license terms, chọn Finish &lt;/p&gt;  &lt;p&gt;-&amp;#160; Sau khi cài đặt Windows Update thành công, chọn Restart now &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture004_5F00_3FC7CA5B.png"&gt;&lt;img title="picture004" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture004" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture004_5F00_thumb_5F00_217D1365.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;2. Chạy Preparation Tool&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Chạy Preparation Tool để cài đặt các Roles &amp;amp; Features cần thiết cho Forefront TMG Server &lt;/p&gt;  &lt;p&gt;-Trong cửa sổ cài đặt Forefront TMG 2010, chọn Run Preparation Tool &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture005_5F00_03325C6F.png"&gt;&lt;img title="picture005" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture005" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture005_5F00_thumb_5F00_073F3AF2.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-Trong hộp thoại Welcome, chọn Next&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture006_5F00_39396C2D.png"&gt;&lt;img title="picture006" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture006" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture006_5F00_thumb_5F00_7AD3A879.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong hộp thoại License Agreement, đánh dấu chọn I accept the terms of the License Agreements, chọn Next&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture007_5F00_515F6739.png"&gt;&lt;img title="picture007" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture007" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture007_5F00_thumb_5F00_0EEF55B4.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong hộp thoại Installation Type, chọn Forefront TMG services and Management, chọn Next &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture008_5F00_70A49EBD.png"&gt;&lt;img title="picture008" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture008" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture008_5F00_thumb_5F00_674B6A3A.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-&amp;#160; Sau khi cài đặt thành công, chọn Finish&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture009_5F00_4900B344.png"&gt;&lt;img title="picture009" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture009" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture009_5F00_thumb_5F00_58A34F06.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;3.Cài đặt Forefront TMG Server &lt;/b&gt;&lt;/p&gt;  &lt;p&gt;- Trong cửa sổ cài đặt Forefront TMG 2010, chọn Run Installation Wizard &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture010_5F00_16333D81.png"&gt;&lt;img title="picture010" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture010" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture010_5F00_thumb_5F00_333BEC49.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong hộp thoại Welcome, chọn Next &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture011_5F00_3748CACC.png"&gt;&lt;img title="picture011" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture011" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture011_5F00_thumb_5F00_54BDAC89.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong hộp thoại License Agreement, chọn I accept the terms in the license agreement, chọn Next&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture012_5F00_391BB144.png"&gt;&lt;img title="picture012" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture012" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture012_5F00_thumb_5F00_48BE4D06.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong hộp thoại Customer Information, khai báo Product Serial Number, chọn Next &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture013_5F00_5860E8C8.png"&gt;&lt;img title="picture013" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture013" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture013_5F00_thumb_5F00_22EAB754.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong hộp thoại Setup Scenarios, chọn Forefront TMG services and Management&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture014_5F00_52A85FD3.png"&gt;&lt;img title="picture014" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture014" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture014_5F00_thumb_5F00_14429C20.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong hộp thoại Installation Path, khai báo đường dẫn cài đặt, chọn Next &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture015_5F00_3C7765E3.png"&gt;&lt;img title="picture015" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture015" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture015_5F00_thumb_5F00_67BE8D9B.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong hộp thoại Define Internal Network, chọn Add để khai báo subnet sử dụng trong hệ thống nội bộ &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture016_5F00_44FD55DE.png"&gt;&lt;img title="picture016" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture016" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture016_5F00_thumb_5F00_0DB6CEA3.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-&amp;#160; Trong hộp thoại Address, chọn Add Adapter...&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture017_5F00_36553AAA.png"&gt;&lt;img title="picture017" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture017" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture017_5F00_thumb_5F00_45F7D66C.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong hộp thoại Select Network Adapters, đánh dấu chọn card LAN (Card LAN là card mạng kết nối và nội bộ), chọn OK&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture018_5F00_713EFE24.png"&gt;&lt;img title="picture018" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture018" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture018_5F00_thumb_5F00_00E199E7.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-&amp;#160; Trong hộp thoại Define Internal Network, kiểm tra subnet nội bộ là 172.16.1.0-172.16.1.255, chọn Next&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture019_5F00_576D58A6.png"&gt;&lt;img title="picture019" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture019" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture019_5F00_thumb_5F00_68E04A2F.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong hộp thoại Services Warning, chọn Next &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture020_5F00_03AC703C.png"&gt;&lt;img title="picture020" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture020" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture020_5F00_thumb_5F00_61576B73.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong hộp thoại Ready to Install the Program, chọn Install&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture021_5F00_111513F3.png"&gt;&lt;img title="picture021" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture021" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture021_5F00_thumb_5F00_44DD0A44.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-&amp;#160; Sau khi cài đặt thành công,chọn Finish &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture022_5F00_749AB2C3.png"&gt;&lt;img title="picture022" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture022" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture022_5F00_thumb_5F00_322AA13E.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Vào Start\All Programs\Microsoft Forefront TMG Management, mở Forefront TMG Management&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture023_5F00_41CD3D00.png"&gt;&lt;img title="picture023" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture023" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture023_5F00_thumb_5F00_588F153A.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong hộp thoại Getting Started Wizard, chọn Configure network settings &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture024_5F00_41639ABC.png"&gt;&lt;img title="picture024" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture024" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture024_5F00_thumb_5F00_77D44CBE.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-Trong hộp thoại Welcome, chọn Next&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture025_5F00_526A5950.png"&gt;&lt;img title="picture025" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture025" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture025_5F00_thumb_5F00_7DB18108.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong hộp thoại Network Template Selection, chọn Edge firewall, chọn Next &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture026_5F00_7B0B5608.png"&gt;&lt;img title="picture026" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture026" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture026_5F00_thumb_5F00_4A77D850.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Để chỉ định card mạng kết nối vào nội bộ, trong hộp thoại Local Area Network (LAN) Setting, chọn card LAN, chọn Next&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture027_5F00_2ED5DD0B.png"&gt;&lt;img title="picture027" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture027" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture027_5F00_thumb_5F00_1E5D6C10.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Để chỉ định card mạng kết nối ra Internet,trong hộp thoại Internet Settings, chọn card EXT, chọn Next, chọn Finish&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture028_5F00_3929921C.png"&gt;&lt;img title="picture028" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture028" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture028_5F00_thumb_5F00_01E30AE1.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong hộp thoại Getting Started Wizard, chọn Configure system settings &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture030_5F00_31A0B360.png"&gt;&lt;img title="picture030" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture030" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture030_5F00_thumb_5F00_21284265.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong hộp thoại Welcome, chọn Next&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture031_5F00_25A153DD.png"&gt;&lt;img title="picture031" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture031" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture031_5F00_thumb_5F00_1528E2E2.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-&amp;#160; Trong hộp thoại Host Identification, bảo đảm khai báo đúng thông tin của máy TMG Server như trong hình bên dưới, chọn Nex, chọn Finish &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture032_5F00_329DC49F.png"&gt;&lt;img title="picture032" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture032" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture032_5F00_thumb_5F00_6665BAF0.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong hộp thoại Getting Started Wizard, chọn Define deployment options &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture034_5F00_23F5A96B.png"&gt;&lt;img title="picture034" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture034" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture034_5F00_thumb_5F00_137D3870.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Hộp thoại Welcome, chọn Next &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture035_5F00_0D5B0D37.png"&gt;&lt;img title="picture035" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture035" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture035_5F00_thumb_5F00_7CE29C3B.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-Trong hộp thoại Microsoft Update Setting, chọn use the Microsoft Update service to check for updates, chọn Next &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture036_5F00_4C4F1E83.png"&gt;&lt;img title="picture036" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture036" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture036_5F00_thumb_5F00_22DADD43.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;-Trong hộp thoại Forefront TMG Protection Features Setting, khai báo License cho NIS &amp;amp; Web Protection như hình bên dưới, đánh dấu chọn Enable Mailware Inspection &amp;amp; Enable URL Filtering, chọn Next &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture037_5F00_606ACBBD.png"&gt;&lt;img title="picture037" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture037" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture037_5F00_thumb_5F00_422014C7.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Hộp thoại NIS Sgnature Update Settings, giữ nguyên cấu hình mặc định, chọn Next &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture038_5F00_7FB00341.png"&gt;&lt;img title="picture038" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture038" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture038_5F00_thumb_5F00_3D3FF1BC.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Hộp thoại Customer Feedback, chọn No, I don&amp;#39;t want to participate, chọn Next &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture039_5F00_1EF53AC6.png"&gt;&lt;img title="picture039" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture039" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture039_5F00_thumb_5F00_7580F985.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Hộp thoại Microsoft Telemetry Reporting Service, chọn chế độ Basic, chọn Next &amp;amp; Finish &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture040_5F00_12F5DB43.png"&gt;&lt;img title="picture040" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture040" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture040_5F00_thumb_5F00_027D6A48.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Trong hộp thoại Getting Started Wizard, bỏ dấu chọn Run the Web Access wizard, chọn Close&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture042_5F00_7204F94C.png"&gt;&lt;img title="picture042" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture042" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture042_5F00_thumb_5F00_41717B94.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;- Kiểm tra cài đặt Forefront TMG Server thành công &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture043_5F00_25CF804F.png"&gt;&lt;img title="picture043" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture043" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture043_5F00_thumb_5F00_753C0296.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;4. Cài Service Pack 1 cho TMG 2010&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Download : &lt;a title="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=f0fd5770-7360-4916-a5be-a88a0fd76c7c" href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=f0fd5770-7360-4916-a5be-a88a0fd76c7c"&gt;http://www.microsoft.com/downloads/en/details.aspx?FamilyID=f0fd5770-7360-4916-a5be-a88a0fd76c7c&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture044_5F00_599A0751.png"&gt;&lt;img title="picture044" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture044" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture044_5F00_thumb_5F00_693CA313.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture045_5F00_1D049965.png"&gt;&lt;img title="picture045" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture045" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture045_5F00_thumb_5F00_5A9487DF.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture046_5F00_513B535C.png"&gt;&lt;img title="picture046" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture046" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture046_5F00_thumb_5F00_32F09C66.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture047_5F00_14A5E570.png"&gt;&lt;img title="picture047" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture047" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture047_5F00_thumb_5F00_59551062.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture048_5F00_2D381371.png"&gt;&lt;img title="picture048" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture048" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture048_5F00_thumb_5F00_5CF5BBF0.png" width="557" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture049_5F00_45CA4172.png"&gt;&lt;img title="picture049" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="480" alt="picture049" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/picture049_5F00_thumb_5F00_1C560032.png" width="557" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://technetvietnam.net/aggbug.aspx?PostID=383" width="1" height="1"&gt;</content><author><name>DaoDuyHieu</name><uri>http://technetvietnam.net/members/DaoDuyHieu/default.aspx</uri></author><category term="FIREWALL" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/FIREWALL/default.aspx" /><category term="ISA" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/ISA/default.aspx" /><category term="FOREFRONT TMG 2010" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/FOREFRONT+TMG+2010/default.aspx" /><category term="TMG" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/TMG/default.aspx" /></entry><entry><title>Cài đặt Forefront Threat Management Gateway (TMG) 2010 - Phần I: Tổng quan Forefront TMG 2010</title><link rel="alternate" type="text/html" href="/blogs/hieudd/archive/2010/12/07/c-224-i-t-forefront-threat-management-gateway-tmg-2010-ph-n-i-t-ng-quan-forefront-tmg-2010.aspx" /><id>/blogs/hieudd/archive/2010/12/07/c-224-i-t-forefront-threat-management-gateway-tmg-2010-ph-n-i-t-ng-quan-forefront-tmg-2010.aspx</id><published>2010-12-07T03:04:00Z</published><updated>2010-12-07T03:04:00Z</updated><content type="html">&lt;p&gt;Forefront Threat Management Gateway (TMG) 2010 l&amp;agrave; phi&amp;ecirc;n bản &amp;quot;Firewall&amp;quot; mới của Microsoft thay thế cho sản phẩm ISA Server 2006. Với những t&amp;iacute;nh năng bảo mật hệ thống được n&amp;acirc;ng cao đ&amp;aacute;ng kể, c&amp;aacute;c bạn c&amp;oacute; thể y&amp;ecirc;n t&amp;acirc;m v&amp;igrave; nh&amp;acirc;n vi&amp;ecirc;n trong c&amp;ocirc;ng ty c&amp;oacute; thể truy cập internet một c&amp;aacute;ch hiệu quả m&amp;agrave; kh&amp;ocirc;ng cần phải lo lắng về phần mềm độc hại (malware) &amp;amp; c&amp;aacute;c mối đe dọa kh&amp;aacute;c.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;B&amp;agrave;i viết bao gồm 3 phần:&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Phần I: Tổng quan Forefront TMG 2010&lt;/p&gt;
&lt;p&gt;Phần II: C&amp;agrave;i đặt Forefront TMG Server&lt;/p&gt;
&lt;p&gt;Phần III: Cấu h&amp;igrave;nh Auto Discovery &amp;amp; triển khai Forefront TMG Client &lt;/p&gt;
&lt;p&gt;-------------&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="color:#ff0000;"&gt;Phần I: Tổng quan Forefront TMG 2010&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/image01_5F00_0CCE0A39.jpg"&gt;&lt;img title="image01" style="border-right:0px;border-top:0px;display:inline;border-left:0px;border-bottom:0px;" alt="image01" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/image01_5F00_thumb_5F00_49F1C5BE.jpg" border="0" height="157" width="640" /&gt;&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;b&gt;A. C&amp;aacute;c chức năng ch&amp;iacute;nh của Forefront TMG 2010&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/image02_5F00_7E25EF04.jpg"&gt;&lt;img title="image02" style="border-right:0px;border-top:0px;display:inline;border-left:0px;border-bottom:0px;" alt="image02" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/image02_5F00_thumb_5F00_5BD0EA3C.jpg" border="0" height="355" width="640" /&gt;&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;B. C&amp;aacute;c t&amp;iacute;nh năng nổi trội của Forefront TMG 2010&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/image03_5F00_3D863346.jpg"&gt;&lt;img title="image03" style="border-right:0px;border-top:0px;display:inline;border-left:0px;border-bottom:0px;" alt="image03" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/image03_5F00_thumb_5F00_786D660F.jpg" border="0" height="333" width="640" /&gt;&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;b&gt;Enhanced Voice over IP:&lt;/b&gt; cho ph&amp;eacute;p kết nối &amp;amp; sử dụng VoIP th&amp;ocirc;ng qua TMG&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&lt;b&gt;ISP Link Redundancy&lt;/b&gt;: hỗ trợ load balancing &amp;amp; failover cho nhiều đường truyền internet &lt;/p&gt;
&lt;p&gt;&lt;b&gt;Web anti-malware:&lt;/b&gt; qu&amp;eacute;t virus, phần mềm độc hại &amp;amp; c&amp;aacute;c mối đe dọa kh&amp;aacute;c khi truy cập web &lt;/p&gt;
&lt;p&gt;&lt;b&gt;URL filtering:&lt;/b&gt; cho ph&amp;eacute;p hoặc cấm truy cập c&amp;aacute;c trang web theo danh s&amp;aacute;ch ph&amp;acirc;n loại nội dung sẵn c&amp;oacute; như: nội dung khi&amp;ecirc;u d&amp;acirc;m, ma t&amp;uacute;y, mua sắm, chat...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;HTTPS inspection:&lt;/b&gt; kiểm so&amp;aacute;t c&amp;aacute;c g&amp;oacute;i tin được m&amp;atilde; h&amp;oacute;a HTTPS để ph&amp;ograve;ng chống phần mềm độc hại &amp;amp; kiểm tra t&amp;iacute;nh hợp lệ của c&amp;aacute;c SSL Certificate &lt;/p&gt;
&lt;p&gt;&lt;b&gt;E-mail protection subscription service:&lt;/b&gt; t&amp;iacute;ch hợp với Forefront Protection 2010 for Exchange Server &amp;amp; Exchange Edge Transport Server để kiểm so&amp;aacute;t viruses, malware, spam e-mail trong hệ thống Mail Exchange &lt;/p&gt;
&lt;p&gt;&lt;b&gt;Network Inspection System (NIS):&lt;/b&gt; ngăn chặn c&amp;aacute;c cuộc tấn c&amp;ocirc;ng dựa v&amp;agrave;o lỗ hổng bảo mật&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&lt;b&gt;Network Access Protection (NAP) Integration:&lt;/b&gt; t&amp;iacute;ch hợp với NAP để kiểm tra t&amp;igrave;nh trạng an to&amp;agrave;n của c&amp;aacute;c client trước khi cho ph&amp;eacute;p client kết nối VPN &lt;/p&gt;
&lt;p&gt;&lt;b&gt;Security Socket Tunneling Protocol (SSTP) Integration:&lt;/b&gt; Hỗ trợ VPN-SSTP&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Windows Server 2008 with 64-bit support:&lt;/b&gt; Hỗ trợ Windows Server 2008 &amp;amp; Windows Server 2008 R2 64-bit&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;C. Bảng so s&amp;aacute;nh chức năng của ISA Server 2006 &amp;amp; Forefront TMG 2010&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/image04_5F00_3D1C9102.jpg"&gt;&lt;img title="image04" style="border-right:0px;border-top:0px;display:inline;border-left:0px;border-bottom:0px;" alt="image04" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/image04_5F00_thumb_5F00_57E8B70E.jpg" border="0" height="401" width="640" /&gt;&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;D. Bảng so s&amp;aacute;nh 2 phi&amp;ecirc;n bản Forefront TMG Standard &amp;amp; Enterprise &lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/image05_5F00_55AEBF03.jpg"&gt;&lt;img title="image05" style="border-right:0px;border-top:0px;display:inline;border-left:0px;border-bottom:0px;" alt="image05" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/image05_5F00_thumb_5F00_02C3ABD2.jpg" border="0" height="341" width="640" /&gt;&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;E. C&amp;aacute;c y&amp;ecirc;u cầu phần cứng khi c&amp;agrave;i đặt ForeFront TMG&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/image06_5F00_72B76DCB.jpg"&gt;&lt;img title="image06" style="border-right:0px;border-top:0px;display:inline;border-left:0px;border-bottom:0px;" alt="image06" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/image06_5F00_thumb_5F00_469A70DA.jpg" border="0" height="366" width="640" /&gt;&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;F. C&amp;aacute;c y&amp;ecirc;u cầu phần mềm khi c&amp;agrave;i đặt ForeFront TMG&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;- Windows Roles and Features     &lt;br /&gt;&amp;nbsp; + Network Policy and Access Server      &lt;br /&gt;&amp;nbsp; + Active Directory Lightweight Directory Services (ADLDS)      &lt;br /&gt;&amp;nbsp; + Network Load Balancing (NLB)&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;- Microsoft&amp;reg; .NET 3.5 Framework SP1     &lt;br /&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;- Windows Web Services API &lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;G. Download Microsoft Forefront TMG 2010&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;- &lt;a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=e05aecbc-d0eb-4e0f-a5db-8f236995bccd"&gt;Forefront Threat Management Gateway (TMG) 2010 Standard Edition and Enterprise Edition&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;- &lt;a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=f0fd5770-7360-4916-a5be-a88a0fd76c7c"&gt;Forefront Threat Management Gateway (TMG) 2010 Service Pack 1 (SP1)&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://technetvietnam.net/aggbug.aspx?PostID=382" width="1" height="1"&gt;</content><author><name>DaoDuyHieu</name><uri>http://technetvietnam.net/members/DaoDuyHieu/default.aspx</uri></author><category term="FIREWALL" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/FIREWALL/default.aspx" /><category term="ISA" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/ISA/default.aspx" /><category term="FOREFRONT TMG 2010" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/FOREFRONT+TMG+2010/default.aspx" /><category term="TMG" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/TMG/default.aspx" /></entry><entry><title>Tool check Hyper V – SecurAble</title><link rel="alternate" type="text/html" href="/blogs/hieudd/archive/2010/12/07/tool-check-hyper-v-securable.aspx" /><id>/blogs/hieudd/archive/2010/12/07/tool-check-hyper-v-securable.aspx</id><published>2010-12-07T02:52:09Z</published><updated>2010-12-07T02:52:09Z</updated><content type="html">&lt;p&gt;Windows IT Pro mới giới thiệu tool check Hyper V, có lẽ sẽ chính xác hơn các tool khác trước đây.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/securable_5F00_58219E25.png"&gt;&lt;img title="securable" style="border-top-width:0px;display:inline;border-left-width:0px;border-bottom-width:0px;border-right-width:0px;" height="351" alt="securable" src="http://technetvietnam.net/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/hieudd/securable_5F00_thumb_5F00_42C6796E.png" width="460" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;b&gt;SecurAble&lt;/b&gt; probes the system&amp;#39;s processor to determine the presence, absence and operational status of three modern processor features: &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;64-bit instruction extensions, &lt;/li&gt;    &lt;li&gt;Hardware support for detecting and preventing      &lt;br /&gt;the execution of code in program data areas, ... and &lt;/li&gt;    &lt;li&gt;Hardware support for system resource “virtualization.” &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt; &lt;strong&gt;Download :&lt;/strong&gt; &lt;a title="http://www.grc.com/files/securable.exe" href="http://www.grc.com/files/securable.exe"&gt;http://www.grc.com/files/securable.exe&lt;/a&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://technetvietnam.net/aggbug.aspx?PostID=381" width="1" height="1"&gt;</content><author><name>DaoDuyHieu</name><uri>http://technetvietnam.net/members/DaoDuyHieu/default.aspx</uri></author><category term="MINI TUTORIALS" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/MINI+TUTORIALS/default.aspx" /><category term="HYPER-V" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/HYPER-V/default.aspx" /><category term="VIRTUALIZATION" scheme="http://technetvietnam.net/blogs/hieudd/archive/tags/VIRTUALIZATION/default.aspx" /></entry></feed>
