Feature | Description |
|---|
Multi-layer firewall | Provides three types of firewall functionality: packet filtering (also called circuit-layer), stateful filtering, and application layer filtering. |
Application layer filtering | Provides deep content filtering through built-in application filters. |
HTTP filtering on a per-rule basis | HTTP policy allows the firewall to perform deep HTTP stateful inspection (application layer filtering).
Extent of the inspection is configured on a per-rule basis. With this capability, you can configure custom constraints for HTTP inbound and outbound access. |
Block access to all executable content | HTTP policy enables you to block all connection attempts to the Microsoft Windows operating system executable content, regardless of the file extension used on the resource. |
Control HTTP file downloads through file extension | HTTP policy enables you to define policy based on file extension, including ”allow all except a specified group of extensions” or “block all extensions except for a specified group.” |
HTTP filtering is applied to all TMG MBE client connections | HTTP policy allows you to control HTTP access for all TMG MBE client connections. |
Control HTTP access based on “HTTP Signatures” | HTTP inspection can help you create “HTTP Signatures” that can be compared to the Request URL, Request headers, Request body, and Response body. This gives you precise control over what content internal and external users can access through the firewall. |
Control allowed HTTP methods | Control what HTTP methods are allowed through the firewall by setting access controls on user access to various methods. For example, you can limit the HTTP POST method to prevent users from sending data to Web sites using the HTTP POST method. |
Extensive protocol support | Gain control over accessing and using any protocol, including IP-level protocols. Users can then use applications such as Ping and Tracert and can create VPN connections using PPTP. In addition, IPSec traffic can be enabled through TMG MBE. |
Support for complex protocols requiring multiple primary connections | Many streaming media and voice or video applications require that the firewall manage complex protocols. TMG MBE can manage these protocols and has an easy-to-use New Protocol Wizard you can use to create protocol definitions. |
Customizable protocol definitions | Control the source and destination port number for any protocol for which you create a firewall rule. This gives the TMG MBE firewall administrator a high level of control over what packets are allowed inbound and outbound through the firewall. |
FTP policy | The TMG MBE FTP policy can be configured to let users upload and download through FTP, or you can limit user FTP access to download only. |
Granular control over IP options | Configure IP options on a granular basis and only allow the IP options you require while blocking all others. |
Firewall user groups | Create custom firewall groups comprised of pre-existing groups in the local accounts database or the Active Directory directory service domain. This increases your flexibility to control access based on user or group membership, because the firewall administrator can create custom security groups from these existing groups. This removes the requirement that the firewall administrator be a domain administrator to create custom security groups for inbound and outbound access control. |
Microsoft Hotmail Web-based e-mail access through the firewall | HTTP filter enables users to access Hotmail through an easy-to-configure firewall rule without the need for special configuration on the client or firewall. |
Network objects | Expand your ability to define network objects by creating computers, networks, network sets, address ranges, subnets, computer sets, and domain name sets. Use network objects to define source and destination settings for firewall rules. |
Firewall Rule wizards | Rule wizards make it easier to create access policy.
Create access policy with a sophisticated firewall rule that you can use to configure any required policy element. You do not need to leave the rule wizard to create a network object. Any network object or relationship can be created within the new wizard. |
Firewall rules represent an ordered list | Firewall rules are represented in an ordered list in which connection parameters are first compared to the top listed rule. TMG MBE moves down the list of rules until it finds a rule matching the connection parameters and enforces the matching rule’s policy. This approach to firewall policy makes it easier to determine why a specific connection is allowed or denied. |
User-based or group-based access policy | Enhanced firewall rules allow you to define the source and destination for each protocol a user or group is able to access. This greatly increases flexibility for inbound and outbound access control. |
FTP support | Gain access to Internet FTP servers, listening on alternate port numbers without requiring special configuration on the client or TMG MBE firewall. The FTP server publishing on alternate port numbers requires nothing more than a simple FTP server publishing rule. |
Port redirection for FTP server publishing rules | Receive a connection on one port number and redirect the request to a different port number on the published server. |
Flood Resiliency | Flood Resiliency feature protects TMG MBE from being permanently unavailable, compromised, or unmanageable during a flooding attack. |
Enhanced remediation during attack | Flood Resiliency provides enhanced remediation during attacks through log throttling, control of memory consumption, and control of pending DNS queries. |