March 2011 - Posts

vNext partenaire de l'Imagine Cup 2011 et sponsor officiel du prix de l'entrepreneur !
23 March 11 03:34 PM | forefrontsecurity | with no comments

Je très suis heureux de vous annoncer que le prix de l’entrepreneur sponsorisé par vNext et Bizspark a été officiellement lancé ce matin !

alt

Vous trouverez l’annonce officielle diffusée aux concurrents de l’Imagine Cup en suivant ce lien :

http://etudiants.frogz.fr/post/2011/03/23/Imagine-Cup-2011-une-GRANDE-nouvelle-pour-nos-competiteurs-Imagine-Cup-!.aspx

C’est une très belle opportunité pour tous les étudiants ayant un projet personnel, innovant et structuré, d’être coachés et dirigés dans leur envie d’entreprenariat.

A vos dossiers !

Publié par Olivier DETILLEUX

TechDays 2011–Vidéo de notre session Forefront EndPoint Protection 2010
17 March 11 06:37 PM | forefrontsecurity | with no comments

Bonjour,

Les vidéos des sessions des techdays 2011 sont maintenant disponibles en ligne. Retrouvez la session autour de FEP 2010 que j’ai eu le plaisir de coanimer avec Stéphane Saunier.

Forefront EndPoint Protection 2010 & retour d'expérience (200)

Publié par Olivier DETILLEUX

UAG Mobile Portal – iPhone / iPad configuration
17 March 11 01:52 PM | forefrontsecurity | with no comments

Hi all,

As I have recently mentioned, the UAG Mobile Portal for iPhone and iPad is “RTM”.

You have to configure your iPhone and iPad before starting to use the app, if your portal is published with a corporate root certificate. By default, this certificate is not stored on your mobile device. You have to add the certification authority certificate on your iPhone and iPad.

You can use the iPhone Configuration Utility to achieve that :

Create a configuration Profile

image

Add a credential configuration

image

Select you root certificate

image

Install the profile on your device

image

image

image

image

Now, you can start using the app.

But don’t forget : A server side configuration is necessary if you want to detect the ID of the device during  the connection. This configuration will be available soon as an open source package.

Published by Olivier DETILLEUX

Enhance the UAG authentication on mobile device with the “UAG Mobile Portal” app by vNext
16 March 11 07:24 PM | forefrontsecurity | with no comments

Hi all,

I am proud to announce that my application (developed with the vNext software team – http://www.vnext.fr) “UAG Mobile Portal” is available on the Apple appStore for iPhone and iPad : http://itunes.apple.com/us/app/uag-mobile-portal/id416883144?mt=8&ls=1

The UAG mobile portal application allows companies to give access to their Forefront™ Unified Access Gateway published corporate website to specific mobile devices depending on their UDID.

Employees will be able to browse their internal resources from any location through their corporate phone only thus limiting the exposure of those resources.


A demo of the usage is available here: http://www.youtube.com/watch?v=GylAXB1kJbc

Some screenshots :

image

image photoimage

You need to configure UAG server side. This configuration is packaged, and not available for the moment. We will soon provide it as an open source package.

The global architecture schema :

image

The application will be available on the Windows Phone 7 MarketPlace also.

Published by Olivier DETILLEUX

How to use your corporate proxy when you are connected with DirectAccess ?
16 March 11 12:53 AM | forefrontsecurity | with no comments

Most of our customers wants to force their users to use the internal proxy when they are connected to the corporate network through DirectAccess.

Force Tunneling

There are different ways to provide this service. The first one is the “force tunneling” option. With this option activate, all the traffic is routed inside the corporate network (excepted local ip addresses). This UAG SP1, configuring Force Tunneling is very easy, as you can see with the following print screens.

Activate the force tunneling option :

image

Specify the proxy server :

image

An that’s it. There are benefits and disadvantage to activate force tunneling. Have a look on this article by the Edge Man (Tom Shinder) : More on DirectAccess Split Tunneling and Force Tunneling

What we can retain is :

  • When Force Tunneling is enabled, all traffic is sent over the DA client tunnel using the IP-HTTPS protocol, but IP-HTTPS is the slowest transition technology protocol for DA
  • When Force Tunneling is enabled, user cannot use the “local name resolution” option.

So, I found that this not the right think to do if you only want to route web traffic through the corporate proxy.

Automatic Proxy Configuration Script

Let’s say that your corporate has a Forefront TMG proxy. You can use the automatic proxy configuration script provided by TMG to configure your clients when they are inside the company. This script is automatically created during TMG configuration. The default URL is : http://proxy.vnext.lab:8080/array.dll?Get.Routing.Script.

In order to configure your clients, you use a Group Policy to force the proxy configuration. But when the users come back home, they say that internet isn’t working. The reason is that this script return the static ipv4 address of the proxy to the browser when there is a request. You can that see in the following capture. The ipv4 address of my proxy is 192.168.1.10, and the local ipv4 address of my DA client 192.168.100.101. Of course, the remote ipv4 address is unreachable.

image

Have a look inside the script. Proxy list is build with the ipv4 address :

image

A workaround is to create you own proxy.pac. In this script, put the proxy dns name instead of the ipv4 address. Forefront TMG doesn't support ipv6 for the moment. But if the internal network card as an ipv6 address, you can also return this ipv6 address. You can add some conditions (for example the source Ip) to return different addresses. But my advise is : When you are using DirectAccess, always use full qualified domain name. UAG will translate this dns name into an ipv6 address.

With the automatic configuration script you can :

  • Force the configuration of the proxy with a proxy.pac for DirectAccess users. Whatever they are inside or outside the network, it will be working.
  • DA Clients are still using teredo or 6to4 when it’s possible
  • Users can use “local name resolution” if the DA server is down. Therefore, the proxy is unreachable. If the proxy is unreachable, the browser switch to direct connection (no proxy).

The WPAD entry and wpad.dat file

You can also use your DNS to store the address of the proxy as a WPAD entry. Don’t forget to unblock this kind of entry in dns (dnscmd /config /globalqueryblocklist), and remember that you can only request the wpad server which publish the wpad.dat file on tcp port 80. You cannot set the 8080 port for example with the dns entry.

Be careful, have a look inside the wpad.dat file. You can also find some ipv4 entry :

image

And if you don’t want to force the proxy ?

Let’s assume that you want to force the use of the proxy for the users when they are inside the network, but not when they are outside, connected with DirectAccess. I think that the best way is to use WPAD entry within DHCP.

An other way is to use the WPAD entry in the DNS, and add an exception in the NRPT for wpad.vnext.lab. Thanks to Tom Shinder for this nice idea Sourire

Published by Olivier DETILLEUX

Windows Phone 7 Application of the day : "Troc Des trains" by vNext
15 March 11 03:52 PM | forefrontsecurity | with no comments

It is not my habit to advertise, but I am very proud to announce that the application : Troc des Trains on Windows Phone 7 is the application of the day, according to the French Microsoft Team.

image

http://frogz.fr/Blog/post/2011/03/15/LAPPLI-DU-JOUR-Troc-des-Trains.aspx

Troc des trains is a mobile application, designed and developed by vNext (http://www.vnext.fr). Congratulations guys !

 

Published by Olivier DETILLEUX

TMG 2010 SP1 and UAG 2010 SP1 are supported on Windows 2008 R2 SP1
07 March 11 10:59 PM | forefrontsecurity | with no comments

Hi all,

As you already know, Windows Server 2008 R2 is SP1. You've certainly thought about deploying this service pack on your UAG or TMG server, but not knowing what would be the risk. Don’t be afraid anymore, the Forefront TMG (ISA) Product Team has the answer :

TMG 2010 SP1 and UAG 2010 SP1 are fully compliant with the new Windows service pack

Have a look here for more information : TMG 2010 SP1 and UAG 2010 SP1 are supported on Windows 2008 R2 SP1

Published by Olivier DETILLEUX

This Blog

News

    We talk about Forefront Unified Access Gateway, Web SSO, DirectAccess, Threat Management Gateway, Identity Manager and other Forefront Technologies. Also, some post about Active Directory and other Identity and Access technos.

Syndication