<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>DirectAccess and Firewalls and NAT</title><link>http://blogs.technet.com/b/tomshinder/archive/2010/05/06/directaccess-and-firewalls-and-nat.aspx</link><description>Its seems like we’ve run into a little confusion recently regarding how to deploy the UAG DA server in a firewalled environment. If you look at our documentation for Packet Filtering for the Internet Firewall ( http://technet.microsoft.com/en-us/library</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: DirectAccess and Firewalls and NAT</title><link>http://blogs.technet.com/b/tomshinder/archive/2010/05/06/directaccess-and-firewalls-and-nat.aspx#3492455</link><pubDate>Mon, 16 Apr 2012 19:14:17 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3492455</guid><dc:creator>Bry</dc:creator><description>&lt;p&gt;Other commenters, please read the closing statement, &amp;quot;that firewall cannot NAT connections between the DirectAccess clients and the UAG DirectAccess Server.&amp;quot;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3492455" width="1" height="1"&gt;</description></item><item><title>re: DirectAccess and Firewalls and NAT</title><link>http://blogs.technet.com/b/tomshinder/archive/2010/05/06/directaccess-and-firewalls-and-nat.aspx#3458068</link><pubDate>Sat, 08 Oct 2011 22:16:41 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3458068</guid><dc:creator>Geekcroft</dc:creator><description>&lt;p&gt;Tom.&lt;/p&gt;
&lt;p&gt;If I have a customer that is doing some kinds of fancy NAT on their ASA - still giving me a public IP address but having a NAT entry for the IP in their rules - will this likely give me some strange niggly issues?&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Stephen&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3458068" width="1" height="1"&gt;</description></item><item><title>re: DirectAccess and Firewalls and NAT</title><link>http://blogs.technet.com/b/tomshinder/archive/2010/05/06/directaccess-and-firewalls-and-nat.aspx#3458067</link><pubDate>Sat, 08 Oct 2011 22:12:15 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3458067</guid><dc:creator>Geekcroft</dc:creator><description>&lt;p&gt;hypothesis, As the UAG server will require a public IP address you may have to change your simple d-link ADSL router.&lt;/p&gt;
&lt;p&gt;NAT, in lamens terms, allows devices behind your firewall to utilize public IP&amp;#39;s whilst having a none-public IP address.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3458067" width="1" height="1"&gt;</description></item><item><title>re: DirectAccess and Firewalls and NAT</title><link>http://blogs.technet.com/b/tomshinder/archive/2010/05/06/directaccess-and-firewalls-and-nat.aspx#3447376</link><pubDate>Tue, 16 Aug 2011 14:10:24 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3447376</guid><dc:creator>hypothesis</dc:creator><description>&lt;p&gt;Hi Tom,&lt;/p&gt;
&lt;p&gt;Is it so necessary to exclude NAT at all? I&amp;#39;m using simple d-link ADSL router to connect to Internet. Isn&amp;#39;t it sufficient to forward proto 41 and UDP 3544 port in and out to DirectAccess server behind firewall?&lt;/p&gt;
&lt;p&gt;Really detailed info but why NAT is so bad and how overcome this!&lt;/p&gt;
&lt;p&gt;Ilya&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3447376" width="1" height="1"&gt;</description></item><item><title>re: DirectAccess and Firewalls and NAT</title><link>http://blogs.technet.com/b/tomshinder/archive/2010/05/06/directaccess-and-firewalls-and-nat.aspx#3330947</link><pubDate>Thu, 06 May 2010 19:56:03 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3330947</guid><dc:creator>Thomas W Shinder - MSFT</dc:creator><description>&lt;p&gt;Hi Don,&lt;/p&gt;
&lt;p&gt;Sure, TMG firewalls are like any other kind of firewall. Just make a ROUTE Network Rule&lt;/p&gt;
&lt;p&gt;Source: Network that the UAG DA server's external interface is connect to&lt;/p&gt;
&lt;p&gt;Destination: External (the default external Network)&lt;/p&gt;
&lt;p&gt;Tom&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3330947" width="1" height="1"&gt;</description></item><item><title>re: DirectAccess and Firewalls and NAT</title><link>http://blogs.technet.com/b/tomshinder/archive/2010/05/06/directaccess-and-firewalls-and-nat.aspx#3330937</link><pubDate>Thu, 06 May 2010 19:10:44 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3330937</guid><dc:creator>BigDon86</dc:creator><description>&lt;p&gt;Hi Tom;&lt;/p&gt;
&lt;p&gt;I'll ask the obvious question....&lt;/p&gt;
&lt;p&gt;Can a UAG DA device sit behind a TMG firewall? &amp;nbsp;If yes, how?&lt;/p&gt;
&lt;p&gt;Thanks for all the good info!&lt;/p&gt;
&lt;p&gt;Don&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3330937" width="1" height="1"&gt;</description></item></channel></rss>