Microsoft Forefront Network Edge Security Delivered!
TMG and UAG Appliances and Services for SMB, Enterprises and MSP's

Appliance Overview
The nAppliance nTMGB 3500B is an integrated threat management gateway appliance based on an embedded version of Microsoft Forefront Threat Management Gateway 2010 - Branch Office Edition. It helps enterprise businesses to connect remote-site branch offices to their corporate headquarters, provide security-enhanced Internet access for branch office, and utilize limited bandwidth more efficiently. It provides HTTP compression, caching of content (including software updates) and site-to-site virtual private network (VPN) capabilities integrated with application-layer filtering and intuitive management which helps makes it easier to securely expand corporate network.

The nAppliance nTMGB 3500B is a fully integrated branch office security gateway appliance, it is easy to deploy with out-of-box turnkey convenience which includes:
The nAppliance nTMGB 3500B is ideal for Mid Sized Branch Office deployments; Bit’s a purpose-built, 1U rack-optimized and most competitive security solutions appliance platform in its class.

Learn about the features and benefits of Microsoft Forefront Threat Management Gateway 2010 (TMG), which is designed to provide a comprehensive, secure Web gateway that helps protect employees from Web-based threats.
HTTPS Inspection, an innovative feature, enables Forefront TMG to inspect inside users’ SSL-encrypted Web traffic.
By inspecting within these encrypted sessions, Forefront TMG can both detect possible malware as well as limit employee Web usage to approved sites. Sensitive sites, such as banking sites, can be excluded from inspection.

| New Feature | Description |
|---|---|
| URL Filtering | Destination URLs are examined for compliance with corporate policy and for malicious potential of destination Web site. Forefront TMG uses Microsoft Reputation Services for URL filtering, combining multiple sources to increase coverage of URLs and categorization. URLs and categories will increase as the Forefront TMG Beta 3 continues through Summer 2009. |
| Web antivirus/anti-malware protection | Inbound and outbound Web traffic is inspected for viruses and malware, including archived folders. Encrypted folders can be blocked. For large files, users are trickled the file to assure them the file is being downloaded. |
| E-mail security | Forefront TMG provides central management for Exchange and Forefront Protection 2010 for Exchange when located on the same server. Forefront TMG does not include either Exchange or Forefront Protection 2010 for Exchange. Both must be purchased and installed separately. |
| HTTPS inspection | HTTPS-encrypted sessions can be inspected for malware or exploits. Specific groups of sites—such as banking sites—can be excluded from inspection for privacy reasons. Users of the TMG Firewall Client can be notified of the inspection. |
| Network Inspection System (NIS) | Traffic can be inspected for exploits of Microsoft vulnerabilities. Based on protocol analysis, NIS enables blocking of classes of attacks while minimizing false positives. Protections can be updated as needed. |
| Enhanced Network Address Translation (NAT) | Forefront TMG now enables you to specify individual e-mail servers that can be published on a 1-to-1 NAT basis. |
| Enhanced Voice over IP support | Forefront TMG includes SIP traversal, enabling simpler deployment of Voice over IP within the network. |
| Windows Server 64-bit support | Forefront TMG is installed on Windows Server 2008 with 64-bit support. |
| Feature | Description |
|---|---|
| Multi-layer firewall | Forefront TMG provides access control and protection on three layers: packet filtering, stateful inspection, and application layer filtering. |
| Application layer filtering | Forefront TMG provides deep content filtering through built-in application filters. |
| Granular HTTP controls | Forefront TMG delivers customizable, granular controls to HTTP traffic, including: - File download controls - Signature-based blocking - HTTP method controls Forefront TMG provides strong controls over Web-based threats. |
| DoS protections | Forefront TMG provides resiliency against flood attacks and re-allocates resources to provide higher security inspection. |
| Extensive protocol support | Forefront TMG delivers out-of-the-box support for many protocols. New protocols can be defined. |
| Feature | Description |
|---|---|
| Highly secure e-mail access from Outlook Client | Remote users can access Exchange Server using the full Outlook MAPI client over the Internet without establishing a VPN connection. The connection is encrypted for security. |
| Simple Outlook Web Access and Microsoft Office SharePoint Server publishing | Simple wizards allow quick configuration of remote access for both Outlook Web Access and SharePoint servers. Outlook Web Access users can be authenticated at the Forefront TMG server, preventing attacks by unauthenticated users. |
| Highly secure publishing of Web servers, internal servers, and Terminal Services | Remote users can access internal resources or Web servers more securely. Link translation is provided. |
| Single sign on | Forefront TMG allow users to access a group of published Web sites without being required to authenticate with each Web site. |
| Delegation of basic authentication | Forefront TMG helps protect published Web sites from unauthenticated access by requiring the Forefront TMG firewall to authenticate the user before the connection is forwarded to the published Web site. This prevents exploits from unauthenticated users from reaching the published Web server. |
| Link translation to internal servers | Forefront TMG includes a link translation feature that you can use to create a dictionary of definitions for internal computer names that map to publicly known names.
Implements link translation automatically during Web publishing. |
| SSL bridging support | To guard against embedded attacks in HTTP traffic, SSL bridging allows SSL protected packets to be decrypted by Forefront TMG, inspected, and re-encrypted. |
| Feature | Description |
|---|---|
| Site-to-site VPN | Forefront TMG enables quick connectivity between sites via wizard-based approach. Also can be configured for tunnel-mode IPSec for support of third party devices. |
| Remote access VPN | Forefront TMG provides termination of L2TP/IPSec and PPTP VPN sessions, using the native Windows VPN services. |
| Inspection of VPN traffic | VPN traffic terminated on the Forefront TMG server is inspected according to the appropriate security policy. |
| VPN quarantine | Forefront TMG provides deep VPN client inspection and integration of your firewall policy. |
| SecureNAT for VPN clients | Forefront TMG helps ensure remote users connected to the network can gain Internet access while maintaining a strong security policy for the corporate network. |
| Publish VPN servers | Forefront TMG can be used to publish internal Windows Servers as VPN servers. |
| Feature | Description |
|---|---|
| Enterprise policy | Policy can be assigned to gateways, arrays, or enterprise-wide. |
| Easy-to-use wizards | Forefront TMG simplifies configuration with multiple wizards for features such as Web publishing, Web access, and array configuration. |
| Real-time monitoring and reporting | Logs may be viewed real-time or historically – including active sessions. |
| Query building | With a built-in query tool, historical data can be found quickly. Complex queries can be built. |
| Report creation and publishing | Reports can be designed for specific needs and then published locally or to a network file share. |
| External logging | Logs may be sent to a Microsoft SQL Server located on the internal network. |
| Delegated permissions | Admin roles can be delegated to users or groups. |
| Feature | Description |
|---|---|
| Network load balancing | Forefront TMG leverages network load balancing to provide fail over and scaling of performance. |
| Network-based configuration | You may configure one or more networks, each with distinct relationships to other networks. Access policies are defined relative to the networks and not necessarily relative to a specific internal network. Forefront TMG extends the firewall and security features to apply to traffic between any networks or network objects. |
| Caching | Forefront TMG provides caching to improve user experience and reduce bandwidth costs. With the centralized cache rule mechanism of Forefront TMG, you can configure how objects stored in the cache are retrieved and served from the cache. |
| Background Intelligent Transfer Service (BITS) caching | Forefront TMG provides the caching mechanism for data received through BITS. Any cache rule that you create can be enabled to cache BITS data. |
| HTTP compression | You can reduce file size by using algorithms to eliminate redundant data during transmission of HTTP packets. |
| Diffserv (Quality of Service) | Forefront TMG includes packet prioritization functionality (provided by the Diffserv Web filter), which scans the URL or domain and assigns a packet priority using Diffserv bits. |
| Compare TMG with ISA Server 2006 and TMG MBE | ISA 2006 | TMG MBE | TMG |
|---|---|---|---|
| Firewall | √ | √ | √ |
| VPN (site-to-site and remote access) | √ | √ | √ |
| Web proxy | √ | √ | √ |
| Caching | √ | √ | √ |
| Arrays for load balancing and failover | √ | √ | |
| Non-domain joined gateway | √ | √ | |
| Windows Server 2008 64-bit support | √ | √ | |
| Web anti-malware | √ | √ | |
| HTTPS inspection | √ | ||
| E-mail security | √ | ||
| Network Inspection System | √ | ||
| ISP redundancy | √ | ||
| Centrally manage Standard and Enterprise Edition gateways together (requires Enterprise Edition gateway) | √ |
nAppliance Forefront appliances are purpose-built, high performance hardware devices integrated with nAppliance designed Oneface system management tools and Microsoft Forefront Edge Security Software Solutions.

Our Net-Gateway appliance platforms for Microsoft Forefront Security solutions are designed for organizations that want an integrated leading edge hardware, security and software service offering from Microsoft on an optimized hardware platform. These platforms offer best-of-breed Microsoft Forefront Edge security packaged with nAppliance’s, security hardened system, performance tuned platform, value added OneFace technology, and world-class support.
nAppliance powered system and hardware management software provides a complete integrated solution for Microsoft Forefront Threat Management Gateway (TMG) and Unified Access Gateway (UAG) and Direct Access (DA) edge security software suites. We have net Gateway models that can be deployed either as standalone units, or as fully redundant, highly available arrays. Our standard business edition appliances are deployed as a standalone device and enterprise edition appliances can be deployed as a standalone device or high-availability (HA) devices with network load balancing (NLB) in a large clustered array for optimal service resiliency.
nAppliance offers a wide range of hardware configurations, each of the models are pre-configured with most optimized hardware components and system management tools to meet our customers unique business requirements. Configurations are fine tuned to deliver various levels of system performance, capacity, scalability and availability required to meet the requirements of small to large size business, small to large size enterprise and branch offices.
nAppliance platforms running Microsoft Forefront Edge Security systems provide the security and management benefits of special purpose hardware products, and provide the familiar management interfaces of other Microsoft technologies. Security appliances often have special purpose hardware specific to network security. Appliance products running Microsoft Embedded Edge Security technologies have the following unique advantages:
Each security appliance has various software and hardware components installed and integrated. This configuration is then carefully tuned and hardened to maximize the security posture of each system. This hardening is exhaustive, costly and difficult to provide in general IT hardware and software only implementations, but imperative on edge security devices.
nAppliance has the lowest total cost of ownership as compared to traditional software alternatives. The nAppliance appliance-based architecture eliminates many of the costs of traditional systems management including software and hardware procurement, installation, off-site training, and the resources required for ongoing upgrades, system maintenance and technical support. Our appliance advantage offers security hardened configurations for smooth “Out-Of-the-Box” experience.

nAppliance Networks, an ISO 9001:2000 company, is a provider of mission critical network edge security infrastructure solutions. Unlike alternatives that are simply based on proprietary or general-purpose server hardware, our appliances are designed for highest reliability, optimized for maximum performance, and manufactured to exact quality specifications. You can trust nAppliance Net-Gateway appliances to deliver the most reliable and comprehensive Forefront solutions.
TMG Server 2010 Appliance (nTMG or nTMGE Series) provides value to IT managers, network administrators, and information security professionals who are concerned about the security, performance, manageability, or reduced cost of network operations. TMG Server 2010 Appliance (nTMG or nTMGE Series) can help you:
Businesses need to eliminate the damaging effects of malware and attackers through a comprehensive set of tools for scanning and blocking harmful content, files, and Web sites. TMG Server 2010 Appliance (nTMG or nTMGE Series) can help organizations protect their environments from internally and externally originating Internet-based threats. With a hybrid proxy-firewall architecture, deep content inspection, granular policies, and comprehensive alerting and monitoring capabilities, TMG Server 2010 Appliance (nTMG or nTMGE Series) makes it easier to manage and protect your network. Read more about
Internet Access Protection
Internet Access Protection with TMG Server 2010 Appliance (nTMG or nTMGE Series).

Smaller Size Deployment (nTMG):

Medium-Large Size Deployment (nTMGE):
Businesses need to provide employees and partners with secure and appropriate remote access to applications, documents, and data from any PC or device.
TMG Server 2010 Appliance (nTMG or nTMGE Series) enables organizations to make their Exchange, SharePoint, and other Web application servers accessible in a more secure way to remote users outside the corporate network. By pre-authenticating users before they gain access to any published servers, inspecting even encrypted traffic at the application layer in a stateful manner, and providing automated publishing tools, TMG Server 2010 Appliance (nTMG or nTMGE Series) makes it easier to provide security for corporate applications accessed over the Internet. Read more about
Secure Remote Access
with TMG Server 2010 Appliance (nTMG or nTMGE Series).

Smaller Size Deployment (nTMG):

Medium-Large Size Deployment (nTMGE):

Medium-Large Size Deployment (Additional nUAG Appliance):
Note: UAG is a standalone appliance, it is not available as software add-on option with a nTMG or nTMGE as a single-appliance package (more)
Businesses need to connect remote-site branch offices to their corporate headquarters, provide security-enhanced Internet access from branch offices and utilize limited bandwidth more efficiently.
Organizations can use TMG Server 2010 Appliance (nTMG or nTMGE Series) to connect to and secure their branch offices, while efficiently utilizing network bandwidth. By providing HTTP compression, caching of content (including software updates) and site-to-site virtual private network (VPN/IPSec) capabilities integrated with application-layer filtering, TMG Server 2010 Appliance (nTMG or nTMGE Series) makes it easier to securely expand corporate networks. Read more about
Branch Office Security
with TMG Server 2010 Appliance (nTMG or nTMGE Series).

Smaller Size Deployment (nTMG):

Medium-Large Size Deployment (nTMGE):
TMG 2010 provides robust, effective, and easy-to-use integrated security. Three versions are available: TMG Server 2010 Standard Edition (nTMG Series), TMG Server 2010 Enterprise Edition (nTMGE Series) and TMG Server 2010 Branch Office Edition (nTMGB Series).
The Following table compares and contrasts the key features of three editions.
| Business Standalone | Corporate Datacenter | Corporate Branch Office | |
|---|---|---|---|
| Microsoft Forefront Threat Management Gateway 2010 | TMG Standard Edition | TMG Enterprise Edition | TMG Branch-Office Edition |
| Deployment Type: | |||
| Business Type | SMB | Enterprise | Branch Office |
| nAppliance Net-Gateway Platform Series | nTMG Series | nTMGE Series | nTMGB Series |
| Supported deployment scenarios | Standalone | Server in a standalone array or an array managed by EMS* | Server in a standalone array or an array managed by EMS* |
| High Availability: | |||
| NLB Arrays for Load Balancing & Failover | No | √ | √ |
| Scale Out: Number of Supported TMG Server in Array | 1 | Unlimited | 2 |
| Non-domain joined gateway | √ | √ | √ |
| ISP Link redundancy | √ | √ | √ |
| Unified Threat Management Functionalities: | |||
| Firewall - Stateful | √ | √ | √ |
| Firewall - Application Layer | |||
| Network IPS (NIS) | √ | √ | √ |
| VPN (site-to-site and remote access) | √ | √ | √ |
| Web Proxy | √ | √ | √ |
| Web Publishing | √ | √ | √ |
| HTTPS inspection | √ | √ | √ |
| Caching , Cache Compression | √ | √ | √ |
| NLB Arrays for CARP Support | √ | ||
| Web Anti-Malware Protection** | √ | √ | √ |
| E-mail Protection*** | √ | √ | √ |
| Configuration Storage Server (CSS) | |||
| Local Management of Firewall Policies and Config Settings | √ | √ | √ |
| Remote Management of Firewall Policies and Config Settings | √ | ||
| Enterprise Management: EMS for Centralized Management | |||
| Management of Enterprise (nTMGE) Edition Gateways | √ | ||
| Management of Branch (nTMGB) Edition Gateways* | √ | ||
| Management of Branch Standard (nTMG) Edition Gateway* | √ | ||
| Type of Microsoft Forefront TMG Editions | Standard | Enterprise (Datacenter) | Branch Office |
| Scale Up: Processor Support | Up to 4 CPU's | Unlimited | Up to 4 CPU's |
* Requires at least one Enterprise Edition nTMGE appliance license, EMS: Enterprise Management Server
** Requires subscription;
*** Requires Exchange License
| Performance Specifications | ||
|---|---|---|
|
Storage Capacity |
: | 300GB |
| Deployment Type | : | Mid-Sized Enterprise/Branch Office |
| Recommended Corporate PCs | : | 3,000 |
| Recommended Corporate Web Users | : | 15,000 |
| Firewall Throughput (Mbps) | : | 2,400 |
| HTTP Throughput (Mbps) | : | 200 |
| VPN Throughput (Mbps) | : | 200 |
| Hardware Specifications | ||
|---|---|---|
|
Processor |
: | Single Processor, Quad Core Xeon |
| Memory | : | 12 GB |
| Network Interfaces (RJ45) | : | 8x GbE LAN |
| System Management Interface (RJ45) | : | 1x iKVM Lights-Out (IPMI) Remote Access |
| Storage – Data (Redundant) | : | Dual SATA Disk, Mirroring (RAID-1), Hotswap |
| Storage - Recovery OS (ARRMS) | : | 2 GB, USB Flash DOM |
| SSL HW Accelerator | : | Cavium CN 1600 Series |
| LCD w/Keypad Display | : | Graphical w/ 6-Keypad |
| System IO Ports (VGA/USB/Serial) | : | 1 / 2 / 1 |
| AC Power Supply | : | Dual Hotswap Redundant, 650 Watts 100 to 240 VAC Auto 47 to 63 Hz, 3A |
| Physical Dimensions | : | Chassis: 19”, 4-post rack-mountable Height: 1.5” (1U), 1 rack unit; Width: 17.5”; Depth: 27” Weight: 30 lbs. |
| Storage Temperature | : | -40°F to 122°F (-40°C to 50°C) 5% to 95% relative humidity, non-condensing |
| Operating Temperature | : | 35°F to 95°F (1.7°C to 35°C) 5% to 95% relative humidity, non-condensing |
| Agency Certifications | : | Safety: UL, FCC, CE, TUV, CB Environmental: WEEE and RoHS |
| Support and Services | : | Standard warranty includes 30-day software support with one-year hardware support; upgradable |
nTMGB-3500B: Threat Management Appliance, Intel Xeon Quad Core, 12GB RAM, 2 x300GB HDD RAID Hotswap, 8 x GbE Ports, 1 x 10/100 iKVM(LOM) Port, PCIe SSL Accelerator, LCD, Dual HotSwap Power Supplies, 1U Rackmount. nAppliance designed Multi Appliance - Oneface System Manager for Remote/Lights-Out management, Quick Appliance PiT Recovery, Restore and Reset Support. Powered by Microsoft Embedded Forefront TMG 2010 Enterprise (BranchOffice) Edition
| Appliance Platform: | |
|---|---|
| 3500B-nAppliance Integrated Branch Security Gateway, TMG 2010 Enterprise | NN-NTMGB-3500B |
| Support Plan Options: | |
|---|---|
| Silver HW Support: Advanced Hardware Replacement Only | |
| Silver Support, HW Advanced Replacement Only, 1 Year, 3500B | SUP-HS-3500B-1 |
| Silver Support, HW Advanced Replacement Only, 3 Years, 3500B | SUP-HS-3500B-3 |
| Silver Support, HW Advanced Replacement Only, 5 Years, 3500B | SUP-HS-3500B-5 |
| Gold Support: 8x5 HelpDesk + Advanced Hardware Replacement | |
| HelpDesk Gold, 8x5 Email + Phone + Advance HW Replacement, 1 Year, 3500B | SUP-HG-3500B-1 |
| HelpDesk Gold, 8x5 Email + Phone + Advance HW Replacement, 3 Years, 3500B | SUP-HG-3500B-3 |
| HelpDesk Gold, 8x5 Email + Phone + Advance HW Replacement, 5 Years, 3500B | SUP-HG-3500B-5 |
| Platinum Support: 24x7 HelpDesk + Advanced Hardware Replacement | |
| HelpDesk Platinum, 24x7 Email + Phone + Advance HW Replacement, 1 Year, 3500B | SUP-HP-3500B-1 |
| HelpDesk Platinum, 24x7 Email + Phone + Advance HW Replacement, 3 Years, 3500B | SUP-HP-3500B-3 |
| HelpDesk Platinum, 24x7 Email + Phone + Advance HW Replacement, 5 Years, 3500B | SUP-HP-3500B-5 |
| Support Renewal Options: | |
|---|---|
| Silver HW Support Renewal; Advanced Hardware Replacement Only | |
| Silver Support, HW Advanced Replacement Only, 1 Year Renewal, 3500B | SUP-HS-3500B-R |
| Silver Support, HW Advanced Replacement Only, 2 Years Renewal, 3500B | SUP-HS-3500B-2R |
| Silver Support, HW Advanced Replacement Only, 3 Years Renewal, 3500B | SUP-HS-3500B-3R |
| Gold Support Renewal; 8x5 HelpDesk + Advanced Hardware Replacement | |
| HelpDesk Gold, 8x5 Email + Phone + Advance HW Replacement, 1 Year Renewal, 3500B | SUP-HG-3500B-R |
| HelpDesk Gold, 8x5 Email + Phone + Advance HW Replacement, 2 Years Renewal, 3500B | SUP-HG-3500B-2R |
| HelpDesk Gold, 8x5 Email + Phone + Advance HW Replacement, 3 Years Renewal, 3500B | SUP-HG-3500B-3R |
| Platinum Support Renewal, 24x7 HelpDesk+Advanced Hardware Replacement | |
| HelpDesk Platinum, 24x7 Email + Phone + Advance HW Replacement, 1 Year Renewal, 3500B | SUP-HP-3500B-R |
| HelpDesk Platinum, 24x7 Email + Phone + Advance HW Replacement, 2 Years Renewal, 3500B | SUP-HP-3500B-2R |
| HelpDesk Platinum, 24x7 Email + Phone + Advance HW Replacement, 3 Years Renewal, 3500B | SUP-HP-3500B-3R |
| nAppliance Product Brochure | Version | Pages | word/pdf | Size |
|---|---|---|---|---|
| nAppliance nTMG Business Series | 1.0 | 4 | 746 kb | |
| nAppliance nTMGE/B Enterprise/Branch Series | 1.0 | 4 | 847 kb | |
| nAppliance nTMG Product Feature Comparison Sheet | 1.0 | 1 | 649 kb | |
| nAppliance nTMGE Product Feature Comparison Sheet | 1.0 | 1 | 665 kb |
| nAppliance Product Datasheet | ||||
|---|---|---|---|---|
| Model: 1500U nTMG Business Series (Small Enterprise) | 1.0 | 1 | 168 kb | |
| Model: 2500U nTMG Business Series (Mid Size Enterprise) | 1.0 | 1 | 169 kb | |
| Model: 3500U nTMG Business Series (Large Enterprise) | 1.0 | 1 | 169 kb | |
| Model: 5500U nTMG Business Series (Very Large Enterprise) | 1.0 | 1 | 169 kb | |
| Model: 1500U nTMGE Enterprise Series (Small Enterprise) | 1.0 | 1 | 166 kb | |
| Model: 2500U nTMGE Enterprise Series (Mid Size Enterprise) | 1.0 | 1 | 167 kb | |
| Model: 3500U nTMGE Enterprise Series (Large Enterprise) | 1.0 | 1 | 169 kb | |
| Model: 5500U nTMGE Enterprise Series (Very Large Enterprise) | 1.0 | 1 | 168 kb | |
| Model: 1500U nTMGB Branch-Office Series (Small Enterprise) | 1.0 | 1 | 166 kb | |
| Model: 2500U nTMGB Branch-Office Series (Mid Size Enterprise) | 1.0 | 1 | 167 kb | |
| Model: 3500U nTMGB Branch-Office Series (Large Enterprise) | 1.0 | 1 | 169 kb | |
| Model: 5500U nTMGB Branch-Office Series (Very Large Enterprise) | 1.0 | 1 | 169 kb |
| TMG Solution Brief | ||||
|---|---|---|---|---|
| enplane TMG Web Security Gateway Diastase | 1.0 | 2 | 865 kb |