Techniques for Blocking Anonymous Public Proxies using Forefront TMG 2010

I’ve spent the better party of the last 16 years implementing and managing edge security and remote access solutions for some of the largest organizations in the world. With a lot of experience enforcing Internet access policies, I can tell you from experience that users will try anything to circumvent those restrictions. One of the most common methods of avoiding in place access controls is public anonymous proxy servers. In this month’s article I’ll demonstrate a few techniques for preventing public anonymous proxy server access using Forefront TMG 2010.

Microsoft Forefront TMG 2010

One of my favorite things about the Microsoft Azure public cloud is the SQL database options that are available. Whenever I'm building a test lab that requires an SQL database, in the past it would take quite a long time to get a VM provisioned and SQL installed and configured. Also, with limited local resources, my test lab SQL servers were often significantly underpowered. With Azure-hosted SQL databases, that's no longer a problem. I can provision a Windows Server 2012 R2 VM with whatever version of SQL I require in just a few minutes. In addition, I'm no longer constrained by local resources. Now I routinely provision very powerful VMs, typically with at least 8 cores and 14GB of RAM, which makes testing much easier. Microsoft Azure also features SQL database as a service options too, which doesn't require provisioning a VM. This works quite well in many cases.

