An application filter must be installed locally on a Forefront TMG computer where it will be invoked. The installation process must include copying the binary files of the application filter to the Forefront TMG computer and registering the application filter as a COM server and as an extension of the Microsoft Firewall service in the stored Forefront TMG configuration. The installation process can include defining protocols, events, alerts, and other elements in the Forefront TMG configuration. Each time that the Firewall service starts on a Forefront TMG computer, it creates an instance of the registered COM object that implements the IFWXFilter interface, known as the filter object, for each application filter that is installed and enabled on the computer. The Forefront TMG Management extension for an application filter should be installed in a completely separate process that includes copying its DLL to the Forefront TMG computer and registering it as an extension.
When an enterprise with central array management is deployed, application filters and protocols can be registered in the stored Forefront TMG configuration on the enterprise level and on the array level. Registering application filters in the array configuration is required for enforcing their policy in the array. Registering application filters in the enterprise configuration is optional, but an application filter that is registered in the enterprise configuration benefits from the following features:
Note Enterprise-level configuration settings are not not available in Forefront TMG Medium Business Edition.
This section contains the following topics:
Build date: 11/30/2009
© 2008 Microsoft Corporation. All rights reserved.