You need to ensure that Server1 can authenticate users from Active Directory by using Windows authentication
You need to ensure that TMG1 can connect to the Internet and to the client computers in all of the internal subnets