DirectAccess Infrastructure Planning and Design Published: October 2009 Updated: November 2011.

Slides:



Advertisements
Similar presentations
Internet Information Services 7.0 and Internet Information Services 7.5 Infrastructure Planning and Design Published: June 2008 Updated: November 2011.
Advertisements

Selecting the Right Network Access Protection (NAP) Architecture Infrastructure Planning and Design Published: June 2008 Updated: November 2011.
Windows® Deployment Services
Windows Server ® 2008 File Services Infrastructure Planning and Design Published: June 2010 Updated: November 2011.
Windows Server ® 2008 and Windows Server ® 2008 R2 Active Directory ® Domain Services Infrastructure Planning and Design Published: February 2008 Updated:
Microsoft ® System Center Configuration Manager 2007 R3 and Forefront ® Endpoint Protection Infrastructure Planning and Design Published: October 2008.
IPv4 - IPv6 Integration and Coexistence Strategies Warakorn Sae-Tang Network Specialist Professional Service Department A Subsidiary.
Blue Coat and the Blue Coat logo are trademarks of Blue Coat Systems, Inc., and may be registered in certain jurisdictions. All other product or service.
WMS02: Direct Access Always Connected: Death of the VPN
Direct Access 2012 Chad Duffey and Tristan Kington Microsoft Premier Field Engineering WSV333.
17/10/031 Summary Peer to peer applications and IPv6 Microsoft Three-Degrees IPv6 transition mechanisms used by Three- Degrees: 6to4 Teredo.
Microsoft ® Forefront ® Unified Access Gateway Infrastructure Planning and Design Published: December 2009 Updated: July 2010.
Malware Response Infrastructure Planning and Design Published: February 2011 Updated: November 2011.
Windows Server ® 2008 Active Directory ® Domain Services Infrastructure Planning and Design Series Published: February 2008 Updated: July 2009.
Windows Server ® Virtualization Infrastructure Planning and Design Published: November 2007 Updated: July 2010.
Unleashing the Power of Ubiquitous Connectivity with IPv6 Sandeep K. Singhal, Ph.D Director of Program Management Windows Networking.
Dan Stolts IT Pro Evangelist US DPE - North East Microsoft Corporation
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 8: Implementing and Managing Printers.
Installing and Maintaining ISA Server. Planning an ISA Server Deployment Understand the current network infrastructure Review company security policies.
Microsoft ® Application Virtualization 4.5 Infrastructure Planning and Design Series.
Windows XP Professional Deployment and Support Microsoft IT Shares Its Experiences Published: May 2002 (Revised October 2004)
Windows Server Virtualization Infrastructure Planning and Design Series.
Microsoft ® Exchange Online— Evaluating Software-plus-Services Infrastructure Planning and Design Published: November 2008 Updated: October 2010.
Microsoft ® SharePoint ® Online— Evaluating Software-plus-Services Infrastructure Planning and Design Published: June 2009 Updated: October 2010.
Microsoft ® Application Virtualization 4.6 Infrastructure Planning and Design Published: September 2008 Updated: February 2010.
WSV404 DirectAccess Server (Server 2008 R2) DirectAccess Client (Windows 7) Internet Native IPv6 6to4 Teredo IP-HTTPS Tunnel over IPv4 UDP, HTTPS,
Week #10 Objectives: Remote Access and Mobile Computing Configure Mobile Computer and Device Settings Configure Remote Desktop and Remote Assistance for.
Terminal Services in Windows Server ® 2008 Infrastructure Planning and Design.
Windows ® Deployment Services Infrastructure Planning and Design Published: February 2008 Updated: January 2012.
Windows Server ® Virtualization Infrastructure Planning and Design Published: November 2007 Updated: January 2012.
Microsoft ® Application Virtualization 4.6 Infrastructure Planning and Design Published: September 2008 Updated: November 2011.
Microsoft ® SQL Server ® 2008 and SQL Server 2008 R2 Infrastructure Planning and Design Published: February 2009 Updated: January 2012.
Microsoft ® System Center Operations Manager Infrastructure Planning and Design Published: November 2012.
Active Directory ® Certificate Services Infrastructure Planning and Design Published: June 2010 Updated: November 2011.
Selecting the Right Network Access Protection Architecture
Microsoft ® System Center Operations Manager 2007 Infrastructure Planning and Design Published: June 2008 Updated: July 2010.
Deploying PKI Inside Microsoft The experience of Microsoft in deploying its own corporate PKI Published: December 2003.
Implementing ISA Server Publishing. Introduction What Are Web Publishing Rules? ISA Server uses Web publishing rules to make Web sites on protected networks.
1 Chapter 6: Proxy Server in Internet and Intranet Designs Designs That Include Proxy Server Essential Proxy Server Design Concepts Data Protection in.
Windows ® User State Virtualization Infrastructure Planning and Design Published: August 2010.
Selecting the Right Virtualization Technology Infrastructure Planning and Design Series.
Internet Information Services 7.0 Infrastructure Planning and Design Series.
Module 8 Configuring Mobile Computing and Remote Access in Windows® 7.
Selecting the Right Virtualization Technology Infrastructure Planning and Design Published: November 2007 Updated: November 2011.
Windows Server ® 2008 File Services Infrastructure Planning and Design Published: October 2008 Updated: July 2009.
Microsoft ® System Center Service Manager Infrastructure Planning and Design Published: December 2010 Updated: April 2012.
Microsoft ® System Center Service Manager 2010 Infrastructure Planning and Design Published: December 2010.
Module 3: Designing IP Addressing. Module Overview Designing an IPv4 Addressing Scheme Designing DHCP Implementation Designing DHCP Configuration Options.
Module 4: Planning, Optimizing, and Troubleshooting DHCP
© 2006 Cisco Systems, Inc. All rights reserved. Optimizing Converged Cisco Networks (ONT) Module 6: Implement Wireless Scalability.
Microsoft ® Exchange Server 2010 with Service Pack 1 Infrastructure Planning and Design Published: December 2010 Updated: July 2011.
Microsoft ® System Center Data Protection Manager 2007 with Service Pack 1 Infrastructure Planning and Design Published: January 2009 Updated: July 2010.
Appendix A UM in Microsoft® Exchange Server 2010.
Windows Server ® 2008 R2 Remote Desktop Services Infrastructure Planning and Design Published: November 2009.
Microsoft ® Enterprise Desktop Virtualization Infrastructure Planning and Design Published: March 2009 Updated: November 2011.
Windows Server ® 2008 R2 Remote Desktop Services Infrastructure Planning and Design Published: July 2008 Updated: February 2011.
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network, Enhanced Chapter 11: Internet Authentication Service.
Windows Server ® 2008 and Windows Server 2008 R2 Print Services Infrastructure Planning and Design Published: June 2010 Updated: November 2011.
Module 5: Designing Security for Internal Networks.
Next Generation Remote Access Always On Seamless and Transparent Bi-Directional Connectivity NOT a VPN!
Microsoft ® System Center Virtual Machine Manager 2008 R2 Infrastructure Planning and Design Series Published: June 2008 Updated: September 2009.
Microsoft ® Forefront ™ Identity Manager 2010 Infrastructure Planning and Design Published: June 2010.
Dynamic Datacenter Infrastructure Planning and Design Published: April 2010 Updated: July 2010.
VIRTUAL SERVERS Chapter 7. 2 OVERVIEW Exchange Server 2003 virtual servers Virtual servers in a clustering environment Creating additional virtual servers.
Virtual Private Network Access for Remote Networks
Microsoft® System Center Virtual Machine Manager 2008
Server-to-Client Remote Access and DirectAccess
Infrastructure Planning and Design
Employee engagement Delivery guide
DirectAccess with Unified Access Gateway (UAG)
Presentation transcript:

DirectAccess Infrastructure Planning and Design Published: October 2009 Updated: November 2011

What Is IPD? Guidance that clarifies and streamlines the planning and design process for Microsoft ® infrastructure technologies IPD: Defines decision flow Describes decisions to be made Relates decisions and options for the business Frames additional questions for business understanding IPD guides are available at

Getting Started DirectAccess

Purpose and Overview Purpose To provide design guidance for DirectAccess Overview DirectAccess overview DirectAccess architecture design process

What Is DirectAccess? DirectAccess: Can provide seamless connectivity experiences for mobile workers when connected to the Internet Enables the mobile workforce to increase their productivity by providing them with the same connectivity experience—whether in or out of the office Allows mobile computers to be managed any time the mobile computer has Internet connectivity, even if the user is not logged on

DirectAccess Design Flow

DirectAccess Architecture

Step 1: Define the Scope of the DirectAccess Project Task 1: Determine the Scope of the Project Which parts of the organization will be participating? Which geographic areas will be included? What are the number of users, access peak time, and maximum number of concurrent connections? What internal resources will the users need to access? What operating system is running on the domain controllers and DNS servers? What operating system is running on each internal resource that will be accessible to DirectAccess clients? Will DirectAccess be used to manage remote computers?

Step 2: Determine Network Requirements Task 1: Determine Connectivity Needs for DirectAccess Clients The first task in this step is to record which external client connectivity methods will need to be designed The following table shows a list of possible DirectAccess client networking configurations and the resulting primary IPv6 connectivity method.

Step 2: Determine Network Requirements (Continued) Task 2: Determine Connectivity Needs for Internal Resources This task focuses on determining how the DirectAccess server and remote clients will be provided access to internal resources If an internal resource has IPv6 connectivity with the DirectAccess server, no further connectivity method is needed. Where IPv6 connectivity is not available, consult the following table for the appropriate alternative internal connection methods.

Step 3: Design DirectAccess Server Infrastructure Task 1: Determine the Server Configuration The DirectAccess server can perform the following functions: Teredo server and relay 6to4 relay IP-HTTPS server ISATAP router Native Internet Protocol version 6 (IPv6) router IPsec tunnel endpoint and gateway Task 2: Determine Placement of Each Server Note that the DirectAccess server must be a member of the Active Directory domain, but cannot be a domain controller

Step 4: Design Web Servers and Certificate Infrastructure Task 1: Design the Computer Certificates Computer certificates required for IPsec can be autoenrolled or manual Task 2: Design the Network Location Servers A URL that is used by DirectAccess clients to detect correctly whether they are on the intranet

Step 4: Design Web Servers and Certificate Infrastructure (Continued) Task 3: Design the Network Location Server Certificates Internally accessible CRL distribution points to determine if network location server is using valid certificates Task 4: Design the DirectAccess Server Certificates A certificate is required for a connection between a DirectAccess client and the DirectAccess server. CRL distribution point must be externally accessible

DirectAccess and Microsoft Forefront Unified Access Gateway To provide fault tolerance, scalability, and increased management, Microsoft Forefront ® Unified Access Gateway (Forefront UAG) can be used in conjunction with DirectAccess Additional reading: Infrastructure Planning and Design guide for UAG is available at Additional reading: Microsoft Forefront Unified Access Gateway and DirectAccess at DirectAccess.aspx DirectAccess.aspx

Summary and Conclusion Carefully consider infrastructure requirements for DirectAccess IPv6 is required, but IPv6 transition technologies can ease the pathway This guide offers major architectural guidance. Refer to product documentation for additional details All the IPD guides are available at

Find More Information Download the full document and other IPD guides: Contact the IPD team: Access the Microsoft Solution Accelerators website:

Questions?

Addenda Benefits of Using the DirectAccess Guide IPD in Microsoft Operations Framework 4.0 DirectAccess in Microsoft Infrastructure Optimization

Benefits of Using the DirectAccess Guide Benefits for Business Stakeholders/Decision Makers Most cost-effective design solution for implementation Alignment between the business and IT from the beginning of the design process to the end Benefits for Infrastructure Stakeholders/Decision Makers Authoritative guidance Business validation questions ensuring solution meets requirements of business and infrastructure stakeholders High integrity design criteria that includes product limitations Fault-tolerant infrastructure Proportionate system and network availability to meet business requirements Infrastructure that’s sized appropriately for business requirements

Benefits of Using the DirectAccess Guide (Continued) Benefits for Consultants or Partners Rapid readiness for consulting engagements Planning and design template to standardize design and peer reviews A “leave-behind” for pre- and post-sales visits to customer sites General classroom instruction/preparation Benefits for the Entire Organization Using the guide should result in a design that will be sized, configured, and appropriately placed to deliver a solution for achieving stated business requirements

IPD in Microsoft Operations Framework 4.0 Use MOF with IPD guides to ensure that people and process considerations are addressed when changes to an organization’s IT services are being planned.

The Role of DirectAccess in Infrastructure Optimization