Microsoft ® Forefront ® Unified Access Gateway Infrastructure Planning and Design Published: December 2009 Updated: July 2010.

Slides:



Advertisements
Similar presentations
Internet Information Services 7.0 and Internet Information Services 7.5 Infrastructure Planning and Design Published: June 2008 Updated: November 2011.
Advertisements

Selecting the Right Network Access Protection (NAP) Architecture Infrastructure Planning and Design Published: June 2008 Updated: November 2011.
Windows® Deployment Services
Windows Server ® 2008 File Services Infrastructure Planning and Design Published: June 2010 Updated: November 2011.
Windows Server ® 2008 and Windows Server ® 2008 R2 Active Directory ® Domain Services Infrastructure Planning and Design Published: February 2008 Updated:
Microsoft Operations Framework (MOF) 4.0
Microsoft ® System Center Configuration Manager 2007 R3 and Forefront ® Endpoint Protection Infrastructure Planning and Design Published: October 2008.
DirectAccess Infrastructure Planning and Design Published: October 2009 Updated: November 2011.
Extending ForeFront beyond the limit TMGUAG ISAIAG AG Security Suite.
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter 14 Upgrading to Exchange Server 2003.
Malware Response Infrastructure Planning and Design Published: February 2011 Updated: November 2011.
Windows Server ® 2008 Active Directory ® Domain Services Infrastructure Planning and Design Series Published: February 2008 Updated: July 2009.
Windows Server ® Virtualization Infrastructure Planning and Design Published: November 2007 Updated: July 2010.
A Technical Overview of Microsoft Forefront Client Security (FCS) Howard Chow Microsoft MVP.
Unified Logs and Reporting for Hybrid Centralized Management
Threat Management Gateway 2010 Questo sconosciuto? …ancora per poco! Manuela Polcaro Security Advisor.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 8 Introduction to Printers in a Windows Server 2008 Network.
Microsoft ® Application Virtualization 4.5 Infrastructure Planning and Design Series.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 7 Configuring File Services in Windows Server 2008.
Windows Server Virtualization Infrastructure Planning and Design Series.
Microsoft ® Exchange Online— Evaluating Software-plus-Services Infrastructure Planning and Design Published: November 2008 Updated: October 2010.
Microsoft ® SharePoint ® Online— Evaluating Software-plus-Services Infrastructure Planning and Design Published: June 2009 Updated: October 2010.
SYSTEM CENTER: ENDPOINT PROTECTION FUNDAMENTALS Howard A. Carter III Senior Consultant Microsoft Consulting Services September 21, 2013 TechGate 2013 –
Microsoft ® Application Virtualization 4.6 Infrastructure Planning and Design Published: September 2008 Updated: February 2010.
Clinic Security and Policy Enforcement in Windows Server 2008.
Designing Active Directory Child Domain Sainath K.E.V Directory Services MVP 5/Aug/2015.
Terminal Services in Windows Server ® 2008 Infrastructure Planning and Design.
Windows ® Deployment Services Infrastructure Planning and Design Published: February 2008 Updated: January 2012.
Windows Server ® Virtualization Infrastructure Planning and Design Published: November 2007 Updated: January 2012.
Microsoft ® Application Virtualization 4.6 Infrastructure Planning and Design Published: September 2008 Updated: November 2011.
Microsoft ® SQL Server ® 2008 and SQL Server 2008 R2 Infrastructure Planning and Design Published: February 2009 Updated: January 2012.
Microsoft ® System Center Operations Manager Infrastructure Planning and Design Published: November 2012.
Active Directory ® Certificate Services Infrastructure Planning and Design Published: June 2010 Updated: November 2011.
Selecting the Right Network Access Protection Architecture
11 SECURITY TEMPLATES AND PLANNING Chapter 7. Chapter 7: SECURITY TEMPLATES AND PLANNING2 OVERVIEW  Understand the uses of security templates  Explain.
Microsoft ® System Center Operations Manager 2007 Infrastructure Planning and Design Published: June 2008 Updated: July 2010.
OFC 200 Microsoft Solution Accelerator for Intranets Scott Fynn Microsoft Consulting Services National Practices.
Windows ® User State Virtualization Infrastructure Planning and Design Published: August 2010.
Selecting the Right Virtualization Technology Infrastructure Planning and Design Series.
Internet Information Services 7.0 Infrastructure Planning and Design Series.
Selecting the Right Virtualization Technology Infrastructure Planning and Design Published: November 2007 Updated: November 2011.
Windows Server ® 2008 File Services Infrastructure Planning and Design Published: October 2008 Updated: July 2009.
Microsoft ® System Center Service Manager Infrastructure Planning and Design Published: December 2010 Updated: April 2012.
Microsoft ® System Center Service Manager 2010 Infrastructure Planning and Design Published: December 2010.
Extending Forefront beyond the limit TMG UAG ISA IAG Security Suite
20411B 8: Installing, Configuring, and Troubleshooting the Network Policy Server Role Presentation: 60 minutes Lab: 60 minutes After completing this module,
Microsoft ® Exchange Server 2010 with Service Pack 1 Infrastructure Planning and Design Published: December 2010 Updated: July 2011.
Microsoft ® System Center Data Protection Manager 2007 with Service Pack 1 Infrastructure Planning and Design Published: January 2009 Updated: July 2010.
Windows Server ® 2008 R2 Remote Desktop Services Infrastructure Planning and Design Published: November 2009.
Microsoft ® Enterprise Desktop Virtualization Infrastructure Planning and Design Published: March 2009 Updated: November 2011.
Windows Server ® 2008 R2 Remote Desktop Services Infrastructure Planning and Design Published: July 2008 Updated: February 2011.
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network, Enhanced Chapter 11: Internet Authentication Service.
Windows Server ® 2008 and Windows Server 2008 R2 Print Services Infrastructure Planning and Design Published: June 2010 Updated: November 2011.
Microsoft ® System Center Virtual Machine Manager 2008 R2 Infrastructure Planning and Design Series Published: June 2008 Updated: September 2009.
What are Solution Accelerators? Overview Next Steps.
© 2008 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED,
Microsoft ® Forefront ™ Identity Manager 2010 Infrastructure Planning and Design Published: June 2010.
Dynamic Datacenter Infrastructure Planning and Design Published: April 2010 Updated: July 2010.
Version 4.0 Living in a Network Centric World Network Fundamentals – Chapter 1.
Managing Network Access Protection. Introduction to NAP Issues  Although corporate networks are highly secured, no control over the configuration of.
Network and Server Basics. Learning Objectives After viewing this presentation, you will be able to: Understand the benefits of a client/server network.
Microsoft® System Center Virtual Machine Manager 2008
Self-service enrollment for Windows desktops
Cisco Data Virtualization
Deployment Planning Services
Forefront Security ISA
Microsoft® System Center Configuration Manager 2007 SP1 with R2
Dev Test on Windows Azure Solution in a Box
Increase and Improve your PC management with Windows Intune
Infrastructure Planning and Design
Presentation transcript:

Microsoft ® Forefront ® Unified Access Gateway Infrastructure Planning and Design Published: December 2009 Updated: July 2010

What is IPD? Guidance that clarifies and streamlines the planning and design process for Microsoft ® infrastructure technologies IPD: Defines decision flow Describes decisions to be made Relates decisions and options for the business Frames additional questions for business understanding IPD guides are available at

Getting Started Microsoft Forefront Unified Access Gateway (UAG)

Purpose and Overview Purpose To provide guidance for designing a Forefront UAG infrastructure Overview Forefront UAG architecture Forefront UAG infrastructure design process

Example of Forefront UAG Architecture MDTSCMITA

Forefront UAG Decision Flow MDTSCMITA

Step 1: Define the Scope of the Forefront Unified Access Gateway Project Task 1: Define the scope of the project Define client populations Define corporate resources client populations will access via Forefront UAG Whether DirectAccess will be used Task 2: Determine the client requirements Where are the client machines located? Will client machines travel between locations? What client operating systems and browsers are in use? What Forefront UAG functionality will the client workstation use? Whether the client will use DirectAccess. Fault-tolerance requirements. Task 3: Determine the endpoint health approach Forefront UAG built-in access policies Network Access Protection (NAP) policies

Step 2: Determine the Number of Forefront Unified Access Gateway Instances Required Task 1: Decide the number of Forefront UAG instances required Add more instances if necessary for: Both DirectAccess and VPN clients Align with organization’s management model or regulatory reasons Network isolation Services beyond the trust boundary

Step 3: Design the Server Infrastructure Task 1: Design and place the Forefront UAG server Task 2: Design fault tolerance and scale out Note that if Forefront UAG is used to provide an array for DirectAccess, use of hardware load balancer is not supported Task 3: Design the data store Built-in Forefront UAG reporter to log events. Log files can be placed on clustered file server if fault tolerance is required. RADIUS accounting server is in NPS and is a second option to log events.

Dependencies The Forefront UAG installation program automatically installs a customized version of the Microsoft Forefront Threat Management Gateway (Forefront TMG). Forefront UAG utilizes many functions that are in Forefront TMG, including the array and the firewall. It also stores the publishing rules for the Forefront UAG portal. If Forefront TMG is uninstalled from a Forefront UAG server, this creates a configuration that Microsoft does not support. Note that Forefront UAG does not support the stand-alone version of Forefront TMG; the only supported configuration is where Forefront UAG automatically installs its own version of Forefront TMG. Further information about Forefront TMG’s role when used with Forefront UAG is available at

Summary and Conclusion The Forefront UAG guide has addressed the fundamental decisions and tasks involved in: Defining the scope of the Forefront UAG project Determining how many Forefront UAG instances will be required Designing the Forefront UAG instances and the server infrastructure in them This guide offers major architectural guidance. Refer to product documentation for additional details. Provide feedback to

Find More Information Download the full document and other IPD guides: Contact the IPD team: Access the Microsoft Solution Accelerators website:

Questions?

Addenda: Benefits for Consultants or Partners IPD in Microsoft Operations Framework 4.0 System Center Operations Manager 2007 in Microsoft Infrastructure Optimization

Benefits of Using the Forefront UAG Guide Benefits for Business Stakeholders/Decision Makers – Most cost-effective design solution for implementation – Alignment between the business and IT from the beginning of the design process to the end Benefits for Infrastructure Stakeholders/ Decision Makers – Authoritative guidance – Business validation questions ensuring solution meets requirements of business and infrastructure stakeholders – High integrity design criteria that includes product limitations – Fault-tolerant infrastructure – Infrastructure that’s sized appropriately for business requirements

Benefits of Using the Forefront UAG Guide (Continued) Benefits for Consultants or Partners – Rapid readiness for consulting engagements – Planning and design template to standardize design and peer reviews – A “leave-behind” for pre- and post-sales visits to customer sites – General classroom instruction/preparation Benefits for the Entire Organization – Using the guide should result in a design that will be sized, configured, and appropriately placed to deliver a solution for achieving stated business requirements

IPD in Microsoft Operations Framework 4.0 Use MOF with IPD guides to ensure that people and process considerations are addressed when changes to an organization’s IT services are being planned.

Forefront UAG in Microsoft Infrastructure Optimization