Dominik Zemp Microsoft Switzerland Ltd Liab. Co. Install and Configure Remote Access for SharePoint (and RemoteApp and DirectAccess)

Slides:



Advertisements
Similar presentations
Secure Single Sign-On Across Security Domains
Advertisements

WMS02: Direct Access Always Connected: Death of the VPN
Direct Access 2012 Chad Duffey and Tristan Kington Microsoft Premier Field Engineering WSV333.
DirectAccess Infrastructure Planning and Design Published: October 2009 Updated: November 2011.
5.1 Overview of Network Access Protection What is Network Access Protection NAP Scenarios NAP Enforcement Methods NAP Platform Architecture NAP Architecture.
Scott Roberts Lead Program Manager Microsoft Session Code: WSV320.
Extending ForeFront beyond the limit TMGUAG ISAIAG AG Security Suite.
The Natural way for Secure Mobile v.1.4
Secure Lync mobile Authentication
Secure SharePoint mobile connectivity
Adwait JoshiJim Harrison Sr. Product ManagerProgram Manager Microsoft Corporation SESSION CODE: SIA308.
SIM403. Claims Provider Trust Relying Party x Relying Party Trust Claims Provider Trust Your ADFS STS Partner ADFS STS & IP Relying Party Trust Partner.
Module 5: Configuring Access for Remote Clients and Networks.
Microsoft Windows 7 Security Ronen Gottlib, CISSP Information Security Lead Microsoft.
1 Objectives Configure Network Access Services in Windows Server 2008 RADIUS 1.
Ronald Beekelaar Beekelaar Consultancy Intelligent Application Gateway (IAG) 2007.
1 Objectives Wireless Access IPSec Discuss Network Access Protection Install Network Access Protection.
Secure Access using IAG 2007 Presented by: Brian Dunleavy - Healthcare Business Manager - Eurodata Susanna Watson – Pre Sales Technical Consultant - Eurodata.
Threat Management Gateway 2010 Questo sconosciuto? …ancora per poco! Manuela Polcaro Security Advisor.
Working remote: what to consider, technology evolution.
Ing. Ondřej Ševeček | GOPAS a.s. | MCM: Directory Services | MVP: Enterprise Security | | |
Enabling Secure Always-On Connectivity [Name] Microsoft Corporation.
© 2005,2006 NeoAccel Inc. Training Access Modes. © 2005,2006 NeoAccel Inc. Agenda 2. Access Terminals 6. Quick Access Terminal Client 3. SSL VPN-Plus.
Getting to know UAG Tom Decaluwé
WSV404 DirectAccess Server (Server 2008 R2) DirectAccess Client (Windows 7) Internet Native IPv6 6to4 Teredo IP-HTTPS Tunnel over IPv4 UDP, HTTPS,
Ing. Ondřej Ševeček | GOPAS a.s. | MCM: Directory Services | MVP: Enterprise Security | Certified Ethical Hacker | |
Network Services Lesson 6. Objectives Skills/ConceptsObjective Domain Description Objective Domain Number Setting up common networking services Understanding.
Course 201 – Administration, Content Inspection and SSL VPN
Gavin Carius Architect Microsoft Services SVR311.
Clinic Security and Policy Enforcement in Windows Server 2008.
Chapter 20: Getting from the Office to the Road: VPNs BAI617.
1 Week #7 Network Access Protection Overview of Network Access Protection How NAP Works Configuring NAP Monitoring and Troubleshooting NAP.
Access Gateway Operation
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter Four Configuring Outlook and Outlook Web Access.
Securing Microsoft® Exchange Server 2010
Federation and Federated Identity: Part 2 Building Federated Identity Solutions with Forefront Unified Access Gateway (UAG) and ADFS v2 John Craddock Infrastructure.
70-411: Administering Windows Server 2012
Implementing Network Access Protection
Objectives Configure routing in Windows Server 2008 Configure Routing and Remote Access Services in Windows Server 2008 Network Address Translation 1.
Microsoft DirectAccess & Work Folders NICHOLAS A. HAY MONROE COUNTY ISD
Extending Forefront beyond the limit TMG UAG ISA IAG Security Suite
Virtual techdays INDIA │ august 2010 Threat Management Gateway 2010 – A Deep Dive Anirudh Singh Rautela │ TSP – Security, Microsoft Corporation.
Module 11: Remote Access Fundamentals
Module 8: Configuring Network Access Protection
Module 9: Designing Network Access Protection. Scenarios for Implementing NAP Verifying the health of: Roaming laptops Desktop computers Visiting laptops.
Module 11: Implementing ISA Server 2004 Enterprise Edition.
Sudarshan Yadav Sr. Program Manager, Microsoft
James O’Neill : Microsoft UK Windows Server 2008 Terminal Services.
Jim Harrison Program Manager, Forefront TMG Microsoft Corporation SESSION CODE: SIA325.
Shai Tirosh Windows Server Regional Director artNET Experts.
Designing Secure SharePoint External Access Ondrej Sevecek | MCM: Directory | MVP: Security |
Welcome Windows Server 2008 安全功能 -NAP. Network Access Protection in Windows Server 2008.
Integrating and Troubleshooting Citrix Access Gateway.
Configuring Network Access Protection
Terminal Services Technical Overview Olav Tvedt TVEDT.info Microsoft Speaker Community
Next Generation Remote Access Always On Seamless and Transparent Bi-Directional Connectivity NOT a VPN!
Providing seamless, secure access to enterprise resources from anywhere.
Access and Information Protection Product Overview Andrew McMurray Technical Evangelist – Windows
1 Week #5 Routing and NAT Network Overview Configuring Routing Configuring Network Address Translation Troubleshooting Routing and Remote Access.
SonicWALL SSL-VPN Series Easy Secure Remote Access Cafferata Cristiano SE Italia.
Uri Lichtenfeld Security Specialist Certified Security Solutions – Microsoft Partner SESSION CODE: SIA312.
Microsoft ® Internet Security and Acceleration Server 2006 Beta Technical Overview Steve Lamb Information Security Evangelist
Edge Security with Forefront Sandeep Modhvadia Security Specialist.
Objavljanje aplikacij preko UAG portala Varnost oddaljenih dostopov in Windows Security Gorazd Šemrov Microsoft Corporation.
Enabling Secure Always-On Connectivity Gustav Kaleta Partner Technology Advisor Microsoft Corporation.
Securing the Network Perimeter with ISA 2004
Forefront Security ISA
Implementing TMG Server Publishing
Server-to-Client Remote Access and DirectAccess
Goals Introduce the Windows Server 2003 family of operating systems
Presentation transcript:

Dominik Zemp Microsoft Switzerland Ltd Liab. Co. Install and Configure Remote Access for SharePoint (and RemoteApp and DirectAccess) In An Hour

What is Forefront UAG? UAG Solution and Internal Architecture How to Publish SharePoint via UAG Live Demos How to Publish RemoteApps, DirectAccess, etc. via UAG Q & A

What are the different Microsoft Remote Access Solutions? Answer: Threat Management Gateway (TMG) Direct Access Remote Desktop Services Windows RAS (SSTP) Unified Access Gateway (UAG) And which ones are for SharePoint? Answer: Threat Management Gateway (TMG) Direct Access Remote Desktop Services Windows RAS (SSTP) Unified Access Gateway (UAG)

Solution and Internal Architecture

Unified Access Gateway (UAG) is next version of Intelligent Application Gateway (IAG) with a vision and mission to provide managed, unmanaged & mobile devices with unified secure anywhere access to on-premise and in-the-cloud applications. What (Data) Who (Identity) Where (Device)

Financial Partner or Field Agent Project Manager Employee Logistics Partner Remote Technician Employee Corporate Managed Laptop Home PC Unmanaged Partner PC Kiosk Financial Partner or Field Agent Project Manager Employee Logistics Partner Corporate Laptop Home PC Kiosk Remote Technician Employee Unmanaged Partner PC Each session is tailored according to its user and the device in use, maximizing security and productivity for that session.

DirectAccess HTTPS (443) Layer3 VPN Business Partners / Sub-Contractors AD, ADFS, RADIUS, LDAP…. Home / Friend / Kiosk Employees Managed Machines Mobile Exchange CRM SharePoint IIS based IBM, SAP, Oracle Terminal / Remote Desktop Services Non web HTTPS / HTTP NPS, ILM Strong authentication Endpoint health detection: NAP and down-level Authorization: Based on health status Who + where Information leakage prevention Attachment/Cache wiper

Active Directory LDAP TACACS RADIUS RSA Smart Card Certificates KCD ADFS etc … using UAG Hooks

No need for directory replication or repetition Alternative approaches require local repository Transparent Web authentication HTTP 401 request Static Web form Dynamic browser-sensitive Web form Kerberos Constraint Delegation Integrates with: Password change management User repositories

Inbuilt policies can check the health of endpoints connecting to UAG portal and applications Check system settings and features on the endpoint Control access to trunk and applications, as well as actions such as downloading and uploading files Supports Windows, Mac OS, and Linux Platform-specific policies enforced according to the operating system on the endpoint device Predefined policies enabled by default Can be edited to check for specific settings or features, as required Administrators can also define their own policies

Enforces compliance and provides remediation for clients connecting through portal trunks or DirectAccess Each scenario will use NAP in a different way For portal trunks, UAG receives statement of health (SoH) from client and enforces policies directly For DirectAccess, IPSec policies require a “health certificate” issued independently by NAP

Wipes out the locally stored content upon session termination Prevents information leakage Removes: Downloaded files and pages AutoComplete form contents AutoComplete URLs Cookies History information Any user credentials

IP VPN Admin Core Web Application Publishing Windows Server TMG Windows NLB RRAS IIS TSG / RDG UAG Filter Session Manager User Manager Config. / Array Manager Internal Site Portal Direct Access DirectAccess Server DNS-ALG NAT-PT ISATAP IP-HTTPS Teredo 6to4 Native IPv6 DTE / DoSP Management UI SCOM MP UAG Logic Tracing & Logging SSTP Layer 3 SSL Tunnel

Technical Details and Live Demos

Enables SharePoint to map Web requests to the correct Web sites and apps Defines alternative public and internal URL names for the SharePoint Web site Should match the URLs typed by the user or provided by the reverse proxy (like UAG) Configured on the SharePoint Central Administration Site

Mistake #1: "I'm not deploying SharePoint in an unusual way, so I don't need to worry configuring Alternate Access Mappings." Mistake #2: Your reverse proxy server's "link translation" feature is sufficient. Mistake #3: Trying to reuse the same URL in AAM or not aligning the URLs to the same zone. Source: access-mappings-part-2-of-3.aspxhttp://blogs.msdn.com/sharepoint/archive/2007/03/19/what-every-sharepoint-administrator-needs-to-know-about-alternate- access-mappings-part-2-of-3.aspx

TMG 2010UAG 2010 Wizards and predefined settings basic Information leakage prevention (Session clean up) Endpoint health-based authorization Web farm load balancing (WFLB) Advanced authentication schemes (e.g. AD FS) Rich client authentication Single sign on Unified portal Application protection (Web application firewall) basic Policy-based access (granular policies) Array support AAM support Customization and manipulation (UI, applications) basic

SharePoint Publishing

How to Publish RemoteApp and DirectAccess

UAG seamlessly integrates Remote Desktop Gateway (RDG) to provide application-level gateway for RDS applications Enables employees to securely access applications that are hosted on Terminal Server or their internal workstation Benefits: Enhanced authentication Single sign-on experience Granular policies based on client health: No anti-virus  no driver sharing RemoteApps are integrated into UAG portal side by side with Web applications Integrated deployment and management with other remote access technologies

In UAG, RD/TS client traffic goes over HTTPS. The HTTPS tunnel is terminated at UAG, therefore we can inspect the traffic. The traffic is then passed to the backend RD Session Host using the RDP protocol. UAG+RDGUAG+RDG RD/TS Client (MSTSC) (MSTSC) RDP over HTTPS RDPRDP RD Session Host (TS Server) RD Session Host (TS Server)

SSL-VPN { { + IPv6 Always On IPv6 IPv4 { { IPv6 or IPv4 UAG and DirectAccess better together: Extends access to line of business servers with IPv4 support Access for down level and non Windows clients Enhances scalability and management Simplifies deployment and administration Hardened Edge Solution

UAG provides IPv6 connectivity between Internet clients and internal servers Native IPv6 connectivity or using transition technologies 23 InternetIntranet 6to4 Teredo IP-HTTPS Native IPv6 ISATAP NAT64 6to4 Teredo IP-HTTPS

Connectivity to corporate network is done using IPv6, protected by IPSec tunnels and transported over IPv4 using IPv6 transition technologies (6to4, Teredo, IP-HTTPS): 24 IPv6 Transition Technologies Infrastructure Tunnel Intranet Tunnel Internet Domain Controllers, DNS, HRA, Management Rest of the machines in corporate network

Step 1: User machine tries to resolve address of an IPv4 only server: DNS64DNS64NAT64NAT64 Host name: x.contoso.com IP: IP: DNS AAAA Query for “x.contoso.com” DNS A Query for “x.contoso.com” DNS AAAA Query for “x.contoso.com” DNS A Response IP: DNS AAAA Response IP: 2a01:110:6:6:6:6:: NAT64 Prefix: 2a01:110:6:6:6:6::/96

Step 2: User machine sends a packet to an IPv4 server: DNS64DNS64NAT64NAT64 Host name: x.contoso.com IP: IP: Packet to: Send packet to: 2a01:110:6:6:6:6:: NAT64 Prefix: 2a01:110:6:6:6:6::/96

RemoteApps and DirectAccess

For more Information please contact Dominik Zemp TSP Security +41 (43) (0) Microsoft Switzerland Richtistrasse Wallisellen

UAG 2010 Eval Download: us/evalcenter/dd aspx UAG Team Blog: TMG Team Blog: Forefront Edge IAG/UAG Support Forum: US/forefrontedgeiag