Solved

External Access to Share point, what's secure?

Posted on 2010-09-23
4
775 Views
Last Modified: 2016-10-25
Hi Guys,

We have ASA 5540, ISA, WISP, SQL, Netscaler and sharepoint, what's the best secure way to architect this with one AD and single sign on?

ASA has outside, inside "LAN", and DMZ .

AD, WISP, ISA, SQL and Sharepoint are on the LAN side.

Netscaler has one leg on the DMZ and one on LAN

Your help is greatly appreciated!
0
Comment
Question by:smartnet
  • 2
4 Comments
 
LVL 51

Accepted Solution

by:
Keith Alabaster earned 500 total points
ID: 33752967
Quite straightforward as Sharepoint and SQL are inside as opposed to in the DMZ. You have not mentioned whether ISA is actually installed as the intetrnal firewall or just as a proxy server but I will assume ISA is joined to the internal domain in either case.

This link provides the TechNet article regarding publishing the majority of common applications - including Sharepoint-  securely through ISA 2006.
http://technet.microsoft.com/en-gb/library/bb794854.aspx

In summary though, using the ISA server publishing wizard is the normal, recognised approach using https bridging and certificates.

Keith
0
 

Author Comment

by:smartnet
ID: 33755541
I think ISA is working as a proxy server rather than a firewall, do you recommend putting it in the DMZ, if so what about authentication??
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 33756400
The recommendation is always to use ISA or FTMG as a firewall/proxy rather than just a proxy and to have ISA or FTMG as a member of the domain.

if ISA/FTMG only has one nic then it can ONLY be a proxy server.

You can use the LDAP connection options though in the general confiuration if you decide to install ISA solely as a proxy server in the DMZ.
0
 
LVL 10

Expert Comment

by:simonlimon
ID: 33761396
It is much better for isa to be a member of the domain, if not you can't really have true sso as kerberos delegation is not possible... That would be the optimal way to publish a web page.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

These days socially coordinated efforts have turned into a critical requirement for enterprises.
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now