?
Solved

network load balancing requirements for ADFS servers and proxy servers in for Office 365

Posted on 2013-06-10
8
Medium Priority
?
1,360 Views
Last Modified: 2013-06-17
Hello all,
I am going to deploy two ADFS servers into the F5 network load balancing. I would like to know their requirement such as port #, DNS record, etc.

Could you please provide me the requirements?
Thanks,
0
Comment
Question by:dongocdung
  • 4
  • 3
8 Comments
 
LVL 43

Assisted Solution

by:Adam Brown
Adam Brown earned 500 total points
ID: 39236351
ADFS communication with clients works over port 443 (HTTPS) only. The servers should be able to communicate with one another freely, though (for the most part). DNS will need to be set up so that the each server has an individual DNS entry that is referenced Internally and the VIP should be set to the Cluster DNS name.
0
 
LVL 6

Assisted Solution

by:Neadom Tucker
Neadom Tucker earned 1500 total points
ID: 39236613
Are you using physical or virtual servers?  If you are using virtual servers what Hyper visor type will you be using.  Xen Server has an issue with Multicast Cluster setups and the cluster does not work well. You will need a 3rd party certificate if you plan on accessing the site from outside the network.  This will need to be on all 3 servers and you will need to create a host entry on your proxy server that points to your Cluster.  It is a pretty simple setup.  There are a few gotchas.

Tucker
0
 

Author Comment

by:dongocdung
ID: 39236681
I am using vmware. I plan to have a virtual IP address for load balancing cluster with two servers. I also create a record for this IP address. In proxy, i also create NATs for public facing. I open port 443. Is my plan OK?
0
A Cyber Security RX to Protect Your Organization

Join us on December 13th for a webinar to learn how medical providers can defend against malware with a cyber security "Rx" that supports a healthy technology adoption plan for every healthcare organization.

 
LVL 6

Accepted Solution

by:
Neadom Tucker earned 1500 total points
ID: 39236705
Yeah so far.  You should not have an issue with your implementation using VMware.  Your Proxy will need a host entry created for (adfs.yourdomain.com) that points to your vIP through your DMZ.  Make sure you allow port 443 from your DMZ to your ADFS vIP.

Just and FYI the latest version of DirSync includes password sync.  So depending on your reasoning on implementing SSO you may not need it.

http://blogs.msdn.com/b/active_directory_team_blog/archive/2013/06/03/making-it-simple-to-connect-ad-to-azure-ad-password-hash-sync.aspx

I hope this helps!

Tucker
0
 

Author Comment

by:dongocdung
ID: 39237694
ADFS server and ADFS Proxy server will use the same service name (sts.domain.com). Which server's ip address do I need to use to create the record in DNS? Do I need to create two records for the same service names?
0
 
LVL 6

Assisted Solution

by:Neadom Tucker
Neadom Tucker earned 1500 total points
ID: 39238252
what is the VIP of your ADFS Loadbalancer?  you create the record for your virtual IP.
0
 

Author Comment

by:dongocdung
ID: 39238620
My ADFS load balancer is 172.25.5.208 and proxy is 192.168.254.16. So, do I need to create two records for them?
0
 
LVL 6

Expert Comment

by:Neadom Tucker
ID: 39253393
you just need the dns info for the load balancer for the internal network.  your external dns should point to the firewall and then NAT to the 254.16
0

Featured Post

 The Evil-ution of Network Security Threats

What are the hacks that forever changed the security industry? To answer that question, we created an exciting new eBook that takes you on a trip through hacking history. It explores the top hacks from the 80s to 2010s, why they mattered, and how the security industry responded.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This month, Experts Exchange’s free Course of the Month is focused on CompTIA IT Fundamentals.
If something goes wrong with Exchange, your IT resources are in trouble.All Exchange server migration processes are not designed to be identical and though migrating email from on-premises Exchange mailbox to Cloud’s Office 365 is relatively simple…
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…

850 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question