?
Solved

network load balancing requirements for ADFS servers and proxy servers in for Office 365

Posted on 2013-06-10
8
Medium Priority
?
1,329 Views
Last Modified: 2013-06-17
Hello all,
I am going to deploy two ADFS servers into the F5 network load balancing. I would like to know their requirement such as port #, DNS record, etc.

Could you please provide me the requirements?
Thanks,
0
Comment
Question by:dongocdung
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
8 Comments
 
LVL 42

Assisted Solution

by:Adam Brown
Adam Brown earned 500 total points
ID: 39236351
ADFS communication with clients works over port 443 (HTTPS) only. The servers should be able to communicate with one another freely, though (for the most part). DNS will need to be set up so that the each server has an individual DNS entry that is referenced Internally and the VIP should be set to the Cluster DNS name.
0
 
LVL 6

Assisted Solution

by:Neadom Tucker
Neadom Tucker earned 1500 total points
ID: 39236613
Are you using physical or virtual servers?  If you are using virtual servers what Hyper visor type will you be using.  Xen Server has an issue with Multicast Cluster setups and the cluster does not work well. You will need a 3rd party certificate if you plan on accessing the site from outside the network.  This will need to be on all 3 servers and you will need to create a host entry on your proxy server that points to your Cluster.  It is a pretty simple setup.  There are a few gotchas.

Tucker
0
 

Author Comment

by:dongocdung
ID: 39236681
I am using vmware. I plan to have a virtual IP address for load balancing cluster with two servers. I also create a record for this IP address. In proxy, i also create NATs for public facing. I open port 443. Is my plan OK?
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 6

Accepted Solution

by:
Neadom Tucker earned 1500 total points
ID: 39236705
Yeah so far.  You should not have an issue with your implementation using VMware.  Your Proxy will need a host entry created for (adfs.yourdomain.com) that points to your vIP through your DMZ.  Make sure you allow port 443 from your DMZ to your ADFS vIP.

Just and FYI the latest version of DirSync includes password sync.  So depending on your reasoning on implementing SSO you may not need it.

http://blogs.msdn.com/b/active_directory_team_blog/archive/2013/06/03/making-it-simple-to-connect-ad-to-azure-ad-password-hash-sync.aspx

I hope this helps!

Tucker
0
 

Author Comment

by:dongocdung
ID: 39237694
ADFS server and ADFS Proxy server will use the same service name (sts.domain.com). Which server's ip address do I need to use to create the record in DNS? Do I need to create two records for the same service names?
0
 
LVL 6

Assisted Solution

by:Neadom Tucker
Neadom Tucker earned 1500 total points
ID: 39238252
what is the VIP of your ADFS Loadbalancer?  you create the record for your virtual IP.
0
 

Author Comment

by:dongocdung
ID: 39238620
My ADFS load balancer is 172.25.5.208 and proxy is 192.168.254.16. So, do I need to create two records for them?
0
 
LVL 6

Expert Comment

by:Neadom Tucker
ID: 39253393
you just need the dns info for the load balancer for the internal network.  your external dns should point to the firewall and then NAT to the 254.16
0

Featured Post

Get MySQL database support online, now!

At Percona’s web store you can order your MySQL database support needs in minutes. No hassles, no fuss, just pick and click. Pay online with a credit card.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

My attempt to use PowerShell and other great resources found online to simplify the deployment of Office 365 ProPlus client components to any workstation that needs it, regardless of existing Office components that may be needing attention.
During and after that shift to cloud, one area that still poses a struggle for many organizations is what to do with their department file shares.
In this video I am going to show you how to back up and restore Office 365 mailboxes using CodeTwo Backup for Office 365. Learn more about the tool used in this video here: http://www.codetwo.com/backup-for-office-365/ (http://www.codetwo.com/ba…
Michael from AdRem Software outlines event notifications and Automatic Corrective Actions in network monitoring. Automatic Corrective Actions are scripts, which can automatically run upon discovery of a certain undesirable condition in your network.…
Suggested Courses

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question