Solved

network load balancing requirements for ADFS servers and proxy servers in for Office 365

Posted on 2013-06-10
8
1,304 Views
Last Modified: 2013-06-17
Hello all,
I am going to deploy two ADFS servers into the F5 network load balancing. I would like to know their requirement such as port #, DNS record, etc.

Could you please provide me the requirements?
Thanks,
0
Comment
Question by:dongocdung
  • 4
  • 3
8 Comments
 
LVL 38

Assisted Solution

by:Adam Brown
Adam Brown earned 125 total points
ID: 39236351
ADFS communication with clients works over port 443 (HTTPS) only. The servers should be able to communicate with one another freely, though (for the most part). DNS will need to be set up so that the each server has an individual DNS entry that is referenced Internally and the VIP should be set to the Cluster DNS name.
0
 
LVL 6

Assisted Solution

by:Neadom Tucker
Neadom Tucker earned 375 total points
ID: 39236613
Are you using physical or virtual servers?  If you are using virtual servers what Hyper visor type will you be using.  Xen Server has an issue with Multicast Cluster setups and the cluster does not work well. You will need a 3rd party certificate if you plan on accessing the site from outside the network.  This will need to be on all 3 servers and you will need to create a host entry on your proxy server that points to your Cluster.  It is a pretty simple setup.  There are a few gotchas.

Tucker
0
 

Author Comment

by:dongocdung
ID: 39236681
I am using vmware. I plan to have a virtual IP address for load balancing cluster with two servers. I also create a record for this IP address. In proxy, i also create NATs for public facing. I open port 443. Is my plan OK?
0
 
LVL 6

Accepted Solution

by:
Neadom Tucker earned 375 total points
ID: 39236705
Yeah so far.  You should not have an issue with your implementation using VMware.  Your Proxy will need a host entry created for (adfs.yourdomain.com) that points to your vIP through your DMZ.  Make sure you allow port 443 from your DMZ to your ADFS vIP.

Just and FYI the latest version of DirSync includes password sync.  So depending on your reasoning on implementing SSO you may not need it.

http://blogs.msdn.com/b/active_directory_team_blog/archive/2013/06/03/making-it-simple-to-connect-ad-to-azure-ad-password-hash-sync.aspx

I hope this helps!

Tucker
0
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

 

Author Comment

by:dongocdung
ID: 39237694
ADFS server and ADFS Proxy server will use the same service name (sts.domain.com). Which server's ip address do I need to use to create the record in DNS? Do I need to create two records for the same service names?
0
 
LVL 6

Assisted Solution

by:Neadom Tucker
Neadom Tucker earned 375 total points
ID: 39238252
what is the VIP of your ADFS Loadbalancer?  you create the record for your virtual IP.
0
 

Author Comment

by:dongocdung
ID: 39238620
My ADFS load balancer is 172.25.5.208 and proxy is 192.168.254.16. So, do I need to create two records for them?
0
 
LVL 6

Expert Comment

by:Neadom Tucker
ID: 39253393
you just need the dns info for the load balancer for the internal network.  your external dns should point to the firewall and then NAT to the 254.16
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

919 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now