Solved

ADFS Resiliency NLB question

Posted on 2015-02-11
3
148 Views
Last Modified: 2015-02-27
Hi

I have an ADFS and ADFS Proxy servers already configured an working as part of an Office 365 setup. I now need to introduce resiliency in the form of an additional ADFS server and an additional ADFS proxy server. Windows NLB is our preferred  method. According to this thread, NLB has to be installed before teh ADFS farm:

https://social.technet.microsoft.com/Forums/windowsserver/en-US/3e6e8524-53aa-4524-972a-1e4df87efd74/sequence-to-setup-adfs-farm-and-nlb-windows-2008-r2?forum=winserverClustering

Is this definitely correct? I.e. is there any other way of adding NLB resiliency without having to re-build the existing ADFS  and ADS proxy servers?

Thanks

m
0
Comment
Question by:mk112233
3 Comments
 
LVL 22

Assisted Solution

by:Matt V
Matt V earned 250 total points
ID: 40604732
Having just built that exact setup, I believe the article is correct.  Because you bind the ADFS service you would need the NLB interface available when you do the ADFS setup.
0
 
LVL 35

Accepted Solution

by:
Mahesh earned 250 total points
ID: 40605209
May be as per article NLB should be setup 1st, but I don't think so

Then what about scenarios where only 1 server is available for initial setup and later you would add another server in farm?

According to my understanding NLB has no direct connection to ADFS, what I mean NLB virtual URL can be used as ADFS URL
There is restrictions on ADFS setup that once you setup ADFS, you cannot change Federation service URL name, if you try to do so, it will break ADFS functionality
If your federation service name is same as server FQDN, then you cannot install NLB because NLB need separate virtual name associated with VIP

I hope in your case ADFS url is different than actual server FQDN and its currently pointing to server actual IP
If above is true, you can go ahead and setup NLB, NLB will require new internal IP as VIP and you should provide ADFS service URL to this VIP in DNS, so this will allow ADFS requests to listen on that specific IP
Ultimately what you are doing is just making some IP changes in DNS and ADFS service URL remains unchanged
The same is true in case of ADFS proxy server

One last thing, you need to change adfs proxy public IP binding to point it to VIP of NLB
0
 
LVL 41

Expert Comment

by:Amit
ID: 40605490
No need to build the ADFS servers.
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This is my first article on Expert Exchange on the Manual Method of Exporting Office 365 Mailboxes to PST format by using the eDiscovery mechanism of Office. Hope you will enjoy the article.
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

930 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now