?
Solved

ADFS Resiliency NLB question

Posted on 2015-02-11
3
Medium Priority
?
206 Views
Last Modified: 2015-02-27
Hi

I have an ADFS and ADFS Proxy servers already configured an working as part of an Office 365 setup. I now need to introduce resiliency in the form of an additional ADFS server and an additional ADFS proxy server. Windows NLB is our preferred  method. According to this thread, NLB has to be installed before teh ADFS farm:

https://social.technet.microsoft.com/Forums/windowsserver/en-US/3e6e8524-53aa-4524-972a-1e4df87efd74/sequence-to-setup-adfs-farm-and-nlb-windows-2008-r2?forum=winserverClustering

Is this definitely correct? I.e. is there any other way of adding NLB resiliency without having to re-build the existing ADFS  and ADS proxy servers?

Thanks

m
0
Comment
Question by:mk112233
3 Comments
 
LVL 22

Assisted Solution

by:Matt V
Matt V earned 750 total points
ID: 40604732
Having just built that exact setup, I believe the article is correct.  Because you bind the ADFS service you would need the NLB interface available when you do the ADFS setup.
0
 
LVL 38

Accepted Solution

by:
Mahesh earned 750 total points
ID: 40605209
May be as per article NLB should be setup 1st, but I don't think so

Then what about scenarios where only 1 server is available for initial setup and later you would add another server in farm?

According to my understanding NLB has no direct connection to ADFS, what I mean NLB virtual URL can be used as ADFS URL
There is restrictions on ADFS setup that once you setup ADFS, you cannot change Federation service URL name, if you try to do so, it will break ADFS functionality
If your federation service name is same as server FQDN, then you cannot install NLB because NLB need separate virtual name associated with VIP

I hope in your case ADFS url is different than actual server FQDN and its currently pointing to server actual IP
If above is true, you can go ahead and setup NLB, NLB will require new internal IP as VIP and you should provide ADFS service URL to this VIP in DNS, so this will allow ADFS requests to listen on that specific IP
Ultimately what you are doing is just making some IP changes in DNS and ADFS service URL remains unchanged
The same is true in case of ADFS proxy server

One last thing, you need to change adfs proxy public IP binding to point it to VIP of NLB
0
 
LVL 44

Expert Comment

by:Amit
ID: 40605490
No need to build the ADFS servers.
0

Featured Post

Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Microsoft has changed the look and feel of Azure AD and Microsoft account sign-in pages so that you will have a more unified look and feel when moving between the two interfaces.
This article will show you step-by-step instructions to build your own NTP CentOS server.  The network diagram shows the best practice to setup the NTP server farm for redundancy.  This article also serves as your NTP server documentation.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Have you created a query with information for a calendar? ... and then, abra-cadabra, the calendar is done?! I am going to show you how to make that happen. Visualize your data!  ... really see it To use the code to create a calendar from a q…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question