Pre-Authentication

Pre-authentication is a feature that lets the reverse proxy authenticate a user before completing the SSL bridge back to an internal server. This way, unauthenticated traffic is not allowed to communicate with internal services, which makes the deployment more secure. Without pre-authentication, the SSL traffic is authenticated by the internal pool server. It is still inspected and filtered for malicious code by the reverse proxy, but pass-through authentication requires the internal servers to handle authentication of the requests.

Not all features of Lync Server support pre-authentication, and whether pre-authentication can be leveraged depends greatly on business requirements.

Specifically, if anonymous remote access is required for web conferences or dial-in conferencing, there must still be some form of anonymous access allowed through the reverse proxy without authentication. In those situations, rules at the reverse proxy must be configured to only pre-authenticate traffic destined for specific virtual directories or FQDNs.

Pre-authentication of traffic can add quite a bit of complexity to an environment, so an early step in troubleshooting issues should be to disable this feature if it’s enabled.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset