Planning the Network for AD FS

Other than standard TCP/IP connectivity, network requirements for AD FS consist of DNS entries that must be configured to direct traffic to the AD FS systems, and firewall ports that need to be opened. Following are the specific DNS requirements for AD FS:

• For internal connectivity to AD FS, a single host record can be added to the internal DNS zone, mapping the fully qualified name of the federation service to either the IP address of the federation server (for single-server installations) or the virtual IP address of the load-balancing cluster (for multiple-server installations).

• For external connectivity to AD FS, a single host record can be added to the external DNS zone, mapping the fully qualified name of the federation service to either the public IP address assigned to the federation server proxy (for single-server federation proxy installations) or the public virtual IP address of the load-balancing cluster (for multiple-server federation proxy installations).

• If the federation server proxy systems in the DMZ are configured to connect to internal DNS servers for DNS resolution, no additional DNS configuration is required to enable the proxy systems to connect to the internal federation servers. However, for security purposes the DMZ servers might not be configured to connect to internal systems for DNS resolution. If there are DNS servers hosted in the DMZ segment for this purpose, a single host record can be added to the DNS zone on the DNS DMZ servers, mapping the fully qualified name of the federation service to either the IP address of the federation server (for single-server installations) or the virtual IP address of the load-balancing cluster (for multiple-server installations). As an alternative, the HOSTS file can instead be edited on each of the federation proxy servers to include the required mapping.


Tip

If a Lync hybrid deployment is planned, additional DNS records will be required to support AD FS with the hybrid configuration. For details, see the “Planning for a Hybrid Deployment” section of this chapter.


Firewall ports that need to be opened for AD FS connectivity include the following:

• For external connectivity to the federation server proxy systems in the DMZ, TCP port 443 needs to be opened inbound.

• For connectivity between the federation server proxies in the DMZ and the internal federation servers, TCP ports 80 and 443 need to be opened between the systems in both directions.

• For connectivity between the internal federation service and Office 365, TCP port 443 needs to be opened outbound.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset