Microsoft Forefront Security Forums | ForefrontSecurity.ORG Knowledge Center | Online Platform | Forums | Community
Go back to www.ForefrontSecurity.ORG     ForefrontSecurity.org on LinkedIn
Welcome Guest Search | Active Topics | Log In | Register

Big-IP and ADFS – Load balancing the ADFS Farm
Idan Plotnik
#1 Posted : Sunday, April 15, 2012 2:03:52 PM(UTC)
Rank: Administration

Groups: Registered, Administrators

Joined: 10/22/2008(UTC)
Posts: 779
Points: 2,351
Location: Israel
FYI ...
https://devcentral.f5.com/weblogs/gcoward/archive/2012/02/24/big-ip-and-adfs-part-1-ndash-ldquoload-balancing-the-adfs.aspx
Just like the early settlers who migrated en masse across the country by wagon train along the Oregon Trail, enterprises are migrating up into the cloud. Well okay, maybe not exactly like the early settlers. But, although there may not be a mass migration to the cloud, it is true that more and more enterprises are moving to cloud-based services like Office 365.
So how do you provide seamless, or at least relatively seamless, access to resources outside of the enterprise? Well, one answer is federation and if you are a Microsoft shop then the current solution is ADFS, (Active Directory Federation Services). The ADFS server role is a security token service that extends the single sign-on, (SSO) experience for directory-authenticated clients to resources outside of the organization’s boundaries. As cloud-based application access and federation in general becomes more prevalent, the role of ADFS has become equally important. Below, is a typical deployment scenario of the ADFS Server farm and the ADFS Proxy server farm, (recommended for external access to the internally hosted ADFS farm).
Warning…If the ADFS server farm is unavailable then access to federated resources will be limited if not completely inaccessible. To ensure high-availability, performance, and scalability the F5 Big-IP with LTM, (Local Traffic Manager), can be deployed to load balance the ADFS and ADFS Proxy server farms. Yes! When it comes to a load balancing and application delivery, F5’s Big-IP is an excellent choice. Just had to get that out there.
So let’s get technical! Part one of this blog series addresses deploying and configuring the Big-IP’s LTM module for load balancing the ADFS Server farm and Proxy server farm. In part two I’m going to show how we can greatly simplify and improve this deployment by utilizing Big-IP’s APM, (Access Policy Manager) so stay tuned.
Idan Plotnik
Identity and Security Engineer
Forefront MVP

עידן פלוטניק
יועץ זהויות ואבטחת מידע
Sponsor  
 
Users browsing this topic
Guest
Forum Jump  
You cannot post new topics in this forum.
You cannot reply to topics in this forum.
You cannot delete your posts in this forum.
You cannot edit your posts in this forum.
You cannot create polls in this forum.
You cannot vote in polls in this forum.

ForefrontSecurity.ORG Design Team
Powered by YAF | YAF © 2003-2010, Yet Another Forum.NET
This page was generated in 0.087 seconds.