Forefront Unified Access Gateway (UAG) online Help
Documentation Home
Welcome to Forefront UAG RC0
Getting Started
Release notes
Product Evaluation
Overview of Forefront UAG
What's new in Forefront UAG RC0
About Forefront TMG with Forefront UAG
Planning and Design
Infrastructure and installation design guide
About this design guide
Terminology
Identifying your deployment goals
Mapping your deployment goals to a design
Planning a design
Planning your network topology
Planning your domain requirements
Planning for remote access requirements
Planning for migration and installation
High availability and scalability design guide
About this design guide
Terminology
Understanding the design process
Identifying your deployment goals
Mapping your deployment goals to a design
Planning a design
Capacity planning
Planning an array
Planning for load balancing
Forefront UAG DirectAccess design guide
Forefront UAG DirectAccess introduction
Understanding the Forefront UAG DirectAccess design process
Identifying your Forefront UAG DirectAccess deployment goals
Mapping your deployment goals to a Forefront UAG DirectAccess design
Planning a Forefront UAG DirectAccess deployment strategy
Resources available to Forefront UAG DirectAccess clients
Choosing an access model
Choosing an Intranet IPv6 Connectivity Design
Choosing a solution for IPv4-only Intranet resources
Designing Active Directory for Forefront UAG DirectAccess
Designing a DNS infrastructure for Forefront UAG DirectAccess
Design Your PKI for DirectAccess
Remote access design guide
Introduction
Terminology
Identifying your deployment goals
Mapping your deployment goals to a design
Planning a design
Planning for DirectAccess
Planning for application publishing
About Forefront UAG trunks
Publishing applications
Publishing Web servers and farms
Planning for Remote Desktop Services (RDS) access
Planning for VPN (SSL network tunnelling) access
Planning for file access
Endpoint access and identity design guide
Introduction
Terminology
Identifying your deployment goals
Mapping your deployment goals to a design
Planning a design
Planning for client endpoint authentication
Planning for frontend authentication
Planning for backend authentication to published servers
Planning for federation with ADFS
Planning for endpoint health checking
Planning authorization for portal applications
Endpoint component deployment design guide
Introduction
About the Endpoint Session Cleanup component
About client endpoint policies
About SSL Tunneling
About the Socket Forwarding component
Identifying your deployment goals
Mapping your deployment goals to a design
Allowing remote client access
Deploying your endpoint components
Securing remote access
Deployment
Deployment checklist
System requirements in Forefront UAG
Installation and migration guide
About this guide
Overview of installation and migration
Planning to install or migrate
Implementing a migration
Migrating a single server
Preparing for server migration
Exporting server configuration settings
Installing a migrated server
Importing migrated server settings
Migrating an array
Preparing for array migration
Exporting array configuration settings
Installing a migrated array
Importing migrated array settings
Implementing an installation
Installation checklist
Installing Forefront UAG software
Running an unattended install
Verifying installation settings
Setting up networks and servers using the Getting Started Wizard
Setting up roles and permissions
Uninstalling Forefront UAG
High availablity and scalability deployment guide
About this guide
Overview
Planning to deploy arrays and load balancing
Implementing an array and load balancing design
Array and load balancing checklist
Configuring the array manager server
Joining a server to an array
Removing a server from an array
Designating an alternative array manager
Updating array manager settings for array members
Modifying credentials used by an array member
Modifying credentials used by the array manager
Configuring network load balancing
Managing network load balanced servers
Verifying the array and load balancing deployment
Forefront UAG DirectAccess deployment guide
About this guide
Overview of Forefront UAG DirectAccess
Planning to deploy Forefront UAG DirectAccess
Implementing Forefront UAG DirectAccess
Forefront UAG DirectAccess prerequisites
Configuring clients for Forefront UAG DirectAccess
Configuring the Forefront UAG DirectAccess server
Assigning IP addresses to the server interfaces
Configuring NAT64 and DNS64
Configuring IPv6 prefix addresses
Configuring authentication options
Identifying infrastructure servers
Specifying the network location server
Identifying DNS servers
Managing remote client computers
Identifying and configuring application servers
Applying the Forefront UAG DirectAccess configuration
Advanced configuration of Forefront UAG DirectAccess
Configuring a network load balanced array for Forefront UAG DirectAccess
Installing Forefront UAG DirectAccess
Remote access deployment guide
About this guide
Overview
Planning to deploy a remote access solution
Implementing a Web portal design
Portal deployment checklist
Setting up a portal
Publishing applications in a portal
Configuring portal settings
Configuring URLs and addresses
Assigning a portal home page
Configuring session limits and timeouts
Adding, removing, and sorting portal applications
Restricting portal applications to specific subnets
Modifying portal application port numbers
Setting portal application dependencies
Managing client endpoints during a session
Applying endpoint policies for a session
Authenticating portal sessions
Configuring a logoff scheme
Configuring traffic inspection during a session
Configuring URL inspection
Configuring URL inspection settings
Configuring global URL parameters
Configuring URL rules
Configuring URL rules when application URLs contain variables
Configuring HTTP filtering
Configuring HTTP compression
Managing internal links during a session
Configuring global HAT parameters
Skipping body parsing for HAT configuration
Configuring search and replace parsing for HAT
Manually replacing URLs for HAT
Configuring portal application settings
Configuring application names and prerequisites
Configuring server addresses and ports for published applications
Configuring content inspection for published applications
Configuring authentication to published servers
Configuring socket forwarding for published applications
Configuring HTTP request smuggling protection for published applications
Configuring cookie encryption for published applications
Restricting access to sections of published applications
Configuring authorization for applications published in a portal
Configuring client endpoint policies for published applications
Configuring download and upload policies for published applications
Configuring a link format for portal applications
Configuring Web client mail services
Duplicating portals
Duplicating portal applications
Redirecting HTTP requests to HTTPS portals
Implementing a directly published Web server design
Application deployment checklist
Setting up an application Web site
Configuring directly published applications
Configuring Web site settings
Configuring session limits and timeouts for directly published applications
Managing client endpoints during a session for directly published applications
Applying endpoint policies for a session
Authenticating application sessions
Configuring a logoff scheme
Applying server name translation to hide Web application servers
Redirecting authenticated requests to alternative servers
Redirecting HTTP requests to HTTPS
Configuring server addresses and ports
Configuring content inspection
Configuring URL inspection for directly published applications
Configuring URL inspection settings for directly published applications
Configuring global URL parameters for directly published applications
Configuring URL rules for directly published applications
Configuring URL rules when application URLs contain variables
Configuring HTTP filtering for directly published applications
Configuring HTTP compression for directly published applications
Configuring authentication
Restricting access to sections of a published application
Configuring client endpoint policies
Configuring download and upload policies
Implementing a VPN (SSL network tunneling) design
VPN (SSL network tunneling) deployment checklist
Configuring VPN client access using SSL network tunneling
Enabling SSL network tunneling
Specifying a maximum number of VPN client connections
Publishing a remote client VPN connection
Selecting a VPN protocol
Assigning IP addresses to VPN clients
Assigning VPN client access to users and groups
Configuring VPN client access using SSL Network Tunneling (Network Connector)
Configuring a VPN gateway (Network Connector)
Assigning IP addresses to VPN clients (Network Connector)
Configuring Internet access for VPN clients (Network Connector)
Adding networks for VPN client access (Network Connector)
Logging VPN client traffic (Network Connector)
Implementing a file access design
File access deployment checklist
Configuring access to mapped Windows shares
Configuring access to file servers
Configuring file access permissions and settings
Remote access solution guides
SharePoint extranet access with Forefront UAG
Introduction to SharePoint publishing
Why enable SharePoint extranet access with Forefront UAG?
SharePoint publishing topologies
Before you publish SharePoint applications
Publishing a SharePoint application
Publishing multiple SharePoint applications on unique ports
Publishing a SharePoint application with identical internal and public host addresses
Publishing multiple SharePoint applications on a single port
Verifying SharePoint publishing
Exchange services access with Forefront UAG
Introduction to Exchange services publishing
Why enable remote access to Exchange services with Forefront UAG?
Exchange services publishing deployment options
Steps for publishing Exchange services scenarios
Verifying Exchange services publishing
Dynamics CRM access with Forefront UAG
Why publish Dynamics CRM with Forefront UAG?
Publishing Dynamics CRM
Remote Desktop Services access with Forefront UAG
Introduction to Remote Desktop Services publishing
Why publish Remote Desktop Services with Forefront UAG?
Steps for publishing Remote Desktop Services
Publishing RemoteApp applications
Publishing Desktop Connections
Internal data center access with Forefront UAG
Why publish data center applications with Forefront UAG?
Publishing applications with Integrated Windows Authentication
Endpoint identity and access control deployment guide
About this guide
Overview
Planning to deploy endpoint identity and access control
Implementing an endpoint identity and access control design
Deploying a client authentication infrastructure
Deploying frontend authentication servers
Configuring LDAP authentication
Configuring RADIUS authentication
Configuring ACE authentication
Configuring TACACS authentication
Configuring WINHTTP authentication
Configuring NT Domain authentication
Configuring Active Directory authentication
Configuring Notes Directory authentication
Configuring Novell Directory authentication
Configuring custom authentication
Deploying backend authentication mechanisms
Deploying a single sign-on solution
Configuring single sign-on with Kerberos constrained delegation
Deploying federation
Deploying access policies for endpoint health validation
Deploying users and groups for portal application authorization
Endpoint component deployment guide
About this guide
Overview of the endpoint component deployment guide
Implementing an endpoint component deployment design
Preparing to deploy endpoint components online
Preparing to deploy endpoint components offline
Installing endpoint components using the Client Components Installer
Installing endpoint components using an installation file
Configuring client endpoints to trust Forefront UAG sites
Restoring endpoint components default settings
Preparing to uninstall endpoint components
Operations
Administering the Forefront UAG server
Modifying server and network settings
Backing up and restoring with export and import
Administering arrays
Administering portals and sites
Administering endpoint access
Monitoring and logging
Configuring event logging
Configuring log limits
Configuring logging
Logging SSL events
Customizing event messages
Disabling logging
Cleaning up log files
Logging to a SQL Server
Working with Web Monitor
Connecting to Web Monitor
Monitoring and managing array members
Monitoring endpoint sessions
Monitoring applications
Monitoring users
Querying events
Monitoring with System Center Operations Manager (SCOM)
Introduction
What's new
Supported configurations
Getting started with the Management Pack
Before you import the Management Pack
How to import the Management Pack
Create a new Management Pack for customizations
Understanding Management Pack operations
Objects the Management Pack discovers
Classes
How health rolls up
Viewing information in the Operations Manager monitoring pane
Key monitoring scenarios
Placing monitored objects in maintenance mode
Appendix: scripts
Optimizing Forefront UAG performance
Technical Reference
User interface help reference
Create Trunk Wizard Help
Add Application Wizard help
Server settings reference (non-Web applications)
Trunk properties help
Published application properties help
Predefined applications reference
Managing the All Domino® (Webmail 5.x/6.x/7.x and iNotes™) Interfaces application
Managing the Citrix NFuse® FR2 (Direct) application
Managing the Citrix NFuse FR2 via SecureGateway application
Managing the Citrix NFuse FR3 (Direct) application
Managing the Citrix NFuse FR3 via SecureGateway application
Managing the Citrix Presentation Server™ (Web Interface 3) application
Managing the Citrix® Secure Access Manager (Direct) application
Managing the Domino iNotes application
Managing the Domino iNotes (Multi Servers) application
Managing the Domino iNotes (Single Server) application
Managing the Domino Offline Services 7.0 (Single/Multi Servers) application
Managing the FTP (Passive Mode) application
Managing the Microsoft ActivSync application
Managing the Microsoft CRM 3.0 application
Managing the Microsoft Dynamics CRM 4.0 application
Managing the Microsoft Office Communicator Web Access application
Managing the Microsoft Outlook Mobile Access 2003 application
Managing the Microsoft Outlook Web Access 5.5 application
Managing the Microsoft Outlook Web Access 2003 SP1/SP2 application
Managing the Microsoft Outlook Web Access 2007 application
Managing the Native Notes® Client (Multi Servers) application
Managing the Native Notes Client (Single Server) application
Managing the Outlook (Corporate/Workgroup Mode) application
Managing the SAP® Enterprise Portal 6 application
Managing the Microsoft SharePoint® Portal Server 2003 application
Managing the Microsoft Office SharePoint Server 2007 application
Managing the Microsoft Office SharePoint Server 2007 (backward compatibility) application
Managing the Terminal Services Web Client (Multi Servers) application
Managing the Terminal Services Web Client (Single Server) application
Managing the WebSphere® Portal 5.02 application
Managing the Webtop® (Documentum) application
Events and errors reference
SQL Server logging fields
Documentation Home
Getting Started