The following should be done before configuring the prerequisites for each Forefront UAG DirectAccess optional setting:
Optional setting | Before you run an optional setting configuration | ||
---|---|---|---|
Client Connectivity Assistant |
Prepare:
|
||
NAP Enforcement |
|
||
Two Factor Authentication
|
If you use two-factor authentication, a PKI smart card, RSA SecureID, or Radius infrastructure must be deployed. In addition when OTP is selected, ensure you do the following:
|
||
Internet Connectivity |
Decide whether to configure split tunneling or force tunneling. |
||
Server Groups |
Create organizational units (OUs) or security groups containing all the Forefront UAG DirectAccess servers. |
||
End-to-End Access |
The following should be prepared before configuring end-to-end access:
|
For planning information, see the following topics:
- Planning for client health verification in Forefront UAG
DirectAccess SP1
(http://go.microsoft.com/fwlink/?LinkId=205666)
- Planning for DirectAccess client Internet access in
Forefront UAG SP1
(http://go.microsoft.com/fwlink/?LinkID=205662)
- Planning for authentication in Forefront UAG DirectAccess
SP1 (http://go.microsoft.com/fwlink/?LinkId=205664)
- Planning Active Directory for Forefront UAG DirectAccess
SP1 (http://go.microsoft.com/fwlink/?LinkId=205663)
- Planning for DirectAccess client Internet access in
Forefront UAG SP1
(http://go.microsoft.com/fwlink/?LinkID=205662)