After you have identified your infrastructure design requirements for each stage of the Forefront Unified Access Gateway (UAG) deployment, you must evaluate your specific deployment goals, and clearly pinpoint infrastructure modifications that are required to meet each goal. Depending on the size of your organization, this might involve multiple IT staff, in addition to the Forefront UAG administrator. Use this guide to help each person involved to identify the shifts that are required in the existing infrastructure, in order to deploy Forefront UAG successfully.
For information on identifying your infrastructure design requirements, see Identifying your infrastructure design requirements.
The following table summarizes the possible deployment goals and provides an overview of the infrastructure modifications required for each goal.
Deployment goal | Infrastructure modifications |
---|---|
Deploy a single Forefront UAG server |
This goal requires you to deploy and install a single Forefront UAG server in your existing network infrastructure. Infrastructure design modifications include:
|
Deploy multiple Forefront UAG servers |
This goal requires you to deploy and install multiple Forefront UAG servers in your existing network infrastructure. Infrastructure design modifications include:
|
Deploy a single Forefront UAG DirectAccess server |
This goal requires you to deploy and install a single Forefront UAG server in your existing network infrastructure, and configure the Forefront UAG server as a DirectAccess server. Infrastructure design modifications include:
|
Deploy multiple Forefront UAG DirectAccess servers |
This goal requires you to deploy and install multiple Forefront UAG servers in your existing network infrastructure, and configure the Forefront UAG server as a DirectAccess server. Infrastructure design modifications include:
|
Deploy Forefront UAG Forefront UAG endpoints |
This goal includes allowing remote endpoints to access corporate applications and resources via Forefront UAG. You can install Forefront UAG endpoint components online when clients connect to a trunk, or offline using the Forefront UAG Client Components installer or an installation file. Infrastructure design modifications include:
|
Authenticate clients for access to Forefront UAG portals and published applications |
This goal requires you to configure front end authentication to verify the credentials of clients connecting to Forefront UAG portal and site sessions. If the backend published servers require authentication, it also requires you to set up authentication mechanisms for verifying client credentials on backend servers. In addition, Forefront UAG supports single sign-on, allowing you to pass credentials supplied during session sign-on to backend servers, thus requiring clients to sign on only once. The following infrastructure design modifications are required:
|
Verify the health of endpoints connecting to Forefront UAG |
Forefront UAG can verify the health of endpoints against inbuilt Forefront UAG access policies, or against Network Access Protection policies downloaded from a Network Policy Server (NPS). In addition to access policies, you can also implement granular authorization policies applications and resources published in a portal, by allowing only authorized users and groups to access specific portal applications. The following infrastructure design modifications are required:
|
Limit application access to specific users and groups |
This goal requires you to configure portal authorization to control access to portal applications. The following infrastructure design modifications are required:
|
Differentiate between different types of endpoints, and define some endpoints as privileged |
This goal requires to configure endpoints as certified, and assign them a more permissive access policy. The following infrastructure design modifications are required:
|
Publish internal applications and resources via Forefront UAG |
This goal requires you to set up Forefront UAG trunks. Using trunks, you can create a Forefront UAG portal or a Web site for accessing a single Web application. After creating a portal trunk, you add applications and resources to it, in order to publish them via the trunk. Infrastructure design modifications include:
|
Log Forefront UAG information |
There are a number of logging options that include the following infrastructure modification:
|
Monitor Forefront UAG activity |
If you have Microsoft System Center Operations Manager 2007 deployed in your organization, configure the Forefront UAG management pack. |