Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the...

35
Forefront UAG mit DirectAccess CA installieren oder existierende verwenden

Transcript of Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the...

Page 1: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

Forefront UAG mit DirectAccess CA installieren oder existierende verwenden

Page 2: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,
Page 3: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

UAG Setup

Page 4: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,
Page 5: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

NIS und Malware Update aktiviert

WFP Filter Konflikt Meldung kann ignoriert werden http://blogs.technet.com/yuridiogenes/archive/2010/02/16/wfp-filter-conflict-detected-alert-after-installing-forefront-tmg-2010.aspx

Page 6: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

UAG Update 1 installieren

Fehlermeldung bei der Installation

Page 7: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

Besitz uebernehmen fuer den SYSTEM Account

Page 8: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

Report Server Konfiguration

Page 9: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

Grundkonfig

Page 10: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,
Page 11: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

Single Server

Page 12: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,
Page 13: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,
Page 14: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

Event Logging zum Exchange Server

Konfig speichern und aktivieren

Page 15: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

Zertifikate http://technet.microsoft.com/en-us/library/ee406213.aspx Autoenrollment fuer Computer Zertifikate

Page 16: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

IP-HTTPS Zertifikat The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field, either an Internet Protocol version 4 (IPv4) address of the Internet interface of the DirectAccess server or the fully qualified domain name (FQDN) of the IP-HTTPS uniform resource locator (URL). For the Enhanced Key Usage field, the Server Authentication object identifier (OID). For the CRL Distribution Points field, a certificate revocation list (CRL) distribution point that is accessible by DirectAccess clients that are connected to the Internet. The IP-HTTPS certificate must have a private key. The IP-HTTPS certificate must be imported directly into the personal store. Zertifikate auf dem UAG Server anfordern http://blogs.technet.com/edgeaccessblog/archive/2010/04/22/deep-dive-into-uag-directaccess-certificate-enrollment.aspx

Page 17: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

Template Berechtigungen

Firewallregel auf TMG Server fuer RPC Zertifikatanforderung

Page 18: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

Strict RPC Checking ausschalten

Neues Zertifikat am UAG Server fuer DirectAccess anfordern

Page 19: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

Common Name und SAN angeben

Page 20: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

Private Key Exportable

Page 21: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

Eigenschaften

Page 22: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

ISATAP Host Eintrag erstellen

ISATAP aus der DNS GlobalQueryBlocklist entfernen

Page 23: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

DirectAccess einrichten AD Gruppe fuer den DA Zugriff angeben

Interne IP v4 Adresse angeben und erste oeffentliche Ipv4 IP

Page 24: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

Root CA Certificate angeben Das IP-HTTPS Zertifikat angeben. Ein Computerzertifikat muss ebenfalls vorhanden sein und auf den CN des internen FQDN des DA Server ausgestellt sein

Page 25: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

FQDN des internen NLS Server angeben

Interne DNS Namensraeume angeben

Page 26: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

Infrastruktur Server Zusammenfassung

End to Egde Aut. Und Verschluesselung

Page 27: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

Zusammenfassung der Konfiguration

Policy wird erstellt

Page 28: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

Powershell Skript

Konfiguration aktivieren

Page 29: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

Sperrlisten Verteilungspunkt und AIA Verteilungspunkt Publishing entfernen

Page 30: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

IP Konfiguration pruefen

Page 31: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

DNS Eintraege pruefen

Group Polices

Page 32: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

Client Computer Zertifikat anfordern

Page 33: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

Ausgestellt auf den internen FQDN

HOSTS Datei fuer Demoumgebung auf dem Windows 7 Ultimate oder EE Client patchen

Test

Page 34: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

Success

NRPT pruefen

Win7 Client DNS Konfig

Page 35: Forefront UAG mit DirectAccess CA installieren oder ... · The IP-HTTPS certificate for the Forefront UAG DirectAccess server must have the following properties: In the Subject field,

Logging auf TMG Seite beim Client Verbindungsaufbau