1. Trang chủ
  2. » Công Nghệ Thông Tin

Tài liệu Module 5: Configuring Access to Internal Resources potx

36 456 0

Đang tải... (xem toàn văn)

Tài liệu hạn chế xem trước, để xem đầy đủ mời bạn chọn Tải xuống

THÔNG TIN TÀI LIỆU

Thông tin cơ bản

Tiêu đề Configuring Access to Internal Resources
Chuyên ngành Networking and Security
Thể loại lecture notes
Định dạng
Số trang 36
Dung lượng 2,8 MB

Các công cụ chuyển đổi và chỉnh sửa cho tài liệu này

Nội dung

What Are Web Publishing Rules?Web publishing rules provide the following features: Secure Web publishing rules enable the use of SSL to encrypt network traffic between client and server

Trang 1

Module 5:

Configuring Access

to Internal Resources

Trang 2

Introduction to Publishing

Configuring Web Publishing

Configuring Secure Web Publishing Configuring Server Publishing

Configuring ISA Server Authentication

Trang 3

Lesson: Introduction to Publishing

Multimedia: Using ISA Server 2004 to Enable Access

to Internal Network Resources

What Are Web Publishing Rules?

What Are Server Publishing Rules?

DNS Configuration for Web and Server Publishing

Trang 4

Multimedia: Using ISA Server 2004 to Enable Access to Internal Network Resources

Trang 5

What Are Web Publishing Rules?

Web publishing rules provide the following features:

Secure Web publishing rules enable the use of SSL to encrypt network traffic between client and server

Web publishing rules provide the following features:

Secure Web publishing rules enable the use of SSL to encrypt network traffic between client and server

Logging client IP address

Content caching Publish multiple Web sites with one IP address Link translation

Logging client IP address

ISA Server

Trang 6

What Are Server Publishing Rules?

Server publishing rules provide the following features:

Server publishing rules forward requests to internal servers based on protocol and port number

Server publishing rules provide the following features:

Server publishing rules forward requests to internal servers based on protocol and port number

Publish content using

multiple protocols

Application layer filtering

for protocols with

application filters

Publish content using

multiple protocols

Application layer filtering

for protocols with

Trang 7

DNS Configuration for Web and Server Publishing

ISA Server ISA

Server

3 4

www.cohovineyard.com

2

Trang 9

Lesson: Configuring Web Publishing

Web Publishing Rules Configuration Components How to Configure Path Mapping

How to Configure Web Listeners

How to Configure Link Translation

How to Configure a New Web Publishing Rule

Trang 10

Web Publishing Rules Configuration Components

Web publishing rules configuration:

Trang 11

Sales Human Resources

Online Store

How to Configure Path Mapping

http://www.cohovineyard.com/hr Virtual Directories

http://www.cohovineyard.com/shop

ISA Server ISA

Server

Trang 12

How to Configure Web Listeners

http://www.cohovineyard.com

Private Web Site

CohoVineyard Web Site

http://private.cohovineyard.com Anonymous Web listener

Authenticated Web listener

ISA Server ISA

Server

Trang 13

How to Configure Link Translation

http://www.cohovineyard.com

Translate Links

ISA Server ISA

Server

Links

Trang 14

How to Configure a New Web Publishing Rule

Web Publishing Rule Wizard configuration:

Trang 15

Practice: Configuring Web Publishing

Configuring a New Web Listener Configuring a New Web Publishing Rule Testing the Web Publishing Rule

Trang 16

Lesson: Configuring Secure Web Publishing

What Is Secure Sockets Layer?

How to Prepare ISA Server for SSL

How SSL Bridging Works

How SSL Tunneling Works

How to Configure a New Secure Web Publishing Rule

Trang 17

What Is Secure Sockets Layer?

Web Server Web

Server

Server Authentication Client Authentication

Encrypted SSL Connection

Encrypted SSL Connection

Trang 18

Den-Web-01.cohovineyard.comHow to Prepare ISA Server for SSL

ISA Server ISA

Server www.cohovineyard.com

Trang 19

How SSL Bridging Works

ISA Server ISA

Server

Trang 20

How SSL Tunneling Works

ISA Server ISA

Server

Trang 21

How to Configure a New Secure Web Publishing Rule

SSL Web Publishing Rule Wizard configuration:

Trang 22

Practice: Configuring Secure Web Publishing

Enabling Access to the Certificate Authority Web Site

Installing a Server Certificate Configuring a New Secure Web Publishing Rule

Testing the Secure Web Publishing Rule

Trang 23

Lesson: Configuring Server Publishing

Server Publishing Configuration Options

How Server Publishing Works

How to Configure a Server Publishing Rule

How to Publish Media Services

How to Publish Microsoft SharePoint Portal Server How to Troubleshoot Web and Server Publishing

Trang 24

Server Publishing Configuration Options

Server publishing rules configuration:

Trang 25

CohoVineyard FTP Site

CohoVineyard Media Site

How Server Publishing Works

ftp://ftp.cohovineyard.com Media Publishing Rule: Port 1755

FTP Publishing Rule: Port 21

ISA Server ISA

Server

Trang 26

How to Configure a Server Publishing Rule

Server Publishing Rule Wizard configuration:

Trang 27

Practice: Configuring Server Publishing

Configuring a New Server Publishing Rule Testing the Server Publishing Rule

Trang 28

How to Publish Media Services

ISA Server includes protocol definitions and application filters for:

ISA Server includes protocol definitions and application filters for:

Microsoft Media Streaming protocol (MMS)

 Uses either TCP port 80 or TCP and UDP port 1755

Enables access for Windows Media Player client

Progressive Networks protocol (PNM)

 Also called RealNetworks Streaming Media protocol

 Uses TCP port 7070

 Enables access for RealPlayer 5.0 and earlier clients

Real Time Streaming Protocol (RTSP)

 Uses port 554 for fast access and port 80 for slower access

 Enables access to media created and read with RealSystem G2 tools

Microsoft Media Streaming protocol (MMS)

 Uses either TCP port 80 or TCP and UDP port 1755

Enables access for Windows Media Player client

Progressive Networks protocol (PNM)

 Also called RealNetworks Streaming Media protocol

 Uses TCP port 7070

 Enables access for RealPlayer 5.0 and earlier clients

Real Time Streaming Protocol (RTSP)

 Uses port 554 for fast access and port 80 for slower access

 Enables access to media created and read with RealSystem G2 tools

Trang 29

How to Publish Microsoft SharePoint Portal Server

ISA Server can securely publish this information to

the Internet using:

ISA Server can securely publish this information to

the Internet using:

Web publishing to publish the HTTP and HTTPS content

using path mapping and link translation to hide the

complexity of the internal network configuration

Flexible authentication to grant only the required level of

Web publishing to publish the HTTP and HTTPS content

using path mapping and link translation to hide the

complexity of the internal network configuration

Flexible authentication to grant only the required level of

A portal can present different types of information

stored on different servers on the internal network

Trang 30

How to Troubleshoot Web and Server Publishing

To troubleshoot Web and server publishing issues:

Check the resource availability

Check the DNS records

Check the error message

Check which ports the ISA Server is listening on

for connections

Check the publishing rule configuration

Check the SSL configuration and certificates

Check the resource availability

Check the DNS records

Check the error message

Check which ports the ISA Server is listening on

for connections

Check the publishing rule configuration

Check the SSL configuration and certificates

Trang 31

Lesson: Configuring ISA Server Authentication

How Authentication and Web Publishing Rules Work

ISA Server Web Publishing Authentication Scenarios

Using RADIUS for Authentication

How to Implement RADIUS Server for ISA Authentication

Trang 32

How Authentication and Web Publishing Rules Work Together

ISA Server uses authentication to grant access to

publishing rules:

ISA Server uses authentication to grant access to

publishing rules:

When the publishing rule specifies a user set other

than the All Users group

Based on the Web listener authentication methods

specified for a Web publishing or secure Web

publishing rule

By processing the firewall rules in order of priority

When a firewall rule matches, but requires

authentication, ISA Server will prompt for

user credentials

When the publishing rule specifies a user set other

than the All Users group

Based on the Web listener authentication methods

specified for a Web publishing or secure Web

publishing rule

By processing the firewall rules in order of priority

When a firewall rule matches, but requires

authentication, ISA Server will prompt for

user credentials

Trang 33

ISA Server Web Publishing Authentication Scenarios

ISA Server and Web server

authentication

ISA Server and Web server

authentication

ISA Server authentication ISA Server

authentication

Web Server authentication Web Server

authentication

ISA Server ISA

Server

Trang 34

Using RADIUS for Authentication

Using RADIUS for authentication means that ISA Server can authenticate users based on their Active Directory credentials without requiring that the computer running ISA Server be a

member of an Active Directory domain

Using RADIUS for authentication means that ISA Server can authenticate users based on their Active Directory credentials without requiring that the computer running ISA Server be a

member of an Active Directory domain

RADIUS Client RADIUS Server

Domain

Controller

ISA Server ISA

Server

Trang 35

To implement RADIUS authentication:

Configure ISA Server to use the RADIUS server and configure a Web listener to use RADIUS authentication

Configure ISA Server to use the RADIUS server and configure a Web listener to use RADIUS authentication

3

Configure the Active Directory user accounts or configure remote access policies to enable dial-in access

Configure the Active Directory user accounts or configure remote access policies to enable dial-in access

Trang 36

Lab: Configuring Access to Internal Resources

Exercise 1: Configuring ISA Server Authentication and Secure Publishing Exercise 2: Testing the ISA

Ngày đăng: 27/02/2014, 05:20