Search
F5 News - News straight from the heart of F5.
You are here: DevCentral > Weblogs

posted on Wednesday, December 23, 2009 6:09 AM

microsoft-logo Microsoft Forefront Unified Access Gateway (UAG) is the evolution of Microsoft’s Intelligent Application Gateway (IAG 2007). Forefront UAG is a secure remote access solution focusing on applying application intelligence and granular access control across applications to enable easy management of access to enterprise applications by mobile and remote employees and partners. Forefront UAG provides centralized management and policy control across all users, devices, and network resources. 

Scaling solutions such as Forefront UAG is often challenging because of the unique requirements raised by such solutions, such as routing server generated connections in situations where the client has a pre-established tunnel to the correct server. This type of persistence of connections requires that the infrastructure solutions used to scale and provide high-availability for Forefront UAG be application-aware and capable of inspecting messages exchanged between the client and Forefront UAG to ensure existing connections are directed to the appropriate server. Without this ability the connections could be directed to the wrong server, i.e. a server without knowledge of the existing connection, and the connection would be dropped.

howf5addresses

F5's BIG-IP Local Traffic Manager (LTM) can be used to provide scalability and high availability for Microsoft's Unified Access Gateway. When deployed on either side of the UAG servers, BIG-IP's load balancing capabilities can be leveraged to route both incoming and outgoing traffic through the most appropriate UAG server. BIG-IP LTM handles this traffic with its intelligent traffic engine, iRules, to track client-to-UAG server tunnels, and match server generated connections to the right UAG server.

It requires more than simple load balancing to properly scale and provide the high-availability necessary for Forefront UAG, including configurations to load balance both inbound and outbound connections. Such configurations can be complex, depending on the environment, and requires both network and application network layer skills. The need for persistence of server-generated connections requires a specific network-side scripting implementation, potentially extending the time to deployment.

To make the configuration of BIG-IP LTM simpler and easily reproduced, F5 has documented the process in a step-by-step deployment guide specifically for Forefront UAG. The deployment guide provides a complete methodology for configuring and deploying UAG in a highly-available, scalable environment, including leveraging IP-HTTPS for additional security.

The deployment guide is available now and can be downloaded here, through F5’s application-specific solution center.

Follow me on Twitter    friendfeed icon_facebook delicious_logo

Related resources:

 



Feedback

10/18/2011 12:06 AM
Gravatar This is a really good read for me. Must admit that you are one of the best bloggers I have ever read. Thanks for posting this informative article.
Google SEO

Let Me Know What You Think


Please use the form below if you have any comments, questions, or suggestions.

Title:
 
Name:
 
Email: (so we can show your gravatar)
Website:
Comment: Allowed tags: blockquote, a, strong, em, p, u, strike, super, sub, code
 
Please add 6 and 5 and type the answer here:

Blog Stats

Posts:244
Comments:1037
Stories:0
Trackbacks:0
  

82,243 Members in 102 Countries and Growing!

Join DevCentral Today!

About DevCentral

DevCentral has been a successful, thriving community for many years. We have always strived to bring you the best technical documentation, discussion forums, blogs, media and much more that we can.

So dive in, get familiar with DevCentral. We hope you like it, we hope it makes your job easier, and lets you get that much more power out of the community. To learn more, make sure to check out the Getting Started section. And if you have any problems, or think something could be easier to use, drop us a line to let us know.

Got It !

We've received your comment and transmitted it directly to DevCentral HQ.

Thanks for taking time to let us know what's on your mind. At DevCentral | Community Matters!

Get In Touch With Us

Have questions, suggestions or just want to get something off your chest?

Use our handy form below to Direct Connect with DevCentral Mission Control.

Send Us Feedback       or