Click to Rate and Give Feedback
TechNet
TechNet Library
Microsoft Forefront
Deployment
 Publishing applications to users lo...
Collapse All/Expand All Collapse All
Whale Communications Intelligent Application Gateway (IAG) 2007
Publishing applications to users located on corporate networks with IAG SP2

You can publish applications to users that are located on your corporate network with Intelligent Application Gateway (IAG) 2007 Service Pack 2 (SP2) by configuring Integrated Windows authentication on a trunk.

Dd278028.note(en-us,TechNet.10).gifNote:
Before you start the configuration process, be sure to read the requirements and limitations that are described in About publishing applications to users located on corporate networks with IAG SP2.
To configure a trunk with Integrate Windows authentication
  1. Create a new trunk as described in the procedure in Publishing applications in an IAG portal or Publishing a single Web application directly with IAG or select an existing trunk.

    Dd278028.note(en-us,TechNet.10).gifNote:
    You can only use Integrated Windows authentication with portal and basic trunks; you cannot use it with Web mail trunks.
    Dd278028.note(en-us,TechNet.10).gifNote:
    The authentication server that you select during trunk configuration must be an Active Directory authentication server that points to the Active Directory forest to which IAG belongs.
  2. On the Configuration console, in the navigation tree, click the trunk that you created or selected in step 1 of this procedure, and then, next to Advanced Trunk Configuration, click the Configure button.

  3. On the Advanced Trunk Configuration dialog box, click the Authentication tab. In the Authenticate user on session login group box, click Use Integrated Windows authentication. You must select at least one of the following:

    • Enable NTLM protocol
    • Enable Kerberos protocol
  4. On the Configuration console, on the toolbar, click the Activate Configuration icon, and then on the Activate Configuration dialog box, click Activate.

    When the configuration is activated, the message "IAG configuration activated successfully" appears.

When working with Integrated Windows authentication, there are two options for authenticating to application servers for single sign-on:

  • Kerberos constrained delegation
  • Authentication pass-through

Using Integrated Windows authentication with Kerberos constrained delegation

When IAG uses Integrated Windows authentication to authenticate users, it does not have the user's password. Given this limitation, it is recommended to use Kerberos constrained delegation to seamlessly authenticate to the application servers. For more information, see Configuring Kerberos constrained delegation with IAG SP2.

Using Integrated Windows authentication with authentication pass-through

Dd278028.note(en-us,TechNet.10).gifNote:
If you want to use NTLM to authenticate to application servers, then you must make sure that the authentication to the trunk is done with NTLM.
To configure authentication pass-through
Dd278028.note(en-us,TechNet.10).gifNote:
Do not select Automatically reply to application-specific authentication requests.

In HTTPS trunks, IAG manipulates the application request of the application server. As a result, the user is presented with a credentials prompt. In order to eliminate the credentials prompt, perform the following procedure.

To eliminate the credentials prompt
  1. On the IAG computer, click Start, and then click Run.

  2. Type the following, and then press ENTER:

    regedit

  3. In the Registry Editor, open the following file:

    HKEY_LOCAL_MACHINE\SOFTWARE\WhaleCom\e-Gap\von\UrlFilter\

  4. Right-click on the window, click New, and then click DWORD VALUE. Name the registry value as follows:

    FullAuthPassthru

  5. Right-click FullAuthPassthru, and then click Modify. In the Value data box, type 1, and then click OK.

  6. On the IAG computer, at a command prompt, type iisreset, and then press ENTER.

    All existing IIS connections are reset.

If the application server does not use the same authentication server as the trunk, follow the standard configuration procedure (for more information, see Preparing for authentication to application servers in IAG). The user will need to provide credentials through a form login when accessing the application for the first time.

© 2010 Microsoft Corporation. All rights reserved. Terms of Use | Trademarks | Privacy Statement
Page view tracker