Forefront UAG DirectAccess prerequisites for SP1
Published: October 21, 2010
Updated: February 1, 2011
Applies To: Unified Access Gateway
The following lists the prerequisites for deploying Forefront Unified Access Gateway (UAG) DirectAccess on single servers, and on multiple servers that use Forefront UAG DirectAccess integrated Network Load Balancing (NLB).
Prerequisites for deploying Forefront UAG DirectAccess SP1
| Prerequisite | Details | ||||
|---|---|---|---|---|---|
|
Infrastructure servers |
You must have at least one domain controller running Windows Server 2003 or later, and a Domain Name System (DNS) server that supports dynamic updates. You can use DNS servers that do not support dynamic updates, but entries must be manually updated. For more information, see Designing a DNS infrastructure for Forefront UAG DirectAccess. |
||||
|
Machine Certificates |
For more information, see Designing your PKI for Forefront UAG DirectAccess. |
||||
|
IP-HTTPS certificates |
You can use two types of IP-HTTPS certificates:
|
||||
|
Forefront UAG DirectAccess server |
The Forefront UAG DirectAccess server has the following requirements:
|
||||
|
Forefront UAG DirectAccess client |
A Forefront UAG DirectAccess client must be:
|
||||
|
Global or universal security groups or Organizational Units (OUs) for Forefront UAG DirectAccess clients |
You can also use existing global or universal groups. For more information, see Create a New Group (http://go.microsoft.com/fwlink/?LinkId=154396). |
||||
|
Network location server with an HTTPS based URL |
This should be on a server with high availability, and a valid SSL certificate trusted by the DirectAccess clients.
For more information, see Specifying the network location server. |
||||
|
Routing |
Configure routing as follows:
For more information, see Designing addressing and routing for the Forefront UAG DirectAccess server. |
||||
|
When using additional firewalls |
When using additional firewalls, apply the following Internet-facing firewall exceptions for Forefront UAG DirectAccess traffic when the Forefront UAG DirectAccess server is on the IPv4 Internet:
For more information, see Packet filtering for the Internet firewall. When using additional firewalls, apply the following Internet-facing firewall exceptions for Forefront UAG DirectAccess traffic when the Forefront UAG DirectAccess server is on the IPv6 Internet:
For more information, see Packet filtering for the Internet firewall. When using additional firewalls, apply the following internal network firewall exceptions for Forefront UAG DirectAccess traffic:
For more information, see Packet filtering for intranet firewalls. |
||||
|
Network interface settings for a single server Forefront UAG DirectAccess deployment. |
The following network interface settings are required for a single server Forefront UAG DirectAccess deployment:
|
||||
|
Network interface settings for network load balanced Forefront UAG DirectAccess server in an array. |
When configuring network interface settings, you must configure static virtual IP addresses (VIPs), and dedicated IP addresses (DIPs). A DIP is the existing per node unique IP address. The following network interface settings are required for a network load balanced Forefront UAG DirectAccess server in an array:
|
Further prerequisites for a Forefront UAG DirectAccess SP1 deployment are described in these topics:
-
Before configuring DirectAccess clients and GPOs in SP1
-
Before configuring the Forefront UAG DirectAccess server in SP1
-
Before configuring infrastructure servers in SP1
-
Before configuring extended authentication and encryption to application servers in SP1
-
Before configuring optional settings in SP1

Note:
Warning: