16.01.2013 Views

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

676 Part VIII: Securing SharePoint <strong>Products</strong> <strong>and</strong> <strong>Technologies</strong><br />

Assumptions<br />

Note You can also publish a SharePoint site using the server publishing<br />

rules on ISA Server 2000. However, Web publishing has many advantages<br />

over server publishing. Server publishing bypasses the proxy service <strong>and</strong><br />

therefore cannot use advanced publishing filters such as SSL bridging, link<br />

translation, <strong>and</strong> basic authentication delegation. We will look into limited<br />

scenarios where you might need to consider using server publishing later in<br />

this chapter.<br />

There are several assumptions that we will make before looking into the ISA server<br />

configuration. We assume you have successfully completed several steps that need<br />

to be performed when you deploy a portal site across the extranet or as an Internet<br />

site.<br />

The steps to be completed are as follows:<br />

■ Extend the portal site into a new website. An additional optional step is to use<br />

a separate application pool to isolate worker processes. You can then either<br />

create a new portal site in the new site or map an existing portal site to the new<br />

site.<br />

■ On the server running SharePoint Portal Server, configure the new site to use<br />

the Basic Authentication method in IIS, <strong>and</strong> remove Integrated Windows<br />

Authentication. This is necessary because if an external user authenticates to a<br />

SharePoint site using Basic authentication, <strong>and</strong> the site is configured to use<br />

both Basic <strong>and</strong> Integrated Windows authentication, the user will not be able to<br />

view search results when he uses a search query on the site. However, if the<br />

site is configured to use only Basic authentication, the user will be able to view<br />

the results of a search.<br />

■ You might need to configure split DNS so that different fully qualified domain<br />

names (FQDNs) are used for accessing the portal externally <strong>and</strong> internally.<br />

Assuming that these steps have already been performed, the sample settings<br />

for the portal site that are used for examples in this chapter are summarized in<br />

Table 25-1.<br />

Table 25-1 Sample Settings for the Portal Site<br />

Parameter Value<br />

External fully qualified domain name (FQDN) external.contoso.com<br />

External IP address 207.46.245.214

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!