16.01.2013 Views

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 25: Firewall Considerations for SharePoint Portal Server Deployments 689<br />

1. In the ISA Management console, click Servers <strong>and</strong> Arrays, click your server<br />

name, click Publishing, <strong>and</strong> then click Web Publishing Rules.<br />

2. Right-click the Web publishing rule you would like to configure, select Properties,<br />

<strong>and</strong> then click the Action tab.<br />

3. On the Action tab, select the Allow delegation of basic authentication credentials<br />

check box. This check box is available only with Feature Pack 1.<br />

Click OK.<br />

More Info For additional information on the ISA Server 2000 Basic<br />

authentication credentials delegation, refer to the Feature Pack 1 product<br />

documentation.<br />

ISA Server 2000 Server Publishing<br />

In general, it is not recommended to use ISA Server 2000 Server publishing for HTTP<br />

servers. Server publishing is used for other protocols such as File Transfer Protocol<br />

(FTP), <strong>and</strong> other servers such as SQL Server. When Server publishing rules are used<br />

instead of Web publishing rules, the ISA Server firewall does not examine HTTP traffic<br />

before forwarding it to the internal SharePoint Portal Server. To examine the<br />

HTTP traffic, ISA Server uses Web application filters that require the Web proxy service.<br />

However, the Web proxy service is bypassed by ISA Server 2000 Server publishing.<br />

With Server publishing, SSL-encrypted HTTP traffic is forwarded to the<br />

internal server without being inspected first by the firewall. Server publishing does<br />

not support link translation <strong>and</strong> Basic credentials authentication. With Server publishing,<br />

the requests are never serviced from the ISA Server cache. Basically, Server<br />

publishing provides packet filtering <strong>and</strong> secure NAT.<br />

There are a limited number of scenarios in which you might need to consider<br />

using Server publishing to make a portal site available externally. Sometimes,<br />

administrators use Server publishing instead of Web publishing to be able see the<br />

actual source IP address in the IIS logs on the computer running SharePoint Portal<br />

Server. When you publish a Web server using a Web publishing rule, the source IP<br />

address that appears in your Web server log files is the internal address of the computer<br />

running ISA Server. When you use a Server publishing rule, the actual source<br />

IP address of the request is shown in the IIS logs.<br />

In other scenarios, Server publishing is used in combination with Web publishing.<br />

For example, consider a scenario in which you have a single ISA Server 2000<br />

server that is used to provide access to two portal sites, as shown in Figure 25-4.<br />

One site is an extranet site where Basic authentication is required. This site is protected<br />

by SSL, <strong>and</strong> Basic authentication delegation is configured on the ISA server.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!