16.01.2013 Views

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

690 Part VIII: Securing SharePoint <strong>Products</strong> <strong>and</strong> <strong>Technologies</strong><br />

Another site is an Internet site that does not require authentication <strong>and</strong> is open to<br />

the general public.<br />

External<br />

User<br />

HTTPS<br />

HTTP<br />

HTTP<br />

ISA Server 2000<br />

HTTPS<br />

Extranet Site<br />

Public Site<br />

User<br />

Public Site<br />

F25XR04<br />

Figure 25-4 Combining Web publishing <strong>and</strong> Server publishing for SharePoint sites<br />

Because the first site delegates authentication to ISA Server, all incoming<br />

requests listeners require authentication. (The Ask Unauthenticated Users For Identification<br />

setting is a global one <strong>and</strong> affects all incoming listeners.) To allow anonymous<br />

access to the second site for the general public, we can configure a Server<br />

publishing rule to make the second site available for external access.<br />

However, to make this configuration work, we also need to make sure there<br />

are two external IP addresses that can be used for the first site <strong>and</strong> the second site,<br />

respectively. Server publishing rules do not provide the ability to publish a service<br />

more than once on the same external interface. In our example, because we have<br />

two different portal sites to publish, we need to have two external IP addresses that<br />

can be bound to the same external interface. We will then use one IP address for the<br />

Web publishing rule to publish the first site, <strong>and</strong> another IP address for the Server<br />

publishing rule to publish the second site. It is important to note that the incoming<br />

requests listener for the first site must be configured for only one IP address using<br />

the option to configure listeners individually per IP address.<br />

When you use Server publishing to publish a SharePoint site, to make sure that<br />

the links on the external clients are not broken, verify that the internal SharePoint<br />

Portal Server is configured to use alternate portal site access settings for external clients.<br />

Refer to Chapter 13 for detailed instructions.<br />

Setting Up a Server Publishing Rule<br />

To configure the Server publishing rule for a SharePoint site, perform the following<br />

steps on ISA Server:<br />

1. Verify that the listeners for incoming Web requests is not configured to listen<br />

on an IP address that will be used to publish SharePoint sites using a Server<br />

publishing rule. The Server publishing rule must not conflict with the incoming<br />

Web requests listener configuration.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!