Jump to content

Recommended Posts

Posted

Hi,

 

We recently invested heavily in an virtualised infrastructure to give us the amount of redundancy we required. The next stage is to federate our Office365 tenancy with ADFS - I have read the documentation, and the recommended practice is to have the Web Application Proxy off the domain, with access only to the ADFS server on 443, pretty much in a DMZ.

 

Our firewall is hosted by our LA, and I only have one subnet 10.10.78.0 - internally we only have a flat network, so there is no VLANs configured. At this point it is pretty hard to achieve what we want to if following the correct practice. I have spoken to our LA and they have secured us a secondary IP range of 10.10.44.0 - they are able to add this range onto our router as a secondary subnet. What they said they can do is create an ACL so only the WAP IP address can access our ADFS server on our network. I'm unsure how secure this would be?

 

If I did go the ACL route on the router, would I need to configure anything on our VM environment? Currently our VMs all sit spread across three hosts on one vSwitch, would I need to configure a new vSwitch to segregate this? I really don't know the best way to go with this. If anyone has any ideas I'd welcome them!

 

Thanks

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...