Publishing Active Directory through ForeFront TMG or ISA Server

Published date Fri, 2009-11-27 16:42
Category
Author Wan Ziyang, Triston
Printable Version | Email this Article
No votes yet
Post to del.icio.us | Furl it | Spurl it

I have been tasked to explore on how to publish the internal LDAP server(MS Active Directory) to public internet with authentication.

After few days of struggling, I am finally able to get it done.

I decided to publish it so that others will not have to suffer like me. :-)

Step 1: Start the "Publish Non-Web Server Protocols"

step1.gif

Step 2 : Give your rule a name

step2.gif

Step 3: Specify your LDAP Server(Active Directory) IP Address

step3.gif

Step 4: Create a new protocol

step4.gif

Step 5: Give your new protocol a name

step5.gif

Step 6: Create a new port range

step6.gif

Step 7: Select "TCP" --> "Inbound" and port is "389" for both

step7.gif

Step 8: Click on "New" to create another one

step8.gif

Step 9: Select "UDP" --> "Recieve" and port is "389" for both

step9.gif

Step 10 : Click "Next" to proceed

step10.gif

Step 11: Leave it as default and go to next step

step11.gif

Step 12: Click "Finish" to complete the wizard

step12.gif

Step 13: Click "Next" to proceed

step13.gif

Step 14: Check "External" Interface and click on "Address"

step14.gif

Step 15: Follow the setting below, highlight on the IP Address you want the server to listen to, and click on "Add"

step15.gif

step16.gif

step17.gif

Step 16: Click "Finish" to complete the wizard

step18.gif

Step 17: You need to modify the rule before it will work. Double click on the newly created rule

step19.gif

Step 18: Go to "To" Tab and choose "Request appear to come from the Forefront TMG computer" or "Request appear to come from the ISA Server computer"

step20.gif

Step 19: Click on "Apply" to active the changes.

step21.gif

Now you need to configure your client to test the rule. I am using "Windows Mail" in Vista

Step 1 : Launch Windows Mail and go to "Tools"-->"Accounts" and click on "Add"

client1.gif

Step 2: Select "Directory Service"

client2.gif

Step 3: key in the public resolvable name of your ForeFront or ISA server and check on "My LDAP server requires me to log on"

client3.gif

Step 4: key in your domain account credential

client4.gif

Step 5: Select "No" for this step

client5.gif

Step 6: Click on "Finish" to complete this wizard

client6.gif

Step 7: go back to "Tools" --> "Accounts" and select your newly creately directory service and click on "Properties"

Under "Advanced" tab, key the "Search base", it's recommended to narrow down the search into a specific OU for best performance, but you can still use domain root as search base.

client8.gif

Step 8: Locate this icon in Windows Mail and click on "People"

client7.gif

Step 9: Select the new directory service

client9.gif

Step 10: key in your search query, and here comes the results :-)

client10.gif

Have fun folks..

Discuss/Post to digWin

About Wan Ziyang(Triston)

Wan Ziyang (Triston) is Sr.Consultant with a System Integrator based in Singapore. He is MCSE since year 2005 and MVP in Exchange Server. Triston leads Singapore MessagingTalk User Group activities where folks interested in Microsoft Messaging Technologies gather for learning and networking. He has done several implementation on various versions of Exchange Servers. He is also Redhat Certified Engineer on EL4.

Featured Links


Subscribe to Articles

Receive monthly article updates.

Join our Exchange forum | View forums