sia306 microsoft forefront unified access gateway: directaccess and beyond

21
Meir Mendelovich Senior Program Manager, UAG Product Group SIA306 Microsoft Forefront Unified Access Gateway (UAG): DirectAccess and Beyond

Upload: louis-goehl

Post on 13-Nov-2014

1.922 views

Category:

Technology


3 download

DESCRIPTION

Announcing Forefront Unified Access Gateway 2010. UAG is the cornerstone of Microsoft's remote access strategy and introduces a variety of new capabilities. This session is intended to announce UAG as well as drill into its core features and capabilities especially with Windows Server DirectAccess. Spend an hour as we unveil this next-generation remote access gateway that brings together the best and brightest remote access technologies. * Ensure always-on connectivity with scale and ease using DirectAccess and UAG. * Easily publish SSL VPN access for non DirectAccess clients. * Extend anywhere-access to Microsoft SharePoint, Exchange, Dyanmics and more. * Improve your Terminal Services deployment leveraging built in scale and management.

TRANSCRIPT

Page 1: SIA306 Microsoft Forefront Unified Access Gateway: DirectAccess and Beyond

Meir MendelovichSenior Program Manager, UAG Product Group

SIA306 Microsoft Forefront Unified Access Gateway (UAG): DirectAccess and Beyond

Page 2: SIA306 Microsoft Forefront Unified Access Gateway: DirectAccess and Beyond

Business Ready SecurityHelp securely enable business by managing risk and empowering people

Highly Secure & Interoperable Platform

IdentityProtect everywhere,access anywhere

Integrate and extend security

across the enterprise

Simplify the security experience, manage compliance

Block

from:

EnableCost Value

Siloed Seamless

to:

Page 3: SIA306 Microsoft Forefront Unified Access Gateway: DirectAccess and Beyond

UAG Vision

Provide employees, partners and customers with seamless secure access to any application or resource, from any device on any network

Increasingly, people envision a world of anywhere access - a world in which the information, the communities, and the

content that they value is available instantly and easily, no matter where they are.

Bill GatesEnabling Secure Anywhere Access in a Connected World, Feb 2007

Page 4: SIA306 Microsoft Forefront Unified Access Gateway: DirectAccess and Beyond

UAG Solution Architecture

DirectAccess

HTTPS (443)

Layer3 VPN

Data Center / Corporate Network

Business Partners /Sub-Contractors

AD, ADFS, RADIUS, LDAP….

Home / Friend / Kiosk

Employees Managed Machines

Mobile

Exchange

CRM

SharePoint

IIS based

IBM, SAP, Oracle

Terminal / Remote Desktop Services

Non web

HTTPS /

HTTP

NPS, ILM

Internet

Page 5: SIA306 Microsoft Forefront Unified Access Gateway: DirectAccess and Beyond

Demo: UAG Web Experience

Page 6: SIA306 Microsoft Forefront Unified Access Gateway: DirectAccess and Beyond

IAG? ISA? UAG? TMG?

Integrated and comprehensive

protection from Internet-based threats

Today Tomorrow

Unified platform for all enterprise remote access

needs

Protection

Access

Forefront Edge Security and Access products provide enhanced network edge protection and application-centric, policy-based access to corporate IT infrastructures

Page 7: SIA306 Microsoft Forefront Unified Access Gateway: DirectAccess and Beyond

UAG In a GlanceWeb

ApplicationPublishin

gSSL VPN

Layer 3 VPN

SSL Network Tunneling,

SSTP

Remote Desktop Services

(TS)

DirectAccess

Enhanced Authentication & Identity

Unified Management

Enterprise Readiness

Enhanced Protection – Edge Ready

Interoperability

Page 8: SIA306 Microsoft Forefront Unified Access Gateway: DirectAccess and Beyond

How UAG is saving you money

Employees remain productive – ANYWHERE.Disaster ready – H1N1, SARS, Weather..All remote access technologies on one platform, one management and possibly on one boxOut of the box non-managed supportMachines are always managedIntegrated load balancing

Page 9: SIA306 Microsoft Forefront Unified Access Gateway: DirectAccess and Beyond

Schedule

RTM: Before end of 2009

Release Candidate 1 (RC1) will be out in few weeks

Release Candidate 0 (RC0) is available for download

Page 10: SIA306 Microsoft Forefront Unified Access Gateway: DirectAccess and Beyond

UAG & DirectAccess

Page 11: SIA306 Microsoft Forefront Unified Access Gateway: DirectAccess and Beyond

DirectAccessExtending network services and resources

to remote users

Page 12: SIA306 Microsoft Forefront Unified Access Gateway: DirectAccess and Beyond

"Light up" remote clients

Decreases patch miss rates

Applies GPOs to remote machines

Pre-logon health checks and remediation

Replaces modal "connect-time" health checks

Full NAP integration

Improved productivity

Not user initiated

Simplified connectivity

Supports authenticated transactions

Supports encrypted transactions

Authentication and encryption mitigate many attacks

DirectAccess is more than Remote Access

Manage OutAccess Policies

Always OnProtected

Transactions

VPNs connect the user to the network

DirectAccess extends the network to the user

Page 13: SIA306 Microsoft Forefront Unified Access Gateway: DirectAccess and Beyond

Compliant Client

Datacenter Servers

Internet

Intranet User

Enterprise Network

Intranet User

IPsec/IPv6

IPsec/I

Pv6

Deperimeterization

Page 14: SIA306 Microsoft Forefront Unified Access Gateway: DirectAccess and Beyond

{

DirectAccess Server

Man

ag

ed

Windows 7

Always On

IPv6

Windows 7

IPv6

IPv4{

PDA

Windows 7 /Windows Vista/

Windows XP

Non-Windows

Unm

anaged

IPv6or

IPv4

UAG and DirectAccess better together: Extends access to servers with IPv4 support

Access for down level and non Windows clients

Enhances scalability and management

Simplifies deployment and administration

Hardened Edge Solution

Page 15: SIA306 Microsoft Forefront Unified Access Gateway: DirectAccess and Beyond

IPv6 Transition Technologies:6to4, Teredo, IP-HTTPS

Under the Hood: IPSec Tunnels

Client Machine UAG

Access Enabling Tunnel*

Domain Controllers

,DNS, NPS, Manageme

nt

Rest of the

machines in

corporate network

Corp Tunnel

* In UAG RC0 there is another tunnel for DNS servers

IPv4 via NAT64IPv6 Nati veISATAP

IPv4 via NAT64IPv6 Nati veISATAP

Internet

Page 16: SIA306 Microsoft Forefront Unified Access Gateway: DirectAccess and Beyond

* In UAG beta there is another tunnel for DNS servers

Client Machine UAG

Domain Controllers

,DNS, NPS, Manageme

nt

Rest of the machines

in corporate network

IP VPN

Adm

inCo

re

Web Application Publishing

17

Windows Server

TMG

Windows NLB

RRAS

IIS

TSG / RDG

UAG Filter

Session Manager User Manager Config. / Array Manager

Internal Site Portal

Direct Access

DirectAccess ServerD

NS6

4

NAT

64

ISAT

AP

IP-H

TTPS

Tere

do

6to4

Nati

ve IP

v6

DTE / DoSP

Management UI SCOM MP

UAG Logic

Tracing & Logging

SSTP

Laye

r 3

SSL

Tunn

el

Under the Hood: UAG Architecture

Page 17: SIA306 Microsoft Forefront Unified Access Gateway: DirectAccess and Beyond

Under the Hood: UAG Architecture

Client Machine UAG

Domain Controllers

,DNS, NPS, Manageme

nt

Rest of the machines

in corporate network

Direct Access

DirectAccess Server

DN

S64

NAT

64

ISAT

AP

IP-H

TTPS

Tere

do

6to4

Nati

ve IP

v6

DTE / DoSP

TMG

NLB UAG Logic

UAG Management

Page 18: SIA306 Microsoft Forefront Unified Access Gateway: DirectAccess and Beyond

DirectAccess Demo

Page 19: SIA306 Microsoft Forefront Unified Access Gateway: DirectAccess and Beyond

Want more?

Page 20: SIA306 Microsoft Forefront Unified Access Gateway: DirectAccess and Beyond

Call to Action

• Download and installhttp://www.microsoft.com/uag

• Read more on our blog:// . . / /http blogs technet com edgeaccessblog

• …and on TechNethttp://technet.microsoft.com/en-us/library/dd861463.aspx

• Visit our forum for feedback & questionshttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/

Page 21: SIA306 Microsoft Forefront Unified Access Gateway: DirectAccess and Beyond

© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries.

The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation.

MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.