72
CHAPTER 2 | Software-defined datacenter
Figure 2-71:
Datacenter firewall
The datacenter firewall is controlled by Network Controller. The tenant administrator can configure
policies and apply them directly to a Vport on the Hyper-V switch. Additionally, as tenant workloads
move around the datacenter, the policy for the tenant can follow them
on their journey between
hosts.
Web Application Proxy
In this section, Yuri Diogenes and David Branscome demonstrate how you can use the updated Web
Application Proxy in Windows Server 2016 to easily access information from anywhere.
Publishing capability enhancements
Users can access company data by using different form factors (e.g., laptop computers, tablets, and
smartphones), which here, for simplicity, we will just refer to as
devices.
These devices can originate
requests from different locations, but the users expect to have an experience similar to what they have
when they are on-premises. IT must ensure that the entire communication channel is secure, from
data at rest in the datacenter (on-premises or in the cloud), to data in transit until it reaches the
destination device. There, it will also be at rest and must also be secure.
To make it possible for users to
securely access company data, Web Application Proxy in Windows
Server 2016 was enhanced to cover more bring-your-own-device (BYOD) scenarios, such as Pre-Auth
with Microsoft Exchange Server, which we will discuss later in more detail. Web Application Proxy
continues to make use of Active Directory Federation Services (AD FS) and AD DS for authentication
and authorization. This integration is very important for BYOD scenarios because it provides the
capability to create custom rules for users who are accessing resources
while physically located on-
premises versus those accessing resources via the Internet.
Note If you are not familiar with Web Application Proxy in Windows Server 2012 R2, read the
article at
http://technet.microsoft.com/library/dn584107.aspx
.
The Web Application Proxy installation experience is similar to that in the previous version of
Windows Server 2012 R2; therefore, you can use the same steps to install it in Windows Server 2016.
When the installation is complete, you are prompted to perform the
post-deployment configurations,
as shown in Figure 2-72.
73
CHAPTER 2 | Software-defined datacenter
Do'stlaringiz bilan baham: