Prev | Current Page 311 | Next

Jesse Varsalone and Jan Kanclirz Jr.

"Microsoft Forefront Security Administration Guide"

17). If an application published
by IAG is using one or both of these ports, the port number can be changed, as
described below.
?–  From the Admin menu in the Confi guration program, click Advanced
Confi guration.
Figure 8.17 Advanced Confi guration
1. In the Default Web Site Ports area, replace the default HTTP or HTTPS
port numbers, as required, and click OK.
2. Activate the confi guration.
Viewing Remote Computer Certifi cate
Once an end user is connected to the newly created Web portal, making sure the session
is secure before logging on is one of the most important steps because the end user
wants assurance that his logon username and password are encrypted.
322 Chapter 8 ??? Using Intelligent Application Gateway 2007
First, the SSL VPN administrator must keep in mind is that the HTTPS Web
portal needs a valid and secure enough certifi cate attached to it. The way to do
this is to make sure the new IAG gateway has a new certifi cate attached to it and
that the certifi cate is valid for a long period. It is suggested to request a certifi cate
be issued for a two-year period or longer. Second, the administrator should make
provision for users accidentally connecting to the Web portal with HTTP instead
of HTTPS. The way to do this is to create a Redirect HTTP to HTTPS Trunk
in the IAG.
Depending on the end user??™s Internet browser, the certifi cate will be accessible
when the end user browses to the IAG Web portal.


Pages:
299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323