InfrastructurePlanningandDesignDirectAccessVersion1.2Published:October2009Updated:February2010Forthelatestinformation,pleaseseewww.microsoft.com/IPDCopyright©2010MicrosoftCorporation.ThisdocumentationislicensedtoyouundertheCreativeCommonsAttributionLicense.Toviewacopyofthislicense,visithttp://creativecommons.org/licenses/by/3.0/us/orsendalettertoCreativeCommons,543HowardStreet,5thFloor,SanFrancisco,California,94105,USA.Whenusingthisdocumentation,providethefollowingattribution:InfrastructurePlanningandDesignisprovidedwithpermissionfromMicrosoftCorporation.Thisdocumentationisprovidedtoyouforinformationalpurposesonly,andisprovidedtoyouentirely"ASIS".YouruseofthedocumentationcannotbeunderstoodassubstitutingforcustomizedserviceandinformationthatmightbedevelopedbyMicrosoftCorporationforaparticularuserbaseduponthatuser’sparticularenvironment.Totheextentpermittedbylaw,MICROSOFTMAKESNOWARRANTYOFANYKIND,DISCLAIMSALLEXPRESS,IMPLIEDANDSTATUTORYWARRANTIES,ANDASSUMESNOLIABILITYTOYOUFORANYDAMAGESOFANYTYPEINCONNECTIONWITHTHESEMATERIALSORANYINTELLECTUALPROPERTYINTHEM.Microsoftmayhavepatents,patentapplications,trademarks,orotherintellectualpropertyrightscoveringsubjectmatterwithinthisdocumentation.ExceptasprovidedinaseparateagreementfromMicrosoft,youruseofthisdocumentdoesnotgiveyouanylicensetothesepatents,trademarksorotherintellectualproperty.Informationinthisdocument,includingURLandotherInternetWebsitereferences,issubjecttochangewithoutnotice.Unlessotherwisenoted,theexamplecompanies,organizations,products,domainnames,e-mailaddresses,logos,people,placesandeventsdepictedhereinarefictitious.Microsoft,ActiveDirectory,Forefront,Hyper-V,Windows,WindowsServer,andWindowsVistaareeitherregisteredtrademarksortrademarksofMicrosoftCorporationintheUnitedStatesand/orothercountries.Thenamesofactualcompaniesandproductsmentionedhereinmaybethetrademarksoftheirrespectiveowners.YouhavenoobligationtogiveMicrosoftanysuggestions,commentsorotherfeedback(“Feedback”)relatingtothedocumentation.However,ifyoudoprovideanyFeedbacktoMicrosoftthenyouprovidetoMicrosoft,withoutcharge,therighttouse,shareandcommercializeyourFeedbackinanywayandforanypurpose.Youalsogivetothirdparties,withoutcharge,anypatentrightsneededfortheirproducts,technologiesandservicestouseorinterfacewithanyspecificpartsofaMicrosoftsoftwareorservicethatincludestheFeedback.YouwillnotgiveFeedbackthatissubjecttoalicensethatrequiresMicrosofttolicenseitssoftwareordocumentationtothirdpartiesbecauseweincludeyourFeedbackinthem.ContentsThePlanningandDesignSeriesApproach....................................................1IntroductiontotheDirectAccessGuide........................................................2DirectAccessinMicrosoftInfrastructureOptimization..................................3DirectAccessDesignProcess.......................................................................4Step1:DefinetheScopeoftheDirectAccessProject....................................7Step2:DetermineNetworkRequirements...................................................9Step3:DesignDirectAccessServerInfrastructure......................................13Step4:DesignWebServersandCertificateInfrastructure..........................16DirectAccessandMicrosoftForefrontUnifiedAccessGateway....................20Conclusion....................................................................