联合服务器代理容量规划Planning for Federation Server Proxy Capacity

联合服务器代理的容量规划有助于您估算:Capacity planning for federation server proxies helps you estimate:

  • 每个联合服务器代理的相应硬件要求。The appropriate hardware requirements for each federation server proxy.

  • 要放在每个组织中的联合服务器和联合服务器代理的数量。The number of federation servers and federation server proxies to place in each organization.

联合服务器代理将安全令牌从企业网络中受保护的联合服务器重定向到联合用户。Federation server proxies redirect security tokens from a protected federation server in the corporate network to federated users. 部署联合服务器代理的目的是允许外部用户连接到联合服务器。The purpose of deploying a federation server proxy is to allow external users to connect to a federation server. 它不会对令牌进行实际签名,也不会在 AD FS 配置数据库中写入数据。It does not actually sign tokens or write to data in the AD FS configuration database. 因此,联合服务器代理的硬件要求通常低于联合服务器的硬件要求。Therefore, the hardware requirements for the federation server proxy are usually lower than the hardware requirements for a federation server.

由于对联合服务器代理的每个请求都会导致向联合服务器或联合服务器场发出请求,因此必须并行执行联合服务器和联合服务器代理的容量规划。Because every request to a federation server proxy results in a request to a federation server or federation server farm, capacity planning for federation servers and federation server proxies must be performed in parallel.

估计 - 联合服务器代理的每秒峰值登录数需要了解将通过联合服务器代理登录的联合用户的使用模式。Estimating the peak sign-ins per second for the federation server proxy requires an understanding of the usage patterns of the federated users that will be signing in through the federation server proxy. 在许多部署中,使用联合服务器代理登录的联合用户位于 Internet 上。In many deployments, the federated users who sign in using the federation server proxy are located on the Internet. 可以 - 通过在将受 AD FS 保护的现有 Web 应用程序上查看这些联合用户的使用模式,来估算每秒的峰值登录数。You can estimate the peak sign-ins per second by looking at the usage patterns of these federated users on the existing Web applications that will be protected by AD FS.

备注

对于生产部署,我们建议为每个部署的联合服务器场实例至少使用两个联合服务器代理。For production deployments, we recommend a minimum of two federation server proxies for each federation server farm instance you deploy.

估计组织所需的联合服务器代理的数目Estimate the number of federation server proxies required for your organization

你首先需要确定要在组织中部署的联合服务器的总数,然后才能估算所需的 AD FS 联合服务器代理计算机的数量。Before you can estimate the number of AD FS federation server proxy machines required, you will first need to determine the total number of federation servers that you will deploy in your organization. 有关如何执行此操作的详细信息,请参阅规划联合服务器容量For more information about how to do this, see Planning for Federation Server Capacity.

一旦你决定了联合服务器的数目,就会将此数量的服务器乘以你预计将从 ( 位于企业网络外部的外部用户发出的传入联合身份验证请求的百分比 ) 。Once you have decided on the number of federation servers, multiply this number of servers by the percentage of incoming federated authentication requests that you expect will be made from external users (located outside of the corporate network). 此计算的值将向你提供要处理外部用户的传入身份验证请求的预计联合服务器代理数。The value of this calculation will provide you with the estimated number of federation server proxies that will handle the incoming authentication requests for your external users.

例如,如果建议的联合服务器数为3,并且预计将从外部用户发出的身份验证请求总数大约为联合身份验证请求总数的60%,则计算结果将等于 1.8 ( 3 X 60, ) 最多可舍入为2。For example, if the number of recommended federation servers is 3, and you expect that the total number of authentication requests that will be made from external users will be approximately 60% of the total number of federated authentication requests, your calculation would equal 1.8 (3 X .60) which you can round up to 2. 因此,在这种情况下,需要部署两个联合服务器代理计算机,以容纳三个联合服务器的外部用户身份验证请求的负载。Therefore, in this case, you would need to deploy two federation server proxy machines to accommodate the load of external user authentication requests for the three federation servers.

在 AD FS 产品团队执行的测试中,发现每个联合服务器代理上的总体 CPU 利用率明显低于同一场的联合服务器上观察到的 CPU 使用率。In tests performed by the AD FS product team, the overall CPU utilization on each federation server proxy was found to be significantly lower than the CPU utilization that was observed on the federation servers for the same farm. 在一个测试中,当一台联合服务器 CPU 指示它已完全饱和时,为同一场提供代理服务的联合服务器代理的 CPU 的使用率仅为20%。In one test, while one federation server CPU was indicating that it was completely saturated, the CPU for a federation server proxy providing proxy services for that same farm was observed at only 20% utilization. 因此,我们的测试表明,联合服务器代理的 CPU 上的负载(使用本部分前面所述的类似硬件规范)可以合理地处理大约三台联合服务器的处理负载。Therefore, our tests revealed that the load on the CPU of a federation server proxy, which uses similar hardware specifications as discussed earlier in this section, could reasonably handle the processing load for approximately three federation servers.

但出于容错目的,我们建议为每个部署的联合服务器场至少使用两个联合服务器代理。However, for fault tolerance purposes, we recommend a minimum of two federation server proxies for each federation server farm you deploy.

另请参阅See Also

Windows Server 2012 中的 AD FS 设计指南AD FS Design Guide in Windows Server 2012