使用 SQL Server 聯盟伺服器陣列Federation Server Farm Using SQL Server

適用於:Windows Server 2012Applies To: Windows Server 2012

這個 Active Directory 同盟服務 (AD FS) 拓撲與它不會複寫發電廠每個聯盟伺服器資料,使用 Windows 內部資料庫 (WID) 部署拓撲聯盟伺服器陣列不同。This topology for Active Directory Federation Services (AD FS) differs from the federation server farm using Windows Internal Database (WID) deployment topology in that it does not replicate the data to each federation server in the farm. 改所有聯盟伺服器可讀取和寫入通用資料庫會儲存在位於公司網路中的 Microsoft SQL server 的伺服器上的資料。Instead, all federation servers in the farm can read and write data into a common database that is stored on a server running Microsoft SQL Server that is located in the corporate network.

部署注意事項Deployment considerations

本節各種考量有關的目標對象、優點和這部署拓撲相關聯的限制。This section describes various considerations about the intended audience, benefits, and limitations that are associated with this deployment topology.

誰應該使用此拓撲?Who should use this topology?

  • 大型的組織超過 100 信任關係,必須為其內部使用者和外部使用者單一 sign\ 上 (SSO) 存取聯盟應用程式或服務提供使用Large organizations with more than 100 trust relationships that need to provide both their internal users and external users with single sign-on (SSO) access to federated application or services

  • 組織已經使用 SQL Server,並且想要利用其現有的工具和專業Organizations that already use SQL Server and want to take advantage of their existing tools and expertise

使用這個拓撲的好處為何?What are the benefits of using this topology?

  • 支援信任關係的數字越大 (more than 100)Support for larger numbers of trust relationships (more than 100)

  • 支援權杖重播偵測 (a security feature) 和成品解析度 \ (安全性判斷提示標記語言 (SAML) 2.0 的一部分 protocol)Support for token replay detection (a security feature) and artifact resolution (part of the Security Assertion Markup Language (SAML) 2.0 protocol)

  • 支援 SQL Server 的完整優點資料庫鏡像、容錯、報告] 下方,和管理工具Support for the full benefits of SQL Server, such as database mirroring, failover clustering, reporting, and management tools

使用這個拓撲限制為何?What are the limitations of using this topology?

  • 這個拓撲預設不提供資料庫冗餘。This topology does not provide database redundancy by default. 聯盟伺服器陣列有 SQL Server 拓撲聯盟伺服器陣列有 WID 拓撲會自動複製 WID 資料庫陣列中每個聯盟伺服器上的,但包含份資料庫Although a federation server farm with WID topology automatically replicates the WID database on each federation server in the farm, the federation server farm with SQL Server topology contains only one copy of the database

注意

SQL Server 支援許多不同的資料與應用程式冗餘選項,包括容錯,請稍後及 SQL Server 複寫數種不同類型。SQL Server supports many different data and application redundancy options including failover clustering, database mirroring, and several different types of SQL Server replication.

Microsoft 的資訊技術 (IT) 部門使用 SQL Server 資料庫鏡像 high\ 安全 (synchronous) 模式和容錯提供 high\ 可用性支援 SQL Server 執行個體。The Microsoft Information Technology (IT) department uses SQL Server database mirroring in high-safety (synchronous) mode and failover clustering to provide high-availability support for the SQL Server instance. Microsoft AD FS product 小組尚未經過測試 SQL Server 交易 (peer-to-peer) 及合併複寫。SQL Server transactional (peer-to-peer) and merge replication have not been tested by the AD FS product team at Microsoft. 如需 SQL Server 的詳細資訊,請查看高可用性方案概觀選取適當的︰ 複寫輸入For more information about SQL Server, see High Availability Solutions Overview or Selecting the Appropriate Type of Replication.

支援的 SQL Server 版本Supported SQL Server Versions

安裝 Windows Server 2012 AD FS 進行支援下列 SQL server 版本:The following SQL server versions are supported with AD FS installed with Windows Server 2012:

  • SQL Server 2008 \ 日 R2SQL Server 2008 / R2

  • SQL Server 2012SQL Server 2012

伺服器配置建議位置與網路Server placement and network layout recommendations

類似的 WID 拓撲聯盟伺服器陣列聯盟伺服器的所有設定為使用一個叢集網域名稱系統 (DNS) 名稱 \(代表同盟服務 name\)和網路負載平衡 (NLB) 叢集組態的一部分一個叢集 IP 位址。Similar to the federation server farm with WID topology, all of the federation servers in the farm are configured to use one cluster Domain Name System (DNS) name (which represents the Federation Service name) and one cluster IP address as part of the Network Load Balancing (NLB) cluster configuration. 這可協助 NLB 主機配置 client 要求的個人聯盟伺服器。This helps the NLB host allocate client requests to the individual federation servers. 聯盟伺服器 proxy 可用於 proxy 伺服器聯盟陣列 client 請求。Federation server proxies can be used to proxy client requests to the federation server farm.

下圖顯示虛構 Contoso 醫藥公司部署其聯盟具有伺服器陣列 SQL Server 拓撲公司網路中的方式。The following illustration shows how the fictional Contoso Pharmaceuticals company deployed its federation server farm with SQL Server topology in the corporate network. 它也示範如何該公司設定周邊網路存取權的 DNS 伺服器,使用適用於企業網路 NLB 叢集、相同叢集 DNS 名稱 (fs.contoso.com) 其他 NLB 主機與兩個聯盟伺服器 proxy (fsp1 and fsp2)。It also shows how that company configured the perimeter network with access to a DNS server, an additional NLB host that uses the same cluster DNS name (fs.contoso.com) that is used on the corporate network NLB cluster, and with two federation server proxies (fsp1 and fsp2).

使用 SQL server 陣列

如需有關如何使用您的網路環境設定聯盟伺服器或聯盟的 proxy 伺服器,查看任一個聯盟伺服器的名稱解析需求聯盟的 Proxy 伺服器的名稱解析需求For more information about how to configure your networking environment for use with federation servers or federation server proxies, see either Name Resolution Requirements for Federation Servers or Name Resolution Requirements for Federation Server Proxies.

也了See Also

Windows Server 2012 中的 AD FS 設計指南AD FS Design Guide in Windows Server 2012