同盟伺服器的名稱解析需求Name Resolution Requirements for Federation Servers

當公司網路上的用戶端電腦嘗試存取應用程式或 Web 服務所保護的 Active Directory Federation Services (AD FS),他們必須先驗證同盟伺服器。When client computers on the corporate network attempt to access an application or Web service that is protected by Active Directory Federation Services (AD FS), they must first authenticate to a federation server. 驗證的一個方式是將透過 Windows 整合式驗證存取本機同盟伺服器的公司網路用戶端。One way to authenticate is to have the corporate network clients access a local federation server through Windows Integrated Authentication.

設定公司 DNSConfigure corporate DNS

因此,透過 Windows 整合式驗證的本機同盟伺服器上的成功名稱解析可能會發生,網域名稱系統(DNS)公司網路中的帳戶夥伴必須設定新的主機(A)會將完整的網域名稱解析的資源記錄(FQDN)同盟伺服器叢集的 IP 位址的同盟伺服器的主機名稱。So that successful name resolution through Windows Integrated Authentication on local federation servers can occur, Domain Name System (DNS) in the corporate network of the account partner must be configured for a new host (A) resource record that will resolve the fully qualified domain name (FQDN) host name of the federation server to the IP address of the federation server cluster.

在下圖中,您可以看到特定案例如何完成這項工作。In the following illustration, you can see how this task is accomplished for a given scenario. 在此案例中,Microsoft 網路負載平衡(NLB)提供現有的同盟伺服器陣列中的單一叢集 FQDN 名稱和單一叢集 IP 位址。In this scenario, Microsoft Network Load Balancing (NLB) provides a single cluster FQDN name and a single cluster IP address for an existing federation server farm.

名稱需求

如需有關如何設定叢集 IP 位址或叢集 FQDN 使用 NLB 的資訊,請參閱指定叢集參數For information about how to configure a cluster IP address or cluster FQDN using NLB, see Specifying the Cluster Parameters.

如需有關如何設定公司 DNS 的同盟伺服器的資訊,請參閱 < 主機(的)至同盟伺服器的公司 DNS 資源記錄For information about how to configure corporate DNS for a federation server, see Add a Host (A) Resource Record to Corporate DNS for a Federation Server.

如需有關如何設定同盟伺服器 proxy 在周邊網路中的資訊,請參閱 < 同盟伺服器 Proxy 的名稱解析需求For information about how to configure federation server proxies in the perimeter network, see Name Resolution Requirements for Federation Server Proxies.

另請參閱See Also

Windows Server 2012 中的 AD FS 設計指南AD FS Design Guide in Windows Server 2012