規劃聯盟伺服器容量Planning for Federation Server Capacity

適用於:Windows Server 2016、Windows Server 2012 R2、Windows Server 2012Applies To: Windows Server 2016, Windows Server 2012 R2, Windows Server 2012

規劃伺服器聯盟容量可協助您估計:Capacity planning for federation servers helps you estimate:

  • 哪些因素拓展 AD FS 設定資料庫的大小。Which factors grow the size of the AD FS configuration database.

  • 每個聯盟伺服器的適當的硬體需求。The appropriate hardware requirements for each federation server.

  • 將每個組織中聯盟伺服器數目。The number of federation servers to place in each organization.

聯盟伺服器發行安全性權杖給使用者。Federation servers issue security tokens to users. 這些權杖顯示信賴供使用。These tokens are presented to a relying party for consumption. 聯盟伺服器發行安全性權杖驗證使用者或之後接收的安全性權杖先前發行的夥伴同盟服務。Federation servers issue security tokens after authenticating a user or after receiving a security token that was previously issued by a partner Federation Service. 當使用者最初登入聯盟應用程式或其的安全性權杖到期時存取聯盟應用程式的安全性權杖要求同盟服務。A security token is requested from a Federation Service when users initially sign in to federated applications or when their security tokens expire while they are accessing federated applications.

聯盟伺服器專為容納 high\ 可用性伺服器發電廠設定使用 Microsoft 網路負載平衡 (NLB) 技術。Federation servers are designed to accommodate high-availability server farm configurations that use Microsoft Network Load Balancing (NLB) technology. 聯盟伺服器發電廠設定服務要求獨立,而不需要存取的任何通用發電廠元件每個要求。Federation servers in a farm configuration can service requests independently, without accessing any common farm components for each request. 因此,還有少參與出聯盟伺服器部署縮放比例。Therefore, there is little overhead involved in scaling out a federation server deployment.

建議:Recommendations:

  • 適用於 mission\ 重大或 high\ 可用性部署,建議您建立的小聯盟伺服器陣列每個協力廠商組織,與每個發電廠,以提供容錯至少兩部聯盟伺服器。For mission-critical or high-availability deployments, we recommend that you create a small federation server farm in each partner organization, with at least two federation servers per farm, to provide fault tolerance.

  • 需可用性和輕鬆聯盟伺服器縮放比例,以查看縮放比例是處理大量的特定同盟服務秒要求建議的方法。With the need for high availability and the ease of scaling out federation servers, scaling out is the recommended method for handling high numbers of requests per second for a particular Federation Service. 向上超過本指南基本設定太製作重大容量處理提高可及範圍。Scaling up beyond the base configuration in this guide is unlikely to produce significant capacity handling gains.

AD FS 設定資料庫的大小和成長AD FS configuration database size and growth

AD FS 設定資料庫大小通常被視為小,並資料庫大小不通常會主要考量 AD FS 部署。The size of the AD FS configuration database is generally considered to be small, and database size does not tend to be a major consideration in AD FS deployments. AD FS 設定資料庫精確大小主要可以仰賴數目信任關係和相關的 trust\ 相關中繼資料,例如宣告,取得規則及監視設定設定為每個信任。The precise size of the AD FS configuration database can depend largely on the number of trust relationships and the associated trust-related metadata—such as claims, claim rules, and monitoring settings configured for each trust. 隨著信任設定資料庫中的項目數目增加,所以會需要更多磁碟空間。As the number of trust entries in the configuration database grows, so does the need for more disk space.

適用於其他部署 AD FS 設定資料庫有關,請查看AD FS 部署拓撲考量For additional deployment information about the AD FS configuration database, see AD FS Deployment Topology Considerations.

記憶體,CPU 磁碟空間需求Memory, CPU and disk space requirements

幸好聯盟伺服器的記憶體、CPU 和磁碟空間需求是太大,且不會有可能是硬體決策開車因素。Fortunately, memory, CPU and disk space requirements for federation servers are modest, and they are not likely to be a driving factor in hardware decisions. 如硬體需求的相關詳細資訊,請查看附錄 a:審查 AD FS 需求For more information about hardware requirements, see Appendix A: Reviewing AD FS Requirements.

注意

在使用市集 AD FS 設定資料庫設定的專屬 SQL Server 聯盟伺服器陣列 AD FS product 小組所執行的測試,SQL Server 的整體負載打算低。In tests that were performed by the AD FS product team using a federation server farm configured with a dedicated SQL Server to store the AD FS configuration database, the overall load on the SQL Server tended to be low. 使用已設定為使用單一 SQL Server four\ federation\ 伺服器發電廠一個測試,在 CPU 使用率不超過 10%,即使測試的目標使用率整合聯盟伺服器。In one test using a four-federation-server farm that was configured to use a single SQL Server, CPU utilization did not exceed 10% despite testing that brought the federation servers to target utilization.

估計聯盟伺服器,您的組織數目Estimate the number of federation servers for your organization

為了簡化計劃聯盟伺服器程序的硬體,AD FS product 的小組負責開發 AD FS 容量規劃縮放試算表。In an effort to streamline the hardware planning process for federation servers, the AD FS product team developed the AD FS Capacity Planning Sizing Spreadsheet. 此 Excel 試算表包含 calculator\ 般的功能,將會提供有關使用者在組織中,建議使用的最佳聯盟伺服器數目傳回 AD FS production 環境預期的使用方式資料。This Excel spreadsheet includes calculator-like functionality that will take expected usage data that you provide about users in your organization and return a recommended optimal number of federation servers for your AD FS production environment.

注意

此試算表會建議可聯盟伺服器數目為基礎的硬體及網路規格期間測試使用 AD FS product 小組。The number of federation servers that this spreadsheet will recommend is based on the hardware and network specifications that the AD FS product team used during testing. 因此,聯盟伺服器,建議您將會試算表數目您必須在此處了解。Therefore, the number of federation servers that the spreadsheet will recommend must be understood within this context. 如需測試期間所使用的規格,查看主題規劃 AD FS 伺服器容量For more information about the specifications used during testing, see the topic titled Planning for AD FS Server Capacity.

請使用 AD FS 容量計畫縮放試算表Using the AD FS Capacity Planning Sizing Spreadsheet

當您使用此試算表時,您將需要選取 [值 \ (任一個40%60%,或80%) 最佳代表您預期的總使用者百分比將會傳送驗證要求您聯盟伺服器使用尖峰期間。When you use this spreadsheet, you will need to select a value (either 40%, 60%, or 80%) that best represents the percentage of total users you expect will send authentication requests to your federation servers during peak usage periods.

然後,您將需要選取 [值 \ (任一個1 分鐘15 分鐘,或1 小時) 最佳代表您預期澳地區的山峰使用句點持續的時間長度。Then, you will need to select a value (either 1 minute, 15 minutes, or 1 hour) that best represents the length of time you expect the peak usage period to last. 例如,您可能會總數人員將會在一段 15 分鐘,登入或 60%的使用者將會在 1 小時的時間登入的使用者的值為估計 40%。For example, you might estimate 40% as the value for the total number of users who will login within a period of 15 minutes, or that 60% of users will login within a period of 1 hour. 在一起,這些值定義您當時建議計算所用的山峰載入設定檔。Together, these values define the peak load profile by which your sizing recommendation will be calculated.

接下來,您將需要指定總數需要目標 claims\ 感知應用程式,根據使用者是否的單一 sign\ 上存取的使用者:Next, you will need to specify the total number of users that will require single sign-on access to the target claims-aware application, based on whether the users are:

  • 從本機電腦確實連接到您的企業網路的登入 Active Directory \(透過整合 authentication\ Windows)Logging into Active Directory from a local computer that is physically connected to your corporate network (through Windows integrated authentication)

  • 不確實連接到您的企業網路的電腦從遠端登入 Active Directory \(透過 Windows 整合驗證或使用者名稱和 password\)Logging into Active Directory remotely from a computer that is not physically connected to your corporate network (through Windows integrated authentication or Username and password)

  • 從另一個組織,而且嘗試值得信賴的合作夥伴從存取目標 claims\ 感知應用程式From another organization and are attempting to access the target claims-aware application from a trusted partner

  • 從 SAML 2.0 身分提供者和已嘗試存取目標 claims\ 感知應用程式From a SAML 2.0 identity provider and are attempting to access the target claims-aware application

如何使用這個試算表How to use this spreadsheet

您可以使用下列步驟想要部署判斷聯盟伺服器建議的數目每個聯盟伺服器發電廠執行個體。You can use the following steps for each federation server farm instance you plan to deploy to determine the recommended number of federation servers.

  1. 下載,然後打開AD FS 容量規劃縮放試算表 Windows Server 2012 R2 的AD FS 容量規劃縮放試算表 Windows Server 2016 的Download and then open the AD FS Capacity Planning Sizing Spreadsheet For Windows Server 2012 R2 or the AD FS Capacity Planning Sizing Spreadsheet For Windows Server 2016.

  2. 格中右邊的期間澳地區的山峰系統使用量預期百分比驗證我的使用者儲存格,按一下 [儲存格,然後選取您估計的系統使用量層級,或是使用 drop\ 向下箭號40%60%80%部署。In the cell to the right of the During the peak system usage period, I expect this percentage of my users to authenticate cell, click the cell and then use the drop-down arrows to select your estimated system utilization level, either 40%, 60% or 80% for the deployment.

  3. 格中右邊的下列一段時間中儲存格,按一下 [儲存格,然後選取使用的 drop\ 向下箭號,1 分鐘15 分鐘,或1 小時選取尖峰的持續時間。In the cell to the right of the within the following period of time cell, click the cell and then use the drop-down arrows to select either 1 minute, 15 minutes, or 1 hour to select the duration of peak load.

  4. 格中右邊的Enter 估計的數字內部應用程式的 \ (例如 SharePoint (2007 or 2010) 或宣告注意 web applications)儲存格、輸入內部應用程式,您將會在組織中使用的數字。In the cell to the right of the Enter estimated number of internal applications (such as SharePoint (2007 or 2010) or claims aware web applications) cell, type the number of internal applications you will use in your organization.

  5. 格中右邊的Enter 估計的數字 online 應用程式 \(例如 Office 365 Exchange Online、SharePoint Online 或 Lync Online\)儲存格、輸入 online 應用程式或服務您將會在您的組織中使用的數字。In the cell to the right of the Enter estimated number of online applications (such as Office 365 Exchange Online, SharePoint Online or Lync Online) cell, type the number of online applications or services you will used in your organization.

  6. 要介紹標題為儲存在號碼使用者的,輸入每個用於您的使用者案例應用程式列上的數字將會需要單一 sign\ 上的存取權。Under the cell titled Number of Users, type a number on each row that applies to an example application scenario your users will need single sign-on access to. 此資料行應包含定義的使用者,不澳地區的山峰使用者秒數。This column should contain the number of defined users, not the peak users per second. 如果您對應用程式存取嘗試必須先進行首頁領域探索頁面上,輸入Y。如果您不確定此選項,輸入YIf access attempts made to the application must first go through the home realm discovery page, type Y. If you are unsure of this selection, type Y.

  7. 檢視的下列建議提供的值:Review the following recommended values that are provided:

    1. 如建議的聯盟伺服器總數,較低右儲存格反白顯示灰色。For the total number of recommended federation servers, see the lower right cell that is highlighted in gray.

    2. 伺服器建議的每個案例應用程式數目,如儲存格列中的灰反白顯示。For the number of servers recommended for each example application scenario, see the cell on the row that is highlighted in gray.

注意

將會自動儲存格要介紹標題為右邊的儲存格計算值總數聯盟伺服器建議的試算表底部包含即可將以每個它之前的個人資料列中的所有值總和新增額外的 20%緩衝公式。The value that will be automatically calculated in the cell to the right of the cell titled Total number of federation servers recommended at the bottom of the spreadsheet contains a formula which will add an additional 20% buffer to the sum total of all the values in each of the individual rows preceding it. 公式新增到總數聯盟伺服器建議的部署的聯盟伺服器,讓它太農場整體載入曾經會叫用它飽點數量,建議您總計此緩衝中的行動組建。The formula added to the Total number of federation servers recommended cell builds in this buffer to your total recommended number of deployed federation servers to make it very unlikely that the overall load on the farm will ever hit its saturation point.

也了See Also

Windows Server 2012 中的 AD FS 設計指南AD FS Design Guide in Windows Server 2012