規劃區域的聯盟 Proxy 伺服器的容量Planning for Federation Server Proxy Capacity

適用於:Windows Server 2016、Windows Server 2012 R2、Windows Server 2012Applies To: Windows Server 2016, Windows Server 2012 R2, Windows Server 2012

規劃區域的聯盟的 proxy 伺服器的容量,可協助您估計:Capacity planning for federation server proxies helps you estimate:

  • 每個聯盟伺服器 proxy 適當的硬體需求。The appropriate hardware requirements for each federation server proxy.

  • 聯盟伺服器及聯盟伺服器 proxy 將每個組織中的數字。The number of federation servers and federation server proxies to place in each organization.

聯盟伺服器 proxy 重新導向從伺服器受保護的聯盟公司網路中的安全性權杖給聯盟使用者。Federation server proxies redirect security tokens from a protected federation server in the corporate network to federated users. 部署聯盟 proxy 伺服器的目的是讓使用者外部連接聯盟伺服器。The purpose of deploying a federation server proxy is to allow external users to connect to a federation server. 不會不確實權杖登入或寫入 AD FS 設定資料庫中的資料。It does not actually sign tokens or write to data in the AD FS configuration database. 因此,聯盟 proxy 伺服器的硬體需求的通常低於聯盟伺服器的硬體需求。Therefore, the hardware requirements for the federation server proxy are usually lower than the hardware requirements for a federation server.

聯盟 proxy 伺服器的每個要求的結果在要求中聯盟伺服器或聯盟伺服器發電廠,因為必須同時執行規劃伺服器聯盟和聯盟的 proxy 伺服器的容量。Because every request to a federation server proxy results in a request to a federation server or federation server farm, capacity planning for federation servers and federation server proxies must be performed in parallel.

估計的山峰 sign\ 單元聯盟 proxy 伺服器秒需要了解使用模式的聯盟使用者將會透過聯盟 proxy 伺服器登入。Estimating the peak sign-ins per second for the federation server proxy requires an understanding of the usage patterns of the federated users that will be signing in through the federation server proxy. 在許多部署,聯盟使用聯盟 proxy 伺服器登入的使用者都位於網際網路。In many deployments, the federated users who sign in using the federation server proxy are located on the Internet. 您可以藉由在現有的 Web 應用程式將會受到 AD FS 查看這些聯盟使用者的使用模式估計的山峰 sign\ 單元秒。You can estimate the peak sign-ins per second by looking at the usage patterns of these federated users on the existing Web applications that will be protected by AD FS.

注意

針對 production 部署,我們建議您的兩個聯盟伺服器 proxy 部署每個聯盟伺服器發電廠執行個體。For production deployments, we recommend a minimum of two federation server proxies for each federation server farm instance you deploy.

估計聯盟伺服器 proxy 您的組織所需的數目Estimate the number of federation server proxies required for your organization

您可以估計的數字之前所需 AD FS 聯盟伺服器 proxy 電腦,您必須先判斷聯盟伺服器,您將會在組織中部署總數。Before you can estimate the number of AD FS federation server proxy machines required, you will first need to determine the total number of federation servers that you will deploy in your organization. 如需如何執行此動作,請查看規劃聯盟伺服器容量For more information about how to do this, see Planning for Federation Server Capacity.

一旦您有認為同盟伺服器的數目乘這個數量的伺服器,連入聯盟驗證的百分比,要求您預期會進行外部使用者 \(位於公司 network\ 以外)。Once you have decided on the number of federation servers, multiply this number of servers by the percentage of incoming federated authentication requests that you expect will be made from external users (located outside of the corporate network). 這項計算的值,將提供您聯盟伺服器 proxy 將會處理您的外部使用者傳入驗證要求的預估數量。The value of this calculation will provide you with the estimated number of federation server proxies that will handle the incoming authentication requests for your external users.

例如,如果建議的聯盟伺服器數目 3,您所預期的外部使用者將會進行驗證要求總數將約 60%總數聯盟的驗證要求的計算想等於 1.8 \ (3 X。60),您可以將最多 2。For example, if the number of recommended federation servers is 3, and you expect that the total number of authentication requests that will be made from external users will be approximately 60% of the total number of federated authentication requests, your calculation would equal 1.8 (3 X .60) which you can round up to 2. 因此,如此,您必須將有兩個聯盟伺服器 proxy 容納外部使用者的三個聯盟伺服器的驗證要求的電腦。Therefore, in this case, you would need to deploy two federation server proxy machines to accommodate the load of external user authentication requests for the three federation servers.

AD FS product 小組所執行的測試,每個聯盟伺服器 proxy 的整體 CPU 使用率找會大幅低於觀察到的相同發電廠聯盟伺服器的 cpu。In tests performed by the AD FS product team, the overall CPU utilization on each federation server proxy was found to be significantly lower than the CPU utilization that was observed on the federation servers for the same farm. 單一測試,請在時同盟伺服器 CPU 已,它完全飽和,指出聯盟伺服器 proxy 提供的相同農地 proxy 服務的 CPU 觀察到,只有 20%使用量。In one test, while one federation server CPU was indicating that it was completely saturated, the CPU for a federation server proxy providing proxy services for that same farm was observed at only 20% utilization. 因此,我們的測試揭露的負載 CPU 聯盟伺服器 proxy,使用類似硬體規格所述先前在本區段中,可能會合理處理處理負載約三個聯盟伺服器。Therefore, our tests revealed that the load on the CPU of a federation server proxy, which uses similar hardware specifications as discussed earlier in this section, could reasonably handle the processing load for approximately three federation servers.

不過,錯誤容錯用途,我們建議針對每個您要部署的聯盟伺服器農場兩個聯盟伺服器 proxy 時最少提供。However, for fault tolerance purposes, we recommend a minimum of two federation server proxies for each federation server farm you deploy.

也了See Also

Windows Server 2012 中的 AD FS 設計指南AD FS Design Guide in Windows Server 2012