26.04.2015 Views

Team Development with Visual Studio Team Foundation Server

Team Development with Visual Studio Team Foundation Server

Team Development with Visual Studio Team Foundation Server

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Networks <strong>with</strong> a domain controller on the perimeter<br />

Figure 17.3 shows architecture for exposing TFS over ISA <strong>with</strong> a domain controller in the<br />

perimeter network.<br />

Figure 17.3 TFS over ISA, Domain Controller on Perimeter Network Architecture<br />

If you do have a domain controller on your perimeter network, remote users can authenticate<br />

directly against the perimeter domain controller. One-way trust between the internal and<br />

perimeter domain controllers allows external users to access the TFS server. Internal users access<br />

the TFS server directly, using Integrated Windows authentication.<br />

Advantages<br />

• Reverse proxies, such as ISA <strong>Server</strong>, authenticate users and inspect traffic.<br />

• Your remote users do not need access to the domain.<br />

• Your remote users do not need VPN access.<br />

Disadvantages<br />

• You cannot use the TFS Proxy at the remote location.<br />

• Your remote users cannot add users to TFS groups.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!