Extranet Publishing with ISA Web app authentication Users Pre-Authentication Publish Users ISA --LAN-- ISA HTML Form Authentication Internal web apps may also require a form login Extranet users have to log in twice (or more!)
What to do? Web app authentication Users Publish Users ISA --LAN-- Remove ISA authentication? “Fixes” the problem, but allows anonymous traffic into the LAN; a security issue.
What to do? Web app authentication Users KC Pre-Authentication D Publish Users ISA --LAN-- Wait for vendor to support Kerberos delegation or NTLM? May not be possible. What if you want LAN users to have a form login?
Solution: Flex. Form Encrypts and stores ISA FBA credentials in memory Extranet users log in once at the perimeter Seamlessly POSTs credentials to the login forms of LAN applications Highly configurable to suit different web forms Rapid development library-- need a feature added? No problem!
Publishing with Flex. Form Web app authentication Users Au to m Pre-Authentication at ic ! Publish Users ISA --LAN-- User logs in at ISA Browser requests web app login page Flex. Form recognizes the request and POSTs the form automatically
Publishing with Flex. Form Web app authentication Users Au to m Pre-Authentication at ic ! Publish Users ISA --LAN-- Even with magic, some assembly is required: each web app is different Configure once, use forever Help is available!