Citrix Blogs

TMG Replacement for Exchange 2013 with NetScaler

NetScaler fulfils not only all the functionality in Forefront Threat Management Gateway, but adds many additional features to optimise, protect and scale web-based applications. One of the principal uses of NetScaler is to front-end applications such as Microsoft Lync, SharePoint and Exchange in enterprise data center of all sizes. But the most customers have used TMG to provide secure access to Exchange for e-mail syncing.

Here is a document which describes what’s possible with NetScaler including a nice feature matrix. But there is no step-by-step or best practice guide to configure the NetScaler to load balance Exchange and to have authentication configured correctly for all services. So I will share my personal experience. With this guide you should be able to configure a NetScaler for external E-Mail access with authentication and SSO to the CAS.

Prerequisites

Setup the LB-Vservers
  • Create for each Exchange server a “Server-Object” under Load Balancing
  • Create for each Exchange service a custom Monitor
  1. /owa (Outlook Web Access)
  2. /ecp (Exchange Control Panel)
  3. /ews (Exchange Web Service)
  4. /Microsoft-Server-ActiveSync (ActiveSync Service for Mobile Mail clients)
  5. /oab (Offline Address Book)
  6. /rpc (Outlook Anywhere or RPC over HTTPS)
  7. /Autodiscover (Autodiscover Service)

  • Create for each Exchange service a “Service Group-Object” and bind the Server-Objects and the appropriate monitor to it

Setup Authentication and AAA-TM Policies

Some settings refer to a post in the Citrix forum that with HTTPOnly Cookie “Yes” some Android native e-mail clients have problems to sync mails.

   

Configure authentication on the LB-Vservers

Configure Redirection to /owa policy

Create the CS-Vserver

With this information you should be able to set up a NetScaler for TMG Replacement and Exchange 2013. This configuration is also applicable for Exchange 2010. Unfortunately there are no specific monitoring service like in the 2013 Server.

Here are the ns.config snips for this configuration:

ns.conf_tmg

Thanks to Rafyel Brooks, who has done a great job, we have now a guide to use Certificate based authentication and  SSO with Kerberos Constrained Delegation

How to configure Citrix NetScaler for Client Certificate Based Authentication with KCD SSO for ActiveSync v1.1

Exit mobile version