This section explains how to create a reverse proxy to protect the name and IP address of your Web server from being exposed to users. Section 2.3, Configuring the Protected Resource for Authentication builds on this configuration and explains how to require authentication to gain access to the Web server.
Table 2-2 Access Gateway Configuration Information
What You Need To Know |
Example |
Your Value |
|
---|---|---|---|
Name of the Identity Server cluster |
idpa |
_______________________ |
|
DNS name of the Access Gateway |
lag.test.novell.com |
_______________________ |
|
Web server information |
|
|
|
IP address |
10.10.16.16 |
_______________________ |
|
DNS name |
digital.test.novell.com |
_______________________ |
|
Names you need to create |
|
|
|
|
Reverse proxy name |
DigitalAirlines |
_______________________ |
|
Proxy service name |
DA |
_______________________ |
|
Protected resource name |
everything |
_______________________ |
For more information, see |
In the Administration Console, click
> .Click
, then click .Configure a reverse proxy:
To configure a proxy service, click
in the Proxy Service section, then fill in the following fields:Proxy Service Name: DA
In Table 2-2, DA is the sample proxy service name.
Published DNS Name: lag.test.novell.com
In Table 2-2, this is the sample DNS name of the Access Gateway.
Web Server IP Address: 10.10.16.16
In Table 2-2, this is the sample IP address of the Web server.
Host Header: Select the
from the drop-down list.Web Server Host Name: digital.test.novell.com
In Table 2-2, this is the sample DNS name of the Web server.
Click
, then configure a protected resource.Click the
tab.In the everything.
section, click , then specifyIn Table 2-2, everything is the sample protected resource name.
In the
section, examine the path. It should be set to /* to match everything on the Web server.Click
to save the configuration.Click the
task, then click .Wait for the health status to turn green. If it doesn’t turn green, click the
icon to discover the cause.If the Access Gateway cannot connect to the Web server, verify the IP address of the Web server.
Use the ping command to verify that the Access Gateway can communicate with the Web server and the Identity Server.
Verify that the Access Gateway can resolve the DNS name of the Identity Server.
For other problems, see Monitoring the Health of an Access Gateway
in the NetIQ Access Manager 3.2 SP2 Access Gateway Guide.
Click the
task, then click .To test that the Access Gateway is protecting the Web server, open a browser and enter the following URL:
http://lag.test.novell.com:80/
The first page of the Web server is displayed. If you get an error, verify the following:
Check the times on the Access Gateway and the Identity Server. Their times need to be synchronized.
Verify that the browser machine can resolve the DNS name of the Access Gateway.