Re: OWA 2003 (NLB/Round Robin)



NLB has built in session affinity which you do not get with round robin.
Round robin merely distributes the requests to the number of servers that
are defined in the DNS zone.

Session affinity will maintain contact with the same server for the duration
of the session.

/Simon
"Steve" <Steve@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:5B8B25DE-14B4-49DD-AE46-CF9556518FB2@xxxxxxxxxxxxxxxx
I used DNS Round Robin as a method to balance between (2) 2003 OWA FE
Servers. Users almost immediately complained about being kicked out of
OWA.

Errors: unable to authenticate / session has expired

One posting I read was forms-based authentication (that I use) could/is at
the center of the problem

_________________________________________________________

Forms-Based Authentication
In forms-based authentication, users are directed to a Hypertext Markup
Language (HTML) form. After the user provides credentials in the form, the
system issues a cookie containing a ticket. On subsequent requests, the
system first checks the cookie to verify if the user was already
authenticated, so that the user does not have to supply credentials again.
Advantages of forms-based authentication include the following:
Credential information is not cached on the client computer. This is
particularly important in a scenario where users are connecting to your
Outlook Web Access server from public computers. Users are required to
reauthenticate if they close the browser, log off from a session, or
navigate
to another Web site.
. You can configure a maximum idle session time-out, so that if a user is
idle for a prolonged period of time, the session expires, and
reauthentication is required.
. Users cannot use the Remember my password option in Internet Explorer.
. Outlook Web Access includes optional functionality that allows a user to
change the password. If a user changes the password during an Outlook Web
Access session, the cookie provided after the user initially logged on
will
no longer be valid. When forms-based authentication is configured on ISA
Server, the user who changes the password during an Outlook Web Access
session will receive the logon page the next time a request is made.
In an ISA Server 2004 Enterprise Edition scenario involving multi-server
ISA
Server arrays, you must ensure that client requests for a particular
session
are handled by the same array member, so that the client's cookie is
recognized. If the request is received by a different member, the cookie
will
not be recognized and the request will be dropped by that ISA Server
member.
An effective way to ensure that the requests are handled by the same
server
member is to enable integrated Network Load Balancing (NLB) on the ISA
Server
array. For more information, see Appendix A: Configuring NLB on the ISA
Server Array
___________________________________________________________

If formed based authentication is the cause, if I switch to nlb will I
still
experience issues because I don't use ISA.

DNS round robin has been removed and owa is acting as 1 fe server and
users
aren't having the problems.

Please comment on using dns round robin and nlb (without isa), trying to
balance the owa between (2) fe servers.

Thanks.



.



Relevant Pages

  • Re: encrypt password for webservices
    ... Requests can be multi-threaded, and some requests can even be droped if ... By associating a session with an IPrincipal object, ... > Client generates a session key and sends it to the server encrypted ... congratulations on getting a grip on security and encryption. ...
    (microsoft.public.dotnet.security)
  • Re: $_SESSION problem - page reload creates new Session ID
    ... > set on a page just viewed because there is a new session created ... As fas as the server is concerned all requests are independant. ... cookie back to the server. ...
    (comp.lang.php)
  • Re: Multiple Terminal Servers Load Balancing
    ... If you use Session Directory and NLB sessions will be split evenly between ... Windows Server System ... I have already set up Terminal Services Roaming ...
    (microsoft.public.windows.terminal_services)
  • Re: RWW Timing
    ... I understand that you want to monitor when and how ... > to an internal Windows XP or Terminal Server computer. ... SBS creates a connection to the internal client on port 3389 which is ... But it can not tell which one session from the RWW, ...
    (microsoft.public.windows.server.sbs)
  • Re: Restricting TS USers
    ... MCSE, CCEA, Microsoft MVP - Terminal Server ... Terminal Services and Microsoft Windows Server 2003 Service Pack ... the remote session does not end immediately. ...
    (microsoft.public.windows.terminal_services)