In addition, if client user certificate authentication (clientTLS authentication using X509 user certificates) is required, ...

In addition, if client user certificate authentication (clientTLS authentication using X509 user certificates) is required, AD FS in %BRAND_WINDOWS_SHORT% Server 2012 R2 requires that TCP port 49443 be enabled inbound on the firewall between the clients and the WAP. This isn't required on the firewall between the WAP and the federation servers.