Module 6: Configuring and Troubleshooting Routing and Remote Access
Module 6: Configuring and Troubleshooting Routing and Remote Access
and Troubleshooting
Routing and Remote
Access
Module Overview
• Configuring Network Access
Health
Registration
Authority
Internet
NAP Health
DHCP Server
Perimeter Intranet Policy Server
Network
Restricted
Network
Remediation
NAP Client with
Servers
limited access
What Is the Network Policy and Access Services Role?
Component Description
Network Policy Server The Microsoft implementation of RADIUS
Server and proxy
Authentication:
Authorization:
PAP Uses plaintext passwords. Typically The least secure authentication protocol.
used if the remote access client and Does not protect against replay attacks,
remote access server cannot negotiate remote client impersonation, or remote
a more secure form of validation. server impersonation.
• Configuration Requirements
Corporate Headquarters
Large Branch Office
VPN Server
VPN Server
VPN Server
Medium Branch Office
VPN
Home Office with
VPN Client
VPN Server
Remote User with VPN Client
Components of a VPN Connection
Virtual Network
Authentication
IP Configuration
Domain Controller
DHCP Server
Tunneling Protocols for a VPN Connection
Encrypted
PPTP:
PPP frame
L2TP:
PPP payload
IP UDP L2TP PPP
(IP diagram, IPX datagram,
header header header header
NetBEUI frame)
PPP frame
L2TP frame
UDP message
SSTP
:
• Encapsulates PPP frames in IP datagrams, and uses port 443 (TCP)
for tunnel management and PPP data frames
• Encryption is performed by the SSL channel of the HTTPS protocol
Configuration Requirements
WAN Options:
Telephone, ISDN,
X.25, or ATM Dial-Up Client
Domain
Controller
Authentication
DHCP
Server Address and Name Server Allocation
Lesson 3: Overview of Network Policies
• What Is a Network Policy?
• Conditions
• Constraints
• Settings
Process for Creating and Configuring a
Network Policy
STAR
T
Yes No
Go to next
Are there Does connection policy
No policies to Yes attempt match
process? policy conditions?
Yes Is the remote access
permission for the user
account set to Deny Access?
No
Reject
No Yes connecti
on
Reject Is the remote attempt
access Is the remote access
connection Yes No permission on the
permission for
attempt the user policy set to Deny
account set to remote access
Yes
permission? Accept
Allow Access? connectio
n
No Does the connectionattempt
attempt match the
user object and
profile settings?
Lesson 4: Overview of the Connection Manager
Administration Kit
• What Is the Connection Manager Administration Kit?
Command Description
Ipconfig Displays current TCP/IP network configuration
values, updates, or releases; DHCP allocated
leases; and used to display, register, or flush DNS
names
Ping Sends ICMP Echo Request messages to verify that
TCP/IP is configured correctly and that a TCP/IP
host is available
Pathping Displays a path of a TCP/IP host and packet losses
at each router along the way
Tracert Displays the path of a TCP/IP host
Authentication and Accounting Logging
Logon information
Virtual machine 6421A-NYC-DC1,
6421A-NYC-SVR1 and
6421A-NYC-CL1
User name Administrator
Password Pa$$w0rd
• Best Practices
• Tools
Notes Page Over-flow Slide. Do Not Print Slide.
See Notes pane.