Implementing Always On VPN : Modern Mobility with Microsoft Windows 10 and Windows Server 2022 🔍
Richard M. Hicks;(auth.)
Apress L. P.; Apress, 1st edition, Erscheinungsort nicht ermittelbar, 2021
English [en] · PDF · 19.6MB · 2021 · 📘 Book (non-fiction) · 🚀/lgli/lgrs/nexusstc/zlib · Save
description
Keine Beschreibung vorhanden.
Erscheinungsdatum: 26.11.2021
Erscheinungsdatum: 26.11.2021
Alternative filename
nexusstc/Implementing Always On VPN: Modern Mobility with Microsoft Windows 10 and Windows Server 2022/0a796de257539ad35123230a42389af0.pdf
Alternative filename
lgrsnf/701.pdf
Alternative filename
zlib/Computers/Microsoft Windows/Richard M. Hicks/Implementing Always On VPN: Modern Mobility with Microsoft Windows 10 and Windows Server 2022_18209142.pdf
Alternative author
Hicks, Richard M.
Alternative publisher
Apress, Incorporated
Alternative publisher
Springer Nature
Alternative publisher
Springer Apress
Alternative edition
1st ed. 2022, Berkeley, CA, Berkeley, CA, 2022
Alternative edition
United States, United States of America
Alternative edition
Springer Nature, [New York, NY], 2022
Alternative edition
lieu de publication inconnu, 2022
Alternative edition
New York, 2021
Alternative edition
1, 20211125
metadata comments
{"edition":"1","isbns":["1484277406","1484277414","9781484277409","9781484277416"],"last_page":357,"publisher":"Apress"}
Alternative description
Table of Contents
About the Author
About the Technical Reviewer
Acknowledgments
Introduction
Chapter 1: Always On VPN Overview
VPN
DirectAccess
Demise of DirectAccess
DirectAccess Replacement
Always On VPN
Always On VPN Infrastructure
Routing and Remote Access Service
Network Policy Server
Infrastructure Independent
Modern Management
Cloud Integration
Summary
Chapter 2: Plan for Always On VPN
VPN Server
Windows Server
Domain Join
Server Core
Network Interfaces
Network Placement
IPv6
Non-Microsoft VPN Devices
IKEv2
Windows Store Client
Authentication Server
Windows Server
PKI
VPN Protocols
IKEv2
SSTP
L2TP
PPTP
Certificates
SSTP
IKEv2
NPS
User Authentication
Device Authentication
TPM
VPN Client IP Addressing
DHCP
Static Pool
Address Range
IPv4 Subnet
IPv6 Prefix
Split vs. Force Tunneling
Split Tunnel
Force Tunnel
Firewall Configuration
IKEv2
SSTP
NAT Configuration
Client Provisioning
Microsoft Endpoint Manager
PowerShell
MECM
Co-management
Summary
Chapter 3: Prepare the Infrastructure
Security Groups
Certificates
Certificate Templates
VPN Server
NPS Server
User Authentication
Device Authentication
Kerberos Authentication
Issue Certificate Templates
Issuing CA Servers
Certificate Autoenrollment
Autoenrollment GPO
Summary
Chapter 4: Configure Windows Server for Always On VPN
Network Policy Server
Preparation
Install NPS
Configure NPS
RADIUS Client
Network Policy
Routing and Remote Access Service Server
Preparation
Network Configuration
Single NIC
Dual NIC
External Interface
Internal Interface
Static Routes
Certificates
IKEv2 IPsec Certificate
Server GUI Domain-Joined
Server GUI Non-Domain Joined
Export CA Certificates
Import CA Certificates
Generate CSR
Request Certificate
Server Core Domain-Joined
Create INF File
Create CSR
Server Core Non-Domain Joined
SSTP Certificate
Install RRAS
Install RSAT
Windows Server
Windows 10
Configure RSAT
Configure RRAS
Optimize RRAS
IKEv2 Settings
IPsec Parameters
IKEv2 Fragmentation
IKEv2 Root Certificate
IKEv2 CRL Check
TLS Configuration
Summary
Chapter 5: Provision Always On VPN Clients
Validation Testing
Verify Certificates
Test Profile
VPN Settings
Authentication Settings
Network Settings
Routing
IPsec Policy
Test Connection
SSTP
IKEv2
Device Authentication
Profile Deployment
Microsoft Endpoint Manager
Profile Configuration
User Tunnel
Device Tunnel
Additional Configuration
Custom XML
XML Configuration
Endpoint Manager
PowerShell Script
User Tunnel
Device Tunnel
SCCM
Group Policy
Group Policy Object
Policy Settings
Summary
Chapter 6: Advanced Configuration
Name Resolution Policy Table
Configure NRPT
Proxy Server
Global Explicit Proxy
Global Proxy Autoconfiguration
Namespace Proxy
Caveat
Traffic Filtering
Direction
Application Filtering
Desktop Application Filter
Windows Store Application Filter
SYSTEM Application Filter
LockDown VPN
LockDown Limitations
Configure LockDown VPN
Deleting LockDown VPN
Summary
Chapter 7: Cloud Deployments
Azure VPN Gateway
Advantages
Disadvantages
Requirements
Gateway SKUs
Site-to-Site Compatibility
Azure VPN Gateway Configuration
User Tunnel
NPS Configuration
Gateway Configuration
Client Configuration
Device Tunnel
Root Certificate
Gateway Configuration
Client Configuration
IKEv2 Cryptography
Update Azure VPN IPsec Policy
Update Client Policy
Azure Virtual WAN
Advantages
Disadvantages
Requirements
Azure Virtual WAN Configuration
Virtual WAN Hub
Certificate Authentication
RADIUS Authentication
Point-to-Site Connection
VNet Connection
Client Configuration
Windows Server RRAS
Supportability
Azure RRAS Configuration
Public IP Address
Inbound Traffic
Client IP Subnet
IP Forwarding
Routing
Third-Party VPN in Azure
Summary
Chapter 8: Deploy Certificates with Intune
Deployment Options
PKCS
SCEP
PKCS Certificates
CA Permissions
Certificate Template
Install Certificate Connector for Intune
PKCS Intune Configuration
Export CA Certificates
Deploy CA Certificates
PKCS User Certificate
PKCS Device Certificate
SCEP Certificates
Service Account
CA Permissions
Certificate Template
Install NDES
Configure NDES
Publish NDES
NDES TLS Certificate
Install Intune Certificate Connector
SCEP User Certificate
SCEP Device Certificate
Summary
Chapter 9: Azure MFA Integration
Azure MFA
Is MFA Necessary?
Risk Mitigation
Certificate Authentication
Additional Considerations
Recommendation
Azure MFA with NPS
Requirements
Install NPS Extension
Update RRAS Authentication
Certificate Management
Troubleshooting Script
Azure Conditional Access
Requirements
Configure Azure Conditional Access
VPN Root Certificate
Publish Certificate
Verify Certificates
NPS Configuration
Update NPS Policy
Conditional Access Policy
Create Policy
Client Configuration
Endpoint Manager UI
EAP Configuration
Custom XML
Third-Party MFA
Summary
Chapter 10: High Availability
VPN High Availability
Prerequisites
Windows NLB
Limitations
Configure NLB
Create NLB Cluster
Add Cluster Nodes
Server Core
External Load Balancer
External Load Balancer Configuration
NPS High Availability
Prerequisites
Update Client Configuration
Update VPN Configuration
NPS Load Balancing
DNS Alias
External Load Balancer
Certificate Configuration
Geographic Load Balancing
Azure Traffic Manager
Azure Traffic Manager and IKEv2
Azure Traffic Manager Profile
Validation Testing
DNS Alias
Summary
Chapter 11: Monitor and Report
RRAS Management Console
Adding Servers
Firewall Requirements
System Health
User Activity
Remote Access Management Console
Overview
System Health
User Activity
Customize Headings
Reporting
PowerShell
System Health
User Activity
Log Files
Disconnecting Sessions
Management Consoles
PowerShell
Permanent Disconnects
User Connections
Device Connections
Summary
Chapter 12: Troubleshooting
Common Error Codes
809
Common Causes
Testing
Port Probe
Network Trace
812
Group Membership
Authentication Type
NPS Communication
Azure Conditional Access
Event Logs
Other Causes
13801
Testing
13806
Missing Client Certificate
Missing Server Certificate
13868
VPN Server
VPN Client
Registry Setting
NPS Configuration
853
Missing Certificate
858
864
Certificate Assignment
Root Certificate
798
Permissions
TPM
Other Known Issues
Clients Prompted for Authentication
RRAS Service Won’t Start
Load Balancing and NAT
SSTP Connect/Disconnect
Custom Cryptography Settings Ignored
Summary
Index
About the Author
About the Technical Reviewer
Acknowledgments
Introduction
Chapter 1: Always On VPN Overview
VPN
DirectAccess
Demise of DirectAccess
DirectAccess Replacement
Always On VPN
Always On VPN Infrastructure
Routing and Remote Access Service
Network Policy Server
Infrastructure Independent
Modern Management
Cloud Integration
Summary
Chapter 2: Plan for Always On VPN
VPN Server
Windows Server
Domain Join
Server Core
Network Interfaces
Network Placement
IPv6
Non-Microsoft VPN Devices
IKEv2
Windows Store Client
Authentication Server
Windows Server
PKI
VPN Protocols
IKEv2
SSTP
L2TP
PPTP
Certificates
SSTP
IKEv2
NPS
User Authentication
Device Authentication
TPM
VPN Client IP Addressing
DHCP
Static Pool
Address Range
IPv4 Subnet
IPv6 Prefix
Split vs. Force Tunneling
Split Tunnel
Force Tunnel
Firewall Configuration
IKEv2
SSTP
NAT Configuration
Client Provisioning
Microsoft Endpoint Manager
PowerShell
MECM
Co-management
Summary
Chapter 3: Prepare the Infrastructure
Security Groups
Certificates
Certificate Templates
VPN Server
NPS Server
User Authentication
Device Authentication
Kerberos Authentication
Issue Certificate Templates
Issuing CA Servers
Certificate Autoenrollment
Autoenrollment GPO
Summary
Chapter 4: Configure Windows Server for Always On VPN
Network Policy Server
Preparation
Install NPS
Configure NPS
RADIUS Client
Network Policy
Routing and Remote Access Service Server
Preparation
Network Configuration
Single NIC
Dual NIC
External Interface
Internal Interface
Static Routes
Certificates
IKEv2 IPsec Certificate
Server GUI Domain-Joined
Server GUI Non-Domain Joined
Export CA Certificates
Import CA Certificates
Generate CSR
Request Certificate
Server Core Domain-Joined
Create INF File
Create CSR
Server Core Non-Domain Joined
SSTP Certificate
Install RRAS
Install RSAT
Windows Server
Windows 10
Configure RSAT
Configure RRAS
Optimize RRAS
IKEv2 Settings
IPsec Parameters
IKEv2 Fragmentation
IKEv2 Root Certificate
IKEv2 CRL Check
TLS Configuration
Summary
Chapter 5: Provision Always On VPN Clients
Validation Testing
Verify Certificates
Test Profile
VPN Settings
Authentication Settings
Network Settings
Routing
IPsec Policy
Test Connection
SSTP
IKEv2
Device Authentication
Profile Deployment
Microsoft Endpoint Manager
Profile Configuration
User Tunnel
Device Tunnel
Additional Configuration
Custom XML
XML Configuration
Endpoint Manager
PowerShell Script
User Tunnel
Device Tunnel
SCCM
Group Policy
Group Policy Object
Policy Settings
Summary
Chapter 6: Advanced Configuration
Name Resolution Policy Table
Configure NRPT
Proxy Server
Global Explicit Proxy
Global Proxy Autoconfiguration
Namespace Proxy
Caveat
Traffic Filtering
Direction
Application Filtering
Desktop Application Filter
Windows Store Application Filter
SYSTEM Application Filter
LockDown VPN
LockDown Limitations
Configure LockDown VPN
Deleting LockDown VPN
Summary
Chapter 7: Cloud Deployments
Azure VPN Gateway
Advantages
Disadvantages
Requirements
Gateway SKUs
Site-to-Site Compatibility
Azure VPN Gateway Configuration
User Tunnel
NPS Configuration
Gateway Configuration
Client Configuration
Device Tunnel
Root Certificate
Gateway Configuration
Client Configuration
IKEv2 Cryptography
Update Azure VPN IPsec Policy
Update Client Policy
Azure Virtual WAN
Advantages
Disadvantages
Requirements
Azure Virtual WAN Configuration
Virtual WAN Hub
Certificate Authentication
RADIUS Authentication
Point-to-Site Connection
VNet Connection
Client Configuration
Windows Server RRAS
Supportability
Azure RRAS Configuration
Public IP Address
Inbound Traffic
Client IP Subnet
IP Forwarding
Routing
Third-Party VPN in Azure
Summary
Chapter 8: Deploy Certificates with Intune
Deployment Options
PKCS
SCEP
PKCS Certificates
CA Permissions
Certificate Template
Install Certificate Connector for Intune
PKCS Intune Configuration
Export CA Certificates
Deploy CA Certificates
PKCS User Certificate
PKCS Device Certificate
SCEP Certificates
Service Account
CA Permissions
Certificate Template
Install NDES
Configure NDES
Publish NDES
NDES TLS Certificate
Install Intune Certificate Connector
SCEP User Certificate
SCEP Device Certificate
Summary
Chapter 9: Azure MFA Integration
Azure MFA
Is MFA Necessary?
Risk Mitigation
Certificate Authentication
Additional Considerations
Recommendation
Azure MFA with NPS
Requirements
Install NPS Extension
Update RRAS Authentication
Certificate Management
Troubleshooting Script
Azure Conditional Access
Requirements
Configure Azure Conditional Access
VPN Root Certificate
Publish Certificate
Verify Certificates
NPS Configuration
Update NPS Policy
Conditional Access Policy
Create Policy
Client Configuration
Endpoint Manager UI
EAP Configuration
Custom XML
Third-Party MFA
Summary
Chapter 10: High Availability
VPN High Availability
Prerequisites
Windows NLB
Limitations
Configure NLB
Create NLB Cluster
Add Cluster Nodes
Server Core
External Load Balancer
External Load Balancer Configuration
NPS High Availability
Prerequisites
Update Client Configuration
Update VPN Configuration
NPS Load Balancing
DNS Alias
External Load Balancer
Certificate Configuration
Geographic Load Balancing
Azure Traffic Manager
Azure Traffic Manager and IKEv2
Azure Traffic Manager Profile
Validation Testing
DNS Alias
Summary
Chapter 11: Monitor and Report
RRAS Management Console
Adding Servers
Firewall Requirements
System Health
User Activity
Remote Access Management Console
Overview
System Health
User Activity
Customize Headings
Reporting
PowerShell
System Health
User Activity
Log Files
Disconnecting Sessions
Management Consoles
PowerShell
Permanent Disconnects
User Connections
Device Connections
Summary
Chapter 12: Troubleshooting
Common Error Codes
809
Common Causes
Testing
Port Probe
Network Trace
812
Group Membership
Authentication Type
NPS Communication
Azure Conditional Access
Event Logs
Other Causes
13801
Testing
13806
Missing Client Certificate
Missing Server Certificate
13868
VPN Server
VPN Client
Registry Setting
NPS Configuration
853
Missing Certificate
858
864
Certificate Assignment
Root Certificate
798
Permissions
TPM
Other Known Issues
Clients Prompted for Authentication
RRAS Service Won’t Start
Load Balancing and NAT
SSTP Connect/Disconnect
Custom Cryptography Settings Ignored
Summary
Index
Alternative description
Implement and support Windows 10 Always On VPN, the successor to Microsoft's popular DirectAccess. This book teaches you everything you need to know to test and adopt the technology at your organization that is widely deployed around the world. The book starts with an introduction to Always On VPN and discusses fundamental concepts along with use cases to compare and contrast it with DirectAccess. You will learn the prerequisites required for implementation and deployment scenarios. The book presents the details of VPN protocols, client IP address assignment, and firewall requirements. Also covered is how to configure Windows Server Routing and Remote Access Service (RRAS) along with performance optimizations. You will go through provisioning Always On VPN to Windows 10 clients. The Configuration Service Provider (CSP) mode is discussed and you will learn to create a configuration XML file and provision it locally using PowerShell. Deploying Always On VPN infrastructure in Microsoft Azure is included, followed by advanced client configuration and integration with Azure security services. You will know how to implement an Always On VPN infrastructure in a redundant and highly available (HA) configuration along with system maintenance and operational support for the VPN and NPS infrastructure. And you will know how to seamlessly troubleshoot and migrate from DirectAccess to Always On VPN. After reading this book, you will be able to plan, design, and implement a Windows 10 Always On VPN solution to meet your specific requirements.What Will You Learn Prepare your infrastructure to support Windows 10 Always On VPN on premises or in the cloud Provision and manage Always On VPN clients using modern management methods such as Intune Understand advanced integration concepts for extending functionality with Microsoft Azure Troubleshoot and resolve common configuration and operational errors for your VPNWho This Book Is For IT professionals and technology administrators for organizations of all sizesAbout the authorsRichard Hicks is the founder and principal consultant at Richard M. Hicks Consulting, Inc. He is a widely recognized enterprise mobility and security infrastructure expert with more than 25 years of experience implementing secure remote access and Public Key Infrastructure (PKI) solutions for organizations around the world. Richard is a former Microsoft Most Valuable Professional (MVP 2009-2019) and is active in the online community, sharing his knowledge and experience with IT professionals on his blog and through various social media channels. Visit his web site https://www.richardhicks.com/ or connect with him on Twitter @richardhicks.
Alternative description
Implement and support Windows 10 Always On VPN, the successor to Microsoft's popular DirectAccess. This book teaches you everything you need to know to test and adopt the technology at your organization that is widely deployed around the world.
The book starts with an introduction to Always On VPN and discusses fundamental concepts and use cases to compare and contrast it with DirectAccess. You will learn the prerequisites required for implementation and deployment scenarios. The book presents the details of recommended VPN protocols, client IP address assignment, and firewall requirements. Also covered is how to configure Routing and Remote Access Service (RRAS) along with security and performance optimizations. The Configuration Service Provider (CSP) is discussed, and you will go through provisioning Always On VPN to Windows 10 clients using PowerShell and XML as well as Microsoft Intune. Details about advanced client configuration and integration with Azure security services are included. You will know how to implement Always On VPN infrastructure in a redundant and highly available (HA) configuration, and guidance for ongoing system maintenance and operational support for the VPN and NPS infrastructure is provided. And you will know how to diagnose and troubleshoot common issues with Always On VPN.
After reading this book, you will be able to plan, design, and implement a Windows 10 Always On VPN solution to meet your specific requirements.
What Will You Learn Prepare your infrastructure to support Windows 10 Always On VPN on premises or in the cloud Provision and manage Always On VPN clients using modern management methods such as Intune Understand advanced integration concepts for extending functionality with Microsoft Azure Troubleshoot and resolve common configuration and operational errors for your VPN
Who This Book Is For
IT professionals and technology administrators for organizations of all sizes
The book starts with an introduction to Always On VPN and discusses fundamental concepts and use cases to compare and contrast it with DirectAccess. You will learn the prerequisites required for implementation and deployment scenarios. The book presents the details of recommended VPN protocols, client IP address assignment, and firewall requirements. Also covered is how to configure Routing and Remote Access Service (RRAS) along with security and performance optimizations. The Configuration Service Provider (CSP) is discussed, and you will go through provisioning Always On VPN to Windows 10 clients using PowerShell and XML as well as Microsoft Intune. Details about advanced client configuration and integration with Azure security services are included. You will know how to implement Always On VPN infrastructure in a redundant and highly available (HA) configuration, and guidance for ongoing system maintenance and operational support for the VPN and NPS infrastructure is provided. And you will know how to diagnose and troubleshoot common issues with Always On VPN.
After reading this book, you will be able to plan, design, and implement a Windows 10 Always On VPN solution to meet your specific requirements.
What Will You Learn Prepare your infrastructure to support Windows 10 Always On VPN on premises or in the cloud Provision and manage Always On VPN clients using modern management methods such as Intune Understand advanced integration concepts for extending functionality with Microsoft Azure Troubleshoot and resolve common configuration and operational errors for your VPN
Who This Book Is For
IT professionals and technology administrators for organizations of all sizes
Alternative description
Implement and support Windows 10 Always On VPN, the successor to Microsoft's popular DirectAccess. This book teaches you everything you need to know to test and adopt the technology at your organization that is widely deployed around the world. The book starts with an introduction to Always On VPN and discusses fundamental concepts and use cases to compare and contrast it with DirectAccess. You will learn the prerequisites required for implementation and deployment scenarios. The book presents the details of recommended VPN protocols, client IP address assignment, and firewall requirements. Also covered is how to configure Routing and Remote Access Service (RRAS) along with security and performance optimizations. The Configuration Service Provider (CSP) is discussed, and you will go through provisioning Always On VPN to Windows 10 clients using PowerShell and XML as well as Microsoft Intune. Details about advanced client configuration and integration with Azure security services are included. You will know how to implement Always On VPN infrastructure in a redundant and highly available (HA) configuration, and guidance for ongoing system maintenance and operational support for the VPN and NPS infrastructure is provided. And you will know how to diagnose and troubleshoot common issues with Always On VPN. After reading this book, you will be able to plan, design, and implement a Windows 10 Always On VPN solution to meet your specific requirements. You will: Prepare your infrastructure to support Windows 10 Always On VPN on premises or in the cloud Provision and manage Always On VPN clients using modern management methods such as Intune Understand advanced integration concepts for extending functionality with Microsoft Azure Troubleshoot and resolve common configuration and operational errors for your VPN
date open sourced
2021-11-25
🚀 Fast downloads
Become a member to support the long-term preservation of books, papers, and more. To show our gratitude for your support, you get fast downloads. ❤️
- Fast Partner Server #1 (recommended)
- Fast Partner Server #2 (recommended)
- Fast Partner Server #3 (recommended)
- Fast Partner Server #4 (recommended)
- Fast Partner Server #5 (recommended)
- Fast Partner Server #6 (recommended)
- Fast Partner Server #7
- Fast Partner Server #8
- Fast Partner Server #9
- Fast Partner Server #10
- Fast Partner Server #11
- Fast Partner Server #12
- Fast Partner Server #13
- Fast Partner Server #14
- Fast Partner Server #15
- Fast Partner Server #16
- Fast Partner Server #17
- Fast Partner Server #18
- Fast Partner Server #19
- Fast Partner Server #20
- Fast Partner Server #21
- Fast Partner Server #22
🐢 Slow downloads
From trusted partners. More information in the FAQ. (might require browser verification — unlimited downloads!)
- Slow Partner Server #1 (slightly faster but with waitlist)
- Slow Partner Server #2 (slightly faster but with waitlist)
- Slow Partner Server #3 (slightly faster but with waitlist)
- Slow Partner Server #4 (slightly faster but with waitlist)
- Slow Partner Server #5 (no waitlist, but can be very slow)
- Slow Partner Server #6 (no waitlist, but can be very slow)
- Slow Partner Server #7 (no waitlist, but can be very slow)
- Slow Partner Server #8 (no waitlist, but can be very slow)
- Slow Partner Server #9 (slightly faster but with waitlist)
- Slow Partner Server #10 (slightly faster but with waitlist)
- Slow Partner Server #11 (slightly faster but with waitlist)
- Slow Partner Server #12 (slightly faster but with waitlist)
- Slow Partner Server #13 (no waitlist, but can be very slow)
- Slow Partner Server #14 (no waitlist, but can be very slow)
- Slow Partner Server #15 (no waitlist, but can be very slow)
- Slow Partner Server #16 (no waitlist, but can be very slow)
- After downloading: Open in our viewer
All download options have the same file, and should be safe to use. That said, always be cautious when downloading files from the internet, especially from sites external to Anna’s Archive. For example, be sure to keep your devices updated.
External downloads
-
For large files, we recommend using a download manager to prevent interruptions.
Recommended download managers: Motrix -
You will need an ebook or PDF reader to open the file, depending on the file format.
Recommended ebook readers: Anna’s Archive online viewer, ReadEra, and Calibre -
Use online tools to convert between formats.
Recommended conversion tools: CloudConvert and PrintFriendly -
You can send both PDF and EPUB files to your Kindle or Kobo eReader.
Recommended tools: Amazon‘s “Send to Kindle” and djazz‘s “Send to Kobo/Kindle” -
Support authors and libraries
✍️ If you like this and can afford it, consider buying the original, or supporting the authors directly.
📚 If this is available at your local library, consider borrowing it for free there.
Total downloads:
A “file MD5” is a hash that gets computed from the file contents, and is reasonably unique based on that content. All shadow libraries that we have indexed on here primarily use MD5s to identify files.
A file might appear in multiple shadow libraries. For information about the various datasets that we have compiled, see the Datasets page.
For information about this particular file, check out its JSON file. Live/debug JSON version. Live/debug page.