Top Banner
Microsoft ® Jump Start M6: Implementing DirectAccess Rick Claus | Technical Evangelist | Microsoft Ed Liberman | Technical Trainer | Train Signal
22
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: 20417A_06.pdf

Microsoft® Jump Start

M6: Implementing DirectAccess

Rick Claus | Technical Evangelist | Microsoft

Ed Liberman | Technical Trainer | Train Signal

Page 2: 20417A_06.pdf

Jump Start Target Agenda | Day One

Day 1 Day 2

Module 1: Installing and Configuring

Servers Based on Windows Server

2012

Module 7: Implementing Failover

Clustering

Module 2: Monitoring and

Maintaining Windows Server 2012

Module 8: Implementing Hyper-V

Module 3: Managing Windows Server

2012 by Using PowerShell 3.0

Module 9: Implementing Failover

Clustering with Hyper-V

- MEAL BREAK - - MEAL BREAK -

Module 4: Managing Storage for

Windows Server 2012

Module 10: Implementing Dynamic

Access Control

Module 5: Implementing Network

Services

Module 11: Implementing Active

Directory Domain Services

Module 6: Implementing Direct Access Module 12: Implementing Active

Directory Federation Services

Page 3: 20417A_06.pdf

Module Overview

•Overview of DirectAccess

• Installing and Configuring DirectAccess

Components

Page 4: 20417A_06.pdf

Problems with Remote Connections

What are the

challenges you face

when implementing

remote connections?

VPN connects remote users to the network

DirectAccess extends the network

to the remotely-connected

computers and users

Page 5: 20417A_06.pdf

What Is DirectAccess?

Connects automatically to the corporate network over the public network

Uses various protocols, including HTTPS, to establish IPv6 connectivity

Supports selected server access and IPSec authentication

Supports end-to-end authentication and encryption

Supports management of remote client computers

Allows remote users to connect directly to intranet servers

Features of DirectAccess

Always-on connectivity

Seamless connectivity

Bidirectional access

Manage-out Support

Improved security

Integrated solution

Benefits of DirectAccess

DirectAccess

server

Page 6: 20417A_06.pdf

What’s New in DirectAccess in Windows Server 2012

• Improved DirectAccess Management:

– Rich monitoring of client computers

– DirectAccess and RRAS coexistence

– Accounting and reporting

– Windows PowerShell and Server Core support

– Unified management wizard and tools

Page 7: 20417A_06.pdf

What’s New in DirectAccess in Windows Server 2012

• Simplified DirectAccess Management:

– Express setup for small and medium deployment

– Works with existing infrastructure

– IPv6 for internal network is not required

– Single NIC adapter

– Single IP address

Page 8: 20417A_06.pdf

What’s New in DirectAccess in Windows Server 2012

• Performance and Scalability:

– Support for high availability and external load balancers

– Improved support for Receive Site Scaling (RSS) running

in virtual machines

– IP-HTTPS interoperability and performance

improvements

– Lower bandwidth utilization

– Streamlined encryption

Page 9: 20417A_06.pdf

What’s New in DirectAccess in Windows Server 2012

•New Deployment Scenarios:

– Deploy multiple endpoints through the world

– Global unified management through single console

– Deploy a server behind a NAT

– Support for one-time password and virtual smart cards

– Off premise provisioning

Page 10: 20417A_06.pdf

DirectAccess Components

Internet websites

DirectAccess server

AD DS domain controller

DNS server

Internal network resources Network location

server

PKI deployment

IPv6/IPsec

External client computers

NRPT/ Connection security rules

Internal client computers

Page 11: 20417A_06.pdf

• Table that defines DNS servers for different

namespaces and corresponding security settings – NRPT is used before the adapter’s DNS settings

•Using NRPT – DNS servers can be defined for each DNS namespace

rather than for each interface

– DNS queries for specific namespaces can be optionally

secured by using IPSec

Name Resolution Policy Table (NRPT)

Page 12: 20417A_06.pdf

Name Resolution Policy Table (NRPT)

Page 13: 20417A_06.pdf

Internet websites

DirectAccess server

AD DS domain controller

DNS server

Internal client computers

Internal network resources

Internet websites

DirectAccess server

Internal client computers

AD DS domain controller

DNS server

CRL dist point

Network location server

How DirectAccess Works for Internal Client Computers

Connection security rules

NRPT

Page 14: 20417A_06.pdf

DirectAccess server

AD DS domain controller

DNS server

Connection security rules

NRPT

External client computers

DNS server

Internal network resources

How DirectAccess Works for External Client Computers

DirectAccess server

AD DS domain controller

DNS server

Connection security rules

NRPT

External client computers

DNS server

Internal network resources

Internet websites

DirectAccess server

AD DS domain controller

DNS server

Connection security rules

NRPT

External client computers

DNS server

Internal network resources

DirectAccess server

AD DS domain controller

DNS server

Connection security rules

NRPT

External client computers

DNS server

Internal network resources

Page 15: 20417A_06.pdf

Prerequisites for Implementing DirectAccess

Active Directory

Group Policy

IPv6 and transition

technologies

IPv6

ICMPv6 Echo

Request traffic

ICMPv6

IPsec policies

PKI

DirectAccess

server

DNS and domain

controller

Page 16: 20417A_06.pdf

Process of Configuring DirectAccess

To configure DirectAccess:

1. Configure the AD DS domain controller and DNS

2. Configure the PKI environment

3. Configure the DirectAccess server

4. Configure the DirectAccess clients and test

intranet and Internet access

Page 17: 20417A_06.pdf

DEMO: Configuring AD DS and Network Services for DirectAccess

• In this demonstration, you will see how to configure

AD DS, PKI, and network services for DirectAccess

Page 18: 20417A_06.pdf

DEMO: Configuring the DirectAccess Server

• In this demonstration, you will see how to configure a

DirectAccess server

Page 19: 20417A_06.pdf

Demonstration: Configuring the DirectAccess Client

• In this demonstration, you will see how to configure a

DirectAccess client

Page 20: 20417A_06.pdf

Windows 7 vs. Windows 8 Client Implementation

• Includes an in-box user

interface for

DirectAccess

troubleshooting

• Automatically choose a

site in multisite

deployment

• Can be used in

deployments that does

not require full PKI

implementations

WINDOWS 8 WINDOWS 7

• No tool from the client

site for monitoring

user interface for

DirectAccess

• Needs to be setup

manually for selected

site in multisite

deployment

• Needs certificate

Page 21: 20417A_06.pdf

Lab Review

•Why would you use a GPO to configure certificate

deployment?

•How do you install the DirectAccess feature?

Page 22: 20417A_06.pdf