DirectAccess
client
Windows 7, 8, 8.1, 10 must be Enterprise Edition
Must be a domain environment
Communication: IPv6 environment
switch
routing device
DA service composition
AD domain environment
GPO Group Policy
PKI certificate
Name Policy Resolution Table
DNS
DA special point
Client: The client does not need to manually configure any network connection, it can automatically switch between different networks, and can directly access the company's internal resources regardless of any public network environment.
Management: External facing client management
Waiting for external clients to connect to the internal network
Waiting for external clients to connect via VPN or other means
DA can help managers manage directly whether the client is in the internal network or not: GPO push, remote management
IPv4-IPv6 Conversion Protocol
ISATAP
6to4
Teredo
IP-Https
Department attention
A group needs to be created for clients that need to use the DA function, and the clients that need to use the DA function are added to the shuffle
DirectAccess & Web App Proxy will conflict with the current routing and remote access services, and the services must be stopped & disabled
virtual private network
Virtual tunnel through public network
VPN
When accessing resources & when accessing across networks - authentication
During data transmission (across networks) - data encryption
Authentication Protocol
Microsoft
MS-chap-v2 - password based
EAP-Certificate Based
data encryption protocol
PPTP-Plaintext Transmission
L2TP-IPsecVPN
shared key
Certificate
IKEv2-VPN reconnection (the client will automatically maintain the current VPN connection when switching networks)
SSTP - Secure Transport over Single Port (443)
Authentication method
VPN support
VPN Server Workgroup Status - Local User
VPN Server Domain Environment - Domain User
VPN+NPS
NPS network authentication (RADIUS server)
VPN server (RADIUS client)
Client VPN broadcast
CMAK Toolkit - Centralized configuration file for client VPN playout
Group Policy - Deploy Client VPN Configurations in Bulk