Windows server 2016 network services (six)

DirectAccess

client

Windows 7, 8, 8.1, 10 must be Enterprise Edition

Must be a domain environment

Communication: IPv6 environment

switch

routing device

DA service composition

AD domain environment

GPO Group Policy

PKI certificate

Name Policy Resolution Table

DNS

DA special point

Client: The client does not need to manually configure any network connection, it can automatically switch between different networks, and can directly access the company's internal resources regardless of any public network environment.

Management: External facing client management

Waiting for external clients to connect to the internal network

Waiting for external clients to connect via VPN or other means

DA can help managers manage directly whether the client is in the internal network or not: GPO push, remote management

IPv4-IPv6 Conversion Protocol

ISATAP

6to4

Teredo

IP-Https

Department attention

A group needs to be created for clients that need to use the DA function, and the clients that need to use the DA function are added to the shuffle

DirectAccess & Web App Proxy will conflict with the current routing and remote access services, and the services must be stopped & disabled

virtual private network

Virtual tunnel through public network

VPN

When accessing resources & when accessing across networks - authentication

During data transmission (across networks) - data encryption

Authentication Protocol

Microsoft

MS-chap-v2 - password based

EAP-Certificate Based

data encryption protocol

PPTP-Plaintext Transmission

L2TP-IPsecVPN

shared key

Certificate

IKEv2-VPN reconnection (the client will automatically maintain the current VPN connection when switching networks)

SSTP - Secure Transport over Single Port (443)


Authentication method

VPN support

VPN Server Workgroup Status - Local User

VPN Server Domain Environment - Domain User

VPN+NPS

NPS network authentication (RADIUS server)

VPN server (RADIUS client)

Client VPN broadcast

CMAK Toolkit - Centralized configuration file for client VPN playout

Group Policy - Deploy Client VPN Configurations in Bulk


Guess you like

Origin http://43.154.161.224:23101/article/api/json?id=324601267&siteId=291194637