当前位置:首页 > CN2资讯 > 正文内容

Setup an SSTP SSL VPN in Windows Server 2012 R2

2天前CN2资讯

So here’s what’s awesome about Secure Socket Tunneling Protocol SSL ×××s: they give your connecting client an IP and make it a full-on part of the network. And this is all done over port 443, a commonly used port which is often enabled on firewalls. SSTP SSL ×××s are not like some fake “SSL ×××s” that just give users a webpage and some sort of RDP.

It’s also relatively easy setup. While there are a lot of tutorials that show how to setup SSTP SSL ×××s using AD CA generated certificates, I strongly suggest you forego that, and just use a globally recognized certificate. This prevents outside users from having to install your CA’s root cert. It also prevents them from having to make a registry change if your CRL is not published and available online. All around, a $5.99 cert that can be obtained in 12 steps is well-worth the time and money invested.

This tutorial will cover how to easily setup an SSTP SSL ××× in Windows 2012 R2 using a legit cert. If you want to use your own domain’s cert, there are other websites that provide step-by-steps. advancedhomeserver.com is my preferred tutorial.

Overall, there are four major steps to this:

  • Install the appropriate certificate

  • Setup Routing and Remote Access

  • Configure NPS (Optional)

  • Setup your client.

  • Install the SSL Certificate

    Step 1

    First, follow my tutorial for getting a legit $5.99 cert, down to creating the .pfx file.

    Step 2

    Import your PFX to the local machine’s Certificate store. To do this, certlm -> Personal -> Certificates -> Right-click, All Tasks -> Import -> Next -> Select your Cert -> Enter your password -> Next -> Finish.

    Install and configure the RRAS role

    Step 1

    Add the Remote Access role. Server Manager -> Manage -> Add Roles and Features ->Remote Access.

    Step 2

    Click Next a couple times, then just click DirectAccess and ×××. DirectAccess seems cool, but it’s only intended for mobile domain-joined computers, which I’m not looking to support.


    Step 3

    Next a couple times. It will force you to install IIS, which is odd, because RRAS can work independently of IIS (you can even stop and disable IIS and RRAS will still work). I would think just the IIS Hostable Web Core would be enough, but whatever. It’s required. Go ahead and accept that it will be installed.

    Step 4

    Once the Role has been installed, click the flag thing at the top, and then Open the Getting Started Wizard.

    Step 5

    Select Deploy ××× Only.

    Step 6

    Once the new window pops up, right click your server name (mine is ××× (local)) thenConfigure and Enable Routing and Remote Access.

    Step 7

    We’re trying to keep our surface area as small as possible, so click on Custom Configuration.

    Step 8

    Next, only check ××× Access.

    Step 9

    The RRAS Sericve will configure itself, and start the service. You will then be returned to the RRAS config window. Right click your server name, then Properties.

    Step 10

    Check that your SSL Certificate binding is the newly installed certificate.

    Step 11

    Next, click on IPv4. Here, you can either do a DHCP forwarding or just give RRAS a few IP addresses to hand out. Click Apply then Okay. You’ll be returned again to the RRAS window.

    At this point, your RRAS server is setup! But I recommend a few more steps.

    If you don’t want to add any additional security (IP restrictions, Group Access to ×××), then you can skip the next section and jump to setting up the client. I find it super interesting, though. I’d give it at least a glance.

    Setup Network Policy Server (Optional)

    Step 1

    Once you’ve returned to the RRAS window, *left-click* Remote Access Logging and Policies. Then right-click and Launch NPS.

    Step 2

    A new Network Policy Server window will pop-up. Here, we can set which users can access the ×××, set the type of authentication encryption, and restrict network access.

    Step 3

    We’ll start by creating a new Network Policy. Right click Network Policy and click New.

    Step 4

    Name your Policy, and select Remote Access Server (×××/Dial-up).

    Step 5

    Leave this window for a moment, go into AD, create a Group and name it ××× Access or whatever you wish, and add some users. Come back, and add that Windows Group by clickingAdd -> Windows Group.

    Step 6

    Confirm and click Next

    Step 7

    Grant this group access.

    Step 8

    Here, you can choose your Authentication Encryption. I disabled all the weaker ones, and only enabled the stronger Microsoft: Secured Password (EAP-MSCHAP v2).

    Step 9

    Here you can set some restrictions if you like. Click Next.

    Step 10

    Click on IP Filter.

    Step 11

    Specify a Filter. I set mine to only allow access to my lab’s subnet.

    Step 12

    Click OK, next, and you’re done setting up NPS!

    There’s more, but I’ll likely cover that later. You can also configure the Network Policy Server which can lock down your network so that only clients with Firewalls enabled and AVs installed will be allowed to connect.

    Setup a Client to Connect

    Step 1

    Log into a Windows machine. SSTP was introduced in Windows Vista, so the OS must be Vista or Greater (or Server 2008 and greater). Go to Network and Sharing Center. Click Setup New Connection or Network.

    Step 2

    Click Connect to a workplace.

    Step 3

    Click Use Internet Connection (×××).

    Step 4

    Fill in your info, and click Don’t connect now; just setup so I can connect later.

    Step 5

    Enter your user information. Don’t forget that if you didn’t setup a Group to access the ××× using NAP, you’ll need to enable Dial-In access within Active Directory Users and Computers for that user.

    Step 6

    We still need to configure a couple more things. Click on your connection -> Properties.

    Step 7

    Click the Security Tab -> Change type of ××× to SSTP. By default, it detects the type of ××× automatically, but slightly slows down the process.

    Also change your authentication as seen below. That’s all you need. Note that, by default, Windows ×××S will use the remote gateway. If you want to modify that, go to Properties -> Networking -> IPv4 -> Advanced -> Uncheck Use Default Gateway on Remote Network.

    Step 8

    Right-click -> Connect.

    Step 9

    Awesome. Poke around ipconfig if you’re interested in seeing your assigned IP, gateway and DNS servers.

    Some final notes

    Don’t forget that you have to expose your ×××’s port 443 at the router. To ensure that things are working, you can also try hitting your ××× server via a browser at https://yourvpn.server.ext. It should return a 404.

    In addition, IIS is not necessary. You can actually stop it, disable the service, and you will still be able to connect to your ×××.

    Enjoy!


    转自:http://blog.netnerds.net/2015/02/setup-an-sstp-ssl-vpn-in-windows-server-2012-r2/

      你可能想看:

      扫描二维码推送至手机访问。

      版权声明:本文由皇冠云发布,如需转载请注明出处。

      本文链接:https://www.idchg.com/info/29540.html

      分享给朋友:

      “Setup an SSTP SSL VPN in Windows Server 2012 R2” 的相关文章

      国外服务器推荐:提升您的在线业务效率的最佳选择

      在如今全球化的时代,选择合适的国外服务器显得尤为重要。互联网的快速发展让许多企业不仅仅局限于当地市场,跨国经营已成为常态。这种趋势使得大量用户开始寻找更为高效、灵活的服务器解决方案,以满足不同地区客户的需求。服务器不仅是维护在线业务的基础设施,还是保证用户体验的关键因素。 选择国外服务器时,不仅需要...

      CentOS 7 如何有效限制服务器带宽

      在CentOS 7系统中,限制服务器带宽不仅关乎到网络性能,更影响到资源的公平利用。网络资源共享在现在的许多应用中显得尤为重要。一旦带宽没有得到合理控制,某些用户或应用可能会消耗过多的网络,导致其他用户受到影响。因此,我深信带宽限制成为了一种有效的网络管理方法。 举个简单的例子,想象一下在公司内网中...

      搬瓦工:性能卓越的VPS服务平台,为您的项目提供最佳选择

      搬瓦工概述 在网上冲浪的时候,大家可能都听说过“搬瓦工”,但对于它的真正含义了解的并不多。搬瓦工(BandwagonHost)是一家以提供虚拟私人服务器(VPS)而闻名的公司,采用KVM架构,深受用户青睐。我在使用搬瓦工的过程中发现,选择这个平台的用户不仅因为它的价格相对较低,还因为它提供的服务非常...

      APT攻击是什么及其防御措施详解

      APT攻击(Advanced Persistent Threat,高级持续性威胁)是一种复杂而长期的网络攻击模式。在我了解这个概念的过程中,逐渐意识到它不仅仅是一种攻击手段,而是一个精密的、组织化的网络战争策略。APT攻击的敌对方通常具备高超的技术能力和丰富的资源,他们的目标是破坏组织的核心设施,或...

      RFCHOST评论:高性能VPS与流媒体解锁的完美选择

      RFCHOST概述 RFCHOST是一家自2015年成立的公司,隶属于上海花卷科技。作为一家新兴的网络服务企业,RFCHOST专注于提供国际线路深层挖掘与构造网络通信服务的一体化解决方案。我一直关注着这个快速发展的品牌,尤其是它在香港和洛杉矶VPS业务上的持续投入与创新。 随着全球数字化进程的加速,...

      NameSilo续费优惠码2024:如何利用优惠码降低域名续费成本

      在域名注册的世界中,NameSilo是一颗璀璨的明珠。成立于2010年的这家公司,迅速赢得了用户的青睐。人们总是追求优质且经济实惠的服务,而NameSilo无疑满足了这一需求。便宜的价格和稳定的服务让它在众多注册商中脱颖而出。 回想起最初使用NameSilo的经历,选择它不仅因为价格的吸引,更多的是...