wesleyw Posted September 24, 2018 Posted September 24, 2018 Hi, I was wondering if I could get any help at all on Always on VPN, I've been reading several articles/'blogs about the technology and deploying it. From what I can see it revolves around 2 servers a VPN server in your DMZ (between Perimeter firewall and internal firewall) and an NPS server on your Corp network. This is where I get stuck as all the articles talk about auto-enrolment of certificates for the NPS and VPN servers but the VPN Servers aren't part of the corp domain and as such cannot be auto enrolled. So I have some questions if anyone could answer them that would be great. The VPN Server in the DMZ needs two Network Interfaces one for the Public facing Perimeter and 1 Internally to talk with the NPS server? We already have DirectAccess working fine does Always on VPN use different Certificates (It doesn't look like it) if so can I just use these for the Clients (Windows 10 PCs)? If I just create a 2 year Certificate for the VPN server and manually update it when it needs to be will that suffice instead of having it on the internal domain? Does anyone have a in depth guide available that could talk me through some of gotchas are sure to come up and a step by step how to at all? Wes
Norphy Posted September 24, 2018 Posted September 24, 2018 Have you read this: https://docs.microsoft.com/en-us/windows-server/remote/remote-access/vpn/always-on-vpn/deploy/always-on-vpn-deploy-deployment There is a bit in there which covers putting a certificate onto the RRAS server.
wesleyw Posted September 24, 2018 Author Posted September 24, 2018 Yes unfortunately so. What it asks is fine if the vpn server in on the internal domain not the dmz.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now