Setting up A Dial In Remote Authentication Server


hey ms guru's,

have ms domain 2 dcs running in server 2003 native mode client machines running xp sp3. have 5 laptops have wireless aircards/modems in them leave office regularly. staff want able access shares/resources on server home , other locations. no 1 uses roaming profiles (and i'd prefer keep way if possible) , documents redirected shares on server using gpos. after doing research believe want setup ipsec/l2tp tunnel between them , (i think) rras/ias server can securely dial in , authenticated on our network. plan setup authentication first check pki key , authenticate user in ad. have been googling hours looking white papers on setting rras server , ias server coming little short. here questions....

have links white papers on setting rras server , ias server , integrating ad domain (aka user accounts needed in ad etc) , how rras , ias work complete dial in process , authentication?

while rras , ias can run on same server smart keep them (security wise) or better have ias running on dc , rras running on separate server?

should place rras(and possibly ias) on external ip , try harden box as possible or should setup nat policy on fortigate 60 pass authentication through rras server (also routers available can authenticate dial in instead of passing through either through pki or tying ad login information/what feature called on router?)

there max number of clients can attached ias/rras server @ 1 time?

i have read cover cover mark minasi's mastering server 2003 ias isn't touched on (only rras). have book recommend?

any appreciated, , if think have overlooked please include it!

ryan

hi ryan,

 

thanks post here.

 

after reading post understand want acquire articles , suggestions implement ipsec/l2tp vpn service in network.

if misunderstand please let me know.

 

i have listed articles refer,  please take time read , answer question , understand how design ,deploy , maintain ipsec/l2tp vpn system.

 

virtual private networking ipsec

http://technet.microsoft.com/en-us/library/cc775944(ws.10).aspx

 

administrator's guide microsoft l2tp/ipsec vpn client

http://technet.microsoft.com/en-us/library/bb742553.aspx

 

planning security vpn

http://technet.microsoft.com/en-us/library/cc786771(ws.10).aspx

 

deploying internet authentication service (ias)

http://technet.microsoft.com/en-us/library/cc783725(ws.10).aspx

 

hope that’s helpful

 

tiger li


please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread.


Windows Server  >  Network Access Protection



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client