08.如何在Windows Server 2016中安装和配置安全的远程访问(VPN)



在本视频中,我将向您展示如何在Windows Server 2016上安装和配置安全(SSTP)远程访问VPN。此配置需要SSL证书进行部署,但可以保证更好的安全性。

SSTP要求:

1.域控制器。
2.服务器认证证书的认证中心。您可以使用内部CA或外部CA。
3.允许在防火墙上使用端口443,并将其转发到内部服务器。
4.坐下来,放松并享受您的安全VPN服务器。 。

39 comments
  1. can you please explane how to make the NLB Web Server templates…because other wise the guide stops because we dont have that step… 🙁 so we cant click a long with you..

  2. quick question, i have deployed DA&VPN. So now its complete different to this, but from da console i can deploy de corp network client and install this on the workstation machine. the question is i need to add those allowed user to any secgroup? because the secGroup in DA was only for machines (so they are machines on the same domain) but what happen if i got a standalone machine? how can i configur that user to use his home machine on that DA&VPN server? thanks in advance.

  3. hi thanx for vids. ,im preparing for my mcsa 70-741 would u recommend this 11 vids to my success in exam?is there any further,for 70-740 i followed ur vids n dumps. anything else would help my exam? any websites like 9tut for ccna? pls give guidance

  4. i have a problem, we created the certificate but you never installe dit on the client pc. I've tried conecting to the vpn, but it gives ou a certificate error (doensnt even ask for it)

  5. Amazing quality videos. Love them. Thanks
    By the way. Seems like Microsoft doesn't have BGInfo anymore? Can you zip up the one you have or had and link it? Would be highly appreciated!

    And in Cisco Anyconnect Secure Mobility Client I get Connection Attempt has failed
    It does find the server, tells me it's insecure and all. But doesn't connect after clicking connect anyways. Is it not supported?

  6. Please i need help. I installed active directory and DNS and i integerated with DNS. When i write nslookup command in cmd it returned local host and ::1 dns instead of domain name and its IP. i tried everything with firewall and i went to the properties of dns server and in the interface i only select the ip but still no use. In the event viewer of DNS its giving error that dns cannot open connection with my static ip plz help.

  7. Good video. The only thing is that you never set your NPS server when you configured your VPN server in Routing and Remote Access setting section. How your connections to VPN server are being routed to the NPS server if you do not setup Radius Authentication as method under "Security" tab, and leave it as "Windows Authentication." ? Thank you,

  8. great video just i need to know alot of tech guys using different methods i try it but never worked with me so i hope urs method gonna work my system

  9. you cannot request a certificate at this time because no certificate types are available. If you need a certificate, please contact your administrator

  10. How can I add Certificate in Personal? In my server 2012 after selecting Active Directory Enrollment Policy I found any things!

  11. Great Video, keep it up. This is exactly what i need, unfortunately i get an error when trying to configure the vpn server saying "the remote access service could not be started" and my system start working very slow.

    i dont know if my nics are setup properly. the thing is, im not realy sure how they suposed to be set up. would be great if you could share you thoughts about this with me.

    im using Hyper V for my virtual servers
    thank you!

  12. Hey guys, I have posted a video on my channel outlining problems I had and how i fixed them.
    The video will be useful to you if:
    Stuck at creating a Certificate,
    Don't have a Domain Controller,
    Certificate error on connecting to VPN
    Come check out the video, I hope it helps!

  13. When im trying to connect with VPN I got error Unknown host. How can I fix that? My DNS is working I can see it using ipconfig/all and nslookup

  14. There are a few other important things that are missing from the tutorial and needs to be cleared:

    1. Fortunately, you can make FREE certificate to make this work. Open IIS, navigate to your server, and click on "Server Certificates". Head to the right menu bar and select "Create a Self-Signed Certificate". Fill the tasks and your certificate is ready to use.
    2. To make this work, you have to open the 443 port on both windows and your router's firewall.
    3. You have to add a forward lookup zone with the chosen virtual hostname on your DNS server. The one you specified in the IIS binding.

    But desptite these, this is a great and very well detailed tutorial, it worked for me.

  15. Great video thanks. Have you to create the video on how to create the self-signed certificate and show how to do site-site VPN IPsec configuration.
    Thanks again.

  16. Your videos are always informative and enjoyable to watch, i did follow all steps as described however when the client connects he get the following error (The certificate's CN name does not match the passed value).

Comments are closed.