Implementing Remote Access Security
How to configure which authentication protocols the remote access server should support
- Click Start, Administrative Tools, and then select Routing And Remote Access to open the Routing And Remote Access console.
- In the console tree, right-click the server that you want to configure and then select Properties from the shortcut menu to access the server Properties dialog box.
- Click the Security tab.
- In the Authentication Provider drop-down list box, select Windows Authentication.
- Click Authentication Methods.
- The Authentication Methods dialog box opens.
- You should disable password based authentication by deselecting/clearing the checkboxes for the following authentication methods:
-
- Microsoft Encrypted Authentication (MS-CHAP)
- Encrypted Authentication (CHAP)
- Shiva Password Authentication Protocol (SPAP)
- Unencrypted Password (PAP).
- Enable the following authentication protocols:
-
- Extensible Authentication Protocol (EAP)
- Microsoft Encrypted Authentication Version 2 (MS-CHAPv2)
- Ensure that the Allow Remote Systems To Connect Without Authentication checkbox is not selected.
- Click OK in the Authentication Methods dialog box.
- Click OK in the server Properties dialog box.
How to allow remote access for specific user
- Click Start, Administrative Tools, and then click Active Directory Users and Computers to open the Active Directory Users and Computers management console.
- In the console tree, expand the domain that contains the user account that you want to enable remote access for.
- Select the Users container.
- In the right pane, locate the user account that you want to configure.
- Right-click the specific user account and then select Properties from the shortcut menu.
- The Properties dialog box of the user opens.
- Click the Dial-in tab.
- In the Remote Access Permission area, click the Allow Access option.
- Click OK.
How to allow remote access based on remote access policy
- Click Start, Administrative Tools, and then click Active Directory Users and Computers to open the Active Directory Users and Computers management console.
- In the console tree, expand the domain that contains the user account that you want to enable remote access for.
- Select the Users container.
- In the right pane, locate the user account that you want to configure.
- Right-click the specific user account and then select Properties from the shortcut menu.
- The Properties dialog box of the user opens.
- Click the Dial-in tab.
- In the Remote Access Permission area, click the Control Access Through Remote Access Policy option.
- Click OK.
How to create a remote access policy for a remote access server
- Click Start, Administrative Tools, and then select Active Directory Users and Computers to open the Active Directory Users and Computers management console.
- In the console tree, select the Users container, right-click the user account which you want to configure and then select Properties from the shortcut menu.
- Click the Dial-in tab. Verify that the Remote Access Permission (Dial-in or VPN) option is specified as Control Access Through Remote Access Policy.
- To configure the remote access policy for the remote access server, click Start, Administrative Tools, and then select Routing And Remote Access to open the Routing And Remote Access console.
- In the console tree, expand the server’s node and then right-click Remote Access Policies and select New Remote Access Policy fom the shortcut menu.
- Select the desired policy configuration settings through the various pages of the New Remote Access Policy Wizard.
How to create a remote access policy to authorize access by user
- Click Start, Administrative Tools, and then select Routing And Remote Access to open the Routing And Remote Access console.
- In the console tree, expand the server’s node and then right-click Remote Access Policies and select New Remote Access Policy from the shortcut menu.
- The New Remote Access Policy Wizard starts.
- Click Next on the New Remote Access Policy Wizard Welcome page.
- On the Policy Configuration Method page, click the Use the wizard to set up a typical policy option.
- Enter a name in the Policy name box, and then click Next.
- On the Access Method page, select between the following options and then click Next: Dial-up, VPN, Wireless, Ethernet.
- On the User or Group Access page, click the User option and then click Next.
- On the Authentication Methods page, specify the authentication methods which the policy will accept and then click Next.
- On the Policy Encryption Level page, specify the encryption types and then click Next.
- Click Finish to create the new remote access policy.
How to create a remote access policy to authorize access by group
- Click Start, Administrative Tools, and then select Routing And Remote Access to open the Routing And Remote Access console.
- In the console tree, right-click Remote Access Policies and then select New Remote Access Policy from the shortcut menu.
- The New Remote Access Policy Wizard starts.
- Click Next on the New Remote Access Policy Wizard Welcome page.
- When the Policy Configuration Method page appears, select the Use the wizard to set up a typical policy option.
- Enter a name in the Policy name box, and then click Next.
- On the Access Method page, select between the following options and then click Next: Dial-up, VPN, Wireless or Ethernet.
- On the User or Group Access page, select the Group option and then click Add to specify the group name.
- Using the Enter the object names to select box, specify the group and then click OK.
- Click Next on the User or Group Access page.
- On the Authentication Methods page, specify the authentication methods which the policy will accept and then click Next.
- On the Policy Encryption Level page, specify the encryption types and then click Next.
- Click Finish to create the new remote access policy.
How to create a remote access policy that allows domain users remote access only through VPN connections
- Click Start, Administrative Tools, and then click Routing and Remote Access to open the Routing and Remote Access console.
- In the console tree, click Remote Access Policies, click the Action menu, and then select the New Remote Access Policy command.
- The New Remote Access Policy Wizard starts.
- Click Next on the initial page of the New Remote Access Policy Wizard.
- On the Policy Configuration Method page, select the Use The Wizard To Set Up A Typical Policy For A Common Scenario option.
- In the Policy Name field, enter a meaningful name that describes the purpose of the remote access policy. Click Next.
- On the Access Method page, select VPN, Use For All VPN Connections. Click Next
- When the User Or Group Access page opens, select the Group option and then click the Add button.
- The Select Groups dialog box opens.
- In the Enter The Object Names To Select field, enter Domain Users, and click the Check Names button.
- Click OK.
- On the Authentication Methods page, select the Microsoft Encrypted Authentication Version 2 (MS-CHAPv2) ption. Click Next.
- On the Policy Encryption Level page, select the encryption strength and click Next.
- Click Finish on the Completing The New Remote Access Policy Wizard page.
How to create a remote access policy that restricts remote access based on connection type
- Click Start, Administrative Tools, and then select Routing And Remote Access to open the Routing And Remote Access console.
- In the console tree, expand the server’s node and then right-click Remote Access Policies and select New Remote Access Policy from the shortcut menu.
- The New Remote Access Policy Wizard starts.
- Click Next on the New Remote Access Policy Wizard Welcome page.
- On the Policy Configuration Method page, click the Set up a custom policy option.
- Enter a name in the Policy name box, and then click Next.
- On the Policy Conditions page, click the add button to add a condition.
- When the Select Attribute dialog box opens, specify the desired attribute and then click the Add button.
- Click Next on the Policy Conditions page.
- On the Permissions page, click the Deny remote access permission option and then click Next.
- When the Profile page appears, use the Edit button if you want to change the profile. Click Next.
- Click Finish to create the new remote access policy.
How to create a remote access policy for VPN access
- Click Start, Administrative Tools, and then click Routing and Remote Access to open the Routing and Remote Access console.
- In the console tree, expand the server node to display the Remote Access Policies node.
- Right-click Remote Access Policies, and then select New Remote Access Policy from the shortcut menu.
- When the New Remote Access Policy Wizard starts, click Next on the initial page of the Wizard.
- Enter a name for the new remote access policy. Click Next.
- On the Policy Conditions page, click Add.
- To restrict VPN users to either use PPTP or L2TP, add the appropriate tunnel-type condition. Click Next.
- Ensure that the Grant Remote Access Permission option is selected on the Permissions page.
- To set profiles, click the Edit Profile button on the Profile page.
- Click Finish.
How to create a remote access policy for wireless access
- Click Start, Administrative Tools, and then click Routing and Remote Access to open the Routing and Remote Access console.
- Click the Action menu, and then select New Remote Access Policy.
- The New Remote Access Policy Wizard launches.
- Click Next on the initial screen of the New Remote Access Policy wizard.
- On the Policy Configuration Method page, select the Use the wizard to set up a typical policy option.
- In the Policy Name field, provide a name for the policy. Click Next.
- On the Access Method page, select the Wireless option. Click Next.
- On the User or Group Access, select the Group option, and then click the Add button.
- Specify the group, and then click OK and Next.
- Select the Smart card or other certificate option and then click Next.
- Click Finish.
How to enable Multilink
- Click Start, Administrative Tools, and then select Routing And Remote Access to open the Routing And Remote Access console.
- In the console tree, expand the server node to display the Remote Access Policies node.
- Select Remote Access Policies.
- In the details pane, double-click the remote access policy that should be configured.
- Click Edit Profile.
- Use the Multilink tab to configure properties for the Multilink policy.
- Click OK
How to configure idle and session time restrictions for an existing profile
- Click Start, Administratve Tools, and then click Routing and Remote Access to open the Routing and Remote Access console.
- In the console tree, expand the server node to display the Remote Access Policies node.
- Select Remote Access Policies.
- In the details pane, select the remote access policy that you want to modify the idle and session times for.
- Click the Action menu and then select Properties from the shortcut menu.
- When the properties dialog box of the remote access policy opens, click Edit Profile.
- Select the Minutes server can remain idle before it is disconnected checkbox. Specify the number of minutes for this setting.
- Select the Minutes the client can be connected checkbox, and then specify the number of minutes for this setting.
- Click OK
- Click OK in the properties dialog box of the remote access policy.
How to configure an encryption level
- Click Start, Administrative Tools, and then select Routing And Remote Access to open the Routing And Remote Access console.
- In the console tree, expand the server’s node and then select Remote Access Policies.
- All remote access policies defined for the remote access server are listed in the details pane of the Routing And Remote Access console.
- Select the remote access policy that you want to configure an encryption level for, click the Action menu and then select Properties.
- When the Properties dialog box of the policy opens, click the Edit Profile button.
- Click the Encryption tab.
- Ensure that the No Encryption checkbox is disabled.
- Enable the following: Basic checkbox, Strong checkbox, and Strongest checkbox.
- Click OK.
How to raise the domain functional level for a domain to enable additional security features
- Open the Active Directory Domains And Trusts console
- Right-click the particular domain whose functional level you want to raise, and select Raise Domain Functional Level from the shortcut menu.
- The Raise Domain Functional Level dialog box opens.
- Use the Select An Available Domain Functional Level list to choose the domain functional level for the domain.
- Click Raise.
- Click OK.
Comments - No Responses to “Implementing Remote Access Security”
Sorry but comments are closed at this time.