SlideShare une entreprise Scribd logo
1  sur  32
Microsoft Windows Server 2012



                                Seminar: Transparant werken met Direct Access.
                                Het nieuwe werken. Thuis, onderweg, bij een klant of op de zaak. Overal
                                waar u bent wilt u dezelfde gebruikerservaring hebben. Met Direct Access
                                is uw laptop met internetvoorziening altijd onderdeel van uw
                                bedrijfsnetwerk. Zo kunt u altijd bij uw bestanden en behoort de
                                complexiteit van VPN connecties tot het grijze verleden! Deze oplossing is
                                perfect voor iedere bedrijfsgrootte, van klein-MKB tot grote enterprise
                                ondernemingen.
 Windows Server 2012
 Trends and Challenges
 Direct Access
 Get Started: Advies en Doen!
The Cloud OS






New    Device
apps   proliferation   Data explosion   Cloud computing
Support for
                                                    Windows
                                  Easy-deployment   PowerShell for
                                  wizard            client and server
Transparent network access
to the end user from any
Internet connection
                                  Support for       Site-to-site
                                  multiple sites    tunneling


Simple to deploy     Flexible     Unified           Built-in support for
and manage           deployment   management        IPv6 translation
centrally            scenarios    experience        technology
                                                                        9
is
Client authentication requests are sent to a KDC Proxy Server service running on the DirectAccess
server
         Kerberos proxy sends Kerberos requests to DCs on behalf of the client
 TCP port 443 NATted or allowed to DA Edge (on firewall)
 DirectAccess server must have a server authentication certificate for TLS
   Will be trusted by clients (forcibly through Group Policy if necessary)
   Self-signed cert used automatically for IPHTTPS/KDC Proxy
with single network interface or multiple interfaces




If so, only IP-HTTPS will be deployed
Data is encrypted by IPSec as well as by SSL, so the data is encrypted
twice




Can configure IP-HTTPS to work when behind authenticating proxy



           IP-HTTPS is now preferred transport
   DNS Query for DirectAccess-NLS.corp.domain.com




   IPv4 (A) DNS Query for da.domain.com
NAT64/DNS64 is the reason DA works on IPv4 Networks
                                                                                          172.16.0.20
       Native IPv4 traffic                                                             IPv4-only Server
       Native IPv6 traffic
                                            fd00:fefe:2::172.16.0.20
                                               IPv6 Prefix - fd00:fefe:2::/96
                                    SERVER IN AAAA IN A80
                                            SERVER FD00:FEFE:2::172.16.0.20
                                                  TCP port 172.16.0.20s
                                           IPv4 Internal Address – 172.16.0.100
                                                             172.16.0.101                          172.16.0.20
                                                               TCP port                            TCP port 80
                                                                 1060
                             IPv6 Network                                      IPv4 Network

                                                       NAT64/DNS64
                                                       gateway (DA)


                                  fd00:fefe:1::bef1:2002, TCP port 1025

                   IPv6 Client                                                              DNS Server
               fd00:fefe:1::bef1:2002                                                       172.16.0.2
                                         8. NAT64 gateway translates theAAAAIPv6
                                        1. NAT64 gatewaysendsthat DNSresponse to
                                        6. DNS64 convertstranslatesto /96 IPv6query
                                         4. NAT64 device forwardsIPv4 query record
                                          2. IPv4-only informs
                                             NAT64 device replies no queryfor
                                         3. DNS Server configuredAAAAAAAA packet
                                        9.9.IPv6 Client Server DNSA with the dynamic
                                        NAT64 devicesendsDNS DNSassociating to
                                                                       the IPv4 for
                                                                        A packet the
                                          5. DNS AAAA one, connection
                                          7. IPv6 Client sends
                                         packet to IPv4, dynamically
                                        IPv4-only IPv4 replies withNAT64 gateway
                                        an IPv6using associated toIPv6 IPv4IPv4
                                         existsaddress used adding Server’s
                                                  Server
                                        to IPv6andServer DNS Server IPv4 address
                                          to authoritative by the
                                          IPv4 for
                                        prefix addressthe information in /96 prefix
                                         Server IPv6 address with anthe the
                                          IPv6
                                         source           address pool
                                          address
                                        translation table
                                          receiver
                                         from the pool
Offline Provisioning of Direct Access Clients
Djoin /provision /machine CLIENT1 /domain corp
/policynames "DirectAccess Client Settings"
/rootcacerts /savefile c:filesprovision.txt
/reuse
Download Windows Server
2012


Learn



Act
MCSA: Windows Server 2012


                          +                           +                          =
    Installing and                                        Configuring Advanced
    Configuring Windows       Administering Windows       Windows Server 2012        MCSA: Windows Server
    Server 2012               Server 2012                 Services                   2012




    Installing and                                        Configuring Advanced
    Configuring Windows       Administering Windows       Windows Server 2012
    Server 2012               Server 2012                 Services                   Find a Learning Partner
MCSE: Server Infrastructure
                                                                          * Requires
                                                                          recertification




                        +                           +                     =
                            Designing and               Implementing an
                            Implementing a Server       Advanced Server       MCSE: Server
  Windows Server 2012       Infrastructure              Infrastructure        Infrastructure




                            Designing and               Implementing an
                            Implementing a Server       Advanced Server
                            Infrastructure              Infrastructure        Find a Learning Partner
MCSE: Desktop Infrastructure
                                                                                * Requires
                                                                                recertification




                        +                            +                          =
                                                         Implementing Desktop
                            Implementing a Desktop       Application                MCSE: Desktop
  Windows Server 2012       Infrastructure               Environments               Infrastructure




                                                         Implementing Desktop
                            Implementing a Desktop       Application
                            Infrastructure               Environments               Find a Learning Partner
Upgrade paths
                                                                                   Windows Server 2012
                                                                           Designing and
                                                                           Implementing a Server     Implementing an Advanced
                                                                                                                                Server Infrastructure
                                                                           Infrastructure            Server Infrastructure

Any of the following certifications qualify:

•   MCSA: Windows Server 2008*
•
•
•
    MCITP: Virtualization Administrator
    MCITP: Enterprise Messaging Administrator
    MCITP: Lync Server Administrator
                                                                                     Either or
•   MCITP: SharePoint Administrator             Upgrading Your Skills to
•   MCITP: Enterprise Desktop Administrator
                                                MCSA Windows Server
                                                2012                                 Both

                                                                           Implementing a Desktop    Implementing Desktop
                                                                                                                                Desktop Infrastructure
                                                                           Infrastructure            Application Environments

Contenu connexe

Tendances

Lesson 5: Configuring Name Resolution
Lesson 5: Configuring Name ResolutionLesson 5: Configuring Name Resolution
Lesson 5: Configuring Name ResolutionMahmmoud Mahdi
 
bdNOG 7 - Re-engineering the DNS - one resolver at a time
bdNOG 7 - Re-engineering the DNS - one resolver at a timebdNOG 7 - Re-engineering the DNS - one resolver at a time
bdNOG 7 - Re-engineering the DNS - one resolver at a timeAPNIC
 
ipv6 mpls by Patrick Grossetete
ipv6 mpls by Patrick Grosseteteipv6 mpls by Patrick Grossetete
ipv6 mpls by Patrick GrosseteteFebrian ‎
 
OpenDNS Whitepaper: Platform Technology
OpenDNS Whitepaper: Platform TechnologyOpenDNS Whitepaper: Platform Technology
OpenDNS Whitepaper: Platform TechnologyCourtland Smith
 
Cisco IPv6 Tutorial by Hinwoto
Cisco IPv6 Tutorial by HinwotoCisco IPv6 Tutorial by Hinwoto
Cisco IPv6 Tutorial by HinwotoFebrian ‎
 
IPv6 Autoconfig
IPv6 AutoconfigIPv6 Autoconfig
IPv6 AutoconfigFred Bovy
 
DHCP (dynamic host configuration protocol)
DHCP (dynamic host configuration protocol)DHCP (dynamic host configuration protocol)
DHCP (dynamic host configuration protocol)Netwax Lab
 
IPv6 How To Set Up a Linux IPv6 Lan
IPv6 How To Set Up  a Linux IPv6 LanIPv6 How To Set Up  a Linux IPv6 Lan
IPv6 How To Set Up a Linux IPv6 LanJumping Bean
 
Gabriel Paues - IPv6 address planning + making the case for WHY
Gabriel Paues - IPv6 address planning + making the case for WHYGabriel Paues - IPv6 address planning + making the case for WHY
Gabriel Paues - IPv6 address planning + making the case for WHYIKT-Norge
 
instructor ppt_chapter8.2.2 - i_pv6 addressing with exercises of IPv6
instructor ppt_chapter8.2.2 - i_pv6 addressing with exercises of IPv6instructor ppt_chapter8.2.2 - i_pv6 addressing with exercises of IPv6
instructor ppt_chapter8.2.2 - i_pv6 addressing with exercises of IPv6cyberjoex
 
Microsoft Certifications 70-411 it exams dumps
Microsoft Certifications 70-411 it exams dumpsMicrosoft Certifications 70-411 it exams dumps
Microsoft Certifications 70-411 it exams dumpslilylucy
 
Eric Vyncke - Layer-2 security, ipv6 norway
Eric Vyncke - Layer-2 security, ipv6 norwayEric Vyncke - Layer-2 security, ipv6 norway
Eric Vyncke - Layer-2 security, ipv6 norwayIKT-Norge
 
Campus networking
Campus networkingCampus networking
Campus networkingJisc
 
Martin J Levy - Hurricane Electric - The IPv6 global view - norway ipv6 - apr...
Martin J Levy - Hurricane Electric - The IPv6 global view - norway ipv6 - apr...Martin J Levy - Hurricane Electric - The IPv6 global view - norway ipv6 - apr...
Martin J Levy - Hurricane Electric - The IPv6 global view - norway ipv6 - apr...IKT-Norge
 
DYNAMIC HOST CONFIGURATION PROTOCOL
DYNAMIC HOST CONFIGURATION PROTOCOLDYNAMIC HOST CONFIGURATION PROTOCOL
DYNAMIC HOST CONFIGURATION PROTOCOLVENKATESHAN A S
 
Building Linux IPv6 DNS Server (Complete Soft Copy)
Building Linux IPv6 DNS Server (Complete Soft Copy)Building Linux IPv6 DNS Server (Complete Soft Copy)
Building Linux IPv6 DNS Server (Complete Soft Copy)Hari
 

Tendances (19)

IPv6 Greenfield
IPv6 Greenfield IPv6 Greenfield
IPv6 Greenfield
 
Lesson 5: Configuring Name Resolution
Lesson 5: Configuring Name ResolutionLesson 5: Configuring Name Resolution
Lesson 5: Configuring Name Resolution
 
I pv6 autoconfig20c
I pv6 autoconfig20cI pv6 autoconfig20c
I pv6 autoconfig20c
 
bdNOG 7 - Re-engineering the DNS - one resolver at a time
bdNOG 7 - Re-engineering the DNS - one resolver at a timebdNOG 7 - Re-engineering the DNS - one resolver at a time
bdNOG 7 - Re-engineering the DNS - one resolver at a time
 
ipv6 mpls by Patrick Grossetete
ipv6 mpls by Patrick Grosseteteipv6 mpls by Patrick Grossetete
ipv6 mpls by Patrick Grossetete
 
OpenDNS Whitepaper: Platform Technology
OpenDNS Whitepaper: Platform TechnologyOpenDNS Whitepaper: Platform Technology
OpenDNS Whitepaper: Platform Technology
 
Cisco IPv6 Tutorial by Hinwoto
Cisco IPv6 Tutorial by HinwotoCisco IPv6 Tutorial by Hinwoto
Cisco IPv6 Tutorial by Hinwoto
 
IPv6 Autoconfig
IPv6 AutoconfigIPv6 Autoconfig
IPv6 Autoconfig
 
DHCP (dynamic host configuration protocol)
DHCP (dynamic host configuration protocol)DHCP (dynamic host configuration protocol)
DHCP (dynamic host configuration protocol)
 
IPv6 How To Set Up a Linux IPv6 Lan
IPv6 How To Set Up  a Linux IPv6 LanIPv6 How To Set Up  a Linux IPv6 Lan
IPv6 How To Set Up a Linux IPv6 Lan
 
Gabriel Paues - IPv6 address planning + making the case for WHY
Gabriel Paues - IPv6 address planning + making the case for WHYGabriel Paues - IPv6 address planning + making the case for WHY
Gabriel Paues - IPv6 address planning + making the case for WHY
 
instructor ppt_chapter8.2.2 - i_pv6 addressing with exercises of IPv6
instructor ppt_chapter8.2.2 - i_pv6 addressing with exercises of IPv6instructor ppt_chapter8.2.2 - i_pv6 addressing with exercises of IPv6
instructor ppt_chapter8.2.2 - i_pv6 addressing with exercises of IPv6
 
Microsoft Certifications 70-411 it exams dumps
Microsoft Certifications 70-411 it exams dumpsMicrosoft Certifications 70-411 it exams dumps
Microsoft Certifications 70-411 it exams dumps
 
Eric Vyncke - Layer-2 security, ipv6 norway
Eric Vyncke - Layer-2 security, ipv6 norwayEric Vyncke - Layer-2 security, ipv6 norway
Eric Vyncke - Layer-2 security, ipv6 norway
 
Campus networking
Campus networkingCampus networking
Campus networking
 
Martin J Levy - Hurricane Electric - The IPv6 global view - norway ipv6 - apr...
Martin J Levy - Hurricane Electric - The IPv6 global view - norway ipv6 - apr...Martin J Levy - Hurricane Electric - The IPv6 global view - norway ipv6 - apr...
Martin J Levy - Hurricane Electric - The IPv6 global view - norway ipv6 - apr...
 
DHCP concept
DHCP conceptDHCP concept
DHCP concept
 
DYNAMIC HOST CONFIGURATION PROTOCOL
DYNAMIC HOST CONFIGURATION PROTOCOLDYNAMIC HOST CONFIGURATION PROTOCOL
DYNAMIC HOST CONFIGURATION PROTOCOL
 
Building Linux IPv6 DNS Server (Complete Soft Copy)
Building Linux IPv6 DNS Server (Complete Soft Copy)Building Linux IPv6 DNS Server (Complete Soft Copy)
Building Linux IPv6 DNS Server (Complete Soft Copy)
 

Similaire à Windows Server 2012 Seminar 4 - De mogelijkheden van Direct Access

Direct access for dummies
Direct access for dummiesDirect access for dummies
Direct access for dummiesAlex de Jong
 
Microsoft Direct Access (Part II)_John Delizo
Microsoft Direct Access (Part II)_John DelizoMicrosoft Direct Access (Part II)_John Delizo
Microsoft Direct Access (Part II)_John DelizoQuek Lilian
 
Openstack meetup: Bootstrapping OpenStack to Corporate IT
Openstack meetup: Bootstrapping OpenStack to Corporate ITOpenstack meetup: Bootstrapping OpenStack to Corporate IT
Openstack meetup: Bootstrapping OpenStack to Corporate ITMirantis
 
Group-7-DHCPv4.pptx
Group-7-DHCPv4.pptxGroup-7-DHCPv4.pptx
Group-7-DHCPv4.pptxIvanTabanag1
 
Module (8) DHCP Server.pptx
Module (8) DHCP Server.pptxModule (8) DHCP Server.pptx
Module (8) DHCP Server.pptxGeorgeThoreJr
 
Dynamic Domain Name System
Dynamic Domain Name SystemDynamic Domain Name System
Dynamic Domain Name SystemRajan Kumar
 
DHCP Services (Ipv4 & 6).pptx
DHCP Services (Ipv4 & 6).pptxDHCP Services (Ipv4 & 6).pptx
DHCP Services (Ipv4 & 6).pptxMohammad Hassan
 
Overview usage of ProudNet
Overview usage of ProudNetOverview usage of ProudNet
Overview usage of ProudNetHyun-jik Bae
 
Lesson 6: Dynamic Host Configuration Protocol A
Lesson 6: Dynamic Host Configuration Protocol ALesson 6: Dynamic Host Configuration Protocol A
Lesson 6: Dynamic Host Configuration Protocol AMahmmoud Mahdi
 
2009 11 06 3gpp Ietf Ipv6 Shanghai Nat64
2009 11 06 3gpp Ietf Ipv6 Shanghai Nat642009 11 06 3gpp Ietf Ipv6 Shanghai Nat64
2009 11 06 3gpp Ietf Ipv6 Shanghai Nat64yacc2000
 
HA System-First presentation
HA System-First presentationHA System-First presentation
HA System-First presentationAvin Chan
 
98 366 mva slides lesson 6
98 366 mva slides lesson 698 366 mva slides lesson 6
98 366 mva slides lesson 6suddenven
 
6WINDGate™ - Enabling Cloud RAN Virtualization
6WINDGate™ - Enabling Cloud RAN Virtualization6WINDGate™ - Enabling Cloud RAN Virtualization
6WINDGate™ - Enabling Cloud RAN Virtualization6WIND
 
Samba and Vista with IPv6
Samba and Vista with IPv6Samba and Vista with IPv6
Samba and Vista with IPv6dinomasch
 
6 understanding DHCP
6 understanding DHCP6 understanding DHCP
6 understanding DHCPHameda Hurmat
 
[2015-05월 세미나] Network Bottlenecks Mutiply with NFV Don't Forget Performance ...
[2015-05월 세미나] Network Bottlenecks Mutiply with NFV Don't Forget Performance ...[2015-05월 세미나] Network Bottlenecks Mutiply with NFV Don't Forget Performance ...
[2015-05월 세미나] Network Bottlenecks Mutiply with NFV Don't Forget Performance ...OpenStack Korea Community
 

Similaire à Windows Server 2012 Seminar 4 - De mogelijkheden van Direct Access (20)

Direct access for dummies
Direct access for dummiesDirect access for dummies
Direct access for dummies
 
Microsoft Direct Access (Part II)_John Delizo
Microsoft Direct Access (Part II)_John DelizoMicrosoft Direct Access (Part II)_John Delizo
Microsoft Direct Access (Part II)_John Delizo
 
Openstack meetup: Bootstrapping OpenStack to Corporate IT
Openstack meetup: Bootstrapping OpenStack to Corporate ITOpenstack meetup: Bootstrapping OpenStack to Corporate IT
Openstack meetup: Bootstrapping OpenStack to Corporate IT
 
Group-7-DHCPv4.pptx
Group-7-DHCPv4.pptxGroup-7-DHCPv4.pptx
Group-7-DHCPv4.pptx
 
Module (8) DHCP Server.pptx
Module (8) DHCP Server.pptxModule (8) DHCP Server.pptx
Module (8) DHCP Server.pptx
 
Dynamic Domain Name System
Dynamic Domain Name SystemDynamic Domain Name System
Dynamic Domain Name System
 
Iaas on xcp
Iaas on xcpIaas on xcp
Iaas on xcp
 
DHCP Services (Ipv4 & 6).pptx
DHCP Services (Ipv4 & 6).pptxDHCP Services (Ipv4 & 6).pptx
DHCP Services (Ipv4 & 6).pptx
 
Overview usage of ProudNet
Overview usage of ProudNetOverview usage of ProudNet
Overview usage of ProudNet
 
Lesson 6: Dynamic Host Configuration Protocol A
Lesson 6: Dynamic Host Configuration Protocol ALesson 6: Dynamic Host Configuration Protocol A
Lesson 6: Dynamic Host Configuration Protocol A
 
DHCP Server Guaidlines using CISCO PACKET TRACER
DHCP Server Guaidlines using CISCO PACKET TRACERDHCP Server Guaidlines using CISCO PACKET TRACER
DHCP Server Guaidlines using CISCO PACKET TRACER
 
2009 11 06 3gpp Ietf Ipv6 Shanghai Nat64
2009 11 06 3gpp Ietf Ipv6 Shanghai Nat642009 11 06 3gpp Ietf Ipv6 Shanghai Nat64
2009 11 06 3gpp Ietf Ipv6 Shanghai Nat64
 
HA System-First presentation
HA System-First presentationHA System-First presentation
HA System-First presentation
 
MVA slides lesson 6
MVA slides lesson 6MVA slides lesson 6
MVA slides lesson 6
 
98 366 mva slides lesson 6
98 366 mva slides lesson 698 366 mva slides lesson 6
98 366 mva slides lesson 6
 
6WINDGate™ - Enabling Cloud RAN Virtualization
6WINDGate™ - Enabling Cloud RAN Virtualization6WINDGate™ - Enabling Cloud RAN Virtualization
6WINDGate™ - Enabling Cloud RAN Virtualization
 
Samba and Vista with IPv6
Samba and Vista with IPv6Samba and Vista with IPv6
Samba and Vista with IPv6
 
6 understanding DHCP
6 understanding DHCP6 understanding DHCP
6 understanding DHCP
 
[2015-05월 세미나] Network Bottlenecks Mutiply with NFV Don't Forget Performance ...
[2015-05월 세미나] Network Bottlenecks Mutiply with NFV Don't Forget Performance ...[2015-05월 세미나] Network Bottlenecks Mutiply with NFV Don't Forget Performance ...
[2015-05월 세미나] Network Bottlenecks Mutiply with NFV Don't Forget Performance ...
 
Cisco MPLS
Cisco MPLSCisco MPLS
Cisco MPLS
 

Plus de CompuTrain. De IT opleider.

Techdays 2013 managing your hybrid cloud datacenter with scom 2012 and what...
Techdays 2013   managing your hybrid cloud datacenter with scom 2012 and what...Techdays 2013   managing your hybrid cloud datacenter with scom 2012 and what...
Techdays 2013 managing your hybrid cloud datacenter with scom 2012 and what...CompuTrain. De IT opleider.
 
Planet azure starship system center exploring new worlds
Planet azure starship system center exploring new worldsPlanet azure starship system center exploring new worlds
Planet azure starship system center exploring new worldsCompuTrain. De IT opleider.
 
Techdays 2013 the road to end user self service with service manager 2012
Techdays 2013   the road to end user self service with service manager 2012Techdays 2013   the road to end user self service with service manager 2012
Techdays 2013 the road to end user self service with service manager 2012CompuTrain. De IT opleider.
 
Windows Server 2012 - Dynamische opslag met Storage Pools
Windows Server 2012 - Dynamische opslag met Storage PoolsWindows Server 2012 - Dynamische opslag met Storage Pools
Windows Server 2012 - Dynamische opslag met Storage PoolsCompuTrain. De IT opleider.
 

Plus de CompuTrain. De IT opleider. (7)

Techdays 2013 managing your hybrid cloud datacenter with scom 2012 and what...
Techdays 2013   managing your hybrid cloud datacenter with scom 2012 and what...Techdays 2013   managing your hybrid cloud datacenter with scom 2012 and what...
Techdays 2013 managing your hybrid cloud datacenter with scom 2012 and what...
 
Planet azure starship system center exploring new worlds
Planet azure starship system center exploring new worldsPlanet azure starship system center exploring new worlds
Planet azure starship system center exploring new worlds
 
Moderne device management door middel van cloud
Moderne device management door middel van cloudModerne device management door middel van cloud
Moderne device management door middel van cloud
 
Cloud. het draait allemaal om de app!
Cloud. het draait allemaal om de app!Cloud. het draait allemaal om de app!
Cloud. het draait allemaal om de app!
 
Techdays 2013 the road to end user self service with service manager 2012
Techdays 2013   the road to end user self service with service manager 2012Techdays 2013   the road to end user self service with service manager 2012
Techdays 2013 the road to end user self service with service manager 2012
 
Windows server 2012 Seminar 3: Hyper-V replica
Windows server 2012 Seminar 3: Hyper-V replicaWindows server 2012 Seminar 3: Hyper-V replica
Windows server 2012 Seminar 3: Hyper-V replica
 
Windows Server 2012 - Dynamische opslag met Storage Pools
Windows Server 2012 - Dynamische opslag met Storage PoolsWindows Server 2012 - Dynamische opslag met Storage Pools
Windows Server 2012 - Dynamische opslag met Storage Pools
 

Windows Server 2012 Seminar 4 - De mogelijkheden van Direct Access

  • 1. Microsoft Windows Server 2012 Seminar: Transparant werken met Direct Access. Het nieuwe werken. Thuis, onderweg, bij een klant of op de zaak. Overal waar u bent wilt u dezelfde gebruikerservaring hebben. Met Direct Access is uw laptop met internetvoorziening altijd onderdeel van uw bedrijfsnetwerk. Zo kunt u altijd bij uw bestanden en behoort de complexiteit van VPN connecties tot het grijze verleden! Deze oplossing is perfect voor iedere bedrijfsgrootte, van klein-MKB tot grote enterprise ondernemingen.
  • 2.
  • 3.  Windows Server 2012  Trends and Challenges  Direct Access  Get Started: Advies en Doen!
  • 4.
  • 6.
  • 7. New Device apps proliferation Data explosion Cloud computing
  • 8.
  • 9. Support for Windows Easy-deployment PowerShell for wizard client and server Transparent network access to the end user from any Internet connection Support for Site-to-site multiple sites tunneling Simple to deploy Flexible Unified Built-in support for and manage deployment management IPv6 translation centrally scenarios experience technology 9
  • 10.
  • 11.
  • 12.
  • 13.
  • 14.
  • 15. is
  • 16. Client authentication requests are sent to a KDC Proxy Server service running on the DirectAccess server Kerberos proxy sends Kerberos requests to DCs on behalf of the client
  • 17.  TCP port 443 NATted or allowed to DA Edge (on firewall)  DirectAccess server must have a server authentication certificate for TLS  Will be trusted by clients (forcibly through Group Policy if necessary)  Self-signed cert used automatically for IPHTTPS/KDC Proxy
  • 18. with single network interface or multiple interfaces If so, only IP-HTTPS will be deployed
  • 19. Data is encrypted by IPSec as well as by SSL, so the data is encrypted twice Can configure IP-HTTPS to work when behind authenticating proxy IP-HTTPS is now preferred transport
  • 20. DNS Query for DirectAccess-NLS.corp.domain.com  IPv4 (A) DNS Query for da.domain.com
  • 21. NAT64/DNS64 is the reason DA works on IPv4 Networks 172.16.0.20 Native IPv4 traffic IPv4-only Server Native IPv6 traffic fd00:fefe:2::172.16.0.20 IPv6 Prefix - fd00:fefe:2::/96 SERVER IN AAAA IN A80 SERVER FD00:FEFE:2::172.16.0.20 TCP port 172.16.0.20s IPv4 Internal Address – 172.16.0.100 172.16.0.101 172.16.0.20 TCP port TCP port 80 1060 IPv6 Network IPv4 Network NAT64/DNS64 gateway (DA) fd00:fefe:1::bef1:2002, TCP port 1025 IPv6 Client DNS Server fd00:fefe:1::bef1:2002 172.16.0.2 8. NAT64 gateway translates theAAAAIPv6 1. NAT64 gatewaysendsthat DNSresponse to 6. DNS64 convertstranslatesto /96 IPv6query 4. NAT64 device forwardsIPv4 query record 2. IPv4-only informs NAT64 device replies no queryfor 3. DNS Server configuredAAAAAAAA packet 9.9.IPv6 Client Server DNSA with the dynamic NAT64 devicesendsDNS DNSassociating to the IPv4 for A packet the 5. DNS AAAA one, connection 7. IPv6 Client sends packet to IPv4, dynamically IPv4-only IPv4 replies withNAT64 gateway an IPv6using associated toIPv6 IPv4IPv4 existsaddress used adding Server’s Server to IPv6andServer DNS Server IPv4 address to authoritative by the IPv4 for prefix addressthe information in /96 prefix Server IPv6 address with anthe the IPv6 source address pool address translation table receiver from the pool
  • 22.
  • 23.
  • 24.
  • 25. Offline Provisioning of Direct Access Clients
  • 26. Djoin /provision /machine CLIENT1 /domain corp /policynames "DirectAccess Client Settings" /rootcacerts /savefile c:filesprovision.txt /reuse
  • 27.
  • 29. MCSA: Windows Server 2012 + + = Installing and Configuring Advanced Configuring Windows Administering Windows Windows Server 2012 MCSA: Windows Server Server 2012 Server 2012 Services 2012 Installing and Configuring Advanced Configuring Windows Administering Windows Windows Server 2012 Server 2012 Server 2012 Services Find a Learning Partner
  • 30. MCSE: Server Infrastructure * Requires recertification + + = Designing and Implementing an Implementing a Server Advanced Server MCSE: Server Windows Server 2012 Infrastructure Infrastructure Infrastructure Designing and Implementing an Implementing a Server Advanced Server Infrastructure Infrastructure Find a Learning Partner
  • 31. MCSE: Desktop Infrastructure * Requires recertification + + = Implementing Desktop Implementing a Desktop Application MCSE: Desktop Windows Server 2012 Infrastructure Environments Infrastructure Implementing Desktop Implementing a Desktop Application Infrastructure Environments Find a Learning Partner
  • 32. Upgrade paths Windows Server 2012 Designing and Implementing a Server Implementing an Advanced Server Infrastructure Infrastructure Server Infrastructure Any of the following certifications qualify: • MCSA: Windows Server 2008* • • • MCITP: Virtualization Administrator MCITP: Enterprise Messaging Administrator MCITP: Lync Server Administrator Either or • MCITP: SharePoint Administrator Upgrading Your Skills to • MCITP: Enterprise Desktop Administrator MCSA Windows Server 2012 Both Implementing a Desktop Implementing Desktop Desktop Infrastructure Infrastructure Application Environments

Notes de l'éditeur

  1.  
  2.