Always On VPN




Windows 10 has a nice feature called Always On VPN.

This is pretty much an acceptance that many people have not deployed Direct Access :)  Although DA is not a VPN solution I prefer AO so I set it up for our recent Windows 10 roll out.

Basically the steps boil down to...


  • Create some certificate templates.
  • Create 2 new VMs.
  • Enroll into those templates
  • Install RRAS and NPS roles
  • Config RRAS and NPS
  • Client Config


The most difficult for me was deciding on how to get the client config to roll out.  We use the Quest appliance KACE here so I used that to deploy a powershell script which sets up the VPN.  Love Windows 10!!

I used MDT to build two Windows 2016 servers - I tried the core but my skills were not up for it!

EDIT: It is not possible to install NPS on core - it does "come with" RRAS but avoid on core!
EDIT:  I ended up making my NPS and RRAS box the same it reduces the server count a bit and proved more reliable/stable (Never found out why)





Comments

Popular posts from this blog

PXE booting, MDT and 802.1x

Intune installation requires a wire...or does it?

Security Policy 1001