microsoft direct access

22
Microsoft Direct Access Microsoft Server 2012 R2 HAIRER Martin

Upload: martin-hairer

Post on 23-Jan-2018

1.069 views

Category:

Technology


2 download

TRANSCRIPT

Page 1: Microsoft direct access

Microsoft Direct AccessMicrosoft Server 2012 R2

HAIRER Martin

Page 2: Microsoft direct access

WHAT IS DIRECT ACCESS?

THE CONCEPT

COMPONENTS

DEPLOYMENT

Page 3: Microsoft direct access

MS Direct Access

Direct Access is the ultimate VPN solution that is one of the enablers for the New Way of Work

Direct Access is always ON

source: microsoft.com

Page 4: Microsoft direct access

MS Direct Access

Seamless and Transparent Corporate Network connectivity for Managed Clients

Remote Access

source: microsoft.com

Page 5: Microsoft direct access

differences to VPN

The DirectAccess client is always

managed.

The DirectAccess client is always

serviceable.

The DirectAccess client uses two

separate tunnels to connect.

Page 6: Microsoft direct access

WHAT IS DIRECT ACCESS?

THE CONCEPT

COMPONENTS

DEPLOYMENT

Page 7: Microsoft direct access

DA Overview

Windows Clients

Corporate Network

Direct Access

VPN

Public Network

osX - Linux Clients

iOS - Android

Page 8: Microsoft direct access

Bi-Directional

Windows 7+

Corporate NetworkPublic Network

Management

Data/Application

Page 9: Microsoft direct access

CONCEPT

DirectAccess extends the network to the remote computer and user

based on End to End IPv6

source: microsoft.com

Page 10: Microsoft direct access

WHAT IS DIRECT ACCESS?

THE CONCEPT

COMPONENTS

DEPLOYMENT

Page 11: Microsoft direct access

COMPONENTS

Windows Server 2012 R2

Windows 7/8/10 (domain joined)

IPv6 and IPsec

Active Directory and

Group Policy

Page 12: Microsoft direct access

DA COMPONENTS

Certificates (PKI)

Network Location Server

DNS64/NAT64

Name Resolution Policy Table

Windows FirewallAdvanced Security

Page 13: Microsoft direct access

WHAT IS DIRECT ACCESS?

THE CONCEPT

COMPONENTS

DEPLOYMENT

Page 14: Microsoft direct access

DEPLOYMENT

Public Network Corporate Network

IPv4 Network

DNS64

NAT64

6to4 tunnel

Teredo tunnel

IPHTTTPS tunnelIPv4

ISATAP

Native IPv6

Page 15: Microsoft direct access

DEPLOYMENT

Enable IPv6

internally

Network Location Server

Client Groups

Firewall Settings

on Clients

Certificate Auto

Enrollment

Direct Access Server

Page 16: Microsoft direct access

DEMO

Page 17: Microsoft direct access

source: https://directaccessguide.files.wordpress.com/2014/03/setupwizard.jpg

Page 18: Microsoft direct access

source: https://robertpearman.files.wordpress.com/2012/10/da21_thumb.png?w=644&h=464

Page 19: Microsoft direct access

source: http://tr1.cbsistatic.com/hub/i/2015/05/07/afbeaa30-f4aa-11e4-940f-14feb5cc3d2a/fig-e-ram-console.jpg

Page 20: Microsoft direct access

source: https://techontip.files.wordpress.com/2013/03/031013_1145_windows20123.png

Page 21: Microsoft direct access

source: https://msdirectaccess.files.wordpress.com/2015/01/directaccess_ad_sites_subnet_031.png

Page 22: Microsoft direct access

THX