About the Author |
|
xix | |
About the Technical Reviewer |
|
xxi | |
Acknowledgments |
|
xxiii | |
Introduction |
|
xxv | |
Chapter 1 Always On VPN Overview |
|
1 | (6) |
|
|
1 | (1) |
|
|
2 | (1) |
|
|
2 | (1) |
|
|
3 | (1) |
|
|
3 | (1) |
|
Always On VPN Infrastructure |
|
|
3 | (1) |
|
Routing and Remote Access Service |
|
|
4 | (1) |
|
|
4 | (1) |
|
Infrastructure Independent |
|
|
4 | (1) |
|
|
5 | (1) |
|
|
5 | (1) |
|
|
5 | (2) |
Chapter 2 Plan for Always On VPN |
|
7 | (14) |
|
|
7 | (2) |
|
|
7 | (1) |
|
|
8 | (1) |
|
|
8 | (1) |
|
|
9 | (1) |
|
|
9 | (1) |
|
|
9 | (1) |
|
Non-Microsoft VPN Devices |
|
|
9 | (2) |
|
|
10 | (1) |
|
|
10 | (1) |
|
|
11 | (1) |
|
|
11 | (1) |
|
|
11 | (1) |
|
|
12 | (1) |
|
|
12 | (1) |
|
|
13 | (1) |
|
|
13 | (1) |
|
|
13 | (1) |
|
|
13 | (2) |
|
|
14 | (1) |
|
|
14 | (1) |
|
|
14 | (1) |
|
|
15 | (1) |
|
|
15 | (1) |
|
|
15 | (1) |
|
|
15 | (1) |
|
|
15 | (1) |
|
|
16 | (1) |
|
|
16 | (1) |
|
|
16 | (1) |
|
|
17 | (1) |
|
Split vs. Force Tunneling |
|
|
17 | (1) |
|
|
17 | (1) |
|
|
17 | (1) |
|
|
18 | (1) |
|
|
18 | (1) |
|
|
18 | (1) |
|
|
18 | (1) |
|
|
19 | (1) |
|
Microsoft Endpoint Manager |
|
|
19 | (1) |
|
|
19 | (1) |
|
|
19 | (1) |
|
|
20 | (1) |
|
|
20 | (1) |
Chapter 3 Prepare the Infrastructure |
|
21 | (38) |
|
|
21 | (1) |
|
|
21 | (1) |
|
|
22 | (31) |
|
|
22 | (7) |
|
|
29 | (6) |
|
|
35 | (8) |
|
|
43 | (5) |
|
|
48 | (5) |
|
Issue Certificate Templates |
|
|
53 | (1) |
|
|
53 | (1) |
|
Certificate Autoenrollment |
|
|
54 | (3) |
|
|
55 | (2) |
|
|
57 | (2) |
Chapter 4 Configure Windows Server for Always On VPN |
|
59 | (56) |
|
|
59 | (1) |
|
|
60 | (1) |
|
|
60 | (1) |
|
|
61 | (9) |
|
|
61 | (2) |
|
|
63 | (7) |
|
Routing and Remote Access Service Server |
|
|
70 | (1) |
|
|
70 | (1) |
|
|
70 | (1) |
|
|
70 | (1) |
|
|
70 | (9) |
|
|
71 | (5) |
|
|
76 | (3) |
|
|
79 | (1) |
|
|
79 | (1) |
|
|
80 | (1) |
|
|
80 | (3) |
|
Server GUI Non-Domain Joined |
|
|
83 | (7) |
|
|
84 | (1) |
|
|
85 | (1) |
|
|
85 | (3) |
|
|
88 | (2) |
|
Server Core Domain-Joined |
|
|
90 | (2) |
|
|
90 | (1) |
|
|
91 | (1) |
|
Server Core Non-Domain Joined |
|
|
92 | (1) |
|
|
92 | (3) |
|
|
95 | (1) |
|
|
96 | (1) |
|
|
96 | (1) |
|
|
96 | (1) |
|
|
96 | (1) |
|
|
97 | (10) |
|
|
107 | (1) |
|
|
108 | (5) |
|
|
108 | (1) |
|
|
109 | (1) |
|
|
110 | (2) |
|
|
112 | (1) |
|
|
112 | (1) |
|
|
113 | (2) |
Chapter 5 Provision Always On VPN Clients |
|
115 | (42) |
|
|
115 | (2) |
|
|
115 | (2) |
|
|
117 | (10) |
|
|
117 | (2) |
|
|
119 | (5) |
|
|
124 | (2) |
|
|
126 | (1) |
|
|
127 | (1) |
|
|
127 | (5) |
|
|
128 | (1) |
|
|
129 | (1) |
|
|
130 | (2) |
|
|
132 | (1) |
|
Microsoft Endpoint Manager |
|
|
132 | (1) |
|
|
133 | (12) |
|
|
133 | (6) |
|
|
139 | (6) |
|
|
145 | (1) |
|
|
145 | (6) |
|
|
146 | (2) |
|
|
148 | (3) |
|
|
151 | (2) |
|
|
152 | (1) |
|
|
152 | (1) |
|
|
153 | (1) |
|
|
153 | (3) |
|
|
153 | (1) |
|
|
153 | (3) |
|
|
156 | (1) |
Chapter 6 Advanced Configuration |
|
157 | (18) |
|
Name Resolution Policy Table |
|
|
157 | (5) |
|
|
158 | (4) |
|
|
162 | (4) |
|
|
162 | (1) |
|
Global Proxy Autoconfiguration |
|
|
163 | (2) |
|
|
165 | (1) |
|
|
166 | (1) |
|
|
166 | (3) |
|
|
169 | (1) |
|
|
169 | (3) |
|
Desktop Application Filter |
|
|
170 | (1) |
|
Windows Store Application Filter |
|
|
171 | (1) |
|
SYSTEM Application Filter |
|
|
171 | (1) |
|
|
172 | (1) |
|
|
172 | (1) |
|
|
173 | (1) |
|
|
173 | (1) |
|
|
174 | (1) |
Chapter 7 Cloud Deployments |
|
175 | (40) |
|
|
175 | (2) |
|
|
175 | (1) |
|
|
176 | (1) |
|
|
176 | (1) |
|
|
176 | (1) |
|
Site-to-Site Compatibility |
|
|
177 | (1) |
|
Azure VPN Gateway Configuration |
|
|
177 | (3) |
|
|
180 | (7) |
|
|
180 | (2) |
|
|
182 | (3) |
|
|
185 | (2) |
|
|
187 | (4) |
|
|
187 | (2) |
|
|
189 | (1) |
|
|
190 | (1) |
|
|
191 | (2) |
|
Update Azure VPN IPsec Policy |
|
|
191 | (1) |
|
|
192 | (1) |
|
|
193 | (1) |
|
|
194 | (1) |
|
|
194 | (1) |
|
|
194 | (1) |
|
Azure Virtual WAN Configuration |
|
|
194 | (12) |
|
|
196 | (2) |
|
Certificate Authentication |
|
|
198 | (1) |
|
|
199 | (1) |
|
|
200 | (2) |
|
|
202 | (1) |
|
|
203 | (3) |
|
|
206 | (1) |
|
|
206 | (1) |
|
|
207 | (7) |
|
|
207 | (3) |
|
|
210 | (1) |
|
|
210 | (1) |
|
|
210 | (1) |
|
|
211 | (3) |
|
|
214 | (1) |
|
|
214 | (1) |
Chapter 8 Deploy Certificates with Intune |
|
215 | (54) |
|
|
215 | (1) |
|
|
215 | (1) |
|
|
216 | (1) |
|
|
216 | (10) |
|
|
217 | (1) |
|
|
218 | (8) |
|
Install Certificate Connector for Intune |
|
|
226 | (9) |
|
PKCS Intune Configuration |
|
|
235 | (4) |
|
|
235 | (1) |
|
|
236 | (3) |
|
|
239 | (5) |
|
|
244 | (2) |
|
|
246 | (9) |
|
|
246 | (1) |
|
|
246 | (2) |
|
|
248 | (7) |
|
|
255 | (3) |
|
|
256 | (2) |
|
|
258 | (1) |
|
|
258 | (1) |
|
Install Intune Certificate Connector |
|
|
259 | (1) |
|
|
260 | (5) |
|
|
265 | (2) |
|
|
267 | (2) |
Chapter 9 Azure MFA Integration |
|
269 | (20) |
|
|
269 | (1) |
|
|
270 | (1) |
|
|
270 | (1) |
|
Certificate Authentication |
|
|
270 | (1) |
|
Additional Considerations |
|
|
271 | (1) |
|
|
271 | (1) |
|
|
271 | (1) |
|
|
272 | (1) |
|
|
272 | (4) |
|
Update RRAS Authentication |
|
|
274 | (1) |
|
|
275 | (1) |
|
|
275 | (1) |
|
|
276 | (1) |
|
|
276 | (1) |
|
Configure Azure Conditional Access |
|
|
276 | (4) |
|
|
276 | (1) |
|
|
277 | (1) |
|
|
278 | (2) |
|
|
280 | (2) |
|
|
280 | (2) |
|
Conditional Access Policy |
|
|
282 | (2) |
|
|
282 | (2) |
|
|
284 | (2) |
|
|
284 | (1) |
|
|
285 | (1) |
|
|
286 | (1) |
|
|
286 | (1) |
|
|
287 | (2) |
Chapter 10 High Availability |
|
289 | (22) |
|
|
289 | (1) |
|
|
289 | (1) |
|
|
290 | (1) |
|
|
290 | (1) |
|
|
291 | (2) |
|
|
291 | (1) |
|
|
292 | (1) |
|
|
293 | (1) |
|
|
293 | (1) |
|
External Load Balancer Configuration |
|
|
294 | (1) |
|
|
295 | (4) |
|
|
295 | (1) |
|
Update Client Configuration |
|
|
296 | (2) |
|
|
298 | (1) |
|
|
299 | (1) |
|
|
299 | (1) |
|
|
300 | (1) |
|
Certificate Configuration |
|
|
300 | (2) |
|
Geographic Load Balancing |
|
|
302 | (1) |
|
|
303 | (1) |
|
Azure Traffic Manager and IKEv2 |
|
|
303 | (1) |
|
Azure Traffic Manager Profile |
|
|
303 | (6) |
|
|
307 | (1) |
|
|
308 | (1) |
|
|
309 | (2) |
Chapter 11 Monitor and Report |
|
311 | (18) |
|
|
311 | (4) |
|
|
311 | (1) |
|
|
312 | (1) |
|
|
313 | (1) |
|
|
314 | (1) |
|
Remote Access Management Console |
|
|
315 | (7) |
|
|
315 | (1) |
|
|
316 | (1) |
|
|
317 | (2) |
|
|
319 | (1) |
|
|
320 | (2) |
|
|
322 | (1) |
|
|
322 | (1) |
|
|
322 | (1) |
|
|
322 | (1) |
|
|
323 | (1) |
|
|
323 | (1) |
|
|
324 | (1) |
|
|
324 | (3) |
|
|
325 | (1) |
|
|
325 | (2) |
|
|
327 | (2) |
Chapter 12 Troubleshooting |
|
329 | (20) |
|
|
329 | (1) |
|
|
330 | (3) |
|
|
330 | (1) |
|
|
331 | (1) |
|
|
332 | (1) |
|
|
332 | (1) |
|
|
333 | (3) |
|
|
333 | (1) |
|
|
334 | (1) |
|
|
334 | (1) |
|
|
335 | (1) |
|
|
335 | (1) |
|
|
336 | (1) |
|
|
336 | (1) |
|
|
336 | (1) |
|
|
337 | (1) |
|
Missing Client Certificate |
|
|
338 | (1) |
|
Missing Server Certificate |
|
|
338 | (1) |
|
|
338 | (3) |
|
|
338 | (1) |
|
|
339 | (1) |
|
|
340 | (1) |
|
|
340 | (1) |
|
|
341 | (1) |
|
|
341 | (1) |
|
|
342 | (1) |
|
|
343 | (2) |
|
|
343 | (2) |
|
|
345 | (1) |
|
|
345 | (1) |
|
|
345 | (1) |
|
|
345 | (1) |
|
|
345 | (3) |
|
Clients Prompted for Authentication |
|
|
346 | (1) |
|
|
346 | (1) |
|
|
346 | (1) |
|
|
347 | (1) |
|
Custom Cryptography Settings Ignored |
|
|
347 | (1) |
|
|
348 | (1) |
Index |
|
349 | |