Тёмный

24. Install and Configure Remote Access VPN on Windows Server 2019 

MSFT WebCast
Подписаться 89 тыс.
Просмотров 163 тыс.
50% 1

Video Series on Advance Networking with Windows Server 2019:
In this video guide, we will learn the steps on How to Install and Configure Remote Access (VPN) on Windows Server 2019 with Network Policy Server. We will also configure port forwarding on router to allow required port to connect VPN server.
1: Install Remote Access Server role.
2: Configure Routing and Remote Access service.
3: Setup User accounts and Group for VPN.
4: Setup NPS Network Access Policy.
5: COnfigure Port Forwarding on Router.
6: Test VPN functionality on Client Machine.
Follow my blogs:
msftwebcast.blogspot.com

Опубликовано:

 

12 ноя 2019

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 163   
@mckalyster
@mckalyster 3 месяца назад
WOW WOW WOW. Can you image how well I felt after watching this????? Best practice ever
@rickdeckard9810
@rickdeckard9810 Год назад
Thanks for not editing out the errors, troubleshooting is sometimes the best way to learn. Appreciate it!
@ThatITGuyy
@ThatITGuyy 2 года назад
Whoever put this video together, I literally struggled watching so many, because they left out key 0.1% facts of the info you were pointing out! Thank you for this video!
@rydahl8370
@rydahl8370 4 года назад
man these videos got me through my exam - MSFT Webcast real mvp
@Staylecrate
@Staylecrate 10 месяцев назад
Amazing video! Thank you so much. I was hung up when configuring my VPN. That check box you did in the network policy error solved my issue. I watched the whole video start to finish anyway and just love the speed you went through it all with. It really erks me when people over-narrate or get side tracked talking about something else. This was quick, concise, and to the point. Thanks again!
@MSFTWebCast
@MSFTWebCast 10 месяцев назад
Thank You.
@Staylecrate
@Staylecrate 10 месяцев назад
@@MSFTWebCast do you know if Microsoft ever fixed the 2019 server update bug that stopped RRAS from working?
@Mrnecropotence
@Mrnecropotence 3 года назад
Thanks for the post man, i have been running through them, yust out of curiosity. Keep up the good work.
@samfalcon8496
@samfalcon8496 Год назад
I really love the way teaching and explaining
@OmegaKatanaXIII
@OmegaKatanaXIII 5 месяцев назад
Thank you for breaking this process down to the point I can easily follow along with the steps.
@super_straight
@super_straight 2 года назад
You are awesome! Many thanks for the clearly explained tutorial. It saved me so much pain and time!!!!🏅
@MSFTWebCast
@MSFTWebCast 2 года назад
Glad it helped!
@krzemyk84
@krzemyk84 3 года назад
Great tutorial! Thank you so much for your help and keep up the good job :)
@mattdent6565
@mattdent6565 4 года назад
Very helpful - thanks!
@yogeshvyas605
@yogeshvyas605 2 года назад
Nice video, Base on ur video I have implemented RAS server in my infra. Thank you so much.
@MSFTWebCast
@MSFTWebCast 2 года назад
Great 👍
@niccite
@niccite 2 года назад
Excellent Tutorial - Thank You!
@MSFTWebCast
@MSFTWebCast 2 года назад
Glad it was helpful!
@violetmakwakwa3060
@violetmakwakwa3060 3 года назад
thank you, the video was very helpful..
@roelhr
@roelhr 3 года назад
Excellent video! Subscribed. Thank you.
@MSFTWebCast
@MSFTWebCast 3 года назад
Thanks for the sub!
@TheRaaju007
@TheRaaju007 2 года назад
Very good explanation.
@boytongo
@boytongo 3 года назад
Very well explained
@alimuratgoral2370
@alimuratgoral2370 3 года назад
Excellent video. Thank you 👍
@MSFTWebCast
@MSFTWebCast 3 года назад
Thank you too!
@danielmaricelmunteanu5059
@danielmaricelmunteanu5059 3 года назад
Thanks, punctual and precise, in what regards the client to client routing through the vpn ..?
@riccardolaporta7746
@riccardolaporta7746 2 года назад
Thanks so much ❤
@schiet100
@schiet100 2 года назад
Thank you!!!
@chimmajhulewala9522
@chimmajhulewala9522 2 года назад
Great, Thanks
@imthi007
@imthi007 3 года назад
Very Impressed , I have tried so many ways VPN not work. but this single Video made my day... Many thanks indeed
@MSFTWebCast
@MSFTWebCast 3 года назад
Glad to hear that
@imthi007
@imthi007 3 года назад
@@MSFTWebCast I need one more favour not able to ping my server ip or not able to access my share folder. Ex. My vpn ip is 10.0.0.103 and my server is 10.0.0.100
@MSFTWebCast
@MSFTWebCast 3 года назад
Please check firewall settings, open required ports for ICMP and File and Printer Sharing Service.
@obaidullahnoor8604
@obaidullahnoor8604 7 месяцев назад
Great sir!!
@victorgarcia-sz7vh
@victorgarcia-sz7vh 3 года назад
Thank you for the video
@MSFTWebCast
@MSFTWebCast 3 года назад
Welcome!
@muhammedfahim8168
@muhammedfahim8168 2 года назад
great job
@AndrewSmith-wf3mf
@AndrewSmith-wf3mf Год назад
Well Done!!!
@AndrewSmith-wf3mf
@AndrewSmith-wf3mf Год назад
Thank U
@nellbeatsdallas
@nellbeatsdallas 4 года назад
Love the videos, How do I set up to where users use fingerprint scanner to access vpn? (Multi-Factor Authentication)
@AndrewSmith-wf3mf
@AndrewSmith-wf3mf Год назад
Perfect
@johnnykerbaj4840
@johnnykerbaj4840 2 года назад
Thanks a lot
@MSFTWebCast
@MSFTWebCast 2 года назад
Thank You too.
@tennisball2012
@tennisball2012 3 года назад
Crazy good video
@MSFTWebCast
@MSFTWebCast 3 года назад
Glad you think so!
@Ranjeetkumar-fj4kp
@Ranjeetkumar-fj4kp 3 года назад
nice..
@jg6111
@jg6111 3 года назад
A good video. Please include a logical diagram too for better understanding. Thank You.
@MSFTWebCast
@MSFTWebCast 3 года назад
Noted..
@hamzabeniffou9324
@hamzabeniffou9324 3 года назад
Hello, I would like to know how can I setup in order to access to my vCenter Server remotely ? is it possible to do it like this way ? do you have a video on this please? thanks
@williamm200
@williamm200 Год назад
Windows making easy to setup
@SunilBaniyal
@SunilBaniyal 3 года назад
After Doing this process can i take my office computer remote from home using Remote Desktop Connection?
@boytongo
@boytongo 3 года назад
Can you please name which is the most secure protocol when using vpn. Thank you so much
@minhtempe
@minhtempe 3 года назад
Thanks for sharing very helpful video. I followed all steps and I can connected to server but I cannot access any files or ping to server. What do I need more? Please help
@micheledimauro1282
@micheledimauro1282 4 года назад
with this kind of Vpn i can successfully connect and ping each ip address in the remote vpn site, but can't reach resources by hostname, any suggest??
@BunjackThuok
@BunjackThuok 3 года назад
Brilliant thanks dear
@MSFTWebCast
@MSFTWebCast 3 года назад
Thank you too
@AvtarSingh-jw3xs
@AvtarSingh-jw3xs 2 года назад
Hi, it's a very helpful video. Please let me know how I connect my Server to use any application remotely using VPN. Like Using RDP, i can connect server remotely through static IP. Please help
@ferhatyildizcomtr
@ferhatyildizcomtr 3 года назад
Hi, How can we do multiple authentication to protect hi vpn? Do you have a video about this?
@DerrickThomas17
@DerrickThomas17 3 года назад
Hey great video. I came across your channel and it's fabulous. Question, everything works great when I test the vpn internally, when external, it connects but cannot ping the file server via IP or name. What am I missing? Thank you and I also subbed to your channel. Keep those great videos coming.
@MSFTWebCast
@MSFTWebCast 3 года назад
Check firewall rule settings on VPN Server and also the IP configuration settings. Might be IP routing related issue.
@MSFTWebCast
@MSFTWebCast 3 года назад
And thank you for sub.
@DerrickThomas17
@DerrickThomas17 3 года назад
@@MSFTWebCast I still cannot browse from the outside. Any ideas?
@visionshahi8196
@visionshahi8196 Год назад
Hey I loved your all videos.. Can you make a video through which we can use remote access vpn to secure remote desktop connection. You just show how we can install and connect it but if you show how we can use it to secure the services. It will be great. Just tried but failed because the remote desktop services have rd gateway and NPS installed. With NPS we have to configure VPN for RD gateway. I tried to add IP VPN static port range as IP scope in firewall for TCP port 3389. But when client computer is connected with VPN the Public IP was not changing, than i read few articles online and found the issue which was "enable remote default gateway server" in VPN connection. But when i enable this internet will not work. I didnt found any video which show proper use of remote access vpn to secure Remote desktop connection and other services. Please can you make one video on this. One of your big subscriber
@parthpardeshi62
@parthpardeshi62 3 года назад
Hi.. I've set up the vpn as per your steps but I'm getting vpn error 806.. I've tried imbounding policy for 1723 port and also ported my router. Still I'm getting that error
@khairisyafi5005
@khairisyafi5005 2 месяца назад
what if i use mobile hotspot? can i use my phone for port forwarding?
@hameedullah3355
@hameedullah3355 2 года назад
Sir would u like to record tutorials on vpn suppose if an organisation has only single server in Headd office, and they have network router and switching in 4 sub offices . How they will use the resources from remote end . Kindy expalin it.
@alexmironescu8797
@alexmironescu8797 5 месяцев назад
Hi, I hope this post finds you well, your tutorial is brilliant, I managed to set up the vpn, I can connect to the server from another pc but only if it's on the local network, I did all the steps you did but without success.Could you help me? I mention that the domain used is hosted as a website. I get this error when I try to connect from a pc on another network: “The network connection between your computer and the VPN server was interrupted. This can be caused by a problem in the VPN transmission and is commonly the result of internet latency or simply that your VPN server has reached capacity. Please try to reconnect to the VPN server. If this problem persists, contact the VPN administrator and analyze quality of network connectivity.” Help me, please
@Checc1
@Checc1 9 месяцев назад
I'm getting the following: "Windows cannot process the object with the name "TestUsers" because of the following error: The specified domain either does not exist or could not be contacted. Any idea how to fix this
@samuelessel5366
@samuelessel5366 Год назад
Hello thanks for the lessons. I want to connect my laptop to my dicom server at work.. pls help
@MuhammadWaqas-gr4gg
@MuhammadWaqas-gr4gg День назад
whats the difference between your PPTP VPN vs "Remote access VPN??? i am not clear
@jeffb1328
@jeffb1328 2 года назад
When I click on Dial in properties on a user I get the error message: "Could not load the Dial-in profile for this user because: The network path was not found", any idea why?
@hv3300
@hv3300 3 года назад
Great video. At 13.22 user you created in test group is different from what you have used -Any thoughts?
@MSFTWebCast
@MSFTWebCast 3 года назад
Yes, the user is same. The User display name is Test User1 and login name is User1 (UPN: User1@mylab.local). Sorry for the confusion.
@hv3300
@hv3300 3 года назад
@@MSFTWebCast Gotcha. Thank you for the clarification.
@bruhcsp
@bruhcsp 4 месяца назад
Good, but you ignored that some people don’t have the Active Directory configured.
@agreniers
@agreniers Год назад
What do I do with the NPS error when trying to activate vpn server..
@mavicmaster
@mavicmaster 3 года назад
Hello, Hope you are doing well. Can this be accessible from outside network? If not, what do i need to do to connect from outside network? Thanks.
@mavicmaster
@mavicmaster 3 года назад
It's works.
@parthpardeshi62
@parthpardeshi62 3 года назад
I'm having an issue.... The vpn is connected from another network it's not showing the shared files, however when it is connected from my office network, the I can see the files.... Please help I've been trying since one month 🥲
@skeemyweenus4995
@skeemyweenus4995 3 года назад
Question for 4:09 . So If you're specifying 10 ip addresses, would that mean that there can only be 10 users using VPN at the same time? If yes, then how can make it so that it can fit (for example) 1,000 users? If that is possible.
@MSFTWebCast
@MSFTWebCast 3 года назад
You need to use bigger subnet with 1000 IPs.
@DytliefMoller
@DytliefMoller 4 месяца назад
very entertaining, good info too
@netitfish
@netitfish 3 года назад
Routing and Remote Access service has not started The specified file cannot be found. Can you help me to resolve this problem? thank you.
@anilahuja3679
@anilahuja3679 4 года назад
Using this video I was able to create the VPN connection and tested it out. I can't see the Remote Server in my Network on the Client PC and can't map a network drive from the Server either. What am I missing?
@yogeshvyas605
@yogeshvyas605 2 года назад
Try to map drive with fully fqdn name
@digimation6862
@digimation6862 2 месяца назад
Remember in the cliente pc enable File AND Share Folder to allow communication of the pc AND the server
@Giancarlo_Sforza
@Giancarlo_Sforza 7 месяцев назад
Did you have to publish any DNS records in Cloudflare or other DNS registrar or is port forwarding just enough for this to work? My question is, how is the remote windows10 client able to locate the windows vpn server via the internet? I suppose port forwarding takes care of that
@MSFTWebCast
@MSFTWebCast 7 месяцев назад
if you want to connect your VPN server using FQDN (name like website address) then DNS registration is required otherwise you can use the static public IP address to connect to your VPN server.
@Giancarlo_Sforza
@Giancarlo_Sforza 7 месяцев назад
@@MSFTWebCast Thank you for the reply, this is very helpful. It seems like on this video you are using the PPTP protocol which is not very safe nowadays hence I am trying to get IKEv2 to work. I found the video very helpful though and made me understand the whole concept a lot better. I was working on setting up an IKEv2 Always On VPN with device certificate issued by my on-prem Cert Authority windows server (not signed by digicert or any other CA). I didn't have much luck so far but I am on good track I just need to enroll a physical laptop to my domain so i can get the device certificate to that laptop or find another way of moving the certificate to a laptop that is not domain joined. I was looking to find a video of yours setting up VPN with the IKEv2 protocol, is there one?
@niteshsantoki
@niteshsantoki Год назад
Hello Sis, After folowing your steps, I still Cant be able to connect over public IP address, It is displaying an error in YELLOW TEXT - " The network connection between your computer and the VPN server was interrupted. This can be caused by a problem in the VPN transmission and is commonly the result of internet latency or simply that your VPN server has reached capacity. Please try to reconnect to the VPN server. If this problem persists, contact the VPN administrator and analyze quality of network connectivity." - I'm not sure what im doing wrong. Please Help. Thank you so much.
@Izzy25
@Izzy25 2 года назад
Does client computer need to be on the same domain? Ex. If user is using personal laptop or iPhone can they still connect? The user itself would be a domain user but the devices wouldn’t be on the domain.
@MSFTWebCast
@MSFTWebCast 2 года назад
Yes they can connect.
@user-hs1nw1hq2x
@user-hs1nw1hq2x Год назад
thak you very much sir. but how do i do this on vmware without router. I don;t have router please reply sir
@christiangutang6189
@christiangutang6189 3 года назад
How were you able to access your router? Because when I tried to put my virtual machine's default gateway in the browser, it said that it can't reach the page.
@MSFTWebCast
@MSFTWebCast 3 года назад
You have to select bridge adapter mode for VirtualBox adapter. Make sure that the IP address is in same range as your router.
@sagarrajput335
@sagarrajput335 4 года назад
i am getting a error "the connection was prevented because of a policy configured on rsa/vpn server. "
@agboolamatthew
@agboolamatthew Год назад
Please I need help. I have been trying to follow your video. Got stuck around step 4. Is there any need to create a special user applied on a group or a normal user can just be used.
@MSFTWebCast
@MSFTWebCast Год назад
Normal user will do the job. Follow the same steps and check everything. If already you have created the NPS policy, you can delete it and restart the NPS service and recreate again.
@babatundeadeyemi2800
@babatundeadeyemi2800 2 года назад
Thanks for this video, its very useful. However, i noticed that once i restart the server, all configuration would go back to default. Is there any way i could keep the configuration permanent. Thnks
@kelkloud24
@kelkloud24 2 года назад
not usually recommended, but you can use deepfreeze
@hubertpowell340
@hubertpowell340 4 года назад
The problem I am having is I can connect to the VPN server from inside my network, but if I try to connect from an external network, I get the message, The remote connection was denied because the user name and password combination you provided is not recognized, or the selected authentication protocol is not permitted on the remote access server.
@UndergroundCarGuys
@UndergroundCarGuys 2 года назад
Could be due to the Domain, you may need to put the @[Domain Name] After the username.
@user-ny6xi8oy8z
@user-ny6xi8oy8z 5 месяцев назад
hi, does this work if I dont have static public IP? if not what are the other way to do this?
@MSFTWebCast
@MSFTWebCast 5 месяцев назад
With dynamic IP address on VPN server, you can use dynamic DNS service provider for VPN connection. There are several dynamic DNS provider which provide dynamic IP address to easy to remember hostname (Dyn DNS or no-ip). Using this static hostname, client can connect to your VPN server. They will automatically update the dynamic IP address in their DNS server to connect hostname to updated dynamic IP address if your dynamic IP address changed.
@moehans9833
@moehans9833 Год назад
can we install this on and active directory server as we only have one server
@MSFTWebCast
@MSFTWebCast Год назад
Yes, you can but from security point of view it will be risky.
@asriishak4881
@asriishak4881 4 года назад
why my server doesn't have 'active directory users & group'?
@mauriziopersi401
@mauriziopersi401 4 года назад
It is a DC?
@CarlMakesItEasy
@CarlMakesItEasy 4 года назад
upgrade to a domain controller through Add roles and features and Active Directory Domain Services
@Information_Dude69
@Information_Dude69 6 месяцев назад
If the Client Machine In Work From Home, Is Client Machine Can Connect VPN With his/her Home internet Connection?
@MSFTWebCast
@MSFTWebCast 6 месяцев назад
Yes, it can.
@muthukannannatarajan747
@muthukannannatarajan747 3 года назад
Ji after connecting the vpn internet browsing is getting disable in client computer what to do for this problem
@redadz9105
@redadz9105 3 года назад
Go to advanced settings of your vpn and enable split tunelling
@samliang4146
@samliang4146 9 месяцев назад
why can;t i open my router setting page when i type in the default gateway address of my nit, i tried both NAT and lan segment, neither of them can open router page. why
@MSFTWebCast
@MSFTWebCast 9 месяцев назад
Ask your network administrator, Might be he/she can help with that.
@ahmedsaad-lk2og
@ahmedsaad-lk2og 2 года назад
ok
@SachinKumar-il2yy
@SachinKumar-il2yy 2 года назад
How we can contact you for further assistance
@zefur321
@zefur321 Год назад
my server is not Active Directory server. Can I enable VPN ?
@MSFTWebCast
@MSFTWebCast Год назад
You can install Remote Access Server role without AD and setup a server to act as a VPN server. You just need to create user accounts from computer management and assign dial-in permission.
@kgerakopoulos
@kgerakopoulos 3 года назад
Can I use this remote to connect outside of local lan? And is it safe from hackers ?
@MSFTWebCast
@MSFTWebCast 3 года назад
Yes, you can use VPN to connect your local LAN over the Internet. Yes, it is safe.
@sjnlim3925
@sjnlim3925 3 года назад
do we need static public ip in this config ?
@MSFTWebCast
@MSFTWebCast 3 года назад
Yes, on VPN servers internet facing interface.
@MohammedESeno
@MohammedESeno Год назад
Hello.. how can I contact you?
@Digitalrozgarmission
@Digitalrozgarmission 2 года назад
the network connection between your computer and the vpn server was interrupted this can be caused by a problem in the vpn tansmission and is commonly the result of internet. getting this error
@jestercagzreynales7611
@jestercagzreynales7611 Год назад
same can anyone pls help
@numanahmad4471
@numanahmad4471 3 года назад
When i try to connect it says “A connection remote computer can not be established. So the port used for this connection was closed “
@MSFTWebCast
@MSFTWebCast 3 года назад
Have you opened the required ports in your router or firewall?
@xyztamilan
@xyztamilan 2 года назад
HI I am connected to vpn but unable to ping the server or access the server. Any idea how to fix it
@MSFTWebCast
@MSFTWebCast 2 года назад
Configure the dial-up connection properties with DNS servers address. You can also configure static routes to connect to the other local network using VPN.
@srinivaskandregula9497
@srinivaskandregula9497 Год назад
when i am connecting to my server vpn i unable to access out side internet as well. is there any solution.
@MSFTWebCast
@MSFTWebCast Год назад
You have to setup NAT on your VPN server.
@androidsavior
@androidsavior 5 месяцев назад
@@MSFTWebCast how to do so ? should i install a second network adapter ?
@20006raghu
@20006raghu 2 года назад
I need your help I'm unable to connect remote acces
@MSFTWebCast
@MSFTWebCast 2 года назад
What kind of error you are receiving?
@mdrashidhussain7168
@mdrashidhussain7168 4 года назад
This is virtual machine...????
@MSFTWebCast
@MSFTWebCast 4 года назад
Yes. entire demo is in virtualbox VM.
@CharcoalProduction
@CharcoalProduction 3 года назад
Why we are not using MSCHAPv2?
@MSFTWebCast
@MSFTWebCast 3 года назад
MS-CHAPv2 is an old authentication protocol. EAP with MS CHAPv2 is more secure and common form or PEAP.
@sanampreet9878
@sanampreet9878 Год назад
But without network policy configuration it is working It is compulsory to configure network policy
@MSFTWebCast
@MSFTWebCast Год назад
If you dont have NPS server, you can grant allow access to dial in in user account property to use VPN without network policy. If you have NPS server then you can setup the NPS policy as per your company requirement, it is not compulsory.
@headara4372
@headara4372 2 года назад
after use vpn what's happen on computer client didn't have internet !
@MSFTWebCast
@MSFTWebCast 2 года назад
The use of VPN is to provide secure communication over Internet while connecting to Office network from Public Network. If there is no internet then this will not work.
@shyamsundermayengbam3221
@shyamsundermayengbam3221 Год назад
Let's make soft!
@anis5709
@anis5709 2 года назад
I got this error msg on 7:45 "Windows cannot proces the object with the name TestUsers: The specified domain either does not exist or could not be contacted" can u help me pls?
@MSFTWebCast
@MSFTWebCast 2 года назад
On Find Now, window can you see your group? Make sure you have used the domain admin or equivalent credential to logon to that server. NPS server must be registered in Active Directory.
@anis5709
@anis5709 2 года назад
@@MSFTWebCast the server dosent had a domain. That was the Problem. I created one :). Im by Step 5 and i dont have the access to the router because the server is hosted online by a provider. Any solution or idea? Thx for ur answer :)
@MSFTWebCast
@MSFTWebCast 2 года назад
@@anis5709 If your server is not part of AD then you can use create Users or Groups on local Server and use it in VPN authentication.
@armandadvar6462
@armandadvar6462 Год назад
I have error on installation process.
@MSFTWebCast
@MSFTWebCast Год назад
What kind of error? Any message?
@muthukannannatarajan747
@muthukannannatarajan747 3 года назад
Only vpn is working
@anilahuja3737
@anilahuja3737 4 года назад
a
@dhilipkumar9784
@dhilipkumar9784 2 года назад
Sir what to give in user name and password, you gave Msdwebcast? Pls reply sir
@dhilipkumar9784
@dhilipkumar9784 2 года назад
While accessing router it asks for user name and password
@MSFTWebCast
@MSFTWebCast 2 года назад
If you have not set up the password no your router then use the default username password. Based on your routers model, you can find the default username and password on Internet.
@naifhomood4309
@naifhomood4309 4 года назад
What if i don’t have a router how can i select pptp port ?
@naifhomood4309
@naifhomood4309 4 года назад
I broadcasting the internet from my iPhone to virtual machine
@MarloMitchell
@MarloMitchell 3 года назад
The accent is adorable.
Далее
25. Set up L2TP/IPSec VPN on Windows Server 2019
13:50
VPNs Explained | Site-to-Site + Remote Access
9:08
Просмотров 817 тыс.
Server 2019 VPN Installation and configuration
9:10
Просмотров 69 тыс.
Always On VPN Deployment Guide
1:45:23
Просмотров 74 тыс.