Network Subsystem: Remote Access Service Objectives

 Remote Access ServerWANprotocolCom linkDUN client

*The Golden Rule: a client is a client is a client ...
1. Communication Links and Protocols (Connectivity)
2. Remote Access Service - emphasis on RAS Server (Configuration)
3. Dial-up Networking - RAS client, DUN Monitor, Autolink feature (Configuration)
4. Multilink PPP (Performance)
5. Callback Security and Dial-in Permission (Security)
6. Password Encryption (Security)
7. Networking Essentials: RAS Server Service as a Gateway, Router, and Firewall (Connectivity)
8. Logs, Dial-Up Networking, Modems, Ports,  DUN Monitor ... (Troubleshooting / Configuration)
9. Interdependencies and Trivia - TAPI settings, Securing DUN for the Net (MISC.)

Communication Links Connectivity

WANCom link

1. Public Switched Telephone Network (PSTN)
2. Integrated Service Digital Network (ISDN)
3. X.25 packet switching network  - transmits data with packet switching protocol. Relies on DCEs, data communication equipment, an elaborate worldwide network of pack forwarding nodes that participate in delivering an X.25 packet. DUN clients can access X.25 directly by using an X.25 packet assembler/disassembler (PAD). PAD does not require an X.25 line plugged into back of computer. Requirement: tele # and PAD service for the carrier.

WAN Protocols Connectivity

WANprotocol

1. SLIP - Serial Line Internet Protocol - primary function is to dial in to Unix Server.

2. PPP - Point-To-Point Protocol

3. MS RAS Protocol -proprietary MS protocol that supports the NetBIOS standard.

4. SecurityPPTP enables ?tunneling? of IPX, NetBEUI, or TCP/IP inside PPP packets to establish a secure link between a client/server over the Internet. PPTP connections establish Virtual Private Networks (VPNs) PPTP uses a encryption more secure than standard communications over the network itself. PPTP over the Internet is safe.

LAN Protocol Connectivity

protocol

1. TCP/ IP
2. IPX (NWLink)
3. NetBEUI
  Network Applet> Bindings Tab > * Only one LAN protocol is used over the RAS connection. The first common protocol identified between the client and server is used. Binding order of protocols to the RAS dial-up adapter on the client is critical (most important MUST be located at the top).

RAS Configuration (emphasis on Server)

Remote Access ServerWANDUN client

RAS Configuration

Network (Configuration)

Dial Up Networking - RAS client

WANDUN client

Dial-Up Networking Client Configuration (Phonebook *.pbk)

Dial-Up Networking Monitor

Multilink PPP Performance

Remote Access ServerWANprotocolDUN client

Multilink PPP Installation

Callback Security and Dial-in Permission Security

Remote Access ServerSecurityWANDUN client

1. Configuring Callback Security and Giving a User the ability to Dial-in to the Remote Access Server Service

1a. Callback Options

2. Configuring Callback Security on the Client

2a. Callback Options

3. Callback and Multilink PPP interdependency

Password Encryption Security

Remote Access ServerSecurityWANDUN client

1. Configuring Password encryption in the Remote Access Server Service

2. Configuring Password encryption on the client

HelpA couple of Tran... questions have become the subject for great debate which no one seems to agree on, soooo, figure I'll add my two cents to it. In a nutshell, the question is this: does Allow Any Authentication Including Clear Text provide both data and password encryption by default when an MS client dials into NT Server? I have been unable to locate a single MS Source that says it doesn't. What may throw you off is the checkbox that enables you to select RSA data encryption "in addtion to" MS-CHAP. Look again! Look at the RAS Server. The setting on the Server reads "require data encryption" in addtion to "require ms encrypted authentication." On the client, it is "accept only" etc. What does this likely mean? It likely means if the client (or the server) can't produce it -- they ain't talking!

Second and probably the best evidence I have been able to find: it appears that RSA data encryption and MS-CHAP authentication as implemented by NT RAS are not seprate beasts afterall (Microsoft Help. Keyword = RSA. Title of document = Data Encryption):

Well, that's my two cents. I say what the heck, it does! In the RL World, set your clients to MS-CHAP and require data encryption to be sure :-)

RAS Server as a Gateway, Router, and Firewall

Remote Access ServerSecurityprotocolWAN

  Configuration

Troubleshooting RAS

troubleshootRemote Access ServerWANDUN client

 
Logging

Start > Programs > Accessories >DUN client> More

Start > Settings > Control Panel > modems > Modem > Properties > Connection Tab >
*Note: The settings in the DUN client applet override the settings you have made in the ports applet for your ports and in the modems applet for your modems when using dial up networking.

Start > Settings > Control Panel > ports> COMx > Settings

Start > Settings > Control Panel > Dial-Up Monitor

HardwareHardware and MISC.

RAS Interdependencies and Other

WANTelephonyCom link