SlideShare a Scribd company logo
1 of 37
Direct Access is the ultimate VPN
solution that is one of the enablers
     for the New Way of Work
Direct Access Benefits
Always On
                    Patch management, health check and GPOs
                                                                      Corporate
             Netw. Lvl. computer/user authentication and encryption
                                                                       Network
  Automatically
connects through
NAT and firewalls
       VPNs connect the user to the network
     DirectAccess extends the network to the remote
                   computer and user
Client         Client and Server applications must be IPv6 compatible Server
 app                                                                  app

IPV6                                                                  IPV6
             Internet                        Corporate intranet




         
Internet                        Corporate intranet




Tunnelling technologies for the Internet and intranet to support IPv6 over IPv4

Internet tunnelling selection based on client location – Internet, NAT, firewa

Encryption/authentication of Internet traffic (end-to-edge/end-to-end)

 Client location detection: Internet or corporate intranet
Forefront
                                                    Native IPv6
                                 Unified
                                 Access
          IPv4 Internet          Gateway              ISATAP
            6to4 tunnel          (UAG)
                                               IPv6 in IPv4 protocol 41
      IPv6 in IPv4 protocol 41
                                                  Corporate Network
      Teredo tunnel                 DNS64
NAT
      IPv6 in UDP port 3544
                                       NAT64           IPv4
    IPHTTPS tunnel
NAT
        IPv6 in HTTPS

  UDP port 3544 blocked
transition mechanism   IPv4    IPv6

Internet                      tunnels
transition technology               IPv6
                               IPv4 Internet


network address translation
IPv6
       packets        dual-stack
IPv4

         Neighbor Discovery
Forefront
                                                    Native IPv6
                                 Unified
                                 Access
          IPv4 Internet          Gateway              ISATAP
            6to4 tunnel          (UAG)
                                               IPv6 in IPv4 protocol 41
      IPv6 in IPv4 protocol 41
                                                  Corporate Network
      Teredo tunnel                 DNS64
NAT
      IPv6 in UDP port 3544
                                       NAT64           IPv4
    IPHTTPS tunnel
NAT
        IPv6 in HTTPS

  UDP port 3544 blocked
Direct Access
corp.example.com zone
IP configured         DNS 1   DNS 2
DNS address


                              Corporate intranet
           Internet
For end-to-edge protection, DirectAccess clients establish an IPsec session to an IPsec
gateway server (which by default is the same computer as the DirectAccess server). The
IPsec gateway server then forwards unprotected traffic, shown in red, to application
servers on the intranet. This architecture works with any IPv6-capable application server
but does not require that server to run IPsec, simplifying the configuration and setup
For end-to-edge with End to End IPSec protection, DirectAccess clients
establish an IPsec session to an IPsec gateway server, and that IPSec traffic
continues all the way to the Intranet server for end to end IPSec protection.
This architecture provides better security than just the End to Edge model.
With end-to-end IPSec protection, DirectAccess clients establish an IPsec
session through the DirectAccess server to each application server to which
they connect. This provides the highest level of security because you can
configure access control on the DirectAccess server and extend IPSec all the
way to the internal server. This architecture requires that application servers
run Windows Server 2008 SP2 or Windows Server 2008 R2 and use both IPv6
and IPsec.
DirectAccess Server                                            Line of Business
     (Server 2008 R2)             Using ISATAP                       Applications


              IPv6                       IPv4                    IPv6




On all internal DCs: Dnscmd /config /globalqueryblocklist wpad
MANAGED     1.   Extends access to line of business servers with IPv4 support
               2.   Access for down level and non Windows clients                    IPv6
               3.   Enhances scalability and management
Windows7
               4.   Simplifies deployment and administration
               5.   Hardened Edge Solution
                                                                                     IPv6
                             DirectAccess                       Always On
Windows7
   UNMANAGED

 Vista                                                             Extend support    IPv4
 XP                          SSL VPN
                                                                   to IPv4 servers



Non
                                             DA Server                               IPv4
Windows                                          +
 PDA                                                                                 IPv4
Direct access for dummies

More Related Content

What's hot

802 11 3
802 11 3802 11 3
802 11 3
rphelps
 

What's hot (20)

Messaging for IoT
Messaging for IoTMessaging for IoT
Messaging for IoT
 
3- NIC Teaming
3- NIC Teaming3- NIC Teaming
3- NIC Teaming
 
Cisco Spark Hybrid Services & Cloud Collaboration
Cisco Spark Hybrid Services & Cloud CollaborationCisco Spark Hybrid Services & Cloud Collaboration
Cisco Spark Hybrid Services & Cloud Collaboration
 
802 11 3
802 11 3802 11 3
802 11 3
 
PLNOG16: Automatyzacja kreaowania usług operatorskich w separacji od rodzaju ...
PLNOG16: Automatyzacja kreaowania usług operatorskich w separacji od rodzaju ...PLNOG16: Automatyzacja kreaowania usług operatorskich w separacji od rodzaju ...
PLNOG16: Automatyzacja kreaowania usług operatorskich w separacji od rodzaju ...
 
Introduction to BRAS
Introduction to BRASIntroduction to BRAS
Introduction to BRAS
 
Ons 2013-nv
Ons 2013-nvOns 2013-nv
Ons 2013-nv
 
Software Defined networking (SDN)
Software Defined networking (SDN)Software Defined networking (SDN)
Software Defined networking (SDN)
 
F5 BigIP LTM Initial, Build, Install and Licensing.
F5 BigIP LTM Initial, Build, Install and Licensing.F5 BigIP LTM Initial, Build, Install and Licensing.
F5 BigIP LTM Initial, Build, Install and Licensing.
 
Linux routing and firewall for beginners
Linux   routing and firewall for beginnersLinux   routing and firewall for beginners
Linux routing and firewall for beginners
 
Delivering Composable NFV Services for Business, Residential and Mobile Edge
Delivering Composable NFV Services for Business, Residential and Mobile EdgeDelivering Composable NFV Services for Business, Residential and Mobile Edge
Delivering Composable NFV Services for Business, Residential and Mobile Edge
 
SDN Scale-out Testing at OpenStack Innovation Center (OSIC)
SDN Scale-out Testing at OpenStack Innovation Center (OSIC)SDN Scale-out Testing at OpenStack Innovation Center (OSIC)
SDN Scale-out Testing at OpenStack Innovation Center (OSIC)
 
MidoNet roadmap
MidoNet roadmapMidoNet roadmap
MidoNet roadmap
 
F5 Meetup presentation automation 2017
F5 Meetup presentation automation 2017F5 Meetup presentation automation 2017
F5 Meetup presentation automation 2017
 
Cci Welcome
Cci WelcomeCci Welcome
Cci Welcome
 
VMworld 2013: VMware NSX Integration with OpenStack
VMworld 2013: VMware NSX Integration with OpenStack VMworld 2013: VMware NSX Integration with OpenStack
VMworld 2013: VMware NSX Integration with OpenStack
 
MidoNet Overview - OpenStack and SDN integration
MidoNet Overview - OpenStack and SDN integrationMidoNet Overview - OpenStack and SDN integration
MidoNet Overview - OpenStack and SDN integration
 
Operations Experience
Operations ExperienceOperations Experience
Operations Experience
 
Software Defined WAN – SD-WAN
Software Defined WAN – SD-WANSoftware Defined WAN – SD-WAN
Software Defined WAN – SD-WAN
 
OpenStack As A Strategy For Future Growth at Cisco
OpenStack As A Strategy For Future Growth at CiscoOpenStack As A Strategy For Future Growth at Cisco
OpenStack As A Strategy For Future Growth at Cisco
 

Viewers also liked

Microsoft Direct Access (Part II)_John Delizo
Microsoft Direct Access (Part II)_John DelizoMicrosoft Direct Access (Part II)_John Delizo
Microsoft Direct Access (Part II)_John Delizo
Quek Lilian
 
Microsoft DirectAccess Remote Access (VPN) with Windows 10 and Server 2012
Microsoft DirectAccess Remote Access (VPN) with Windows 10 and Server 2012Microsoft DirectAccess Remote Access (VPN) with Windows 10 and Server 2012
Microsoft DirectAccess Remote Access (VPN) with Windows 10 and Server 2012
Kemp
 

Viewers also liked (6)

Microsoft Direct Access (Part II)_John Delizo
Microsoft Direct Access (Part II)_John DelizoMicrosoft Direct Access (Part II)_John Delizo
Microsoft Direct Access (Part II)_John Delizo
 
SVR401: DirectAccess Technical Drilldown, Part 1 of 2: IPv6 and transition te...
SVR401: DirectAccess Technical Drilldown, Part 1 of 2: IPv6 and transition te...SVR401: DirectAccess Technical Drilldown, Part 1 of 2: IPv6 and transition te...
SVR401: DirectAccess Technical Drilldown, Part 1 of 2: IPv6 and transition te...
 
SVR402: DirectAccess Technical Drilldown, Part 2 of 2: Putting it all together.
SVR402: DirectAccess Technical Drilldown, Part 2 of 2: Putting it all together.SVR402: DirectAccess Technical Drilldown, Part 2 of 2: Putting it all together.
SVR402: DirectAccess Technical Drilldown, Part 2 of 2: Putting it all together.
 
Microsoft DirectAccess Remote Access (VPN) with Windows 10 and Server 2012
Microsoft DirectAccess Remote Access (VPN) with Windows 10 and Server 2012Microsoft DirectAccess Remote Access (VPN) with Windows 10 and Server 2012
Microsoft DirectAccess Remote Access (VPN) with Windows 10 and Server 2012
 
NAT64 and DNS64 in 30 minutes
NAT64 and DNS64 in 30 minutesNAT64 and DNS64 in 30 minutes
NAT64 and DNS64 in 30 minutes
 
презентация Power point
презентация Power pointпрезентация Power point
презентация Power point
 

Similar to Direct access for dummies

2009 11 06 3gpp Ietf Ipv6 Shanghai Nat64
2009 11 06 3gpp Ietf Ipv6 Shanghai Nat642009 11 06 3gpp Ietf Ipv6 Shanghai Nat64
2009 11 06 3gpp Ietf Ipv6 Shanghai Nat64
yacc2000
 
Internet Protocol Version 6 By Suvo 2002
Internet Protocol Version 6 By Suvo 2002Internet Protocol Version 6 By Suvo 2002
Internet Protocol Version 6 By Suvo 2002
suvobgd
 

Similar to Direct access for dummies (20)

Windows Server 2012 Seminar 4 - De mogelijkheden van Direct Access
Windows Server 2012 Seminar 4 - De mogelijkheden van Direct AccessWindows Server 2012 Seminar 4 - De mogelijkheden van Direct Access
Windows Server 2012 Seminar 4 - De mogelijkheden van Direct Access
 
6. IPv6 Internetzugang für Privatkunden: Die Lösung von Swisscom - Martin Gysi
6. IPv6 Internetzugang für Privatkunden: Die Lösung von Swisscom - Martin Gysi6. IPv6 Internetzugang für Privatkunden: Die Lösung von Swisscom - Martin Gysi
6. IPv6 Internetzugang für Privatkunden: Die Lösung von Swisscom - Martin Gysi
 
2009 11 06 3gpp Ietf Ipv6 Shanghai Nat64
2009 11 06 3gpp Ietf Ipv6 Shanghai Nat642009 11 06 3gpp Ietf Ipv6 Shanghai Nat64
2009 11 06 3gpp Ietf Ipv6 Shanghai Nat64
 
IPv6 - A Real World Deployment for Mobiles
IPv6 - A Real World Deployment for MobilesIPv6 - A Real World Deployment for Mobiles
IPv6 - A Real World Deployment for Mobiles
 
I pv6
I pv6I pv6
I pv6
 
6WINDGate™ - Powering the New-Generation of IPsec Gateways
6WINDGate™ - Powering the New-Generation of IPsec Gateways6WINDGate™ - Powering the New-Generation of IPsec Gateways
6WINDGate™ - Powering the New-Generation of IPsec Gateways
 
6WINDGate™ - Accelerated Data Plane Solution for EPC and vEPC
6WINDGate™ - Accelerated Data Plane Solution for EPC and vEPC6WINDGate™ - Accelerated Data Plane Solution for EPC and vEPC
6WINDGate™ - Accelerated Data Plane Solution for EPC and vEPC
 
A10 Networks: IPv6 Solutions for Enterprise by Paul Nicholson at gogoNET LIVE...
A10 Networks: IPv6 Solutions for Enterprise by Paul Nicholson at gogoNET LIVE...A10 Networks: IPv6 Solutions for Enterprise by Paul Nicholson at gogoNET LIVE...
A10 Networks: IPv6 Solutions for Enterprise by Paul Nicholson at gogoNET LIVE...
 
6WINDGate™ - Enabling NFV for Telco Architectures
6WINDGate™ - Enabling NFV for Telco Architectures6WINDGate™ - Enabling NFV for Telco Architectures
6WINDGate™ - Enabling NFV for Telco Architectures
 
6WINDGate™ - Enabling Cloud RAN Virtualization
6WINDGate™ - Enabling Cloud RAN Virtualization6WINDGate™ - Enabling Cloud RAN Virtualization
6WINDGate™ - Enabling Cloud RAN Virtualization
 
Advances in IPv6 Mobile Access
Advances in IPv6 Mobile AccessAdvances in IPv6 Mobile Access
Advances in IPv6 Mobile Access
 
Ipv6 ppt
Ipv6 pptIpv6 ppt
Ipv6 ppt
 
Ipv6 presention
Ipv6 presentionIpv6 presention
Ipv6 presention
 
Ipv6 presention
Ipv6 presentionIpv6 presention
Ipv6 presention
 
CGNAT Wide Screen
CGNAT Wide ScreenCGNAT Wide Screen
CGNAT Wide Screen
 
Advances in IPv6 in Mobile Networks Globecom 2011
Advances in IPv6 in Mobile Networks Globecom 2011Advances in IPv6 in Mobile Networks Globecom 2011
Advances in IPv6 in Mobile Networks Globecom 2011
 
Internet Protocol Version 6 By Suvo 2002
Internet Protocol Version 6 By Suvo 2002Internet Protocol Version 6 By Suvo 2002
Internet Protocol Version 6 By Suvo 2002
 
IPv6/IPv4 Transition: The experience sharing of Tunnel Broker deployment
IPv6/IPv4 Transition: The experience sharing of Tunnel Broker deployment IPv6/IPv4 Transition: The experience sharing of Tunnel Broker deployment
IPv6/IPv4 Transition: The experience sharing of Tunnel Broker deployment
 
Robert Raszuk - Technologies for IPv4/IPv6 coexistance
Robert Raszuk - Technologies for IPv4/IPv6 coexistanceRobert Raszuk - Technologies for IPv4/IPv6 coexistance
Robert Raszuk - Technologies for IPv4/IPv6 coexistance
 
Building Linux IPv6 DNS Server (Draft Copy)
Building Linux IPv6 DNS Server (Draft Copy)Building Linux IPv6 DNS Server (Draft Copy)
Building Linux IPv6 DNS Server (Draft Copy)
 

More from Alex de Jong (7)

Surviving public speaking
Surviving public speakingSurviving public speaking
Surviving public speaking
 
Client management.ppt
Client management.pptClient management.ppt
Client management.ppt
 
Pki for dummies
Pki for dummiesPki for dummies
Pki for dummies
 
What’s new in windows server 2012
What’s new in windows server 2012What’s new in windows server 2012
What’s new in windows server 2012
 
Windows 7 deployment
Windows 7 deploymentWindows 7 deployment
Windows 7 deployment
 
Deploying windows 8
Deploying windows 8Deploying windows 8
Deploying windows 8
 
Windows 7 Deployment
Windows 7  DeploymentWindows 7  Deployment
Windows 7 Deployment
 

Direct access for dummies

  • 1.
  • 2.
  • 3. Direct Access is the ultimate VPN solution that is one of the enablers for the New Way of Work
  • 4.
  • 5.
  • 7.
  • 8.
  • 9.
  • 10. Always On Patch management, health check and GPOs Corporate Netw. Lvl. computer/user authentication and encryption Network Automatically connects through NAT and firewalls VPNs connect the user to the network DirectAccess extends the network to the remote computer and user
  • 11. Client Client and Server applications must be IPv6 compatible Server app app IPV6 IPV6 Internet Corporate intranet 
  • 12. Internet Corporate intranet Tunnelling technologies for the Internet and intranet to support IPv6 over IPv4 Internet tunnelling selection based on client location – Internet, NAT, firewa Encryption/authentication of Internet traffic (end-to-edge/end-to-end) Client location detection: Internet or corporate intranet
  • 13. Forefront Native IPv6 Unified Access IPv4 Internet Gateway ISATAP 6to4 tunnel (UAG) IPv6 in IPv4 protocol 41 IPv6 in IPv4 protocol 41 Corporate Network Teredo tunnel DNS64 NAT IPv6 in UDP port 3544 NAT64 IPv4 IPHTTPS tunnel NAT IPv6 in HTTPS UDP port 3544 blocked
  • 14. transition mechanism IPv4 IPv6 Internet tunnels
  • 15. transition technology IPv6 IPv4 Internet network address translation
  • 16.
  • 17. IPv6 packets dual-stack IPv4 Neighbor Discovery
  • 18. Forefront Native IPv6 Unified Access IPv4 Internet Gateway ISATAP 6to4 tunnel (UAG) IPv6 in IPv4 protocol 41 IPv6 in IPv4 protocol 41 Corporate Network Teredo tunnel DNS64 NAT IPv6 in UDP port 3544 NAT64 IPv4 IPHTTPS tunnel NAT IPv6 in HTTPS UDP port 3544 blocked
  • 20. corp.example.com zone IP configured DNS 1 DNS 2 DNS address Corporate intranet Internet
  • 21. For end-to-edge protection, DirectAccess clients establish an IPsec session to an IPsec gateway server (which by default is the same computer as the DirectAccess server). The IPsec gateway server then forwards unprotected traffic, shown in red, to application servers on the intranet. This architecture works with any IPv6-capable application server but does not require that server to run IPsec, simplifying the configuration and setup
  • 22. For end-to-edge with End to End IPSec protection, DirectAccess clients establish an IPsec session to an IPsec gateway server, and that IPSec traffic continues all the way to the Intranet server for end to end IPSec protection. This architecture provides better security than just the End to Edge model.
  • 23. With end-to-end IPSec protection, DirectAccess clients establish an IPsec session through the DirectAccess server to each application server to which they connect. This provides the highest level of security because you can configure access control on the DirectAccess server and extend IPSec all the way to the internal server. This architecture requires that application servers run Windows Server 2008 SP2 or Windows Server 2008 R2 and use both IPv6 and IPsec.
  • 24.
  • 25. DirectAccess Server Line of Business (Server 2008 R2) Using ISATAP Applications IPv6 IPv4 IPv6 On all internal DCs: Dnscmd /config /globalqueryblocklist wpad
  • 26.
  • 27.
  • 28.
  • 29.
  • 30.
  • 31.
  • 32.
  • 33.
  • 34.
  • 35.
  • 36. MANAGED 1. Extends access to line of business servers with IPv4 support 2. Access for down level and non Windows clients IPv6 3. Enhances scalability and management Windows7 4. Simplifies deployment and administration 5. Hardened Edge Solution IPv6 DirectAccess Always On Windows7 UNMANAGED Vista Extend support IPv4 XP SSL VPN to IPv4 servers Non DA Server IPv4 Windows + PDA IPv4