Enterprise Applications - eWeek

Enterprise Applications: LABS GALLERY: Windows 7 DirectAccess Connects Remote Clients sans VPN


Windows 7s DirectAccess is a next-generation access technology designed to connect remote clients in the age of the vanishing network perimeter. The following slideshow details installation and setup of DirectAccess during eWEEK Labs' tests. DirectAccess is one of the features Microsoft is pitching as a "better together" benefit of using Windows 7 in tandem with Windows Server 2008 R2.
 
  • LABS GALLERY: Windows 7 DirectAccess Connects Remote Clients sans VPN
    by Andrew Garcia
  • Installing DirectAccess
    From the Server Manager, administrators can easily install the DirectAccess feature (it's not a Role), which also installs the Group Policy Management snap-in.
  • No Tools
    DirectAccess installation must be done from the server itself, directly or via Remote Access. There is no admin pack or tool to install on a Windows desktop.
  • DirectAccess Setup
    The DirectAccess setup wizard walks the administrator through the process, defining eligible client machines, the DirectAccess server, target intranet servers and core intranet directory management elements.
  • DA Clients
    Base authentication is per machine, not per user. PCs are assigned to a security group eligible to use DirectAccess. This step sets up a filter, including machines permitted to receive DirectAccess configuration via Group Policy.
  • Adapters
    The administrator defines which NIC goes to which network.
  • Certificates
    Using my domain's certificate services, I created the certificate that is passed here to the client machines.
  • Location Server
    Administrators must define a location server on the intranet. Clients check this address to determine whether they are local or remote.
  • NRPT
    DirectAccess leverages a new feature in Windows 7 called the Name Resolution Policy Table. This table maps a DNS namespace to a DNS server, allowing remote clients to know when to phone home and when to go to the regular Internet.
  • Apply Policy
    After creating the policy, I could save it and apply it immediately. My first attempt failed due to a DNS suffix problem on the DirectAccess server. I just wish the wizard could have told me that.
  • Group Policy Objects
    Applying the DirectAccess policy creates Group Policy Objects that are applied to the Default Domain Policy, filtered to allowed client machines. Here is a sample policy. As it is an ADMX template, don't ever expect to find DirectAccess ported to Windows XP (although it may be to Vista one day).
  • DNS
    DirectAccess relies on IPv6 for connectivity, so internal application servers and the DNS server must support IPv6.
xڽZ[s۸~~d_nw7ŗXbwIHB ,JVeSjy|8oi&4oAuB>K9lHbc.!KvfzC7o``ƛVYQ|v$UK*7-;RLDL1OwҨxLO^>.B࿎F:|=F#mX021q #yF.#An{R7Yh[((6j{A،LQLDruzH&$fvȿ+|>o~QLg\M<4#9 "L7'f*Ή{'_tt6g4Wln(3сױ1,?ۈnS3aܰ)M)vtZ4ܪwP臑WhNdm\)I;-<><:1)+Vʢ M&x9tKS:f:bLÃnF1>PC ';!{0#p\V5Ra5G\攪1O|؈{G{(a(;}eq+)P0nC-U̥zU\Ɋn'p` Ձ ^2R`-*T հq셜Þݙo&)?>d R_E!*aR= ׼>Iqv* .[1aCuTD,O4͌3Ky W&?׀c:sBrZ)ĺQĴdv-[9Ϛ 7s.9n ٝօrI/ ah~I%_zlgŎvjf]ffSO0[h>\ !I$STؖN ik'?aWyQq& XR?Ó,)uN~t@|@>c/1)rd|>s\MbSH;{$+}7icqD8 +9 (< ^0ZV {7VeLt"dY> "6#h9p\+ɻtqO@"f.[㑙CB0e_.Ն^ovﶍ#+𫄐Х$^Xr:= vA͘wsN%!JfI+knsqeQapS#Z7>g67c 3O#$vjڧDw% vӂֽWˆלWestOuO~)\9c.4ga-q a cp+)=jѤ:>*7p}SUA^8/VK@V ncFјfTT>g_Y#xO3+(XP.u1sgֽ]0? V|țjUxמo4g{l qEig`oiXI%k#׉x`+,B!S]OLmSgNVӪ2讞]BU:m-.U3g`GG*ar;LmTkqء9j[Xo2cQ JvV_ܔ&˼C]`I`z#p7PD'RMApuPy#y&յy8$Pc.kEb oDz j*cnW~#Z3H䈘 M؞(.D-bt7")th8ɗn &5 ;όF)xp98R.'2]([yw~ޑZuU )RX^c݆̪f;OY*@Λ5`(3<>яv&NXyB)@ SPpxdMADfTaz8ak`9 &*nZS4,PB qٓu"fˆI^KerDdT!Ǫl or AmkB Cs.)(iͩu ?YdbPds[6d$ͺ4X9X؅$ wwv3]»C.0x` acmA4sǑg,Rm.!?^>qL玩&G \01cX{}=+rx>qekZFEbp\|rvP~|x{/: L"s}{zap'xtOO{Wp QXa,m7:~y3Ne`)7}x/\t| Zh3Ow?7mXΊF+c+Ѩ~=ŴYI2UeTF,7vZFSƼ ܟ.^: w%16:tq@N㭲P ƫzD>,