24. Install and Configure Remote Access VPN on Windows Server 2019

Поделиться
HTML-код
  • Опубликовано: 10 окт 2024
  • Video Series on Advance Networking with Windows Server 2019:
    In this video guide, we will learn the steps on How to Install and Configure Remote Access (VPN) on Windows Server 2019 with Network Policy Server. We will also configure port forwarding on router to allow required port to connect VPN server.
    1: Install Remote Access Server role.
    2: Configure Routing and Remote Access service.
    3: Setup User accounts and Group for VPN.
    4: Setup NPS Network Access Policy.
    5: COnfigure Port Forwarding on Router.
    6: Test VPN functionality on Client Machine.
    Follow my blogs:
    msftwebcast.bl...

Комментарии • 169

  • @mckalyster
    @mckalyster 6 месяцев назад +4

    WOW WOW WOW. Can you image how well I felt after watching this????? Best practice ever

  • @rickdeckard9810
    @rickdeckard9810 Год назад +7

    Thanks for not editing out the errors, troubleshooting is sometimes the best way to learn. Appreciate it!

  • @ThatITGuyy
    @ThatITGuyy 2 года назад +5

    Whoever put this video together, I literally struggled watching so many, because they left out key 0.1% facts of the info you were pointing out!
    Thank you for this video!

  • @rydahl8370
    @rydahl8370 4 года назад +12

    man these videos got me through my exam - MSFT Webcast real mvp

  • @Staylecrate
    @Staylecrate Год назад +2

    Amazing video! Thank you so much. I was hung up when configuring my VPN. That check box you did in the network policy error solved my issue. I watched the whole video start to finish anyway and just love the speed you went through it all with. It really erks me when people over-narrate or get side tracked talking about something else. This was quick, concise, and to the point. Thanks again!

    • @MSFTWebCast
      @MSFTWebCast  Год назад

      Thank You.

    • @Staylecrate
      @Staylecrate Год назад

      @@MSFTWebCast do you know if Microsoft ever fixed the 2019 server update bug that stopped RRAS from working?

  • @OmegaKatanaXIII
    @OmegaKatanaXIII 8 месяцев назад +1

    Thank you for breaking this process down to the point I can easily follow along with the steps.

  • @samfalcon8496
    @samfalcon8496 2 года назад +1

    I really love the way teaching and explaining

  • @imthi007
    @imthi007 3 года назад

    Very Impressed , I have tried so many ways VPN not work. but this single Video made my day... Many thanks indeed

    • @MSFTWebCast
      @MSFTWebCast  3 года назад

      Glad to hear that

    • @imthi007
      @imthi007 3 года назад

      @@MSFTWebCast I need one more favour not able to ping my server ip or not able to access my share folder. Ex. My vpn ip is 10.0.0.103 and my server is 10.0.0.100

    • @MSFTWebCast
      @MSFTWebCast  3 года назад

      Please check firewall settings, open required ports for ICMP and File and Printer Sharing Service.

  • @wotizit
    @wotizit 16 дней назад +1

    SHUKRIA

  • @alexmironescu8797
    @alexmironescu8797 8 месяцев назад

    Hi, I hope this post finds you well, your tutorial is brilliant, I managed to set up the vpn, I can connect to the server from another pc but only if it's on the local network, I did all the steps you did but without success.Could you help me? I mention that the domain used is hosted as a website.
    I get this error when I try to connect from a pc on another network:
    “The network connection between your computer and the VPN server was interrupted. This can be caused by a problem in the VPN transmission and is commonly the result of internet latency or simply that your VPN server has reached capacity. Please try to reconnect to the VPN server. If this problem persists, contact the VPN administrator and analyze quality of network connectivity.”
    Help me, please

  • @yogeshvyas605
    @yogeshvyas605 2 года назад +1

    Nice video, Base on ur video I have implemented RAS server in my infra.
    Thank you so much.

  • @MuhammadWaqas-gr4gg
    @MuhammadWaqas-gr4gg 2 месяца назад

    whats the difference between your PPTP VPN vs "Remote access VPN??? i am not clear

  • @Giancarlo_Sforza
    @Giancarlo_Sforza 9 месяцев назад

    Did you have to publish any DNS records in Cloudflare or other DNS registrar or is port forwarding just enough for this to work?
    My question is, how is the remote windows10 client able to locate the windows vpn server via the internet? I suppose port forwarding takes care of that

    • @MSFTWebCast
      @MSFTWebCast  9 месяцев назад +1

      if you want to connect your VPN server using FQDN (name like website address) then DNS registration is required otherwise you can use the static public IP address to connect to your VPN server.

    • @Giancarlo_Sforza
      @Giancarlo_Sforza 9 месяцев назад

      @@MSFTWebCast
      Thank you for the reply, this is very helpful.
      It seems like on this video you are using the PPTP protocol which is not very safe nowadays hence I am trying to get IKEv2 to work.
      I found the video very helpful though and made me understand the whole concept a lot better.
      I was working on setting up an IKEv2 Always On VPN with device certificate issued by my on-prem Cert Authority windows server (not signed by digicert or any other CA).
      I didn't have much luck so far but I am on good track I just need to enroll a physical laptop to my domain so i can get the device certificate to that laptop or find another way of moving the certificate to a laptop that is not domain joined.
      I was looking to find a video of yours setting up VPN with the IKEv2 protocol, is there one?

  • @SunilBaniyal
    @SunilBaniyal 4 года назад +1

    After Doing this process can i take my office computer remote from home using Remote Desktop Connection?

  • @alimohamed-lx8tq
    @alimohamed-lx8tq Месяц назад +1

    Thank you 😊

  • @danielmaricelmunteanu5059
    @danielmaricelmunteanu5059 3 года назад

    Thanks, punctual and precise, in what regards the client to client routing through the vpn ..?

  • @super_straight
    @super_straight 2 года назад +2

    You are awesome! Many thanks for the clearly explained tutorial. It saved me so much pain and time!!!!🏅

  • @mavicmaster
    @mavicmaster 3 года назад +1

    Hello,
    Hope you are doing well.
    Can this be accessible from outside network? If not, what do i need to do to connect from outside network? Thanks.

  • @visionshahi8196
    @visionshahi8196 Год назад

    Hey I loved your all videos.. Can you make a video through which we can use remote access vpn to secure remote desktop connection. You just show how we can install and connect it but if you show how we can use it to secure the services. It will be great. Just tried but failed because the remote desktop services have rd gateway and NPS installed. With NPS we have to configure VPN for RD gateway. I tried to add IP VPN static port range as IP scope in firewall for TCP port 3389. But when client computer is connected with VPN the Public IP was not changing, than i read few articles online and found the issue which was "enable remote default gateway server" in VPN connection. But when i enable this internet will not work. I didnt found any video which show proper use of remote access vpn to secure Remote desktop connection and other services. Please can you make one video on this. One of your big subscriber

  • @samuelessel5366
    @samuelessel5366 Год назад

    Hello thanks for the lessons. I want to connect my laptop to my dicom server at work.. pls help

  • @williamm200
    @williamm200 Год назад +1

    Windows making easy to setup

  • @niteshsantoki
    @niteshsantoki Год назад

    Hello Sis, After folowing your steps, I still Cant be able to connect over public IP address, It is displaying an error in YELLOW TEXT - " The network connection between your computer and the VPN server was interrupted. This can be caused by a problem in the VPN transmission and is commonly the result of internet latency or simply that your VPN server has reached capacity. Please try to reconnect to the VPN server. If this problem persists, contact the VPN administrator and analyze quality of network connectivity." - I'm not sure what im doing wrong. Please Help. Thank you so much.

  • @bruhcsp
    @bruhcsp 7 месяцев назад

    Good, but you ignored that some people don’t have the Active Directory configured.

  • @quaryum1208
    @quaryum1208 3 года назад

    Hi, How can we do multiple authentication to protect hi vpn? Do you have a video about this?

  • @remotedesktop-q1g
    @remotedesktop-q1g Год назад

    thak you very much sir. but how do i do this on vmware without router. I don;t have router please reply sir

  • @DytliefMoller
    @DytliefMoller 7 месяцев назад +1

    very entertaining, good info too

  • @roelhr
    @roelhr 4 года назад +2

    Excellent video! Subscribed. Thank you.

  • @agboolamatthew
    @agboolamatthew 2 года назад

    Please I need help. I have been trying to follow your video. Got stuck around step 4. Is there any need to create a special user applied on a group or a normal user can just be used.

    • @MSFTWebCast
      @MSFTWebCast  2 года назад

      Normal user will do the job. Follow the same steps and check everything. If already you have created the NPS policy, you can delete it and restart the NPS service and recreate again.

  • @boytongo
    @boytongo 4 года назад

    Can you please name which is the most secure protocol when using vpn. Thank you so much

  • @Checc1
    @Checc1 Год назад

    I'm getting the following:
    "Windows cannot process the object with the name "TestUsers" because of the following error:
    The specified domain either does not exist or could not be contacted.
    Any idea how to fix this

  • @minhtempe
    @minhtempe 4 года назад

    Thanks for sharing very helpful video. I followed all steps and I can connected to server but I cannot access any files or ping to server. What do I need more? Please help

  • @khairisyafi5005
    @khairisyafi5005 5 месяцев назад

    what if i use mobile hotspot? can i use my phone for port forwarding?

  • @AvtarSingh-jw3xs
    @AvtarSingh-jw3xs 3 года назад

    Hi, it's a very helpful video. Please let me know how I connect my Server to use any application remotely using VPN. Like Using RDP, i can connect server remotely through static IP. Please help

  • @hameedullah3355
    @hameedullah3355 2 года назад

    Sir would u like to record tutorials on vpn suppose if an organisation has only single server in Headd office, and they have network router and switching in 4 sub offices .
    How they will use the resources from remote end .
    Kindy expalin it.

  • @hv3300
    @hv3300 3 года назад

    Great video. At 13.22 user you created in test group is different from what you have used -Any thoughts?

    • @MSFTWebCast
      @MSFTWebCast  3 года назад

      Yes, the user is same. The User display name is Test User1 and login name is User1 (UPN: User1@mylab.local). Sorry for the confusion.

    • @hv3300
      @hv3300 3 года назад

      @@MSFTWebCast Gotcha. Thank you for the clarification.

  • @TheRaaju007
    @TheRaaju007 2 года назад

    Very good explanation.

  • @Izzy25
    @Izzy25 2 года назад

    Does client computer need to be on the same domain? Ex. If user is using personal laptop or iPhone can they still connect? The user itself would be a domain user but the devices wouldn’t be on the domain.

  • @violetmakwakwa3060
    @violetmakwakwa3060 3 года назад +1

    thank you, the video was very helpful..

  • @nellbeatsdallas
    @nellbeatsdallas 4 года назад +1

    Love the videos, How do I set up to where users use fingerprint scanner to access vpn? (Multi-Factor Authentication)

  • @hamzabeniffou9324
    @hamzabeniffou9324 4 года назад

    Hello, I would like to know how can I setup in order to access to my vCenter Server remotely ? is it possible to do it like this way ? do you have a video on this please? thanks

  • @Archon_Dude69
    @Archon_Dude69 9 месяцев назад

    If the Client Machine In Work From Home, Is Client Machine Can Connect VPN With his/her Home internet Connection?

  • @obaidullahnoor8604
    @obaidullahnoor8604 10 месяцев назад +1

    Great sir!!

  • @AndrewSmith-wf3mf
    @AndrewSmith-wf3mf Год назад +1

    Thank U

  • @jeffb1328
    @jeffb1328 2 года назад

    When I click on Dial in properties on a user I get the error message: "Could not load the Dial-in profile for this user because: The network path was not found", any idea why?

  • @krzemyk84
    @krzemyk84 3 года назад +1

    Great tutorial! Thank you so much for your help and keep up the good job :)

  • @jg6111
    @jg6111 4 года назад

    A good video. Please include a logical diagram too for better understanding. Thank You.

  • @christiangutang6189
    @christiangutang6189 3 года назад

    How were you able to access your router? Because when I tried to put my virtual machine's default gateway in the browser, it said that it can't reach the page.

    • @MSFTWebCast
      @MSFTWebCast  3 года назад +2

      You have to select bridge adapter mode for VirtualBox adapter. Make sure that the IP address is in same range as your router.

  • @muhammedfahim8168
    @muhammedfahim8168 2 года назад +1

    great job

  • @parthpardeshi62
    @parthpardeshi62 3 года назад

    Hi..
    I've set up the vpn as per your steps but I'm getting vpn error 806..
    I've tried imbounding policy for 1723 port and also ported my router.
    Still I'm getting that error

  • @niccite
    @niccite 2 года назад +1

    Excellent Tutorial - Thank You!

  • @anilahuja3679
    @anilahuja3679 4 года назад +1

    Using this video I was able to create the VPN connection and tested it out. I can't see the Remote Server in my Network on the Client PC and can't map a network drive from the Server either. What am I missing?

    • @yogeshvyas605
      @yogeshvyas605 2 года назад

      Try to map drive with fully fqdn name

    • @digimation6862
      @digimation6862 5 месяцев назад

      Remember in the cliente pc enable File AND Share Folder to allow communication of the pc AND the server

  • @riccardolaporta7746
    @riccardolaporta7746 2 года назад +1

    Thanks so much ❤

  • @skeemyweenus4995
    @skeemyweenus4995 3 года назад

    Question for 4:09 . So If you're specifying 10 ip addresses, would that mean that there can only be 10 users using VPN at the same time? If yes, then how can make it so that it can fit (for example) 1,000 users? If that is possible.

    • @MSFTWebCast
      @MSFTWebCast  3 года назад +1

      You need to use bigger subnet with 1000 IPs.

  • @chimmajhulewala9522
    @chimmajhulewala9522 2 года назад +1

    Great, Thanks

  • @babatundeadeyemi2800
    @babatundeadeyemi2800 3 года назад

    Thanks for this video, its very useful. However, i noticed that once i restart the server, all configuration would go back to default. Is there any way i could keep the configuration permanent. Thnks

    • @kelkloud24
      @kelkloud24 2 года назад

      not usually recommended, but you can use deepfreeze

  • @AndrewSmith-wf3mf
    @AndrewSmith-wf3mf Год назад +1

    Perfect

  • @parthpardeshi62
    @parthpardeshi62 3 года назад

    I'm having an issue.... The vpn is connected from another network it's not showing the shared files, however when it is connected from my office network, the I can see the files....
    Please help I've been trying since one month 🥲

  • @netitfish
    @netitfish 3 года назад

    Routing and Remote Access service has not started The specified file cannot be found. Can you help me to resolve this problem? thank you.

  • @JohnPaulCorrea-i9t
    @JohnPaulCorrea-i9t 7 месяцев назад

    hi, does this work if I dont have static public IP? if not what are the other way to do this?

    • @MSFTWebCast
      @MSFTWebCast  7 месяцев назад

      With dynamic IP address on VPN server, you can use dynamic DNS service provider for VPN connection. There are several dynamic DNS provider which provide dynamic IP address to easy to remember hostname (Dyn DNS or no-ip). Using this static hostname, client can connect to your VPN server. They will automatically update the dynamic IP address in their DNS server to connect hostname to updated dynamic IP address if your dynamic IP address changed.

  • @micheledimauro1282
    @micheledimauro1282 4 года назад

    with this kind of Vpn i can successfully connect and ping each ip address in the remote vpn site, but can't reach resources by hostname, any suggest??

  • @schiet100
    @schiet100 2 года назад +1

    Thank you!!!

  • @kgerakopoulos
    @kgerakopoulos 3 года назад

    Can I use this remote to connect outside of local lan? And is it safe from hackers ?

    • @MSFTWebCast
      @MSFTWebCast  3 года назад

      Yes, you can use VPN to connect your local LAN over the Internet. Yes, it is safe.

  • @muthukannannatarajan747
    @muthukannannatarajan747 4 года назад +1

    Ji after connecting the vpn internet browsing is getting disable in client computer what to do for this problem

    • @redadz9105
      @redadz9105 3 года назад +1

      Go to advanced settings of your vpn and enable split tunelling

  • @DerrickThomas17
    @DerrickThomas17 3 года назад

    Hey great video. I came across your channel and it's fabulous. Question, everything works great when I test the vpn internally, when external, it connects but cannot ping the file server via IP or name. What am I missing? Thank you and I also subbed to your channel. Keep those great videos coming.

    • @MSFTWebCast
      @MSFTWebCast  3 года назад +1

      Check firewall rule settings on VPN Server and also the IP configuration settings. Might be IP routing related issue.

    • @MSFTWebCast
      @MSFTWebCast  3 года назад

      And thank you for sub.

    • @DerrickThomas17
      @DerrickThomas17 3 года назад

      @@MSFTWebCast I still cannot browse from the outside. Any ideas?

  • @AndrewSmith-wf3mf
    @AndrewSmith-wf3mf Год назад +1

    Well Done!!!

  • @moehans9833
    @moehans9833 2 года назад

    can we install this on and active directory server as we only have one server

    • @MSFTWebCast
      @MSFTWebCast  2 года назад

      Yes, you can but from security point of view it will be risky.

  • @BunjackThuok
    @BunjackThuok 3 года назад

    Brilliant thanks dear

  • @sanampreet9878
    @sanampreet9878 2 года назад

    But without network policy configuration it is working
    It is compulsory to configure network policy

    • @MSFTWebCast
      @MSFTWebCast  2 года назад

      If you dont have NPS server, you can grant allow access to dial in in user account property to use VPN without network policy. If you have NPS server then you can setup the NPS policy as per your company requirement, it is not compulsory.

  • @boytongo
    @boytongo 4 года назад

    Very well explained

  • @samliang4146
    @samliang4146 Год назад

    why can;t i open my router setting page when i type in the default gateway address of my nit, i tried both NAT and lan segment, neither of them can open router page. why

    • @MSFTWebCast
      @MSFTWebCast  Год назад

      Ask your network administrator, Might be he/she can help with that.

  • @hubertpowell340
    @hubertpowell340 4 года назад

    The problem I am having is I can connect to the VPN server from inside my network, but if I try to connect from an external network, I get the message, The remote connection was denied because the user name and password combination you provided is not recognized, or the selected authentication protocol is not permitted on the remote access server.

    • @UndergroundCarGuys
      @UndergroundCarGuys 2 года назад

      Could be due to the Domain, you may need to put the @[Domain Name] After the username.

  • @alimuratgoral2370
    @alimuratgoral2370 3 года назад

    Excellent video. Thank you 👍

  • @agreniers
    @agreniers Год назад

    What do I do with the NPS error when trying to activate vpn server..

  • @Digitalrozgarmission
    @Digitalrozgarmission 2 года назад

    the network connection between your computer and the vpn server was interrupted this can be caused by a problem in the vpn tansmission and is commonly the result of internet. getting this error

  • @srinivaskandregula9497
    @srinivaskandregula9497 Год назад

    when i am connecting to my server vpn i unable to access out side internet as well. is there any solution.

    • @MSFTWebCast
      @MSFTWebCast  Год назад

      You have to setup NAT on your VPN server.

    • @androidsavior
      @androidsavior 8 месяцев назад

      @@MSFTWebCast how to do so ? should i install a second network adapter ?

  • @zefur321
    @zefur321 Год назад

    my server is not Active Directory server. Can I enable VPN ?

    • @MSFTWebCast
      @MSFTWebCast  Год назад

      You can install Remote Access Server role without AD and setup a server to act as a VPN server. You just need to create user accounts from computer management and assign dial-in permission.

  • @asriishak4881
    @asriishak4881 4 года назад +2

    why my server doesn't have 'active directory users & group'?

    • @mauriziopersi401
      @mauriziopersi401 4 года назад

      It is a DC?

    • @CarlMakesItEasy
      @CarlMakesItEasy 4 года назад

      upgrade to a domain controller through Add roles and features and Active Directory Domain Services

  • @dhilipkumar9784
    @dhilipkumar9784 2 года назад

    Sir what to give in user name and password, you gave Msdwebcast? Pls reply sir

    • @dhilipkumar9784
      @dhilipkumar9784 2 года назад

      While accessing router it asks for user name and password

    • @MSFTWebCast
      @MSFTWebCast  2 года назад

      If you have not set up the password no your router then use the default username password. Based on your routers model, you can find the default username and password on Internet.

  • @anis5709
    @anis5709 2 года назад

    I got this error msg on 7:45 "Windows cannot proces the object with the name TestUsers: The specified domain either does not exist or could not be contacted" can u help me pls?

    • @MSFTWebCast
      @MSFTWebCast  2 года назад +1

      On Find Now, window can you see your group? Make sure you have used the domain admin or equivalent credential to logon to that server. NPS server must be registered in Active Directory.

    • @anis5709
      @anis5709 2 года назад

      @@MSFTWebCast the server dosent had a domain. That was the Problem. I created one :). Im by Step 5 and i dont have the access to the router because the server is hosted online by a provider.
      Any solution or idea?
      Thx for ur answer :)

    • @MSFTWebCast
      @MSFTWebCast  2 года назад

      @@anis5709 If your server is not part of AD then you can use create Users or Groups on local Server and use it in VPN authentication.

  • @Ranjeetkumar-fj4kp
    @Ranjeetkumar-fj4kp 3 года назад

    nice..

  • @SachinKumar-il2yy
    @SachinKumar-il2yy 2 года назад

    How we can contact you for further assistance

  • @sagarrajput335
    @sagarrajput335 4 года назад

    i am getting a error "the connection was prevented because of a policy configured on rsa/vpn server.
    "

  • @tennisball2012
    @tennisball2012 3 года назад

    Crazy good video

  • @mattdent6565
    @mattdent6565 4 года назад

    Very helpful - thanks!

  • @sjnlim3925
    @sjnlim3925 3 года назад

    do we need static public ip in this config ?

    • @MSFTWebCast
      @MSFTWebCast  3 года назад

      Yes, on VPN servers internet facing interface.

  • @numanahmad4471
    @numanahmad4471 4 года назад

    When i try to connect it says “A connection remote computer can not be established. So the port used for this connection was closed “

    • @MSFTWebCast
      @MSFTWebCast  4 года назад

      Have you opened the required ports in your router or firewall?

  • @mdrashidhussain7168
    @mdrashidhussain7168 4 года назад +1

    This is virtual machine...????

    • @MSFTWebCast
      @MSFTWebCast  4 года назад

      Yes. entire demo is in virtualbox VM.

  • @CharcoalProduction
    @CharcoalProduction 3 года назад

    Why we are not using MSCHAPv2?

    • @MSFTWebCast
      @MSFTWebCast  3 года назад

      MS-CHAPv2 is an old authentication protocol. EAP with MS CHAPv2 is more secure and common form or PEAP.

  • @victorgarcia-sz7vh
    @victorgarcia-sz7vh 3 года назад

    Thank you for the video

  • @MohammedESeno
    @MohammedESeno Год назад

    Hello.. how can I contact you?

  • @20006raghu
    @20006raghu 2 года назад

    I need your help I'm unable to connect remote acces

    • @MSFTWebCast
      @MSFTWebCast  2 года назад

      What kind of error you are receiving?

  • @MarloMitchell
    @MarloMitchell 4 года назад

    The accent is adorable.

  • @armandadvar6462
    @armandadvar6462 Год назад

    I have error on installation process.

    • @MSFTWebCast
      @MSFTWebCast  Год назад

      What kind of error? Any message?

  • @shifa7474
    @shifa7474 2 месяца назад

    window server 2019 routing and Remote access not starting

    • @MSFTWebCast
      @MSFTWebCast  2 месяца назад

      Any specific errors that you are getting while starting the service?

    • @shifa7474
      @shifa7474 2 месяца назад

      @@MSFTWebCast the system can't find the file specified..

    • @MSFTWebCast
      @MSFTWebCast  2 месяца назад

      @@shifa7474 Can you please check the event viewer for any error or warning related to VPN/Routing and remote access.

  • @shyamsundermayengbam3221
    @shyamsundermayengbam3221 2 года назад

    Let's make soft!

  • @ahmedsaad-lk2og
    @ahmedsaad-lk2og 2 года назад

    ok

  • @akkayalarnserdar3184
    @akkayalarnserdar3184 3 года назад

    i cant found bloody "active directory users and computers" on my god damn pc

    • @MSFTWebCast
      @MSFTWebCast  3 года назад

      Is it domain controller? If not then you can also use local users and group.

    • @akkayalarnserdar3184
      @akkayalarnserdar3184 3 года назад +1

      @@MSFTWebCast im sorry about behaving angry, thank you for answer,

  • @muthukannannatarajan747
    @muthukannannatarajan747 4 года назад

    Only vpn is working

  • @Benmaluco9
    @Benmaluco9 4 года назад

    PPTP = Insecure

  • @anilahuja3737
    @anilahuja3737 4 года назад

    a