Securing Remote Access and VPN Servers

Remote Access and VPN Server Security Issues

Remote Access Servers (RAS) provides access to the network for remote users. The different types of remote access connections are Dial-in remote access, VPN remote access, and Wireless remote access. Dial-in remote access uses modems, servers running the Routing and Remote Access (RRAS) service, and the Point-to-Point (PPP) protocol to enable remote users to access the network. VPN remote access provides secure and advanced connections through a non-secure network. VPN access uses encryption to create the VPN tunnel between the remote access client and the corporate network. Wireless users connect to the network by connecting to a wireless access point (WAP). Wireless networks do not have the inbuilt physical security of wired networks, and are more prone to attacks from intruders. To secure wireless networks and wireless connections, administrators can require all wireless communications to be authenticated and encrypted. There are a number of wireless security technologies that can be used to protect wireless networks.

Basic security measures for securing remote access servers are listed here:

Additional security measures for securing remote access servers are listed below:

Using Authentication and Encryption Methods to Secure Access to Remote Access and VPN Servers

There are a number of different authentication methods supported by Windows Server 2003 Routing and Remote Access Service (RRAS) which you can configure to authenticate remote users when they attempt to connect to remote access servers:

To configure an authentication method,

  1. Click Start, Click Start, Administrative Tools, and then click Routing and Remote Access to open the Routing and Remote Access console.
  2. In the console tree, select the remote access server, and then click the Action menu to select the Properties command.
  3. Switch to the Security tab.
  4. Click the Authentication Methods button.
  5. The Authentication Methods dialog box opens.
  6. Specify the authentication method you want to use.

To disable the weaker password based authentication methods,

  1. Click Start, Administrative Tools, and then click Routing and Remote Access to open the Routing and Remote Access console.
  2. In the console tree, select the remote access server that you want to configure, and then click the Action menu to select the Properties command.
  3. Switch to the Security tab.
  4. Click the Authentication Methods button.
  5. The Authentication Methods dialog box opens.
  6. Clear the Microsoft Encrypted Authentication (MS-CHAP) checkbox.
  7. Clear the Encrypted Authentication (CHAP) checkbox.
  8. Clear the Shiva Password Authentication Protocol (SPAP) checkbox.
  9. Clear the checkbox for Unencrypted Password (PAP) checkbox.
  10. Click OK.

To secure VPN remote access connections, consider configuring either of these levels of encryption:

Using Remote Access Policies and Remote Access Profiles to Secure Remote Access

Remote access policies can be used to specify which users are allowed to establish connections to remote access servers. Remote access policies enable Administrators to restrict user access, based on the actual user, group membership, and time of day. You can also use remote access policies to control which authentication protocols and encryption methods clients utilize. After a connection is established to a remote access server, you can through remote access policies also configure restrictions for the connection. Remote access profiles contains a set of properties that are applied to remote access connections that match the conditions specified in the remote access policy. Through remote access profiles, you can specify what actions should occur once the connection is authorized by the remote access server.

To control connections to remote access servers through remote access policy,

  1. Click Start, Administrative Tools, and then click Active Directory Users and Computers to open the Active Directory Users and Computers management console.
  2. In the console tree, expand the domain that contains the user account that you want to enable remote access for.
  3. Select the Users container.
  4. In the right pane, locate the user account that you want to configure.
  5. Right-click the specific user account and then select Properties from the shortcut menu.
  6. Click the Dial-in tab.
  7. In the Remote Access Permission area, click the Control Access Through Remote Access Policy option.
  8. Click OK.


Top 5 Free Networking Tools

Bookmark Securing Remote Access and VPN Servers

Latest Blog Posts


English English GermanGerman SpanishSpanish FrenchFrench ItalianItalian PortuguesePortuguese RussianRussian DutchDutch
GreekGreek HindiHindi JapaneseJapanese KoreanKorean ChineseChinese Chinese (Simplified)Chinese (Simplified) ArabicArabic

Copyright 2009 Tech-FAQ. All rights reserved. Privacy Policy.