Configuring Mobile Networking - Virtual Private Networks
8 important questions on Configuring Mobile Networking - Virtual Private Networks
What is the main function of a VPN (Virtual Private Network)
What does a Remote Access VPN do
What are the VPN authentication protocols
PAP
- Password Authentication Protocol.
- Old protocol that uses plaintext, not recommended.
CHAP
- Challenge-Handshake Auth. Protocol.
MSCHAPv2
- Microsoft's improvement on CHAP, uses Mutual authentication (2-way).
EAP/PEAP
- Extensible Authentication Protocol.
- Authentication is negotiated, can use certificates.
- Higher grades + faster learning
- Never study anything twice
- 100% sure, 100% understanding
Authentication types that support Certificates
EAP-TLS
PEAP-TLS
PEAP-MSCHAPv2
Certification are recommended over passwords as they provide better security.
What is a App-Triggered VPN and how to configure it
Triggers and starts using a VPN after a specific application is used.
Can only be configured using powershell using the following command:
- AddVpnConnectionTriggerApplication
And requires the Split Tunneling feature to be enabled using powershell (default is off).
What is a Network Location Server (NLS) used for
This server is used by DirectAccess to determine of the client is on the local network or outside of it.
If the NLS is detected, the client knows it is in the local network and does not attempt to start a DirectAccess VPN tunnel.
If it does not detect the NLS it will automatically start and setup the VPN tunnel to the corporate network.
What is Always On VPN and what are its requirements
Successor to DirectAccess
- No IPv6 requirements
- Can only be implemented by using a MDM (Mobile Device Management) tool
Requirements:
- Only supports Windows 10.
- A Certification Authority.
- NPS (RADIUS) server.
- RRAS (Routing and Remote Access Service) server.
- AS User accounts.
Always on VPN authentication methods
Device Tunnel:
- Only supported on Windows 10 Enterprise / Education.
- Authenticates even before the user logs in onto the device.
- Device must be domain joined.
- The device needs to have a computer certificate.
User Tunnel:
- Supports all Windows 10 editions.
- Device can be in domain, workgroup or Azure AD.
- Authenticates when the user logs in.
The question on the page originate from the summary of the following study material:
- A unique study and practice tool
- Never study anything twice again
- Get the grades you hope for
- 100% sure, 100% understanding