<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>How SSTP based VPN connection works</title><link>http://blogs.technet.com/b/rrasblog/archive/2007/01/10/how-sstp-based-vpn-connection-works.aspx</link><description>In this blog, I will explain how SSTP based VPN tunnel works - i.e. the data flow during VPN connection coming up and how data transfer occurs. 
 The flow to get VPN connection up looks like: 
 1) Client gets Internet connectivity and then establishes</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>Forefront TMG Beta 3 is Released</title><link>http://blogs.technet.com/b/rrasblog/archive/2007/01/10/how-sstp-based-vpn-connection-works.aspx#3252660</link><pubDate>Tue, 09 Jun 2009 22:12:21 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3252660</guid><dc:creator>Forefront TMG (ISA Server) Product Team Blog</dc:creator><description>&lt;p&gt;Hi Everyone: Our third and final planned beta is upon us and I am proud to announce that Forefront TMG&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3252660" width="1" height="1"&gt;</description></item><item><title>2005 east texas high school football schedules</title><link>http://blogs.technet.com/b/rrasblog/archive/2007/01/10/how-sstp-based-vpn-connection-works.aspx#1956602</link><pubDate>Fri, 14 Sep 2007 18:09:08 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1956602</guid><dc:creator>2005 east texas high school football schedules</dc:creator><description>&lt;p&gt;2005 east texas high school football schedules&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1956602" width="1" height="1"&gt;</description></item><item><title>re: How SSTP based VPN connection works</title><link>http://blogs.technet.com/b/rrasblog/archive/2007/01/10/how-sstp-based-vpn-connection-works.aspx#608067</link><pubDate>Thu, 25 Jan 2007 07:59:18 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:608067</guid><dc:creator>rrasblog</dc:creator><description>&lt;p&gt;Que: Haven't seen any specs yet, but it would be preferrable to have the connection reference appear as any (yet another &lt;a rel="nofollow" target="_new" href="https://server.some.net/sstpservice"&gt;https://server.some.net/sstpservice&lt;/a&gt;) URI to client and it would also make sure the web server portion is general HTTP/1.1 compliant with virtualhost -feauters etc. all functioning would be *very* convinient. The second, or is it third already, issue that pops in my mind is to make sure AAA hooks to infrastructure behind is flexible enough, a layered solution like EAP perhaps. (Just remember to include both TTLS &amp;amp; TLS too, only PEAP as CHAP bound is crap for anyone not having _ALL_ their passwords in AD).&lt;/p&gt;
&lt;p&gt;Ans: Yes it will be HTTP1.1 compliant. The SSTP URI will be something fixed (&lt;a rel="nofollow" target="_new" href="https://server.some.net//sra_"&gt;https://server.some.net//sra_&lt;/a&gt;{BA195980-CD49-458b-9E23-C84EE0ADCD75}/).&lt;/p&gt;
&lt;p&gt;Yes - the AAA infrastructure will be flexible and same as RRAS. i.e. you can &amp;nbsp;use &amp;nbsp;radius server for doing AAA with same PPP authentication algorithms (like MSCHAPv2, EAP, PEAP with different inner EAP methods etc).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=608067" width="1" height="1"&gt;</description></item><item><title>re: How SSTP based VPN connection works</title><link>http://blogs.technet.com/b/rrasblog/archive/2007/01/10/how-sstp-based-vpn-connection-works.aspx#607839</link><pubDate>Thu, 25 Jan 2007 02:02:46 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:607839</guid><dc:creator>CK</dc:creator><description>&lt;p&gt;Please, please, please strongly consider submitting this to be formally standardized. &amp;nbsp;We don't need another PPTP, L2TP, or Yet Another Proprietary SSL VPN. &amp;nbsp;IPsec stinks, but at least it's a standard and there is at least a chance for interoperability.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=607839" width="1" height="1"&gt;</description></item><item><title>SSL VPN and NAP</title><link>http://blogs.technet.com/b/rrasblog/archive/2007/01/10/how-sstp-based-vpn-connection-works.aspx#605323</link><pubDate>Tue, 23 Jan 2007 02:23:49 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:605323</guid><dc:creator>Network Access Protection (NAP)</dc:creator><description>&lt;p&gt;Happy New Year to everyone! There is some exciting news being announced on the RRAS blog around a new&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=605323" width="1" height="1"&gt;</description></item><item><title>re: How SSTP based VPN connection works</title><link>http://blogs.technet.com/b/rrasblog/archive/2007/01/10/how-sstp-based-vpn-connection-works.aspx#603302</link><pubDate>Sat, 20 Jan 2007 17:53:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:603302</guid><dc:creator>Anonymous Coward</dc:creator><description>&lt;p&gt;Haven't seen any specs yet, but it would be preferrable to have the connection reference appear as any (yet another &lt;a rel="nofollow" target="_new" href="https://server.some.net/sstpservice"&gt;https://server.some.net/sstpservice&lt;/a&gt;) URI to client and it would also make sure the web server portion is general HTTP/1.1 compliant with virtualhost -feauters etc. all functioning would be *very* convinient. The second, or is it third already, issue that pops in my mind is to make sure AAA hooks to infrastructure behind is flexible enough, a layered solution like EAP perhaps. (Just remember to include both TTLS &amp;amp; TLS too, only PEAP as CHAP bound is crap for anyone not having _ALL_ their passwords in AD).&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=603302" width="1" height="1"&gt;</description></item><item><title>Microsoft developing new secure VPN tunneling protocol</title><link>http://blogs.technet.com/b/rrasblog/archive/2007/01/10/how-sstp-based-vpn-connection-works.aspx#602606</link><pubDate>Sat, 20 Jan 2007 04:45:12 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:602606</guid><dc:creator>Stray Thoughts</dc:creator><description>&lt;p&gt;Microsoft is working on a remote access tunneling protocol for Vista and Longhorn Server that lets client&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=602606" width="1" height="1"&gt;</description></item><item><title>SSTP FAQ - Part 2: Client Specific</title><link>http://blogs.technet.com/b/rrasblog/archive/2007/01/10/how-sstp-based-vpn-connection-works.aspx#600056</link><pubDate>Wed, 17 Jan 2007 21:03:28 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:600056</guid><dc:creator>Routing and Remote Access Blog</dc:creator><description>&lt;p&gt;In this FAQ, I will cover client specific queries of SSTP 1) How to enable SSTP based VPN connection&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=600056" width="1" height="1"&gt;</description></item></channel></rss>