<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Ian Hameroff : Secure Remote Access</title><link>http://blogs.technet.com/ianhamer/archive/tags/Secure+Remote+Access/default.aspx</link><description>Tags: Secure Remote Access</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Networkin' Forums-o-Plenty!</title><link>http://blogs.technet.com/ianhamer/archive/2007/04/18/networkin-forums-o-plenty.aspx</link><pubDate>Thu, 19 Apr 2007 01:30:10 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:787330</guid><dc:creator>ianhamer</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/ianhamer/comments/787330.aspx</comments><wfw:commentRss>http://blogs.technet.com/ianhamer/commentrss.aspx?PostID=787330</wfw:commentRss><wfw:comment>http://blogs.technet.com/ianhamer/rsscomments.aspx?PostID=787330</wfw:comment><description>&lt;p&gt;Great news networking fans, we've doubled the number of of Windows Server "Longhorn" focused TechNet forums focused on networking related workloads and features.&amp;nbsp; In addition to the &lt;a href="http://blogs.technet.com/ianhamer/archive/2006/06/28/new-windows-server-quot-longhorn-quot-platform-networking-technical-discussion-forum.aspx"&gt;Platform Networking&lt;/a&gt; forum launched a number of months back, we really kicked off a new &lt;a href="http://forums.microsoft.com/TechNet/ShowForum.aspx?ForumID=1510&amp;amp;SiteID=17"&gt;Network Infrastructure Servers&lt;/a&gt; forum to focus on our four main networking server roles:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://www.microsoft.com/technet/network/dhcp/default.mspx"&gt;DHCP&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="http://technet2.microsoft.com/windowsserver/en/technologies/featured/dns/default.mspx"&gt;DNS&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="http://www.microsoft.com/technet/network/rras/default.mspx"&gt;RRAS&lt;/a&gt;&lt;/li&gt; &lt;li&gt;NPS (formerly known as &lt;a href="http://www.microsoft.com/technet/network/ias/default.mspx"&gt;IAS Server&lt;/a&gt;, and more commonly called &lt;a href="http://www.microsoft.com/technet/community/chats/trans/network/07_0129_tn_radius.mspx"&gt;RADIUS&lt;/a&gt; by the masses)&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;The beauty of these forums is they are a great way to connect with folks like me (if you think that's a great deal and all) and members of the Windows networking engineering team.&amp;nbsp; Oh yeah, we've got a lot of non-Softies logging hours on the forums help address question you may have while checking out all the &lt;a href="http://www.microsoft.com/technet/network/evaluate/new_network.mspx"&gt;new networking features in Windows Server "Longhorn" and Windows Vista&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;Oh.&lt;/p&gt; &lt;p&gt;Yeah.&lt;/p&gt; &lt;p&gt;Don't forget the &lt;a href="http://forums.microsoft.com/TechNet/ShowForum.aspx?ForumID=576&amp;amp;SiteID=17"&gt;Network Access Protection&lt;/a&gt; and &lt;a href="http://forums.microsoft.com/TechNet/ShowForum.aspx?ForumID=580&amp;amp;SiteID=17"&gt;Terminal Services&lt;/a&gt; forums either.&lt;/p&gt; &lt;p&gt;Come to think of it, just check'em all out at:&lt;br&gt;&lt;a title="http://forums.microsoft.com/TechNet/default.aspx?ForumGroupID=161&amp;amp;SiteID=17" href="http://forums.microsoft.com/TechNet/default.aspx?ForumGroupID=161&amp;amp;SiteID=17"&gt;http://forums.microsoft.com/TechNet/default.aspx?ForumGroupID=161&amp;amp;SiteID=17&lt;/a&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=787330" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ianhamer/archive/tags/Network+Access+Protection/default.aspx">Network Access Protection</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Networking/default.aspx">Windows Networking</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Secure+Remote+Access/default.aspx">Secure Remote Access</category></item><item><title>WinVista VPN Client-o-Rama</title><link>http://blogs.technet.com/ianhamer/archive/2007/02/27/winvista-vpn-client-o-rama.aspx</link><pubDate>Tue, 27 Feb 2007 19:24:09 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:664473</guid><dc:creator>ianhamer</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/ianhamer/comments/664473.aspx</comments><wfw:commentRss>http://blogs.technet.com/ianhamer/commentrss.aspx?PostID=664473</wfw:commentRss><wfw:comment>http://blogs.technet.com/ianhamer/rsscomments.aspx?PostID=664473</wfw:comment><description>&lt;p&gt;One of the most common questions we are getting from customers who are preparing to upgrade their environment to Windows Vista is: "&lt;em&gt;Will my VPN client from &amp;lt;insert vendor&amp;gt; work with Vista?"&lt;/em&gt;&lt;/p&gt; &lt;p&gt;Good question.&amp;nbsp; Nah, that's a great question.&amp;nbsp; Why?&amp;nbsp; Well, considering the sear number of laptops and all the mobile computing enhancements in Windows Vista, it's no surprise that users would be "on the road" and wanting to gain access back to the mothership. &lt;/p&gt; &lt;p&gt;To help you find out the release schedules of VPN clients that will be 100% compatible with our latest client OS, we've setup a living KB article entitled:&lt;/p&gt; &lt;p align="center"&gt;&lt;a href="http://support.microsoft.com/?id=929490" target="_blank"&gt;Windows Vista-compatible third-party virtual private network (VPN) client schedules&lt;/a&gt;&lt;/p&gt; &lt;p align="left"&gt;For fans of the Article IDs, it's 929490.&amp;nbsp; The article has already been updated a bunch of times as we get the latest info in from vendors like Checkpoint, Cisco, and Aventail.&amp;nbsp; As you can imagine, we've been working with these vendors (IPsec and SSL-VPNs alike) for several years during the ramp up to release of WinVista.&amp;nbsp; Many of them are now just putting the final touches on their client software and hammering through the last set of test plans before releasing to customers.&lt;/p&gt; &lt;p align="left"&gt;It's important to note that the information provided on this KB article is provided by the third-parties, not Microsoft.&amp;nbsp; So, my recommendation is you check out this article, zero in on the details for your particular VPN solution, and follow the links provided to the vendor's site for more details.&lt;/p&gt; &lt;p align="left"&gt;On another note, there are lots of alternatives if you're feeling the VPN compatibility blues.&amp;nbsp; For example, you should do a good inventory of what you actually need to make available remotely and see if alternative (yet still secure) solutions could be a better route (including potential cost savings).&amp;nbsp; &lt;br&gt;&lt;/p&gt; &lt;p align="left"&gt;For example, most of the remote access requirements here at Microsoft are related to Exchange.&amp;nbsp; It's likely no surprise that 'softies are email junkies.&amp;nbsp; We can't get enough.&amp;nbsp; Seriously, we need help.&amp;nbsp; Anyhow, instead of opening up a fat VPN tunnel for just email access, we use the &lt;a href="http://technet.microsoft.com/en-us/library/bb123741.aspx" target="_blank"&gt;Outlook Anywhere&lt;/a&gt;&amp;nbsp;(formerly known as RPC over HTTP) to, effectively, provide an application specific SSL based solution for remote email access.&amp;nbsp; Neat stuff and it doesn't change the end-user experience.&amp;nbsp; I just pop open Outlook (even though it's likely already open) and once I have a routable IP address...BAM...I'm getting my email fix.&lt;/p&gt; &lt;p align="left"&gt;A second option is to look at using the &lt;a href="http://www.microsoft.com/forefront/edgesecurity/sra.mspx" target="_blank"&gt;reverse proxy/application publishing features of ISA Server 2006 and IAG 2007&lt;/a&gt;.&amp;nbsp; We've used some of this for securely exposing applications, like our expense report tool, without needing to fully VPN in.&amp;nbsp; We can still employ strong, multi-factor user authN, but it's still not a full VPN tunnel being setup.&lt;/p&gt; &lt;p align="left"&gt;Lastly, there are our Secure Remote Access solutions that are already ready for Windows Vista:&lt;/p&gt; &lt;ul&gt; &lt;ul&gt; &lt;ul&gt; &lt;ul&gt; &lt;li&gt; &lt;div align="left"&gt;&lt;a href="http://www.microsoft.com/technet/network/rras/default.mspx" target="_blank"&gt;Connection Manager w/ RRAS (PPTP or L2TP/IPsec VPN)&lt;/a&gt;&lt;/div&gt;&lt;/li&gt; &lt;li&gt; &lt;div align="left"&gt;&lt;a href="http://www.microsoft.com/isaserver/prodinfo/features.mspx#EID" target="_blank"&gt;ISA Server 2006 VPN (PPTP or L2TP/IPsec VPN)&lt;/a&gt;&lt;/div&gt;&lt;/li&gt; &lt;li&gt; &lt;div align="left"&gt;&lt;a href="http://www.microsoft.com/forefront/edgesecurity/iag/default.mspx" target="_blank"&gt;Intelligent Application Gateway 2007 (SSL VPN)&lt;/a&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;/ul&gt; &lt;p align="left"&gt;Check this stuff out, as well as the Windows Vista &lt;a href="http://technet.microsoft.com/en-us/windowsvista/aa905051.aspx?wt_svl=20309a&amp;amp;mg_id=20309b" target="_blank"&gt;app compat kits&lt;/a&gt; recently release.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=664473" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Networking/default.aspx">Windows Networking</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Secure+Remote+Access/default.aspx">Secure Remote Access</category></item></channel></rss>