Lab: How to install VPN access on Windows
Server 2016
File Name: LAB14 - How to install VPN access on Windows Server 2016
Start Date / /20 Completion Dt: / /20 Term:
Student ID: Student Name:
Tutor: Completed:
This practical focuses on: A / NA Supervisor Comments.
Student: Attention required for practice. Head of Faculty / Academic
Unacceptable response?
Focus and Concentration are not enough?
Achievement – Average / Satisfied
Step by Step How to Install and Configure VPN in Windows Server 2016
Remote access role is a VPN which protects the network connection or your remote connection from one
side to another and protecting both sides from attacks or data sniffing as VPN protocol uses a tunnel
inside of a standard data connection.
Note: You’ll need to open a TCP port 1723 on your firewall as this port is used for the VPN access.
Installing and configuring a VPN server using Windows Server 2016 is easy way. By following the
guidance in this article, a VPN server can be implemented in just a few minutes. VPN provides secure
access to organizations’ internal data and applications to clients and devices that are using the Internet.
To properly implement and support a VPN environment within your organization, you must understand
how to select a suitable tunneling protocol, configure VPN authentication, and configure the server role
to support your chosen configuration.
For this demo purposes, i will be using 2 VM, and 1 Windows 10 client VM which is all running in Hyper-V.
1 – VPN Server Require 2 NIC:
Ethernet 1: LAN
Ethernet 2: Internet
Ethernet 1: LAN
Ethernet 2: Internet
2
Page
2 – Windows 10 Client.
Require 1 NIC:
Ethernet 1: Internet
02 – Creating VPN Users
OU & User in Active
Directory.
1 – Create a new OU – In
the New Object –
Organizational Unit
dialog box, in the Name
box, type VPN Users,
and then click OK.
3
Page
2 – In the Active Directory
Users and Computers
console,
expand Windows.ae, right-
click VPN Users OU, click
New, and then click User.
3 – right-click user,
Properties.
4
Page
Allow Access enabled for
Remote Access to connect
to your VPN Server. and
Okay.
03 – Installation
1 – open your Server
Manager and click on Add
Roles and Features.
2 – click on Next.
5
Page
3 – Now select Role-based
or feature-based
installation option and
click on Next.
4 – Now select desired
server you’d like to install
Routing and Remote
Access on.
5 – From the Roles lists
select Remote Access and
click on Next.
6
Page
6 – Click Next, no
additional features
required at this point.
7 – Just click on Next.
8 – In next tab you need to
select DirectAccess and
VPN (RAS), Click Add
Features in the popup
window.
7
Page
9 – On confirmation page
click Install to begin.
10 – After installation
process is finished, click
on Open the Getting
Started Wizard.
8
Page
11 – In this tab
press Deploy VPN only.
04 –
Configuration
1 – Right click on your
server and
choose Configure and
Enable Routing and
Remote Access.
9
Page
2 – Click on Next.
3 – On the new wizard
select Remote Access
(dial-up or VPN).
4 – On the next page
select VPN.
10
Page
5 – Here select network
adapter that connects
your server to the
Internet.
6 – Here select network
adapter that connects
your server to the VPN
Clients.
7 – Here you can choose
the method of distribution
for IP addresses – via DHCP
or manually. Select the
second way.
11
Page
8 – In this tab press New.
9 – In popup window
specify range of IP
addresses, press OK,
return to previous tab and
click on Next.
10 – In this tab you can
choose the method of
authentication.
Select Routing and
Remote Access.
12
Page
11 – Press Finish. and Click
Okay, now configuration is
finished.
12 – Next, in the Routing
and Remote Access
console, expand DC-
CLOUD,
right-click ports,
click Properties. 13
Page
13 – Verify that 128
ports exist
for SSTP, IKEv2,
PPTP, and L2TP, then dou
ble-click WAN Miniport
(SSTP). Maximum ports
box, type 5, and then
click OK, Routing and
Remote Access message
box, click Yes.
14
Page
14 – Repeat the same step
no:13 for IKEv2,
PPTP, and L2TP, then
click OK.
05 – Client
Connectivity
Testing
1 – On the Windows 10
client PC, open Network
and Sharing
Center, then click Set up a
new connection or
network.
2 – Next, on the Choose a
connection option
interface, click Connect to
a workplace, and then
click Next.
15
Page
3 – On the How do you
want to connect? interface,
click Use my Internet
connection (VPN).
4 – On the Connect to a
Workplace
interface, click I’ll set up
an Internet connection
later.
5 – In the Internet address
box,
type 131.107.0.10 (DC-
CLOUD VPN Server IP
Address).
— In the Destination name box, type
New Help Tech VPN connection,
select Allow other people to use this
connection checkbox, and then
click Create. —
16
Page
6 – Next,
right click NewHelpTech
VPN connection, and then
click Connect.
7 – In the sign-in dialog
box, type the domain user
from VPN Users OU Name
Sifad and box, type
Password, and then click
OK.
17
Page
8 – Verify that you are
connected to Windows by
using a PPTP connection,
right click
NewHelpTech VPN
connection, and then click
Status.
Orait, that all for now,
we’ve connected
to NewHelpTech VPN-
connection successfully.
Summary…………………………………………….
Implementing a client-based VPN solution for secure remote access using Windows Server 2016 has many
advantages over dedicated and proprietary security appliances. Windows-based VPN servers are easy to
manage, cost effective, and offer greater deployment flexibility. However, at this point additional
configuration is required to properly secure incoming connections.
18
Page