{"id":1494,"date":"2018-11-16T11:51:59","date_gmt":"2018-11-16T11:51:59","guid":{"rendered":"http:\/\/www.RiptideHosting.com\/blog\/?p=1494"},"modified":"2020-04-22T20:37:06","modified_gmt":"2020-04-23T02:37:06","slug":"windows-server-2016-vpn","status":"publish","type":"post","link":"https:\/\/www.RiptideHosting.com\/blog\/windows-server-2016-vpn\/","title":{"rendered":"Windows Server 2016 VPN"},"content":{"rendered":"<p><strong><u>Update:\u00a0 See link here for Setting up the VPN Role on Server 2019-<a href=\"http:\/\/www.riptidehosting.com\/blog\/how-to-install-vpn-server-on-windows-server-2019\/\"> http:\/\/www.riptidehosting.com\/blog\/how-to-install-vpn-server-on-windows-server-2019\/<\/a><\/u><\/strong><\/p>\n<p><strong><u>Windows Server 2016 VPN <\/u><\/strong><\/p>\n<p>Using a VPN with RDP is more secure because it provides two steps to access your network.\u00a0 You could require clients to connect with a VPN first before being able to RDP to the server.\u00a0 Unless you are using our Dedicated Server Hosting offering where you can have a hardware vpn device, you will need to install a software VPN on the server.\u00a0 One option is using the free built-in Windows VPN role service. Other software VPN options available have been Hamachi (acquired by LogMeIn), Zerotier which provides software defined networking capabilities, and other options.<\/p>\n<p>WINDOWS SERVER BUILT-IN VPN ROLE:<\/p>\n<p>If you are interested in setting up the built-in VPN role on Windows Server 2016 and then limiting RDP access to private IPs after VPN is connected, contact Riptide Hosting for a post we wrote on how to set this up.\u00a0 PPTP VPN using Windows Authentication is password based so strong\/complex passwords are still very important. Other VPN protocols, certificate authentication, may provide stronger security depending on your needs and environment.\u00a0 You can use the built-in Windows VPN to setup a L2TP VPN with preshared keys too.<\/p>\n<p>General steps to install the (free) built-in VPN role on Windows Server 2016:<\/p>\n<ul>\n<li>Add \u201cRemote Access\u201d server role with \u201cDirectAccess and VPN (RAS)\u201d role service.<\/li>\n<li>Open the Getting Started Wizard, select \u201cDeploy VPN only\u201d, \u201cConfigure and Enable Routing and Remote Access\u201d, Select \u201cCustom Configuration\u201d, Select \u201cVPN access\u201d only. Start Service.\u00a0 Reboot<\/li>\n<li>Go into \u201cRouting and Remote Access\u201d properties, IPv4 tab to add static IP address pool with private IPs<\/li>\n<li>Change Network Adapter settings, IPv4, to add secondary IP from private IP range above<\/li>\n<li>Adjust User Properties for each user on the Dial-In tab to Allow \u201cNetwork Access Permission\u201d<\/li>\n<li>Setup VPN Connection on each user PC (may need to uncheck \u201cuse default gateway on remote network\u201d if having internet issues on the PC)<\/li>\n<li>Adjust Server Firewall rules to disable RDP access on port 3389<\/li>\n<li>Test deployment (verify you can\u2019t RDP without using VPN first, etc.)<\/li>\n<li>Our steps generally follow the steps in these links with a few additional items noted<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.thomasmaurer.ch\/2016\/10\/how-to-install-vpn-on-windows-server-2016\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/www.thomasmaurer.ch\/2016\/10\/how-to-install-vpn-on-windows-server-2016\/<\/a><\/p>\n<p><a href=\"https:\/\/www.starwindsoftware.com\/blog\/how-to-install-vpn-access-on-windows-server-2016\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/www.starwindsoftware.com\/blog\/how-to-install-vpn-access-on-windows-server-2016<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Update:\u00a0 See link here for Setting up the VPN Role on Server 2019- http:\/\/www.riptidehosting.com\/blog\/how-to-install-vpn-server-on-windows-server-2019\/ Windows Server 2016 VPN Using a VPN with RDP is more secure because it provides two steps to access your network.\u00a0 You could require clients to connect with a VPN first before being able to RDP to the server.\u00a0 Unless you [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2,7,15],"tags":[46,52,70,83],"class_list":["post-1494","post","type-post","status-publish","format-standard","hentry","category-all-posts","category-remote-desktop-hosting","category-windows-server-2016","tag-rdp","tag-remote-desktop","tag-terminal-server-vpn","tag-windows-server-hosting"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.RiptideHosting.com\/blog\/wp-json\/wp\/v2\/posts\/1494","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.RiptideHosting.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.RiptideHosting.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.RiptideHosting.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.RiptideHosting.com\/blog\/wp-json\/wp\/v2\/comments?post=1494"}],"version-history":[{"count":4,"href":"https:\/\/www.RiptideHosting.com\/blog\/wp-json\/wp\/v2\/posts\/1494\/revisions"}],"predecessor-version":[{"id":1756,"href":"https:\/\/www.RiptideHosting.com\/blog\/wp-json\/wp\/v2\/posts\/1494\/revisions\/1756"}],"wp:attachment":[{"href":"https:\/\/www.RiptideHosting.com\/blog\/wp-json\/wp\/v2\/media?parent=1494"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.RiptideHosting.com\/blog\/wp-json\/wp\/v2\/categories?post=1494"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.RiptideHosting.com\/blog\/wp-json\/wp\/v2\/tags?post=1494"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}