Network Positioning of a Windows Server 2012 R2 Direct Access & VPN Server

Reposted moved from Windows Server Forums- Security
Hi
I'm in the process of creating a new active directory forest with a single domain using AD.Contoso.com to use the Microsoft example. The reason I have decided on AD.XXXXXXXXX.com is to get way from using split horizon (Split Brain) DNS. The requirements
for our new domain are :-
2012 R2 AD
Direct Access & VPN
Exchange 2013 OWA, Active Sync Outlook Anywhere (Possibly a Hybrid Config where we have on premises mailboxes and some exchange online mailboxes Office 365 etc)
Lync 2013 ?
SharePoint 2013 ?
Microsoft Active Directory Certificate Services
System Center Configuration Manager 2012 R2
Two way trusts between old forest and new to enable Transition/Migration
Ok so that's what I'm aiming for so now the question.
They are allowing me to purchase a next Generation Firewall may be a Barracuda NG firewall or a Cisco ASA X series so I need some advice on what type of network topology I should configure. I've read that using the two NIC configuration for
the 2012 R2 Direct Access Server is preferable, one nic on the internal network one on the perimeter. The problem I have with this is that it bridges the internal network and the perimeter bypassing the backend Firewall see image
The other alternative is to dispense with the perimeter network use the Direct Access server with a single NIC and setup the NG Firewall in a three-legged config with the DA server on the DMZ.
So all you security experts out there what would be your design for this simple domain? we don't need any HA or Load Balancing.
Thanks
Simon

Ok I'm not sure we are going to get any advice on this subject but one last effort. Our budget can only stretch to one next generation firewall so I'm considering the following three legged firewall design with a two NIC 2012 R2 Direct
Access server. If someone could validate this configuration or suggest an alternative then I would be grateful.

Similar Messages

  • Unable to install lan realtek rtl8101 and network controller driver on windows server 2008

    Hi Guys,
    i am trying to install realtek rtl 8101 f amily driver and network controller driver on windows server 2008 but unable to install.
    Hp device Model.:- hp pavilion g4 1303au
    Model no.:- 5c03213jsh
    network controller Device ID: PCI\VEN_168C&DEV_0032&SUBSYS_1785103C&REV_01\4&211965BF&0&0020
    Name: PCI Device
    Device ID: PCI\VEN_10EC&DEV_5209&SUBSYS_3564103C&REV_01\4&34BC5A71&0&0030
    Name: SM Bus Controller
    Device ID: PCI\VEN_1022&DEV_780B&SUBSYS_3564103C&REV_13\3&2411E6FE&0&A0
    thanks,
    Amit Rai

    Hi:
    SMBus controller:
    Here is what I have done...I have zipped up and attached below under Attachments, the raw smbus controller driver files for you to unzip and manually install. 
    Download and unzip the file.
    Go to the device manager and click on the smbus controller needing drivers.  Click on the driver tab.  Click on Update Driver.
    Select the Browse my computer for driver software option and browse to the driver folder that you unzipped.
    Make sure the Include Subfolders box is checked and the driver should install.  Then reboot.
    Ethernet:  Download and install the 1st driver on the list.
    http://www.realtek.com.tw/downloads/downloadsView.aspx?Langid=1&PNid=14&PFid=7&Level=5&Conn=4&DownTy...
    Card reader (PCI dev.):  Download and install the first driver on the list.
    http://www.realtek.com.tw/downloads/downloadsView.aspx?Langid=1&PNid=15&PFid=25&Level=4&Conn=3&DownT...
    Wireless:  You will have to try the Vista driver for the Atheros wireless card...
    http://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/psi/swdDetails/?sp4ts.oid=5060882&sp...
    Attachments:
    sp66185.zip ‏7 KB

  • Unable to install Network Adapter Driver for Windows Server 2012

    Hi,
    We have purchased a new computer for our office. And on that machine, we want to install Windows Server 2012 Standard with GUI.
    Windows Server got installed on that machine. But we are unable to install drivers for our LAN card Intel® 82579V Gigabit Network Connection.
    Please help us to get it working.
    Thanks,
    Ronak Shah

    It is not working as the system is having Intel® 82579V Gigabit Network Card
    I guess, it's not supported on windows server 2012
    https://downloadcenter.intel.com/Detail_Desc.aspx?agr=Y&ProdId=3299&DwnldID=18725&ProductFamily=Ethernet+Components&ProductLine=Ethernet+Controllers&ProductProduct=Intel%C2%AE+82579+Gigabit+Ethernet+Controller&lang=eng
    NOTE: The following devices do not have driver or software support for Windows Server
    2008 R2:
     - Intel® 82566MC Gigabit Network Connection
     - Intel® 82566MM Gigabit Network Connection
     - Intel® 82567LF Gigabit Network Connection
     - Intel® 82567V Gigabit Network Connection
     - Intel® 82577LC Gigabit Network Connection
     - Intel® 82579V Gigabit Network Connection
    Regards, Santosh
    I do not represent the organisation I work for, all the opinions expressed here, are my own.
    This posting is provided AS IS with no warranties or guarantees and confers no rights.
    Blog |
    Wiki

  • Transferring network user files from Windows Server 2003 to Mac OSX 10.5.8

    I'm wondering if any network admins out there have a suggested method of transferring network user files from a Windows Server 2003 to an XServe running 10.5.8?
    When we did the file transfer, clicking and dragging, there were a myriad permissions issues that subsequently arose. Surely there is a way to strip permissions off files PRIOR to the transfer?? Maybe not, but I'm wondering how you folks have done it.
    We have had nothing but persistent permissions issues since the transfer (i.e. folks who should have access to files, being denied access, including the local server admin!!). This also translates to synch errors for network mobile accounts.
    Thanks,
    John Orban
    System Administrator
    The Country School

    http://www.laurentnomine.com/2009/09/invalid-file-handle-when-copying-files-from -os-x-leopard-10-5-to-vista7/

  • IPhoto not showing up -- Network Home Folders on Windows server

    When our users who have their home folder on a Windows server open iMovie, they can't access their iPhoto library within iMovie. The same is true for the 3rd party app, ComicLife. Is there something going wrong where the Windows server is screwing up whatever links the iPhoto library with other apps? Users who are on the Apple server are working just fine.
    Thanks for any help you can give.
    For reference, this is any mac client on 10.4.9 with Networked home folders going to either Win2003 server or Mac Server 10.4.10.

    In case anyone else is looking... This was being caused by connecting to the home folders on the windows server using AFP. Switching it to SMB fixed the problem.

  • Windows 10 Enyerprise Preview - Direct Access Enable?

    I downloaded and install Windows 10 Enterprise Edition. The Direct Access feature is not working. Can someone advise me if that feature is enabled in the preview edition.
    Thanks
    Shri

    Hi Andrew
    Thank you for the link.
    We need to add the Windows 10 Version number in the GPO, as stated below
    Select * from Win32_OperatingSystem WHERE (ProductType = 3) OR ((Version
    LIKE '6.2%' OR Version LIKE '6.3%' OR VERSION LIKE '6.4%') AND
    (OperatingSystemSKU = 4 OR OperatingSystemSKU = 27 OR OperatingSystemSKU = 72 OR OperatingSystemSKU = 84)) OR (Version LIKE '6.1%' AND (OperatingSystemSKU = 4 OR OperatingSystemSKU = 27 OR OperatingSystemSKU = 70 OR OperatingSystemSKU = 1 OR OperatingSystemSKU
    = 28 OR OperatingSystemSKU = 71))
    (the new text is the OR VERSION LIKE '6.4%') After the necessary GPO update propagation delays, DA properly runs on Win 10. Just thought I would post this for others knowledge.

  • How do I set access to the same network share on a Windows server for multiple users on an iMac (school set-up) in Lion 10.7.3?

    We've got them authenticating/binding with AD (after hours of troubleshooting to get working), and their Home drive on the Windows 2003 server loads in the dock, but they also want to be able to load the same network shares on the server e.g. "Students$" for every student that logs onto the iMac.  I realise without Lion server we can't control it by group, but if we could at least set it up consistently for the students that would be a great start.
    Thanks.

    When you install you get the opportunity to install it for "All Users".
    It sounds like you have a demo version on your Mac however, you need to delete it:
    http://www.freeforum101.com/iworktipsntrick/viewtopic.php?t=105&mforum=iworktips ntrick
    Peter

  • Windows Server 2012 Standard - HP OfficeJet Pro 8600 Plus printer not working after promoting to Domain Controller / AD Services

    An associate and myself installed the built-in drivers for the HP OfficeJet Pro 8600 Plus multi-function (network) printer on a Windows Server 2012 Standard server installation and everything worked fine whenever I want to print anything directly from the
    Windows Server machine (there's a reason for this, so please understand that ;)  ).
    We were able to print without any problems from the Windows Server 2012 machine, using the drivers from Microsoft.  Mainly, because HP has not listed any specific support for Windows Server 2012, only Windows Server 2008 R2, however, the drivers that
    came with Windows 2012 seem to work very well.
    PROBLEM: I later had to promote the Windows Server 2012 to a Domain Controller, and created the Active Directory configurations, even enabled the Print Services.  After doing all of that, the HP printer will not print anything.  It's like all print
    requests directly from the Windows Server go to Nil.
    Has anyone encountered a problem like this before? The only thing I can think of is that after perhaps something affected printing directly once we promoted the server to being a DC, and added other features / roles.  I even tried installing the
    HP drivers for Windows Server 2008 R2, and the results are still the same...nothing prints.  Trust me, the printer is set as the Default Printer and even when choosing to print, we make sure the HP OfficeJet Pro is selected, and is on, as other Windows
    Client PC's can print to it directly.
    Does anyone have any suggestions we could try?  Thanks in advance.

    While it is quite a while since this was posted - I can concur a similar issue exists.
    We have spent the better part of a day trying to work out why other HP printers work fine but our 8620 prints are not printing and going to Nil.  The print server is hosted on a shared DC.  Comparing to the initial posters details, for some reason
    it seems to be most commonly related to the OfficeJet Pro 8600/8610/8620/8630 series printers.
    I ended up doing a print server migration from the domain controller to stand alone host and all printers now work from a single server rather than a mix.  Domain controller OSes varied from 2008, 2012, 2012 R2 (tested with multiple) and only after
    all of those failed then tried a stand alone server os machine as a last resort which worked fine.  Printing directly from Win 7 / 8 /8.1 clients to the IP always worked.

  • Windows Server 2012 very slow performance executing files

    Hello,
    I am running windows server 2012 as dc with 2 clients connected running win7 pro x64, this is a new setup.
    Whenever i try to open a large file from the client or an application from the client it takes forever to startup or to load. The performance monitor indicates a maximum workload of 15% at all times.
    I have tried all the following potential solutions i found, however none of them seem to do the trick.
    - enable write cache = http://social.technet.microsoft.com/Forums/en-US/a76f6e97-3266-4ba1-ba90-ad5318ec4937/slow-file-sharing-performance-on-windows-server?forum=winservergen
    - change group policy = http://support.microsoft.com/kb/829700/nl
    - change group policy as = http://social.technet.microsoft.com/Forums/en-US/bcb4b580-50ef-4f10-bc9b-16db1bf24804/slow-network-file-execution-on-windows-server-2012?forum=winserverfiles
    Does anyone have any ideas?
    With kind regards

    Hi,
    You could disable SMBv3 on server 2012 to check if the issue related to SMB protocol. 
    How to enable and disable SMBv1, SMBv2, and SMBv3 in Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2, Windows 8, and Windows Server 2012
    http://support.microsoft.com/kb/2696547/en-us
    Warning: We do not recommend that you disable SMBv2 or SMBv3. Disable SMBv2 or SMBv3 only as a temporary troubleshooting measure. Do not leave SMBv2 or SMBv3 disabled.
    Please also refer to the Forum FAQ to troubleshoot the slow performance issue:
    [Forum FAQ] Troubleshooting Network File Copy Slowness
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/7bd9978c-69b4-42bf-90cd-fc7541ccb663/forum-faq-troubleshooting-network-file-copy-slowness?forum=winserverPN
    Regards,
    Mandy
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Windows server 2012 standard - slow performance in file sharing

    I recently installed two windows server 2012, one is for DC, one is for File Sharing; it works fine in the beginning.
    Lately, it comes a problem, every once a while it is very slow when opening a file on the server from a client PC; but when i restart the file server then  it will be fine again.
     

    Hi Simon,
    Based on your description, how is the workload of the file server?
    Before going further, regarding slow network performance when opening a file that is located in a shared folder on a remote network computer, the following article can be
    referred to as reference.
    Slow network performance when you open a file that is located in a shared folder on a remote network computer
    http://support.microsoft.com/kb/829700
    Besides, the following thread may have focused on the similar issue and can be worth taking a look.
    Slow network file execution on Windows Server 2012
    http://social.technet.microsoft.com/Forums/en-US/bcb4b580-50ef-4f10-bc9b-16db1bf24804/slow-network-file-execution-on-windows-server-2012?forum=winserverfiles
    Best regards,
    Frank Shen

  • Windows Server 2012 - Direct Access clients and the Windows 8 firewall

    Hi,
    We're running a simple proof-of-concept for Server 2012 Direct Access, we have a single DA server behind a firewall using NAT. We have a number of client devices setup for DA and running Windows 8.
    Our issue is that we can only get the Windows 8 direct access clients to connect (when outside the corporate network) and work with the windows firewall disabled (public network profile). 
    With the windows firewall disabled everything works exactly as expected. When outside the corporate network the client detects the network state (public network profile), connects via DA and all internal resources can be accessed successfully...fantastic.
    Is there some specific guidance on manually configuring the windows 8 firewall for Direct Access ? We've tried the obvious TCP:443 with edge traversal enabled but without success.
    Much of the information we have found relates to UAG rather than Windows 2012 DA.
    Any assistance is appreciated.

    Hi,
    There isn’t any specific configuration on the firewall.
    Just confirm that port 443 can be forwarded to DirectAccess server.
    Of course, make sure you are using IPsec first.
    Check the links:
    STEP 6: Test DirectAccess Client Connectivity from Behind a NAT Device
    http://technet.microsoft.com/en-us/library/hh831524.aspx#TeredoCLIENT1
    DirectAccess for Windows Server 2012 Installation & Configuration Guide
    http://syscomlab.blog.com/2012/09/directaccess-for-windows-server-2012-guide/
    Please Note: Since the web site is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of this information.
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Using Shared Review via Network Folder on Windows server and PC and Mac users commenting

    We are having initiation and connection problems on the Macs (running OS 10.6.4 Snow Leopard)  with Shared Reviews (from Acrobat 9) that are stored on a Windows 2008 Server connecting via SMB. I would be very interested to hear from anyone who is successfully:
    1) Initiating Shared Reviews from a Macintosh via "Automatically collect comments on my own internal server" and navigating to a folder (with full read/write permissions for all) on a Windows server. We cannot get Acrobat (via the automated SR set-up wizard) to verify the network folder location on the Macs so that a Mac user can initiate a Shared Review. On Windows (using Parallels or logging in to a PC directly), the same users have no problem initiating and accessing Shared Reviews.
    2) Accessing Shared Reviews on a network folder (set up on a Windows 2008 server) via a Mac running OSX 10.6.4 and Acrobat 9. All users have read/write access to the folder and can navigate to it via the server. They can save documents to the network folder and open other documents there as well. When they open a Shared Review-enabled PDF for commenting, they get the error message that Acrobat cannot connect to the server. Retry results in the same error message.
    We use Shared Reviews extensively and have no problems with PC users accessing the files and Mac users accessing them via Windows (Parallels or on a PC). This is very frustrating so I would really appreciate any ideas, especially if anyone is actually doing Shared Reviews this way.
    Thanks.

    Unfortunately, this is NOT fixed based on the testing I have done.
    1) I am still unable to connect to the network folder on a Windows server from the Mac to initiate a Shared Review In Acrobat version 9.4.6. Same error message as previous Unable to locate server. See screenshot:
    2) One of the Mac users (also upgraded to Acrobat 9.4.6) who was invited to participate in a Shared Review (initiated using Parallels/Windows) was initially able to open the file and Publish comments. However, after she did and closed the file, she was unable to reopen the same file, connect to the server and add comments. And no other Mac user could access the file after she added her first comments. We all got the error message "Unable to connect etc" See screenshot.
    3) I opened the same file in Parallels/Windows with no problem. However, the Mac user's comments were not there. I could add comments and publish in Windows.
    4) When I tried to access the Tracker from my Mac (review was initiated via Parallels), I got the error message File not Found when I tried to access the test review via my Mac (see screenshot).
    Could you give me more information about the fix? I would also be happy to talk to you or send more details if that would help.
    Our set up has not changed from the original information I sent (there may have been some Mac updates -- we are all on OS 10.6.8 but still Snow Leopard). Server has not changed.

  • Network issues with Windows Server 2008 and MacOS

    Hello there,
    I believe it is a long shot, but i am running out of options. I got a video streaming server software running on my windows server 2008. It has a client that runs on MacOS and Windows. The windows client works just fine, but the macos client cannot stream
    a few videos.
    I've tried installing the streaming server on windows 7 and my mac client worked just fine, so I believe that win server 2008 got some sort of configuration that is blocking the correct communication between software. 
    Since the software devs could not tell me what's wrong or how to fix it, I thought I might get some help here (kinda of a last hope thing). I have tried installing codecs, enabling desktop experience and nothing worked.
    So, here is my question: Is there anything that windows server has that windows 7 do not that might be causing this scenerio?
    Thanks,
    Lucas

    Hi,
    Have you disabled the firewall on the windows server? The firewall may block the traffic if it isn’t configured properly.
    If it still doesn’t work after disabling the firewall, please install the Network Monitor on the windows server and client. Then capture the traffic of the video when the server and windows7 runs your software.
    Try to compare the traffic of windows server and windows7. Find out the difference between them.
    To download Network Monitor, click the link below,
    Microsoft Network Monitor 3.4
    http://www.microsoft.com/en-hk/download/details.aspx?id=4865
    The following article is about how to use the Network Monitor,
    Network Monitor
    http://technet.microsoft.com/en-us/library/cc938655.aspx
    Hope this helps.
    Steven Lee
    TechNet Community Support

  • Network Connectivity Assistant in Windows 8.1

    What happened to the Network Connectivity Assistant in Win8.1? In Win8 it would launch a "DirectAccess" dialog like the one in this blog:
    http://blog.msgeneral.nl/2012/03/direct-access-connectivity-assistant-in.html
    But in Win8.1 double-clicking and righ-clicking doesn't do anything:

    As Richard points out you can only access the NCA via the following.
    To access the DirectAccess connection properties in Windows 8.1, press
    Window Key + I, click Change PC Settings, and then click
    Network.
    Highlight Connections and click Workplace Connection.
    It is a step back for those that are used to the DCA or Win8 NCA.
    Note: also you need to have a email client enabled on the client to get the logs.
    Also there is the "Microsoft DirectAccess Client Troubleshooting Tool "
    Regards
    Regards, Rmknight

  • Direct Access and WIndows Phone 8.1?

    Hi all –
    I am reaching out to the community here because I haven’t been able to find anything concrete. 
    The scenario is that we wish to have links which are sent through an on-prem SharePoint farm resolve on a user’s Windows Phone whilst roaming. 
    The root of the issue is that the client does not have split DNS in place. 
    Therefore when they send a link from the SharePoint site it’s URL is mysite.acme.int, for example, which is not resolvable from outside of the corporate network;
    Acme.com is however.
    We have Direct Access (2012 R2) in place and use Windows Phone 8.1. 
    What I am trying to determine is whether or not we can leverage a DA connection with the Windows Phones in order to attain URL resolution.
    Barring that does anyone have any bright ideas on how to conquer the problem?
    Kind regards and thanks in advance!
    Wren

    Hi Wren,
    Agree with Rmknight. Windows Phone doesn't support DirectAccess at present.
    For detailed information, please refer to the link below:
    https://businessmobilitycenter.microsoft.com/en/webinars/Pages/Webinar-Managing-Enterprise-Content-and-Information-on-Lumia-Windows-Phone-8-1.aspx
    Best Regards.
    Steven Lee Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

Maybe you are looking for