Presentation is loading. Please wait.

Presentation is loading. Please wait.

配置远程访问. 概述 在 Windows 2000 中检测远程访问 配置入站连接 配置出站连接 配置多链路连接 配置身份验证协议 配置加密协议 为 DHCP 集成配置路由和远程访问.

Similar presentations


Presentation on theme: "配置远程访问. 概述 在 Windows 2000 中检测远程访问 配置入站连接 配置出站连接 配置多链路连接 配置身份验证协议 配置加密协议 为 DHCP 集成配置路由和远程访问."— Presentation transcript:

1 配置远程访问

2 概述 在 Windows 2000 中检测远程访问 配置入站连接 配置出站连接 配置多链路连接 配置身份验证协议 配置加密协议 为 DHCP 集成配置路由和远程访问

3 在 Windows 2000 中检测远程访问 建立远程访问连接 数据传输协议 虚拟专用网络协议( VPN )

4 建立远程访问连接 LAN Protocols Remote Access Protocols Local Area Network LAN Protocols Remote Access Protocols Remote Access Protocols Internet Remote Access Client Remote Access Server

5 数据传输协议 Remote Access Client PPP SLIP (client only) Microsoft RAS ARAP (server only) TCP/IP NWLink NetBEUI AppleTalk Remote Access Protocols LAN Protocols

6 虚拟专用网络协议( VPN ) ClientServer PPTP Internetwork Must Be IP Based No Header Compression No Tunnel Authentication Built-in PPP Encryption L2TP Internetwork Can Be IP, Frame Relay, X.25, or ATM Based Header Compression Tunnel Authentication Uses IPSec Encryption Internet PPTP or L2TP

7 配置远程访问连接 配置远程访问服务 配置虚拟专用网络端口 配置调制解调器和电缆端口 配置用户拨入设置

8 启动远程访问服务 Routing and Remote Access Server Status SERVERX (local) ActionView Configure and Enable Routing and Remote Access Disable Routing and Remote Access Delete Refresh Export List... Properties Help All Tasks View

9 配置虚拟专用网络端口 Routing and Remote Access ActionView Routing and Remote Access Server Status SERVERX (local) Ports Dial-In Clients (0) IP Routing Remote Access Policies NameDeviceCommentStatus Ports WAN Miniport (PPTP)(VPN3-4)VPNInactive WAN Miniport (PPTP)(VPN3-3)VPNInactive WAN Miniport (PPTP)(VPN3-2)VPNInactive WAN Miniport (PPTP)(VPN3-1)VPNInactive WAN Miniport (PPTP)(VPN3-0)VPNInactive WAN Miniport (L2TP)(VPN2-4)VPNInactive WAN Miniport (L2TP)(VPN2-3)VPNInactive WAN Miniport (L2TP)(VPN2-2)VPNInactive WAN Miniport (L2TP)(VPN2-1)VPNInactive WAN Miniport (L2TP)(VPN2-0)VPNInactive Direct Parallel (LPT1)PARALLELInactive Modem (COM 3)MODEMInactive PPTP Ports L2TP Ports Cable and Modem Ports

10 配置调制解调器和电缆端口 Ports Properties RAS Device Configuration In the list below, select those devices which can be used by the Routing and Remote Access Services. Devices: UsageDeviceTypeNum... Ras None WAN Miniport (PPTP) WAN Miniport (L2TP) Direct Parallel PPTP L2TP Parallel Configure Configure ports - WAN Miniport (PPTP) You can enable this device to accept inbound remote access requests and to enable demand-dial routing connections. Remote access (inbound) Demand-dial routing (inbound/outbound) Phone number of this device: Ports You can adjust the port limit for a device which supports dynamic ports (such as virtual circuits). Maximum ports: 5 OKCancel Ports, Grouped By Type Function of Port Phone Number (if applicable) Number of Virtual Ports

11 配置用户拨入设置 User1 Properties GeneralAddressAccountProfileTelephonesOrganization Member OfEnvironmentTimeouts Dial-in Remote Access Permission (Dial-in or VPN) Callback Options Apply Static Routes Allow access Deny access Control access through Remote Access Policy Verify Caller-ID: No Callback Set by Caller (Routing and Remote Access Service only) Always Callback to: Assign Static IP Address Define routes to enable for this Dial-in connection. OKCancel Apply Static Routes... Permissions Caller ID Callback IP Routing

12 配置出站连接 考查硬件选项 创建拨号连接 连接到虚拟专用网 通过电缆直接连接

13 考查硬件选项 Connection Methods PSTN ISDN Cable Modem X.25 Direct Connection

14 创建拨号连接 Network Connection Type You can choose the type of network connection... Network Connection Type You can choose the type of network connection... Network Connection Wizard Dial-up to private network Dial-up to the Internet Connect using my phone line (modem or ISDN) Connect to the Internet using my phone line (modem or ISDN) Client Remote Access Server Client ISP Server Internet

15 连接到虚拟专用网 Windows 2000 VPN Server Internet Adapter Intranet Adapter Corporate Intranet VPN Remote Access Client Internet Tunnel

16 通过电缆直接连接 Host Guest This computer has the information you want to access. Host or Guest To connect two computers, specify which one you are using. Host or Guest To connect two computers, specify which one you are using. Network Connection Wizard Choose the role you want for this computer This computer will be used to access information on the host computer. Select a Device This is the device that will be used to make the connection. Select a Device This is the device that will be used to make the connection. Network Connection Wizard Select a device: Communications Port (Com1) Communications Port (Com2) Direct Parallel (LPT1) Communications Port (Com1) Communications Port (Com2) Direct Parallel (LPT1) Communications Port (Com1)

17 配置身份验证协议 标准身份验证协议 可扩展的身份验证协议

18 标准身份验证协议 ProtocolProtocolSecuritySecurity PAP 低 低 SPAP 中 中 CHAP 高 高 MS-CHAP 高 高 Use when The client and server cannot negotiate using more secure validation Connecting a Shiva LANRover and Windows 2000–based client or a Shiva client and a Windows 2000–based remote access server You have clients that are not running Microsoft operating systems You have clients running Windows NT version 4.0 and later or, Microsoft Windows 95 and later MS-CHAP v2 MS-CHAP v2 高 高 You have dial-up clients running Windows 2000, or VPN clients running Windows NT 4.0 or Windows 98

19 可扩展的身份验证协议 允许客户和服务器协商他们将使用的身份 验证方法 支持所使用的身份验证 –MD5-CHAP – 传输层安全性 – 附加的第三方的身份验证方法 确保支持通过 API 进行身份验证的方法

20 配置加密协议 Edit Dial-in Profile Dial-in ConstraintsIPMultilink AdvancedEncryptionAuthentication NOTE: These encryption settings apply only to the Windows 2000 Routing and Remote Access Service. Select the level(s) of encryption that should be allowed by this profile. No Encryption Basic Strong Strongest OKCancelApply Members of this group dial-in profile can use IPSec 56-bit Data Encryption Standard (DES) or MPPE 40-bit data encryption Members of this group dial-in profile can use IPSec 56-bit DES or MPPE 56-bit data encryption Members of this group dial-in profile can use IPSec Triple DES (3DES) or MPPE 128-bit data encryption

21 为 DHCP 集成配置路由和远程访问 为 DHCP 集成配置路由和远程访问 利用 DHCP 将 IP 地址分配给远程访问客户 机 为使用 DHCP 而配置路由和远程访问

22 利用 DHCP 将 IP 地址分配给远程 访问客户机 If DHCP Server is Available If DHCP Server is Unavailable Remote Access Server Obtains 10 IP Addresses at a Time Remote Access Server Uses Automatic Private IP Addressing

23 为使用 DHCP 而配置路由和远程访问 GeneralSecurity IP PPPEvent Logging Enable IP routing Allow IP-based remote access and demand-dial connections IP address assignment This server can assign IP addresses by using: Dynamic Host Configuration Protocol (DHCP) Static address pool FromToNumberIP Add…Mask Add… Edit… Remove Use the following adapter to obtain DHCP, DNS, and WINS addresses for dial-up clients. Adapter: OKCancel Apply LONDON (local) Properties Corpnet:

24 复习 在 Windows 2000 中检测远程访问 配置入站连接 配置出站连接 配置身份验证协议 配置加密协议 为 DHCP 集成配置路由和远程访问


Download ppt "配置远程访问. 概述 在 Windows 2000 中检测远程访问 配置入站连接 配置出站连接 配置多链路连接 配置身份验证协议 配置加密协议 为 DHCP 集成配置路由和远程访问."

Similar presentations


Ads by Google