KAPLAN SCHOOL OF INFORMATION SYSTEMS AND TECHNOLOGY IT375 Window Enterprise Administration Course Name – IT375-01 Introduction to Network Security Instructor.

Slides:



Advertisements
Similar presentations
CPSC Network Layer4-1 IP addresses: how to get one? Q: How does a host get IP address? r hard-coded by system admin in a file m Windows: control-panel->network->configuration-
Advertisements

5.1 Overview of Network Access Protection What is Network Access Protection NAP Scenarios NAP Enforcement Methods NAP Platform Architecture NAP Architecture.
1.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 1: Introducing Windows Server.
4.1 Configuring Network Access Components of a Network Access Services Infrastructure What is the Network Policy and Access Services Role? What is Routing.
11 TROUBLESHOOTING Chapter 12. Chapter 12: TROUBLESHOOTING2 OVERVIEW  Determine whether a network communications problem is related to TCP/IP.  Understand.
Module 5: Configuring Access for Remote Clients and Networks.
1 Objectives Configure Network Access Services in Windows Server 2008 RADIUS 1.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 11: Planning Network Access.
Module 10: Configuring Virtual Private Network Access for Remote Clients and Networks.
1 Objectives Wireless Access IPSec Discuss Network Access Protection Install Network Access Protection.
Hands-On Microsoft Windows Server 2003 Administration Chapter 11 Administering Remote Access Services.
Hands-On Microsoft Windows Server 2003 Networking Chapter 1 Windows Server 2003 Networking Overview.
MCITP Guide to Microsoft Windows Server 2008 Server Administration (Exam #70-646) Chapter 10 Configuring Remote Access.
Virtual Private Network (VPN) © N. Ganesan, Ph.D..
Configuring Routing and Remote Access (RRAS) and Wireless Networking Lesson 5.
Chapter 11: Dial-Up Connectivity in Remote Access Designs
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 10: Remote Access.
© 2012 Cisco and/or its affiliates. All rights reserved. 1 CCNA Security 1.1 Instructional Resource Chapter 10 – Implementing the Cisco Adaptive Security.
1 Microsoft Windows NT 4.0 Authentication Protocols Password Authentication Protocol (PAP) Challenge Handshake Authentication Protocol (CHAP) Microsoft.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 9 Network Policy and Access Services in Windows Server 2008.
Chapter 6 Configuring, Monitoring & Troubleshooting IPsec
Virtual Private Networks (Tunnels). When Are VPN Tunnels Used? VPN with PPTP tunnel Used if: All routers support VPN tunnels You are using MS-CHAP or.
Course 6421A Module 7: Installing, Configuring, and Troubleshooting the Network Policy Server Role Service Presentation: 60 minutes Lab: 60 minutes Module.
Network Services Lesson 6. Objectives Skills/ConceptsObjective Domain Description Objective Domain Number Setting up common networking services Understanding.
Module 3: Planning and Troubleshooting Routing and Switching.
Configuring Routing and Remote Access(RRAS) and Wireless Networking
CN2140 Server II Kemtis Kunanuraksapong MSIS with Distinction MCT, MCITP, MCTS, MCDST, MCP, A+
Chapter 20: Getting from the Office to the Road: VPNs BAI617.
Introduction to Networking Concepts. Introducing TCP/IP Addressing Network address – common portion of the IP address shared by all hosts on a subnet/network.
Module 8: Configuring Virtual Private Network Access for Remote Clients and Networks.
Module 9: Planning Network Access. Overview Introducing Network Access Selecting Network Access Connection Methods Selecting a Remote Access Policy Strategy.
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 12: Routing.
Objectives Configure routing in Windows Server 2008 Configure Network Address Translation 1.
Remote Access Chapter 4. Learning Objectives Understand implications of IEEE 802.1x and how it is used Understand VPN technology and its uses for securing.
Remote Access Chapter 4. Learning Objectives Understand implications of IEEE 802.1x and how it is used Understand VPN technology and its uses for securing.
11.59 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 11: Introducing WINS, DNS,
70-411: Administering Windows Server 2012
Implementing Network Access Protection
Objectives Configure routing in Windows Server 2008 Configure Routing and Remote Access Services in Windows Server 2008 Network Address Translation 1.
1 Chapter Overview Using the New Connection Wizard to configure network and Internet connections Using the New Connection Wizard to configure outbound.
Module 12: Routing Fundamentals. Routing Overview Configuring Routing and Remote Access as a Router Quality of Service.
1 Week 6 – NPS and RADIUS Install and Configure a Network Policy Server Configure RADIUS Clients and Servers NPS Authentication Methods Monitor and Troubleshoot.
Module 8: Designing Network Access Solutions. Module Overview Securing and Controlling Network Access Designing Remote Access Services Designing RADIUS.
20411B 8: Installing, Configuring, and Troubleshooting the Network Policy Server Role Presentation: 60 minutes Lab: 60 minutes After completing this module,
Module 9: Configuring IPsec. Module Overview Overview of IPsec Configuring Connection Security Rules Configuring IPsec NAP Enforcement.
1 Chapter 12: VPN Connectivity in Remote Access Designs Designs That Include VPN Remote Access Essential VPN Remote Access Design Concepts Data Protection.
Module 11: Remote Access Fundamentals
VIRTUAL PRIVATE NETWORK By: Tammy Be Khoa Kieu Stephen Tran Michael Tse.
11.59 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 11: Introducing WINS, DNS,
Hands-On Microsoft Windows Server Introduction to Remote Access Routing and Remote Access Services (RRAS) –Enable routing and remote access through.
Module 9: Designing Network Access Protection. Scenarios for Implementing NAP Verifying the health of: Roaming laptops Desktop computers Visiting laptops.
BZUPAGES.COM. What is a VPN VPN is an acronym for Virtual Private Network. A VPN provides an encrypted and secure connection "tunnel" path from a user's.
Page 1 TCP/IP Networking and Remote Access Lecture 9 Hassan Shuja 11/23/2004.
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network, Enhanced Chapter 11: Internet Authentication Service.
11 SECURING NETWORK COMMUNICATION Chapter 9. Chapter 9: SECURING NETWORK COMMUNICATION2 OVERVIEW  List the major threats to network communications. 
Module 1: Configuring Routing by Using Routing and Remote Access.
1 Week #5 Routing and NAT Network Overview Configuring Routing Configuring Network Address Translation Troubleshooting Routing and Remote Access.
Routing with Windows Server 2003 Chapter 9. Objectives for this Chapter Manage Routing And Remote Access routing interfaces Manage packet filters Manage.
Using Routing and Remote Access Chapter Five. Exam Objectives in this Chapter:  Plan a routing strategy Identify routing protocols to use in a specified.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 4: Planning and Configuring Routing and Switching.
1 Objectives Wireless Access IPSec Discuss Network Access Protection Install Network Access Protection.
Configure and Security Remote Acess. Chapter 8 Advance Computer Network Lecture Sorn Pisey
1 Welcome to Designing a Microsoft Windows 2000 Network Infrastructure.
Configuring Routing and Remote Access (RRAS) and Wireless Networking Lesson 5.
UNIT 7 SEMINAR Unit 7 Chapter 9, plus Lab 13 Course Name – IT482 Network Design Instructor – David Roberts – Office Hours: Tuesday.
Chapter 1 Introduction to Networking
Module 9: Configuring Network Access
Securing the Network Perimeter with ISA 2004
Configuring and Troubleshooting Routing and Remote Access
Lesson #10 MCTS Cert Guide Microsoft Windows 7, Configuring Chapter 10 Configuring Network and Firewall Settings.
Presentation transcript:

KAPLAN SCHOOL OF INFORMATION SYSTEMS AND TECHNOLOGY IT375 Window Enterprise Administration Course Name – IT Introduction to Network Security Instructor – Jan McDanolds, MS, Security+ Contact Information: AIM – JMcDanolds Phone: Office Hours: Tuesday, 7:00 PM ET or Thursday, 7:00 PM ET

UNIT 6 REVIEW File Services and Print Services Chapter 7: Discuss File Services in Windows Server 2008 Install the Distributed File System (DFS) Discuss and create shared file resources Chapter 8: Discuss the Windows Printer Model and how it is implemented Install the Print Services components of Windows Server 2008 Deploy printers with Windows Server 2008 Configure printers on a Windows Server 2008 network No quiz Any questions about File Services, DFS or Print Services?

UNIT 7 What is a router? Unit 7 covers Chapter 9 – Network Policy and Access Services in Windows Server 2008 A router is a device that holds information about the state of its own network interfaces and contains a list of possible sources and destinations for network traffic. A router directs incoming and outgoing packets based on source and destination information. In Chapter 3, routers were introduced (pg. 84). TCP/IP addresses enable routers to interconnect subnets or networks. Do you need a dedicated hardware router, a software-based router, or a combination of both?

UNIT 7 Network Policy and Access Services in Windows Server 2008 Chapter 9 Configure routing in Windows Server 2008 Configure Routing and Remote Access Services (RRAS) in Windows Server 2008 Describe Network Policy Server Discuss wireless networking with Windows Server 2008

UNIT 7 Configuring RRAS as a Router Windows Server 2008 can act as a software-based router for small networks. It can also act as a DHCP relay agent.

UNIT 7 Configuring Routing in Windows Server 2008 Routing and Remote Access Services (RRAS) Only recommended for use in small networks that require simple routing directions - Not recommended for large and complex environments Dial-up remote access server Virtual private network (VPN) remote access server Internet Protocol (IP) router for connecting subnets of a private network Network address translator (NAT) for connecting a private network to the Internet Dial-up and VPN site-to-site demand-dial router

UNIT 7 Viewing local routes Open the command prompt and type route print

UNIT 7 Working with Routing Tables Routing tables are composed of routes Routes - direct data traffic to its destination based on the information it contains Routing tables - can be managed in the RRAS console or from the command line using the route command

UNIT 7 Configuring RRAS as a Router RRAS in Windows Server 2008 supports remote user or site-to-site connectivity by using virtual private network (VPN) or dial-up connections. RRAS consists of the following components: Remote Access - deploy VPN connections to provide end users with remote access to your organization's network. You can also create a site-to-site VPN connection between two servers at different locations. Routing - as a software router it offers routing services to businesses in local area network (LAN) and wide area network (WAN) environments or over the Internet by using secure VPN connections. Routing is used for multiprotocol LAN-to-LAN, LAN-to- WAN, VPN, and network address translation (NAT) routing services.

UNIT 7 Configuring Routes Static routing is limited for the following reasons: Requires manual creation and management Should not be used on networks with more than 10 subnets All affected routers require reconfiguration if the network changes Dynamic protocols Route traffic based on information they discover about remote networks from other routers Routing Information Protocol version 2 (RIPv2) Uses partner routers, or RIP neighbors, in determining the dynamic routes it can use for forwarding packets of data

UNIT 7 Configuring a DHCP Relay Agent DHCP relay agent – Manages communication between a DHCP server and clients on subnets without a DHCP server. With RRAS, network adapters listen for DHCP broadcast messages Type netsh ? To view syntax and options

UNIT 7 Configuring Dial-on-Demand Routing Demand-dial routing Allows a server to initiate a connection only when it receives data traffic bound for a remote network Can use dial-up networks instead of more expensive leased lines

UNIT 7 Configuring Remote Access Services Dial-up networking Connects remote users to their networks using a standard phone line Virtual Private Networks (VPN) Allows client connections to a network from remote locations Works by creating a secure tunnel for transmitting data packets between two points VPN tunneling protocols: Point-to-Point Tunneling Protocol, Layer 2 Tunneling Protocol, Secure Socket Tunneling Protocol

UNIT 7 Routing and Remote Access Properties Routing and Remote Access IPv4 and IPv6

UNIT 7 VPN Firewall Ports Outbound and Inbound

UNIT 7 Network Address Translation (NAT) NAT allows you to shield internal IP address ranges from public networks by allowing internal clients to access the Internet through a shared IP address ( , etc.)

UNIT 7 Introduction to Network Policy Server Network Policy Server (NPS) Role service that provides a framework for creating and enforcing network access policies for client health Can be used to: Configure a RADIUS server (Remote Authentication Dial-in User Service) Configure a RADIUS proxy Configure and implement Network Access Protection (NAP) NPS Console - Central utility for managing RADIUS clients and remote RADIUS servers Network health and access policies NAP settings for NAP scenarios Logging settings

UNIT 7 Introduction to RADIUS RADIUS - Industry-standard protocol that provides centralized authentication, authorization, and accounting for network access devices Components of RADIUS RADIUS clients Network access servers RADIUS proxy RADIUS server User account database

UNIT 7 RADIUS with proxy server

UNIT 7 RADIUS without proxy server

UNIT 7 RADIUS message flow EAP - Extensible Authentication Protocol

UNIT 7 RADIUS Server Used on networks to perform authentication, authorization, and accounting for RADIUS clients RADIUS client Can be an NPS, which replaces the IAS from previous versions of Windows Server RADIUS - Standardized network protocol that centralizes the following process for user connections Authentication Authorization Accounting

UNIT 7 RADIUS Proxy and NAP NPS - Can be configured as a RADIUS proxy RADIUS proxies Route RADIUS messages between RADIUS clients and RADIUS servers Network Access Protection (NAP) Provides a tool for you to block external and internal network threats Can be broken into three parts Health policy validation Health policy compliance Limited access

UNIT 7 Authentication Protocols Supported authentication protocols: -Extensible Authentication Protocol–Transport Layer Security (EAP-TLS) -Protected Extensible Authentication Protocol– Transport Layer Security (PEAP-TLS) -Protected PEAP–Microsoft Challenge Handshake Authentication Protocol version 2 (PEAP- MSCHAPv2)

UNIT 7 Wireless Access Configuration 802.1x standard - Developed by the Institute of Electrical and Electronics Engineers (IEEE) On 802.1x networks - Network access control provides an authentication mechanism to allow or deny network access based on port connection Categories of EAP implementations EAP over local area network (LAN) EAP over wireless 802.1x uses a three-component model for authenticating access to networks Supplicant Authenticator Authentication server

UNIT 7 Wireless Configuration 802.1X authentication process

UNIT 7 Unit 7 Part A - Assignment Part A – Complete nine Chapter 9 labs.

UNIT 7 Unit 7 Part B - Assignment Part B – Synopsis of Windows Server 2008 Essay