{"id":2427,"date":"2018-01-05T20:04:07","date_gmt":"2018-01-05T20:04:07","guid":{"rendered":"http:\/\/microsoftgeek.com\/?p=2427"},"modified":"2018-01-05T20:04:07","modified_gmt":"2018-01-05T20:04:07","slug":"how-to-install-vpn-access-on-windows-server-2016","status":"publish","type":"post","link":"https:\/\/microsoftgeek.com\/?p=2427","title":{"rendered":"How to install VPN access on Windows Server 2016"},"content":{"rendered":"<p>Remote access role is a VPN which protects the network connection or your remote connection from one side to another and protecting both sides from attacks or data sniffing as VPN protocol uses a tunnel inside of a standard data connection.<\/p>\n<p><strong>Note:<\/strong>\u00a0You\u2019ll need to open a TCP port 1723 on your firewall as this port is used for the VPN access.<\/p>\n<p>Also, I\u2019d like to point out that this might not be a guide for enterprise deployment as there you\u2019ll perhaps use a hardware VPN from your router or use a Direct Access feature which however relies on Internet Protocol version six (IPv6) technologies to establish client connections.<\/p>\n<h2><span lang=\"EN-US\">How to install VPN on Windows Server 2016 \u2013 The steps:<\/span><\/h2>\n<p>Install a Remote access role via the\u00a0<strong>Add Roles and Features Wizard<\/strong>. Open\u00a0<strong>Server Manager<\/strong>\u00a0either locally on the server that will host the remote access role or on a computer that has Server Manager configured to connect to the server you\u2019re deploying the role.<\/p>\n<p>Then select\u00a0<strong>Add Roles and Features Wizard<\/strong>\u00a0from the\u00a0<strong>Manage Menu<\/strong>. Click next on the before you begin page if it is displayed. Then select Role-Based or Feature-Based installation and click next.<\/p>\n<p>On the Select Server Role page, scroll down and then select check box\u00a0<strong>Remote Access<\/strong>. And then click next.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-5600 aligncenter\" src=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Remote-Access-Role.png\" sizes=\"auto, (max-width: 781px) 100vw, 781px\" srcset=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Remote-Access-Role.png 781w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Remote-Access-Role-300x214.png 300w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Remote-Access-Role-768x547.png 768w\" alt=\"Remote Access Role\" width=\"781\" height=\"556\" \/><\/p>\n<p>You\u2019ll need to click two more times to get to the Remote access Role Services, where you\u2019ll have to select\u00a0<strong>Direct Access and VPN<\/strong>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-5601 aligncenter\" src=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/DirectAccess-and-VPN.png\" sizes=\"auto, (max-width: 783px) 100vw, 783px\" srcset=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/DirectAccess-and-VPN.png 783w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/DirectAccess-and-VPN-300x213.png 300w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/DirectAccess-and-VPN-768x545.png 768w\" alt=\"DirectAccess and VPN\" width=\"783\" height=\"556\" \/><\/p>\n<p>Accept the installation of sub-components, such as IIS\u2026 Accept all the defaults.<\/p>\n<p>It will take some time to finish the installation of all components and sub-components.<\/p>\n<p>Then click on the link Open the Getting Started Wizard to open the configuration wizard.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-5602 aligncenter\" src=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Open-the-getting-started-wizard.png\" sizes=\"auto, (max-width: 815px) 100vw, 815px\" srcset=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Open-the-getting-started-wizard.png 815w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Open-the-getting-started-wizard-300x135.png 300w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Open-the-getting-started-wizard-768x345.png 768w\" alt=\"Open the getting started wizard\" width=\"815\" height=\"366\" \/><\/p>\n<p>A new window will appear. You\u2019ll need to click Deploy VPN only which will configure VPN by using the Routing and Remote Access console.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-5603 aligncenter\" src=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Deploy-VPN-Wizard.png\" sizes=\"auto, (max-width: 647px) 100vw, 647px\" srcset=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Deploy-VPN-Wizard.png 647w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Deploy-VPN-Wizard-300x234.png 300w\" alt=\"Deploy VPN Wizard\" width=\"647\" height=\"504\" \/><\/p>\n<p>After you click on that part, you\u2019ll open the Routing and Remote Access console. Right click on the Server name and click on\u00a0<strong>Configure and Enable Routing and Remote Access<\/strong>.<\/p>\n<p>Note: You can also launch this console via\u00a0<strong>Control Panel &gt; System and Security &gt; Administrative tools<\/strong>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-5604 aligncenter\" src=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Configure-and-enable-Remote-Access.png\" sizes=\"auto, (max-width: 617px) 100vw, 617px\" srcset=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Configure-and-enable-Remote-Access.png 617w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Configure-and-enable-Remote-Access-300x213.png 300w\" alt=\"Configure and enable Remote Access\" width=\"617\" height=\"439\" \/><\/p>\n<p>Click Next and Select\u00a0<strong>Custom Configuration<\/strong>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-5605 aligncenter\" src=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Select-Custom-Configuration.png\" sizes=\"auto, (max-width: 497px) 100vw, 497px\" srcset=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Select-Custom-Configuration.png 497w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Select-Custom-Configuration-300x254.png 300w\" alt=\"Select Custom Configuration\" width=\"497\" height=\"421\" \/><\/p>\n<p>So far, it\u2019s been very simple. Let\u2019s go and finish the configuration. All we need to do on the next screen is to tick the checkbox\u00a0<strong>VPN access<\/strong>\u00a0as we only want this feature to be active.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-5606 aligncenter\" src=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Select-the-service-VPN-Access.png\" sizes=\"auto, (max-width: 496px) 100vw, 496px\" srcset=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Select-the-service-VPN-Access.png 496w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Select-the-service-VPN-Access-300x251.png 300w\" alt=\"Select the service - VPN Access\" width=\"496\" height=\"415\" \/><\/p>\n<p>You\u2019ll then have only one page which displays the summary of your selections. Confirm by clicking the Finish button.\u00a0 After few seconds, you\u2019ll see a pop-up window asking you to start the Routing and Remote Access service. Click on\u00a0<strong>Start Service<\/strong>\u00a0button.<\/p>\n<h2>Next Step \u2013 Allow some users to connect to your newly configured VPN server<\/h2>\n<p>Usually this kind of small environment can be used for system administrators requiring access to remotely installed server, or for a small group of users within an organization. Depending on the architecture, the server can be part of a Microsoft Domain and have a central management of users through an\u00a0Active Directory\u00a0(AD) or it can be a standalone server which is just outside of any domain.<\/p>\n<p>For the sake of simplicity, we consider this case, but in both cases, you\u2019ll need to configure at least one user to access through the VPN and we\u2019ll show you how.<\/p>\n<p>So if you\u2019re in \u201cWorkgroup\u201d environment you can use a Computer Management Console (MMC), and if you\u2019re in a domain environment this can be done in the user properties of an Active Directory user.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-5607 aligncenter\" src=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Allow-access-to-the-users.png\" sizes=\"auto, (max-width: 696px) 100vw, 696px\" srcset=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Allow-access-to-the-users.png 696w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Allow-access-to-the-users-300x263.png 300w\" alt=\"Allow access to the users\" width=\"696\" height=\"611\" \/><\/p>\n<p>Usually, there is a DHCP server within a company environment. If that\u2019s not the case, you\u2019ll have to add a static address pool.<\/p>\n<p>You can find the settings in the properties of your VPN server, where you can click on the IPv4 tab and enable and configure the\u00a0<strong>Static address pool<\/strong>. Make sure to use the same subnet as your static address of your server.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-5608 aligncenter\" src=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Add-a-static-address-pool-if-you-dont-have-DHCP.png\" sizes=\"auto, (max-width: 895px) 100vw, 895px\" srcset=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Add-a-static-address-pool-if-you-dont-have-DHCP.png 895w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Add-a-static-address-pool-if-you-dont-have-DHCP-300x162.png 300w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Add-a-static-address-pool-if-you-dont-have-DHCP-768x414.png 768w\" alt=\"Add a static address pool if you don't have DHCP\" width=\"895\" height=\"483\" \/><\/p>\n<p>Well, this is about.<\/p>\n<p>From the client\u2019s perspective. The client has to configure a VPN connection from the client\u2019s end. So, depending on the\u00a0Operating system\u00a0the client is using, the setup might differ.<\/p>\n<p>But basically, you\u2019ll should set up new VPN connection.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-5609 aligncenter\" src=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Configure-VPN-on-the-client-side-1024x359.png\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" srcset=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Configure-VPN-on-the-client-side-1024x359.png 1024w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Configure-VPN-on-the-client-side-300x105.png 300w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Configure-VPN-on-the-client-side-768x269.png 768w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Configure-VPN-on-the-client-side.png 1234w\" alt=\"Configure VPN on the client side\" width=\"1024\" height=\"359\" \/><\/p>\n<p>And then<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-5610 aligncenter\" src=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Setup-VPN-connection-client-side-1024x359.png\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" srcset=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Setup-VPN-connection-client-side-1024x359.png 1024w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Setup-VPN-connection-client-side-300x105.png 300w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Setup-VPN-connection-client-side-768x269.png 768w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Setup-VPN-connection-client-side.png 1234w\" alt=\"Setup VPN connection - client side\" width=\"1024\" height=\"359\" \/><\/p>\n<p>This will create a new connection within the\u00a0network\u00a0connection window there.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-5611 aligncenter\" src=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/New-VPN-connection.png\" sizes=\"auto, (max-width: 911px) 100vw, 911px\" srcset=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/New-VPN-connection.png 911w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/New-VPN-connection-300x157.png 300w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/New-VPN-connection-768x403.png 768w\" alt=\"New VPN connection\" width=\"911\" height=\"478\" \/><\/p>\n<p>To finally get this screen after connecting and entering your password.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-5612 aligncenter\" src=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Connection-details.png\" sizes=\"auto, (max-width: 917px) 100vw, 917px\" srcset=\"https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Connection-details.png 917w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Connection-details-300x198.png 300w, https:\/\/www.starwindsoftware.com\/blog\/wp-content\/uploads\/2017\/05\/Connection-details-768x506.png 768w\" alt=\"Connection details\" width=\"917\" height=\"604\" \/><\/p>\n<h2>Wrap up:<\/h2>\n<p>This is the simplest way of doing it. It involves, however, opening the TCP 1723 port on the firewall. Note that another solution of remote access exists, but they usually involve installation of third party tools on the\u00a0server side, and also on the client side.<\/p>\n<p>You may want to avoid installing those tools on company servers and stick to traditional Built-in VPN from\u00a0Microsoft, for remote administration.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Remote access role is a VPN which protects the network connection or your remote connection from one side to another and protecting both sides from attacks or data sniffing as VPN protocol uses a tunnel inside of a standard data connection. Note:\u00a0You\u2019ll need to open a TCP port 1723 on your firewall as this port [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16,63],"tags":[],"class_list":["post-2427","post","type-post","status-publish","format-standard","hentry","category-vpn","category-server-2016-2016"],"_links":{"self":[{"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/posts\/2427","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2427"}],"version-history":[{"count":1,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/posts\/2427\/revisions"}],"predecessor-version":[{"id":2428,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/posts\/2427\/revisions\/2428"}],"wp:attachment":[{"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2427"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2427"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2427"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}