MCSE Planning and Maintaining a Windows Server 2003 Network Infrastructure: Exam 70-293 Study Guide and DVD Training System

EXAM 70-293 OBJECTIVE 3

Even if your network is small, chances are you have a need for remote access, whether for traveling employees, telecommuters, or remote branches. You can choose from several methods of remote access, including dial-in access, VPN access through the Internet, and wireless networking. Which methods you support and how you configure them will depend on the needs of your organization and its individual users.

Note

Wireless access to a network is not as remote as access by modem or VPN; in fact, most wireless technologies are limited to the area of a building or small group of buildings. But wireless access shares some features with these methods: the access is typically temporary and it can be managed in many of the same ways.

Analyzing Organizational Needs

Different organizations have different needs in a remote access strategy. The following are some of the organizational needs you might need to address:

Analyzing User Needs

You also need to consider the needs of individual users when planning a strategy for remote access. The following are some needs you might have to address:

Selecting Remote Access Types To Allow

When you plan which types of remote access to allow, you should consider how they meet your organization’s needs and the needs of the users, the expense and administrative effort involved in implementing each one, and their relative levels of security. In the next sections, we’ll look in more detail at those aspects of each of the remote access types mentioned earlier: dial-in, VPN, and wireless.

Dial-In

The traditional method of remote access uses a pool of modems and a server running the Routing and Remote Access (RRAS) service. Although there are alternatives, such as VPN access, modems still have some advantages:

Dial-in access typically uses PPP (point-to-point protocol) for communication. This is an Internet-standard protocol for dial-in connections. PPP supports a negotiation process that authenticates and authorizes the user and can also assign an IP address, DNS server addresses, and other critical configuration elements for remote access.

Note

SLIP (Serial Line Internet Protocol) was the original protocol used for dial-in connections. While SLIP has largely been replaced by the more reliable and secure PPP, it is still used with some older equipment, and you can support it if necessary.

VPN

A VPN (virtual private network) uses encryption to create a virtual connection, or tunnel, between a remote node and your network, using a public network such as the Internet. VPN access has a number of advantages over dial-in remote access:

While VPN access is theoretically less secure than a dial-up connection, because data is transmitted over a public network, Windows Server 2003 supports strong levels of encryption to minimize this risk. You can also mandate a level of encryption so that clients that do not support your minimum encryption level cannot connect to the network.

Wireless Remote Access

Wireless network access is rapidly becoming more popular as a facet of remote access strategies. Wireless networks using the 802.11 standard enable a number of wireless users to connect to your network by connecting to a wireless access point, or WAP. While wireless networks typically span a room or building, they can also be scaled upward to cover several buildings, and systems of multiple WAPs have been configured to cover an area as large as a neighborhood or town.

The 802.11 standards do allow for security, but many wireless networks are not configured for maximum security, and allowing wireless access is always a security risk. You should plan for wireless access when your users will be within range of a WAP but without access to a wired connection, and when security is not the highest priority.

Note

A new standard, 802.1x, adds security to 802.11 wireless networks by making use of EAP (Extensible Authentication Protocol) instead of the authentication features of PPP. 802.1x enables you to connect through multiple access points without changing the configuration and is supported by Windows XP and Windows Server 2003.

Категории