Help and Support
 

powered byLive Search

How to deploy a Secure Socket Tunneling Protocol (SSTP)-based VPN server that uses Network Load Balancing (NLB) in Windows Server 2008

Article ID:947029
Last Review:February 8, 2008
Revision:1.3
Beta Information
This article discusses a beta release of a Microsoft product. The information in this article is provided as-is and is subject to change without notice.

No formal product support is available from Microsoft for this beta product. For information about how to obtain support for a beta release, see the documentation that is included with the beta product files, or check the Web location where you downloaded the release.

INTRODUCTION

This article describes how to deploy a Secure Socket Tunneling Protocol (SSTP)-based virtual private network (VPN) server that uses Network Load Balancing (NLB) in Windows Server 2008.

SSTP is a new kind of VPN tunnel that is available in the Routing and Remote Access Server role in Windows Server 2008. SSTP allows for Point-to-Point Protocol (PPP) packets to be encapsulated over HTTP. This functionality allows for a VPN connection to be more easily established through a firewall or through a network address translation (NAT) device. Also, this behavior allows for a VPN connection to be established through an HTTP proxy device.

Large organizations frequently have multiple VPN servers that perform load balancing of the VPN connections. In the scenario in the "More Information" section, the VPN server, such as a computer that is running Routing and Remote Access, will be enabled for NLB. This article describes how to deploy SSTP-based VPN servers that use NLB.

Back to the top

MORE INFORMATION

Consider the following scenario. Two servers that are running Routing and Remote Access are located in a perimeter network (also known as DMZ, demilitarized zone, and screened subnet). Both servers are enabled for NLB. Additionally, both servers have the same virtual IP addresses, 1.2.3.4. Finally, the public IP address has a DNS name of server.contoso.com. In this scenario, use the following guidelines to deploy SSTP-based VPN servers that use NLB in Windows Server 2008:
Enable NLB on each server that is running Routing and Remote Access.
Install the same computer certificate on each server that is running Routing and Remote Access. This certificate should have the same subject name (CN) as the host name through which the VPN clients connect. The same certificate is used so that the SSL negotiation is successful. If the client will be connecting to the public IP address of the NAT router, the subject name is the virtual IP address of each server that is running Routing and Remote Access, such as 1.2.3.4. If the client will be connecting by using the host name, the subject name is the DNS name of the public IP address, such as server.contoso.com.
Install the server that is running Routing and Remote Access by using Server Manager on all servers that are running Routing and Remote Access.
Configure the server that is running Routing and Remote Access by using the Routing and Remote Access configuration wizard.

Back to the top

REFERENCES

For more information, click the following article number to view the article in the Microsoft Knowledge Base:
947031 (http://support.microsoft.com/kb/947031/) How to troubleshoot Secure Socket Tunneling Protocol (SSTP)-based connection failures in Windows Server 2008

Back to the top


APPLIES TO
Windows Server 2008 Datacenter
Windows Server 2008 Enterprise
Windows Server 2008 for Itanium-Based Systems
Windows Server 2008 Standard
Windows Web Server 2008

Back to the top

Keywords: 
kbexpertiseinter kbhowto kbinfo KB947029

Back to the top

Article Translations

 

Related Support Centers

Other Support Options

  • Need More Help?
    Contact a Support professional by Email, Online or Phone.
  • Customer Service
    For non-technical assistance with product purchases, subscriptions, online services, events, training courses, corporate sales, piracy issues, and more.
  • Newsgroups
    Pose a question to other users. Discussion groups and Forums about specific Microsoft products, technologies, and services.