|
Lesson 3
Securing Remote Access
5-33
❑
Encryption—Enables you to specify the types of encryption that clients can
use when connecting to the server.
❑
Advanced—Enables you to set values for special attributes that RADIUS serv-
ers use when communicating with the Routing and Remote Access server.
Creating Remote Access Policies
To create a remote access policy, you open the Routing And Remote Access
console,
expand the icon for your Routing and Remote Access server, and click the
Remote
Access Policies subheading (see Figure 5-9). In the details pane is a list
of the policies
that already exist on the server. You can modify these policies or add new
ones.
f05pm09
Figure 5-9
The Remote Access Policies node in the Routing And Remote Access console
Important
Before RRAS can use remote access policies to regulate access to the server
by group membership, you must configure the user’s account by selecting the
Control Access
Through Remote Access Policy option button in the Dial-in tab in the user’s
Properties dialog
box in the Active Directory Users And Computers console.
When you select New Remote Access Policy from the console’s Action menu, the
New
Remote Access Policy Wizard launches and walks you through the steps of
creating the
new policy by specifying values for the conditions described earlier. After
you finish using
the wizard, the console adds the new policy to the bottom of the list in the
details pane.
Tip
Administrators can configure remote access policies to either grant or deny
user
access based on the specified conditions. In some cases, it is easier to
deny access based
on a smaller set of conditions than it is to grant them based on a larger
set. For example, if
nine groups should receive permission to access the network remotely, and
one group should
be denied permission, it is easier to grant all users permission by default
and explicitly deny
permission to that one group rather than grant permission to nine different
groups.
|