Chapter 4 Flashcards
What is maintained by a NAT device to record which internal client traffic must be routed outside?
A mapping table
What must be installed to provide Windows Server with NAT server capability?
The Remote Access server role
How do you set up NAT on Windows Server?
Server Manager > Tools > Routing and Remote Access > Right-click server > Configure and Enable Routing and Remote Access > from the Route and Remote Access Server Setup Wizard, choose NAT > select the public and private interfaces
What is a recommended step that makes NAT configuration easier?
Name your network connections so they are easily identifiable, by right-clicking Start and selecting Network Connections
Where can you configure NAT settings?
The Routing and Remote Access console
How can you configure NAT to allow certain private clients to use public addresses?
Reserve public addresses
What two additional network services can be enabled from within NAT?
DHCP and DNS resolution
Where can you monitor NAT’s DHCP service?
In the Routing and Remote Access console, right-click the NAT node, and select Show DHCP Allocator Information
Where can you monitor NAT’s DNS service?
In the Routing and Remote Access console, right-click the NAT node, and select Show DNS Proxy Information
What are two remote access scenarios where VPN is used?
Remote access by allowing remote users to connect to a site
Site-to-site (S2S) allowing for connections between remote sites
What are three common characteristics of VPNs?
Authentication between client and server, encryption of data, and encapsulation through tunneling
What are the four VPN protocols available in Windows Server?
Point-to-Point Tunneling Protocol (PPTP)
Layer 2 Tunneling Protocol with Internet Protocol Security (L2TP/IPsec)
Secure Socket Tunneling Protocol (SSTP)
Internet Key Exchange Version 2 (IKEv2)
Which VPN protocol is widely supported, but is considered to be less secure than its alternatives?
PPTP
What authentication methods are available for PPTP?
Microsoft Challenge Handshake Authentication Protocol version 2 (MS-CHAPv2)
Extensible Authentication Protocol-Transport Layer Security (EAP-TLS)
What protocols does L2TP use?
It combines PPTP and Layer 2 Forwarding L2F, but unlike PPTP, uses IPsec for encryption
Which protocol is based on HTTPS, and what is its key advantage?
SSTP, uses port 443 which is usually open in most firewalls
Which protocol is particularly useful for mobile devices and why?
IKEv2, the only protocol that supports VPN reconnect
What port is used by PPTP?
TCP 1723
What ports are used by L2TP?
UDP 500, 1701, and 4500
What port is used by SSTP?
TCP 443, also used by HTTPS
What port is used by IKEv2?
UDP 500
What VPN authentication methods are supported by Windows Server 2016?
PAP, CHAP, MS-CHAPv2, and EAP
Which VPN authentication protocol uses insecure plaintext authentication?
PAP
Which VPN authentication protocol uses challenge/response and stores passwords with reversible encryption?
CHAP
Which VPN authentication protocol uses challenge/response, but has better security than some others?
MS-CHAPv2
Which VPN authentication protocol is the most secure and supports multiple authentication methods?
EAP
What role service is required to deploy the RAS Gateway in Windows Server?
DirectAccess and VPN (RAS) role service
What scenarios are supported by RAS Gateway?
Multitenant-aware VPN gateway Multitenant-aware NAT gateway Forwarding gateway DirectAccess server GRE tunneling Dynamic routing with BGP
What type of RAS Gateway deployment allows for virtual machines on virtual networks to access the Internet?
Multitenant-aware NAT gateway