There are a few other important things that are missing from the tutorial and needs to be cleared: 1. Fortunately, you can make FREE certificate to make this work. Open IIS, navigate to your server, and click on "Server Certificates". Head to the right menu bar and select "Create a Self-Signed Certificate". Fill the tasks and your certificate is ready to use. 2. To make this work, you have to open the 443 port on both windows and your router's firewall. 3. You have to add a forward lookup zone with the chosen virtual hostname on your DNS server. The one you specified in the IIS binding. But desptite these, this is a great and very well detailed tutorial, it worked for me.
@AngelSO3TheArcher6 жыл бұрын
This belong in the same network... What about remote networks wanting access to our VPN server? VPN server must have a Public IP or can i setup my VPN with Port Forwarding...? Newbie here
@KukuDjamasi3 жыл бұрын
At location 7:24, you never mentioned how you configured the certificate template. Please can you describe how you did this, thanks
@sheivongamboa2 жыл бұрын
Great vid bro.... rewatch over and over again...
@souheilcharada4 жыл бұрын
@NLB Solutions, can the remote Access server be a Hyper-V virtual machine ? the scenario is to have remote users access an internal server which is part of a internal hyper-v network.
@shahinpashayev6 жыл бұрын
Great video thanks. Have you to create the video on how to create the self-signed certificate and show how to do site-site VPN IPsec configuration. Thanks again.
@jmcgilvary6 жыл бұрын
What a great series. Excellent quality, very well explained. Thanks!!
@saadspl7 жыл бұрын
Hi, Nick i have seen almost every major topic video you created to counter check on our technique and get various thing to keep for us. Thus i found your video very helpful in terms of detail explanation regarding every topic you made for those who are in the filed IT & Acting as Admin somewhere to cope at their end on a quick way. Overall provided info, clear voice and step you created relevant to topic are quite good. Keep providing more tips & tricks. Thanks
@etjonkoti9473 жыл бұрын
Hello,Great Video.I tryed to configure and enable the RRAS but when i type start the service it doesn't start saying that can not find the file specified event id:7024 Any sugestion?
@mrtau62794 жыл бұрын
When you connect from a Win10... is it a remote location on a different internet location (different network)? Cos I'm having difficulties connecting from a remote location but connecting locally is not a problem.
@fhoseinh5 жыл бұрын
Good video. The only thing is that you never set your NPS server when you configured your VPN server in Routing and Remote Access setting section. How your connections to VPN server are being routed to the NPS server if you do not setup Radius Authentication as method under "Security" tab, and leave it as "Windows Authentication." ? Thank you,
@joepessiii62396 жыл бұрын
good video, but will you be able to let us know 1. configuring your router to expose the VPN server from outside ? IP address and port number ? is it IP:443 ? for SSTP ? then 2. does the client need to have a certificate installed? Which cert is that going to be ?
@bradleylucca74003 жыл бұрын
You prolly dont give a shit but does someone know a tool to get back into an Instagram account? I stupidly lost the account password. I love any assistance you can offer me.
@remyhendrix98173 жыл бұрын
@Bradley Lucca Instablaster :)
@bradleylucca74003 жыл бұрын
@Remy Hendrix i really appreciate your reply. I found the site through google and I'm in the hacking process now. Looks like it's gonna take a while so I will reply here later with my results.
@bradleylucca74003 жыл бұрын
@Remy Hendrix it worked and I finally got access to my account again. I am so happy! Thanks so much, you saved my account!
@remyhendrix98173 жыл бұрын
@Bradley Lucca Glad I could help xD
@startxit99666 жыл бұрын
Awesome video. All good but we must remember port forwarding is a must. You said no port forwarding needed and that's miss leading. Port 443 need to be forwarded to the web server. Else you will get errors that might get complicated in troubleshooting from error logs or firewall logs. Also. Come on man your client is not even going thru a NAT he is definitely on the same network or Hosted on a VM side by side. 10.0.0.15 server and 10.0.0.25 client. But in general the video is awesome . Nice detailed explanation , hands up thumbs up
@NLBSolutions6 жыл бұрын
Hi Eduard, thank you for the valuable input. Few valid points were mentioned and they should not be disregarded. Thank you.
@cymatia3 жыл бұрын
Great video thank you. Question: I have high-speed connections both at my home and my office. Yet I can only have 10 mbs connection from home to office VPN. What do you think that I am doing wrong. Thank you.
@elliotmnyaluza69463 жыл бұрын
Thanks for let us now. the setting are going to be the same if I have FortiGate D100 as my firewall?
@Rootwitch066 жыл бұрын
I'm getting the error: "The revocation function was unable to check revocation because the revocation server was offline". If I change the client VPN connection type to Automatic, it connects fine, but it uses the WAN Miniport (IKEv2) (VPN2) security protocol.
@SandeepKumar-p7g6lАй бұрын
Hi Nick, I am waiting for 20742, as you mentioned in your direct access episode. Please 🙏
@chettsalzman91684 жыл бұрын
Great Video. What about a server that is stand-alone, not a DC or AD, what would I need to do differently? Thank You.
@gabrielguirola6246 жыл бұрын
Thanks for the video it is very helpful. Are there any videos that you have created that explains a little bit more on how you did the cert on minute 7:27 please. That is the only thing I am missing and I can not figure it out.
@PBI01-NL4 жыл бұрын
Same, I don't get it too...
@steved70857 жыл бұрын
Nicely articulated and good video presentation, thanks for sharing your knowledge.
@NLBSolutions7 жыл бұрын
Thank you Steve! Much appreciated!
@pcexpress97245 жыл бұрын
i have a problem, we created the certificate but you never installe dit on the client pc. I've tried conecting to the vpn, but it gives ou a certificate error (doensnt even ask for it)
@sale6664 жыл бұрын
Hey I have a PPTP connection works fine PC to PC at home network connects no problem with my user name and password.. Using an android phone I get an error unsuccessful? Do you know why it would kick my phone but not my PC of my server I connect to?
@whyaskme29423 жыл бұрын
I really like your videos. You explain the subject really well. I had a PPTP connection and looks like someone has been trying to hack in. Due to that, I setup a SSTP VPN Connection. I have a 3rd Party SSL Certificate. Do I need to open a port on the router to allow SSTP traffic? I did point Port 443 to my server. Without doing it, how will the packets know to which server it should go? I get an error "No connection could be made because the target machine actively refused it.". I checked the Firewall on the server and it allows traffic. Thank you.
@roberto.dilello5 жыл бұрын
quick question, i have deployed DA&VPN. So now its complete different to this, but from da console i can deploy de corp network client and install this on the workstation machine. the question is i need to add those allowed user to any secgroup? because the secGroup in DA was only for machines (so they are machines on the same domain) but what happen if i got a standalone machine? how can i configur that user to use his home machine on that DA&VPN server? thanks in advance.
@motiondesign2501 Жыл бұрын
Sire we can use user accunt to autenticate without users of Active Directory ?
@guiu9753 жыл бұрын
Hello and thank you for your hard work in research and most important sharing your experience with us, beginners. I have a kindly request. When you right click on your server domain you have there Configure and Enable Routing .... and Disable Routing and Remote.. On my server Standard Edition 2016 are both greyed out. I can't access them to start the configuration. In Services RRAS is running also in server Firewall everything that is remote is Allowed. Is a mistake I installed first Remote Access ? I've searched hard on Google but nothing. Also I can't uninstall Remote Access Management. Many thanks
@nightdragon46116 жыл бұрын
I tried everything you did here, even paid for a personal SSL certificate through comodo and it doesn't work for me. I set up my client on my mobile hotspot so I wan't on the same network as my vpn server and it refuses to connect for some reason.
@NLBSolutions6 жыл бұрын
Hi Christopher, I would suggest for you to double check the settings slowly and you will find the answer.
@CarlTripulca3 жыл бұрын
Thank for the tutorial for sharing i have now knowledge this field
@jawadzia72725 жыл бұрын
Please i need help. I installed active directory and DNS and i integerated with DNS. When i write nslookup command in cmd it returned local host and ::1 dns instead of domain name and its IP. i tried everything with firewall and i went to the properties of dns server and in the interface i only select the ip but still no use. In the event viewer of DNS its giving error that dns cannot open connection with my static ip plz help.
@offensivebias39654 жыл бұрын
Is it really okay for a domain server to become a remote server or should i have dedicated remote server ?
@chhoemdara22344 жыл бұрын
Does it do the same way with digitalocean server2016?
@kitaspidate58355 жыл бұрын
hi thanx for vids. ,im preparing for my mcsa 70-741 would u recommend this 11 vids to my success in exam?is there any further,for 70-740 i followed ur vids n dumps. anything else would help my exam? any websites like 9tut for ccna? pls give guidance
@svensivic6 жыл бұрын
Great video, thanks am trying to do the same thing at home, but I am having difficulties with Certificate enrolment policy. If you can it would be great to have a video on that. Thanks
@yousefhowmy5976 жыл бұрын
Your videos are always informative and enjoyable to watch, i did follow all steps as described however when the client connects he get the following error (The certificate's CN name does not match the passed value).
@sarahhinderjacobboyd44136 жыл бұрын
Another great video. Thank you for sharing your knowledge!
@ninabeer49596 жыл бұрын
Can i create Users without a Domain Controller because we dont have one
@LarsSchretlen4 жыл бұрын
can you please explane how to make the NLB Web Server templates...because other wise the guide stops because we dont have that step... :( so we cant click a long with you..
@vascogama75604 жыл бұрын
Dear Sir, Thanks a lot....May God bless you
@PanSparda6 жыл бұрын
When im trying to connect with VPN I got error Unknown host. How can I fix that? My DNS is working I can see it using ipconfig/all and nslookup
@carlosreis97754 жыл бұрын
Getting message cannot request certificate at this time no certificates types available at the point of request a new certificate
@donaldhuang20106 жыл бұрын
Is this PC of the remote user in behind the firewall of the corporate too? If the user is outside of the firewall what happens when they connect? Shouldn't there be any more settings for connect to the corporate? Thanks.
@NLBSolutions6 жыл бұрын
Hi Donald, using SSTP connection will go through the corporate firewall over port 443, so you need to have that one open. Usually most firewalls have this already enabled.
@nickcalderone755 жыл бұрын
Great video! Very well done and very easy to follow. Thanks.
@darylzero31397 жыл бұрын
Great Video. So once this is setup and a user is connected can they then RDP to their desktop computer?
@NLBSolutions7 жыл бұрын
Thank you Daryl, yes they will be able to. Just remember to allow RDP to their desktop computers and to add them in the Remote Access Users group on them.
@darylzero31397 жыл бұрын
Thank you.
@chrismohawk6 жыл бұрын
We used this method at work and recently its stopped working giving the error the network connection was aborted by the local machine.Trawled the internet but couldn't find an answer. All the certificates are still good
@SuperChelseaSW65 жыл бұрын
How do the win server 2016 connect to the domain controller?
@Ed-xs8xo7 жыл бұрын
Thank you for your thoroughness and thoughtfulness.
@NLBSolutions7 жыл бұрын
Thank you Ed. Much appreciated.
@josefilipe64267 жыл бұрын
Great posting - Thank you I'm having some trouble connecting, so.. Are there any ports that must be opened on the VPN server? My VPN server has 2 nics, one connected to the external firewall and one connected to the internal network. Thanks in advance.
@NLBSolutions7 жыл бұрын
Hi Jose, depending on what VPN you are trying to configure, if you are using this tutorial there should be no need - 443 should be open.
@Grand_Alchemist4 жыл бұрын
will this work with ports other than 443?
@StefanoLardieri4 жыл бұрын
How to set PEAP Authentication witch is more secure ?
@nonsense67916 жыл бұрын
It would be better if VPN server sitting behind your firewall, which means you need to configure a port forward on your firewall for Https connection.
@Rajkorule7 жыл бұрын
Hello, I've tried this out, but will need some help. I have Windows Server 2016 Virtual Machine (VMware Workstation) and my Host OS is Windows 10. The network between Host and Guest OS is set to NAT. The questions I have are: 1. How to setup my router so that external connections are connected to my VM Guest Machine? Do I need to change network connection to Bridged? 2. Because I've got dynamic IP address from my Internet Provider, so I am using ddns on my router. When i Create Self Signed Certificate, Do i need to create it for that address? If no, which one?
@NLBSolutions7 жыл бұрын
Hi Rajkorule, 1. You can achieve this using NAT or Bridged mode. With NAT you will need to configure your physical router to Forward the VPN traffic to the VMware NAT adapter and then configure the Port Forwarding from the VMware workstation to the server (Virtual Network Editor -> NAT Network -> NAT Settings). 2. The certificate will be configured for your specific hostname, so it should not make any issues.
@wyattcooper35144 жыл бұрын
I keep getting "Certificate types are not available" .....What am I missing? I went and checked for the templates and that's missing entirely.....any help is much appreciated.
@wyattcooper35144 жыл бұрын
OK I fixed that. I guess what I would like to see if how to make the certificate you are using here.
@conversiondesign7 жыл бұрын
I am setting up a server with ESXi 6.5. I am running windows server 2016 on a virtual machine which is going to be hosting QuickBooks. I have set up several users in which can remote into their account and open QuickBooks. I also need them to be able to remote in from off the network. I have a FiOS-G1100 router from Frontier. What do you think I should do so that users can access the server from off the network?
@NLBSolutions7 жыл бұрын
Hi, Microsoft VPN solution is a good candidate. You can use any other third party tools if you like or if your firewall/router support VPN.
@Giancarlo_Sforza3 жыл бұрын
I get this error: You cannot request a certificate at this time because no certificate types are available. If you need a certificate please contact your administrator.
@orchik14 жыл бұрын
Thank you very much, perfect video, explained very well. Subscribed!
@vorkpalur7 жыл бұрын
Thank you Nick for such detailed video. Is it the same as Direct Access configuration? Do you have video about PPTP configuration also?
@NLBSolutions7 жыл бұрын
Hi Peeter, thank you for the support. DA is a bit different when it comes to configuring. I already have a video about PPTP but on Windows Server 2012 R2 - kzbin.info/www/bejne/Y3aUeKmaf6iijpI
@RajaG-qy8tg6 жыл бұрын
NLB Solutions
@yuripeters29914 жыл бұрын
does it configure the same way with server 2019
@markanthonym.mendoza53025 жыл бұрын
you cannot request a certificate at this time because no certificate types are available. If you need a certificate, please contact your administrator
@marexas6 жыл бұрын
Hi, if my server is not on AD but on workgroup, is it available to configure SSTP VPN for remote users?
@NLBSolutions6 жыл бұрын
It would be a bit tricky to achieve.
@doostjoon1005 жыл бұрын
How can I add Certificate in Personal? In my server 2012 after selecting Active Directory Enrollment Policy I found any things!
@PBI01-NL4 жыл бұрын
Same problem
@keneemma6 жыл бұрын
Sir some help what if my machine is not a member of a domain of company , can i still join it to vpn ?? help
@Blaze25305 жыл бұрын
Check out a follow up video I posted on my channel on how to get around this.
@ankammachowdariy176 жыл бұрын
Excellent Video.Thank you man for such a Great Video
@NLBSolutions6 жыл бұрын
Thank you for your comment Ankamma!
@mhvdm5 жыл бұрын
Amazing quality videos. Love them. Thanks By the way. Seems like Microsoft doesn't have BGInfo anymore? Can you zip up the one you have or had and link it? Would be highly appreciated! And in Cisco Anyconnect Secure Mobility Client I get Connection Attempt has failed It does find the server, tells me it's insecure and all. But doesn't connect after clicking connect anyways. Is it not supported?
@nesserkhan21966 жыл бұрын
Hi NLB, after following your awesome clip above i get a error which states: The remote computer refused the network connection. can you point to the right direction to fix this please?
@NLBSolutions6 жыл бұрын
Hi Nesser, by the look of the error it makes me think it could be the firewall blocking.
@enrikaci91165 жыл бұрын
Great Video, keep it up. This is exactly what i need, unfortunately i get an error when trying to configure the vpn server saying "the remote access service could not be started" and my system start working very slow. i dont know if my nics are setup properly. the thing is, im not realy sure how they suposed to be set up. would be great if you could share you thoughts about this with me. im using Hyper V for my virtual servers thank you!
@thegamerfour95087 жыл бұрын
Great video. Can't wait to give this a try. Have you had a chance to create the video on how to create the self-signed certificate? Can you include this link?
@NLBSolutions7 жыл бұрын
Hi Gamerfour, thank you for your nice comment. This is definitely a video that will be created in here. Stay tuned!
@lucboisvert72166 жыл бұрын
Great video, thank you. I too would like to know how to create the self-signed certificate. Is this in the works? Thanks again.
@nhtushar6 жыл бұрын
Do I have to port forward my router? Here is my situation: modem>router1>some devices+router2>server(this come from the router 2) I wanna access my server remotely.
@startxit99666 жыл бұрын
Nahid Tushar he is in VM . Yes you need to forward port 443
@keaco736 жыл бұрын
Great video thanks! Would you recommend roaming profiles in order to use the same profile for same user via RDS and local LAN login?
@NLBSolutions6 жыл бұрын
Hi Keith, roaming profiles, ah yes, to be honest I can recall only few successful and proper working implementations on roaming profiles. In general remote desktop roaming profiles can improve the user experience a lot when you have an RDS farm with several terminal servers. Consideration would be if your users have huge local profiles and they try to login to different servers, which can cause a lot of unneeded traffic.
@keaco736 жыл бұрын
NLB Solutions would you say roaming profiles would be the only way to accomplish that?
@avinoamgrosman6 жыл бұрын
Is the vpn server require a public network card? beacuse the client is connecting at first to a public address
@NLBSolutions6 жыл бұрын
Hi there, no you can configure NAT to forward the traffic to the internal IP address of the VPN server.
@picklerick67596 жыл бұрын
Any chance you can show how to configure the Always ON vpn feature with WIndows 10 and Server 2012/2016?
@NLBSolutions6 жыл бұрын
Hi Pickle, will work on bringing this one too. Stay tuned!
@Eimantas.Surgelis5 жыл бұрын
So where is the video about free ceretificate creation?
@ziadjamal65815 жыл бұрын
great video just i need to know alot of tech guys using different methods i try it but never worked with me so i hope urs method gonna work my system
@mcai8rw27 жыл бұрын
Flipping great tutorial video. I followed it with a Windows Server 2008R2 server, and it was almost exactly the same. Thanks! I too am eagerly wanting to see you do a video about SSL certificates and being your own Certificate Authority in a business.
@NLBSolutions7 жыл бұрын
Hi, thank you for the support. Coming your way shortly !
@kenerik4 жыл бұрын
Thanks for letting us know 😉
@kyletrocio81002 жыл бұрын
fr stay on the grind
@sohosterable7 жыл бұрын
Do you know if I will need a Windows Server 2016 VPN license?
@NLBSolutions6 жыл бұрын
Hi Sohosterable, except from the Windows Server 2016 license you will not need any additional ones for VPN.
@neontetravienna6 жыл бұрын
Hi, I have followed your video. The last step you have login to VPN. But how did you create the username and password? Or is that the same user name and password to log in to server?
@NLBSolutions6 жыл бұрын
Hi Neontetra, this is a normal user account from Active Directory. The account you use to login to our client machines.
@hamidtabatabaei22277 жыл бұрын
Thank you Nick. Great!
@NLBSolutions7 жыл бұрын
Thank you again, Hamid!
@Squirrel-Master-Dot-Net6 жыл бұрын
Fantastic Video! Also, the only one I found where the accent isn't too strong to where it's annoying or incomprehensible.
@gibson76544 жыл бұрын
How did you create the free certificate at 7:10?
@etjonkoti9473 жыл бұрын
first you have to add the ADCS role than you can create ss certificates
@robbyzoom54535 жыл бұрын
great video. thank you!
@ethiraj67246 жыл бұрын
Well explained .. Thank you
@silverdiamend7 жыл бұрын
How do you get that information on your right corner??
@NLBSolutions7 жыл бұрын
Hi Aljan, it is called BGinfo - technet.microsoft.com/en-us/sysinternals/bginfo.aspx
@silverdiamend7 жыл бұрын
Thanks, and you make great video''s.
@NLBSolutions7 жыл бұрын
Thank you, Aljan!
@industrialfrench3 жыл бұрын
super tutorial, Большой
@Matthewdoesmc816 жыл бұрын
do u have to do the certificate?
@NLBSolutions6 жыл бұрын
Hi Matt, yes you will have to have one.
@JPV19877 жыл бұрын
Great video !
@NLBSolutions7 жыл бұрын
Thank you, Jean-Pierre!
@espigal6 жыл бұрын
Well, nice video but incomplete. Afther all this, it will faill if we use a "free" certificate.
@dgtal29264 жыл бұрын
Too many restrictions for a public website in IIS. Pass
@DaveBoxBG7 жыл бұрын
How can you do this WITHOUT domain (DC) ?
@NLBSolutions7 жыл бұрын
Hi Jawbreaker, there are third party VPN solutions you can use.
@AbOALeeL5 жыл бұрын
Awesome . Thanks !
@satishkumar0017 жыл бұрын
great video...👍
@NLBSolutions7 жыл бұрын
Thank you, Satish! Much appreciated!
@olaxerp93785 жыл бұрын
Please post mcsa 70-742
@nizambd064 жыл бұрын
Thank You So Much
@boubacrsow6 жыл бұрын
Hello dear, thx for this video, it's really helped me, but i need to know, what should i configurate first ?
@PanSparda5 жыл бұрын
Did you fix that?
@Lobotommy1107 жыл бұрын
24:00 Where do i get my correct address from?
@NLBSolutions7 жыл бұрын
Hi Obummer, you will need to have an Internet domain and you can create the A record in the DNS zone. In my case I used a local DNS server and added this zone to it.
@PanSparda5 жыл бұрын
@@NLBSolutions could u tell us how u added it? Could you explain that?
@XxViralCodexX7 жыл бұрын
i get nothing on 7:37 how can i get that option thanks
@NLBSolutions7 жыл бұрын
Hi Viral, in order to get this you need to have AD Certificate Server on your network.
@rogerrichardson76617 жыл бұрын
Is there a way to set this up without an AD Certificate Server on the network?
@PanSparda6 жыл бұрын
@@NLBSolutions I Installed AD Certificates and still I get nothing on 7:37. Can you help me? What you did before
@mozky33145 жыл бұрын
Nothing worked for me you were vague
@jpr2075 жыл бұрын
Hi there great video. How do you connect to the vpn server outside the network. Also I cannot connect to dc01/rdweb outside my network. But it does work on my server