What's New

Deploying SSTP VPNs with Windows Server 2012

Secure Socket Tunneling Protocol (SSTP) gives you the ability to connect to your job's network from any location that has an active internet connections, and is not filtering https. This port is usually open for normal secure web site traffic. Step 1 - Make sure you have two NICs on your machine with static IP address. vlcsnap-2013-05-24-22h47m33s212

Step 2 – I have my domain controller installed on the same machine which we will install SSTP/VPN but it’s not recommended to have it in your domain controller.

vlcsnap-2013-05-24-23h18m47s1

Step 3 – Open you “Server Manger” and Click on > Manage > Add Roles and Features

vlcsnap-2013-05-24-23h18m58s117

Step 4 – The wizard will start and you will Click > Next > Next > Next

vlcsnap-2013-05-24-23h19m01s144

Step 5 – Choose “Active Directory Certificate Services” and Add the features when prompted

vlcsnap-2013-05-24-23h19m24s122

Step 6 – Click Next > Next > Choose “Certification Authority Web Enrollment” > When prompted add features

vlcsnap-2013-05-24-23h19m50s125

Step 7 – Click Next > Click Install

vlcsnap-2013-05-24-23h19m52s141

Step 8 – Click on the “Configure Active Directory Certificate Services on the destination server

vlcsnap-2013-05-24-23h20m08s43

Step 9 – You will get the “AD CS Configuration” wizard. Click Next.

vlcsnap-2013-05-24-23h20m22s182

Step 10 – Make sure to check off “Certification Authority Web Enrollment” then click on Next.

vlcsnap-2013-05-24-23h20m36s72

Step 11 – Click on Next > Next > Next > Next > Next > Next

vlcsnap-2013-05-24-23h20m38s89

Step 12 – Click on “Configure”

vlcsnap-2013-05-24-23h21m22s14

Step 13 – Once the configuration is completed open up a run command and type in “mmc

vlcsnap-2013-05-24-23h21m41s204

Step 14 – Click on File > Add/Remote Snap-in….

vlcsnap-2013-05-24-23h21m47s16

Step 15 – Add “Certification Authority

vlcsnap-2013-05-24-23h21m51s49

Step 16 – You are adding the “Local Computer

vlcsnap-2013-05-24-23h21m54s86

Step 17 – Go to the MMC and navigate to the “Certificate Templates” node and right-click to “Manage

vlcsnap-2013-05-24-23h22m06s207

Step 18 – Locate “IPSec” > right-click and “duplicate template

vlcsnap-2013-05-24-23h22m17s57

Step 19 – This will open up when you duplicate the IPSec template

vlcsnap-2013-05-24-23h22m23s115

Step 20 – Go to General Tab > Give it a name

vlcsnap-2013-05-24-23h22m26s148

Step 21 – Go to Request Handling tab > check off “Allow private key to be exported

vlcsnap-2013-05-24-23h22m40s34

Step 22 – Got to the Extension tab > Click on “Application Polices” > Click on Edit

vlcsnap-2013-05-24-23h23m10s70

Step 23 – Click on Add

vlcsnap-2013-05-24-23h23m13s105

Step 24 – Locate “Server Authentication” > click on OK

vlcsnap-2013-05-24-23h23m20s173

Step 25 – That’s it for the part 🙂

vlcsnap-2013-05-24-23h23m35s73

<hr>

Step 1:  Open “Active Directory Users and Computers” > double-click on a user and go into the “Dial-in” tab and check off “Allow access”

vlcsnap-2013-05-25-12h45m16s14

Step 2: Open Server Manager > Manager > Add Roles and Features > Click on Next > Next > Next > Check “Network Policy and Access Services” – when prompted add all features

vlcsnap-2013-05-25-12h45m46s62

Step 3: Click Next > Next > Next > Next > Install > Close

vlcsnap-2013-05-25-12h46m12s62

Step 4: Open Server Manager > Add Roles and Features > Next > Next > Next > Next > Check off “Remote Access” – when prompted add all features

vlcsnap-2013-05-25-12h46m49s178

Step 5: Click Next > Next > Check off “Routing” > Next > Install

vlcsnap-2013-05-25-12h47m02s48

Step 6: When completed DO NOTOpen the Getting Started Wizard” for the Remote Service role > click on Close

vlcsnap-2013-05-25-12h47m15s177

Step 7: Open up the run command and type in “mmc”

vlcsnap-2013-05-25-12h47m44s211

Step 8: File > Add or Remove Snap-ins > “Certificates” > “Computer Account” > “Local Computer” > OK

vlcsnap-2013-05-25-12h48m05s166

Step 9: Expand Certificates > Personal > Certificates > Right-click > All-Tasks > “Request New Certificates

vlcsnap-2013-05-25-12h48m18s45

Step 10: Click on Next > Next > locate the certificates > Click on “More information is required to enroll for this certificate…

vlcsnap-2013-05-25-12h48m34s205

Step 11: Subject Name – Type “Common name” > add your value “vpn.bjn.com” > click on Add > Apply > OK

vlcsnap-2013-05-25-12h49m19s143

Step 12: Select your Certificate > Enroll

vlcsnap-2013-05-25-12h49m25s200

Step 13: Click on Finish

vlcsnap-2013-05-25-12h49m36s54

Step 14: Open the run command and type in rrasmgmt.msc

vlcsnap-2013-05-25-12h50m00s35

Step 15: Right-click on the server node “Configure and Enable Routing and Remote Access

vlcsnap-2013-05-25-12h50m18s220

Step 16: Click on Next > Next > Check off “VPN

vlcsnap-2013-05-25-12h50m46s243

Step 17: Highlight the first Ethernet > Disable “Enable security on the selected interface by…”

vlcsnap-2013-05-25-12h50m56s88

Step 18: Click on “From a specified range of addresses” > Next

vlcsnap-2013-05-25-12h51m08s207

Step 19: Click on New > Specify your range > OK > Next

vlcsnap-2013-05-25-12h51m35s220

Step 20: Click on Next > Finish > OK > OK

vlcsnap-2013-05-25-12h52m12s74

Step 21: Go back to your RRAS console > Right-click on server node > Properties

vlcsnap-2013-05-25-12h52m30s253

Step 22: Click on the “Security” tab > at the bottom change the “Certificate” type

vlcsnap-2013-05-25-12h52m33s26

Step 23: Click on the drop down and pick your “Certificate” > Apply > OK

vlcsnap-2013-05-25-12h52m38s77

About BjTechNews (1065 Articles)
An IT guy trying to learn everything about technology and sharing it with you all. I'm a blogger and video blogger who highlights daily news in the tech industry, promoting tips and hacks for fellow techies.

4 Comments on Deploying SSTP VPNs with Windows Server 2012

  1. Did you change the VPN type in the client? I’ve been trying to set this up for several days without any success and was so pleased when I managed to connect through … until I ran netstat on my client and it showed that I was connected via PPTP. I changed the security on the client to SSTP VPN rather than leave it at automatic and it failed yet again with “The certificate’s CN name does not match the passed value”!
    I’ll try with a new VM tomorrow as I know I’m so close to getting this working!

  2. Awesome work, thanks for sharing!

  3. Hey just wanted to give you a brief heads up and let
    you know a few of the images aren’t loading properly. I’m not sure why but I think its a linking issue.
    I’ve tried it in two different internet browsers and both show the same results.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from BTNHD

Subscribe now to keep reading and get access to the full archive.

Continue reading