MobilOne wrote: Thank you for the quick reply there, netadmin. I may be getting this wrong, but perhaps James was saying that it's best if the RRAS server wasnt a part of the domain. Maybe I just listen to him again?
bertieb wrote: MobilOne wrote: Thank you for the quick reply there, netadmin. I may be getting this wrong, but perhaps James was saying that it's best if the RRAS server wasnt a part of the domain. Maybe I just listen to him again? I think in the CBT he was referring to the fact it shouldn't be installed on a domain controller if you're providing remote access services, due to the security risk it would represent (i.e. the RRAS server would most likely be on the edge of the network accepting incoming connections, and if it got hacked they'd potentially have access to your full AD environment) Though he does say in another nugget (when discussing IAS) about having stand alone boxes and using the IAS (Radius) services for centralised authentication, as NetAdmin2436 said Lab it up and it'll make a lot more sense, some of the CBT's confused me at first!