Windows 2008 sstp vpn配置

Windows 2008 sstp vpn配置

服务端:


首先,在windows 2008服务器上添加网络策略和访问服务的角色
Windows-Live-Writer_da5fe0a23645_14A23_image_2.png)

Windows-Live-Writer_da5fe0a23645_14A23_image_4.png

Windows-Live-Writer_da5fe0a23645_14A23_image_6.png

Windows-Live-Writer_da5fe0a23645_14A23_image_8.png

Windows-Live-Writer_da5fe0a23645_14A23_image_10.png

Windows-Live-Writer_da5fe0a23645_14A23_image_12.png

Windows-Live-Writer_da5fe0a23645_14A23_image_14.png

Windows-Live-Writer_da5fe0a23645_14A23_image_16.png

Windows-Live-Writer_da5fe0a23645_14A23_image_18.png

Windows-Live-Writer_da5fe0a23645_14A23_image_20.png

Windows-Live-Writer_da5fe0a23645_14A23_image_22.png

 

安装成功后,在服务器管理中展开角色,按照下图配置并启用路由和远程访问

Windows-Live-Writer_da5fe0a23645_14A23_image_24.png

Windows 2008 sstp vpn配置

Windows 2008 sstp vpn配置

启用成功后

先设置ipv4地址池
Windows 2008 sstp vpn配置

Windows 2008 sstp vpn配置

Windows 2008 sstp vpn配置

然后需要将服务端证书copy到客户端

按照如下步骤将服务端证书导出

Windows 2008 sstp vpn配置

Windows 2008 sstp vpn配置

 

Windows-Live-Writer_da5fe0a23645_14A23_image_30.png

Windows-Live-Writer_da5fe0a23645_14A23_image_32.png

Windows-Live-Writer_da5fe0a23645_14A23_image_36.png

Windows-Live-Writer_da5fe0a23645_14A23_image_38.png

Windows-Live-Writer_da5fe0a23645_14A23_image_40.png

导出后,桌面上就会有sstpvpn.p7b的证书,将证书复制到客户端

然后创建名为sstpvpn的账户

Windows-Live-Writer_da5fe0a23645_14A23_image_42.png

 

开启其网络访问权限

Windows-Live-Writer_da5fe0a23645_14A23_image_44.png

服务端设置完毕

客户端(windows7及其以后的windows系统):

先导入证书sstpvpn.p7b

Windows-Live-Writer_da5fe0a23645_14A23_image_46.png

Windows-Live-Writer_da5fe0a23645_14A23_image_48.png

Windows-Live-Writer_da5fe0a23645_14A23_image_52.png

Windows-Live-Writer_da5fe0a23645_14A23_image_54.png

Windows-Live-Writer_da5fe0a23645_14A23_image_56.png

Windows-Live-Writer_da5fe0a23645_14A23_image_58.png

然后在C:\WINDOWS\SYSTEM32\Driver\etc\hosts中配置如下信息

182.254.231.191(服务器外网IP) 10_249_164_110(证书CN名)

设置客户端vpn连接

Windows-Live-Writer_da5fe0a23645_14A23_image_60.png

 

Windows-Live-Writer_da5fe0a23645_14A23_image_62.png

 

在连接属性中进行如下设置

 

现在就可以通过刚刚创建的vpn连接来远程连接服务器了,用户名密码就是刚刚创建的sstpvpn账户

以上设置连接后,客户端与服务器之间只是建立了隧道,但是客户端无法通过服务器上网,需要在服务器开启NAT

Windows 2008 sstp vpn配置
Windows 2008 sstp vpn配置

Windows 2008 sstp vpn配置

Windows-Live-Writer_da5fe0a23645_14A23_image_26.png

Windows-Live-Writer_da5fe0a23645_14A23_image_50.png

这样,客户端连接后即可通过服务器代理上网

Comments

No comments yet. Why don’t you start the discussion?

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注