• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 345
  • Last Modified:

How to switch from VPN MS-CHAP v2 authentification to PEAP ?

Hi everybody,

I have a server 2008 R2 where the Network Policy and Access Services is installed.

Actually, the VPN type is PPTP using MS-CHAP v2 authentification and since MS-CHAP v2 has been broken, it's recommended to use PEAP so I'm trying to do so...

I read a bunch of pages about this but no one is clear about the steps I should follow from here so I'm looking for a step by step description of what I must exactly do to configure my VPN to use PEAP instead of actually MS-CHAP v2.

I assume that I will have to change the authentification protocol type on the client side and on my network policy on the server as well but it seems that there are certificates involved in this process but I can't find much about this part... I think I will have to install the active directory certificate services or something like that but I will not go further without any accurate information...

Thanks for your help !

Anthony
0
Anthony_86
Asked:
Anthony_86
  • 3
  • 2
1 Solution
 
Rob WilliamsCommented:
If at all concerned about security it is recommended you install a VPN capable router.  Configuring Microsoft servers to use more secure methods including certificates can be involved and time consuming.  VPN routers these days are very affordable, starting at $150.  They increase security by moving the authentication to the perimeter of the network, use proper IPsec, and improve performance slightly by offloading the encryption/decryption to a dedicated device.

If you want to use a Microsoft option, Server 2008 and newer are ideally suited to an SSTP VPN
http://technet.microsoft.com/en-us/library/cc731352(v=ws.10).aspx
https://www.youtube.com/watch?v=QKSNDITI3pE
0
 
Anthony_86Author Commented:
Hi Rob,

Thanks for your answer... Indeed all roads lead to Rome :)

For the moment I would just like to implement the PEAP authentification to my existing VPN so I will see if someone else has the knowledge of those steps and can describe me those...

Otherwise, I may consider to follow one of your suggestion and at that moment I will accept your comment as solution :)

Have a nice day !

Anthony
0
 
Rob WilliamsCommented:
No problem. I am afraid I am not much help with it, I have not done so since Server 2000. Thanks for the feedback.  I will continue to follow to see hoe you make out.

Cheers!
--Rob
0
 
Anthony_86Author Commented:
Hi Rob,

Just for info, I finally buyed a VPN router, I was for me the most simple way to solve this...

Thanks ;)
0
 
Rob WilliamsCommented:
Glad to hear.  Thanks Anthony.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

  • 3
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now