Server 2008 VPN and DC
My company only has one server running Server 2008 Enterprise as a DC. Can i setup VPN on that server? If I can, what would be the disadvantages of doing so?
March 25th, 2011 5:38am
There are lots of problems with that. My advice would be simply don't do it.
If you do not have another server, look at options to run VPN on your Internet router.
Bill
Free Windows Admin Tool Kit Click here and download it now
March 25th, 2011 6:51am
Hi,
We don't suggest that a domain controller with more than one NIC and/or IP address, and/or RRAS installed on it (for VPN, routing, dialup, etc), or with a PPPoE adapter from your ISP's ADSL line, because multihomed DCs will cause numerous issues.
Multihomed DCs with DNS, RRAS, and/or PPPoE adapters
http://msmvps.com/blogs/acefekay/archive/2009/08/17/multihomed-dcs-with-dns-rras-and-or-pppoe-adapters.aspx
Brent
Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread. ”
March 25th, 2011 7:13am
Not to disagree, running a VPN or Terminal services is never a good idea on a DC, for security reasons. You don't want to allow direct remote access to your DC.
However if using a single NIC (Single-homed) the windows VPN will work fine on a DC. If doing so make sure in the DNS management console under interfaces that DNS is not bound to the VPN adapter, that can cause problems.
In this day of IPSec VPN routers being as inexpensive as $150, why not invest in a suitable perimeter device. This offloads the encryption process to a dedicated device, moves the connection to the network perimeter, offers slightly better performance, better
security, and more control.Rob Williams
Free Windows Admin Tool Kit Click here and download it now
March 25th, 2011 9:01pm


