Platinum Edition Using Windows NT Server 4

Previous chapterNext chapterContents


Chapter 15

Using Remote Access Service (RAS)

Some of the main topics in this chapter are

Remote Access Service (RAS) is a secure method of accessing your host network from anywhere by using a variety of methods, most commonly ISDN and analog modems. RAS has several options that can be used to protect against hackers.

Windows NT's inclusion of RAS puts it in a class by itself. With most other network operating systems, and even minis and mainframes, remote access to the network or computer can be a tricky or expensive proposition. With an AS/400, it requires an ASCII terminal controller, a piece that few AS/400 systems have, or a gateway of some sort. For Novell, it's a product named NetWare Connect. Other operating systems have different methods of enabling access from a remote location.

Installing RAS

RAS service is installed via the network applet in Control Panel. The following steps describe how to install RAS on a server or on a Windows NT Workstation.


NOTE: When RAS is installed, it always shows up as Remote Access Service in the Networking applet but shows up as Dial-Up Networking in the Start menu and when trying to dial out.
1. Open the Network Properties dialog box.

2. Click the Services tab to display the dialog box in Figure 15.1.

3. Click the Add button to display the Select Network Service dialog box, as shown in Figure 15.2.

4. Select Remote Access Service from the list of services, and click OK.

5. Enter the path to find the Windows NT Server files.

Fig. 15.1

The Services tab shows all the installed services.

Fig. 15.2

Select Remote Access Service.

6. If no modems are defined, you must answer Yes to the Remote Access Setup dialog box, as shown in Figure 15.3, to add modems.

Fig. 15.3

You must configure a modem to install RAS.

7. The Install New Modem Wizard appears (see Figure 15.4). Click Next to enable Windows NT to automatically detect a modem.

8. If you have more than one port, select the port that you want Windows NT to scan.
Windows NT checks the selected COM port, looking for the modem. If Windows NT finds your modem, it displays the Install New Modem Wizard.

9. Click Next to select the ports on which to install the modem; when finished, click Next.

Fig. 15.4

Windows NT will try to detect your modem for you.

10. If the dialog box notifies you that your modem has set up successfully, click Finish to complete the modem installation.

If Windows NT does not detect your modem, you're notified that you need to select your modem from a list. If you don't find your modem on the list, you must configure your modem by using the disk provided by the manufacturer. Follow these steps to properly add the modem:

1. Click Next in the Install New Modem Wizard dialog box.

2. Select the manufacturer and model of the modem that you have, and click Next.

3. Select which ports to install the modem on, or select all ports, and click Next.

4. Click Finish to return to the Add RAS Device dialog box (see Figure 15.5).

Fig. 15.5

After a modem has been created, it still must be added to RAS.

5. Select the modem that you just installed from the RAS Compatible Devices list, and click OK to return to the Remote Access Setup dialog box (see Figure 15.6).

Fig. 15.6

Remote Access Setup shows a list of all modems that have been defined for RAS.

6. Select the port, and click Configure to display the Configure Port Usage dialog box (see Figure 15.7).

Fig. 15.7

Configuring the port ensures that it can be used for dial out as well as dial in.

7. Select the proper dial-in/dial-out options. In most cases, you want to set this to Dial Out and Receive Calls, which enables the modem to be used for inbound calls and outbound calls. By default, Windows NT Server defines modems to Receive Calls Only. Windows NT Workstation defines modems for Dial Out Only by default. Click OK to return to the Remote Access Setup dialog box.

If you need to add modems, click Add, and repeat steps 2 through 4.

8. Click Network to open the Network Configuration dialog box (see Figure 15.8).

Fig. 15.8

The Network Configuration dialog box controls what protocols are available.

9. Select the protocols that can be used for dial-out. Normally, all the protocols you have installed are selected here so that any protocol can be used to dial another network.

10. Select the protocols to be used for dial-in access. Each protocol has special options [radical][apple]%cific to iu-hat must also be configured.

11. If NetBEUI has been selected for dial-in, click the NetBEUI configuration button to show the RAS Server NetBEUI Configuration dialog box (see Figure 15.9).

12. Select whether the NetBEUI client should be enabled to access the Entire Network or This Computer Only. When finished, click OK to return to the Network Configuration dialog box.

Fig. 15.9

NetBEUI options are simple, just like the protocol itself.

  1. 13. If the TCP/IP protocol is not enabled for dial-in, skip to Step 25. Press the TCP/IP configuration button to show the RAS Server TCP/IP Configuration dialog box (see Figure 15.10).

Fig. 15.10

TCP/IP options are a little more complex.

14. Select whether the TCP/IP client should be enabled to access the Entire Network or This Computer Only. If you're enabling clients to access the Internet through this RAS server, you must select Entire Network.

15. Determine the method of assigning IP addresses to clients. If your network has a DHCP server, you can select to enable DHCP to configure the remote client. This is recommended because the remote client will also receive any other DHCP settings, such as domain name and WINS server addresses. However, you can define a static pool of addresses for RAS to use. Each port that is connected requires two IP addresses; the first is for the port on the server, the second for the client machine.

16. Check Allow Remote Clients to Request a Predetermined IP Address if you want the remote client to be able to keep the IP address it wants to use. I discourage the use of this because it can cause IP conflicts and will simplify the process of IP spoofing.

17. If IPX is not enabled for dial-in, skip to Step 21. Click the IPX configuration button to show the RAS Server IPX Configuration dialog box (see Figure 15.11).

18. Select whether the IPX client should be enabled to access the Entire Network or This Computer Only. Normally, this setting remains Entire Network.

19. Determine whether you want Windows NT Server to allocate network numbers for each remote client automatically or from a range of network numbers. Normally, Windows NT automatically assigns IPX network numbers by finding network numbers that are not in use. It might be helpful to specify a range of network numbers so that you can identify that the user is remote based on the network number of his address.

Fig. 15.11

IPX Configuration options reqire few adjustments.

20. Check Assign Same Network Number to All IPX Clients if you want all the IPX clients on this RAS server to use the same IPX network number. This is the default for RAS.

21. Select Allow Remote Clients to Request IPX Node Number if you need nodes to have a specific address for some application. Normally, this option is left off.

22. Close the Network Configuration, Remote Access Setup, and Network dialog boxes.

23. When prompted to restart your computer, select Yes. RAS will not install completely until you've rebooted your computer.

Adding a New Dial-Up Networking Entry

After RAS has been installed on the server and on the workstation, a dial-up entry must be created in the workstation phone book to tell the workstation how to connect with the server. Follow these steps:

1. Choose My Computer, Dial-Up Networking; or select Start, Programs, Accessories, Dial-Up Networking.

2. If no entries have been created yet, click OK in the Dial-Up Networking dialog box that appears to create a new entry. If you already have entries in your phone book, you will see the Dial-Up Networking dialog box shown in Figure 15.12. Click New to create a new entry.

Fig. 15.12

If an entry already exists, Windows NT shows it when starting Dial-Up Networking.

3. Enter the name of the phone book entry in the New Phonebook Entry Wizard dialog box, as shown in Figure 15.13.

Fig. 15.13

Enter the name of the new phone book entry.

4. Leave the I Know All About Phonebook Entries and Would Rather Edit the Properties Directly check box blank if you want to have Windows NT prompt you through filling out the parameters. Click Next to precede to the Server dialog box shown in Figure 15.14.

Fig. 15.14

Describe the connection type that you are making.

5. Check the I Am Calling the Internet option and make sure that both the Send My Plain Text Password If That's the Only Way to Connect and The Non-Windows NT Server I Am Calling Expects Me to Type Login Information After Connecting, or to Know TCP/IP Addresses Before Dialing options are cleared. Click Next to proceed to the Modem or Adapter dialog box, as shown in Figure 15.15.


NOTE: If you're calling a nonWindows NT server, such as to connect to the Internet, you might need to change some of the options on the Server tab. Refer to the section "Editing a Dial-Up Networking Entry" for more information.
6. Select a modem port from the list of available ports. Click Next to display the Phone Number dialog box, as shown in Figure 15.16.

Fig. 15.15

Select a modem or adapter to use to call the server.

Fig. 15.16

Enter the phone number of the RAS server.


NOTE: Other ports, such as the PPTP ports shown previously in Figure 15.15, have special uses and will not work to dial out with. Make sure that you select a modem for your Dial-Up Networking entry.
7. Enter the Phone Number of the server you're calling. Or click the Use Telephony Dialing Properties check box to enter the number with an area code, as shown in Figure 15.17. You should use the Telephony options when in a notebook so that Windows NT can change how the number is dialed, based on your current location.

Fig. 15.17

Using telephony properties enables you to enter the number with the country code and area code separated.

8. Click Next to show the New Phonebook Entry Wizard dialog box; then click Finish to show the Dial-Up Networking dialog box.

If in Step 4, you decided that you would rather enter the settings manually, check the I Know All About Phonebook Entries and Would Rather Edit the Properties Directly check box, and click Finish. The New Phonebook Entry dialog box appears, as shown in Figure 15.18. At this stage, a new set of steps begins, as follows.

Fig. 15.18

The New Phonebook Entry dialog box enables you to set advanced options.

1. Select a modem port from the list in the Dial Using combo box.

2. Enter the phone number of the server in the Phone Number field. Or select the Use Telephony Dialing Properties check box, and click OK to enter the number with separate country code, area code, and number.

3. Configure alternate numbers by clicking Alternates. The Phone Numbers dialog box appears, as in Figure 15.19.

FIG. 15.19

Adding alternate numbers enables you to dial multiple numbers, which are not in a hunt group or rotary.

4. Enter additional phone numbers in the New Phone Number box, and click Add to add them to the list. If you make a mistake, select the incorrect number from the Phone Numbers list box, and click Delete.

5. Select phone numbers to move in priority by clicking the Up [arrowup] and Down [arrowdown] buttons.

6. Click OK to return to the New Phonebook Entry dialog box, and click OK to save the new connection.

Editing a Dial-Up Networking Entry

Sometimes the default parameters that Windows NT sets up for an entry won't connect you to a server, and some changes to the defaults are required. This section discusses each of the tabs on the phonebook entry and what the options mean.To edit a Dial-Up Networking entry:

1. Open Dial-Up Networking by selecting Start and choosing Programs, Accessories, Dial-Up Networking. The Dial-Up Networking dialog box appears.

2. Select an entry from the Phonebook Entry to Dial combo box, and click More. Select Edit Entry and Modem Properties to show the Edit Phonebook Entry dialog box. The Edit Phonebook Entry dialog box is exactly the same as the New Phonebook Entry dialog box. The first tab that can be used to customize the Dial-Up Networking entry is the Basic tab.

Basic

The Basic tab contains all the basic entries that are common to every dial-up entry: name, phone number, and modem. Normally, this is the only tab that must be filled out to make a connection to a server, whether a Windows NT or PPP server. Keep in mind the following tips about entries in the Basic tab:

Server

When you select the Server tab of the Edit Phonebook Entry dialog box, a page similar to the one shown in Figure 15.20 appears. This page controls how Windows NT tries to negotiate a connection to the remote server. Windows NT is capable of connecting to multiple server types, not just Windows NT servers.

In the Dial-Up Server Type drop-down list box, Windows NT lists three options:

Fig. 15.20

The Server tab has options for the type of server to which the entry is to connect.

In addition to selecting the protocols you want to use with your connection, it might be necessary to set some TCP/IP options, as shown in Figures 15.21 and 15.22. The PPP TCP/IP Settings dialog box appears when PPP is selected as a protocol, and the SLIP TCP/IP Settings dialog box appears when SLIP is selected as a protocol. Either can be displayed by clicking the TCP/IP Settings button on the Server tab.

Fig. 15.21

PPP TCP/IP options are largely automatic.

Fig. 15.22

SLIP TCP/IP options are entirely manual.

IP address options and name server options should normally be left as automatic, except when using SLIP as a connection method or in those cases in which the automatic setting doesn't work. SLIP doesn't support the automatic settings; it expects that you'll hard-code the necessary information into the connection. This is one of the reasons that SLIP is no longer used very often.


NOTE: Enhanced options such as PPTP and Multi-link are not available on a SLIP connection. If your ISP is still using SLIP as its only connection type, consider a new ISP.

The Use IP Header Compression option sometimes confuses older servers and must be turned off. This option should be one of the first options turned off if you're having trouble with a connection. Whenever possible, however, it should be turned on because it will improve performance.

The Use Default Gateway on Remote Network option changes the default gateway on your system to be the default gateway on the remote system. Unless you're connecting to a single remote network and are locally connected to a large network, leave this option on.

If you're using SLIP, you have the option of adjusting the frame size, but normally this should be left at the default setting. Clicking OK closes the SLIP or PPP TCP/IP Settings dialog box.

On the Server tab, you also have the option of enabling software compression. This is largely at your discretion. It provides marginal improvement over modem-based compression, which becomes ineffective when this option is turned on. The cost is additional CPU time.

The final option, Enable PPP LCP Extensions, turns off PPP LCP extensions. This option should be left on unless you're having difficulty with a non-Windows NT server that might not be processing some of the extensions to the PPP standard that Windows NT supports.

Script

The Script tab contains information on how to connect to servers that don't support Windows NT's normal connection method. Sometimes, servers are incapable of correctly interpreting Windows NT's logon sequence because they expect a user to log on and then start a PPP or SLIP session. Windows NT's scripting capability enables you to connect to these servers manually or automatically, even if they can't understand Windows NT's logon sequence.

There are three options on the Script page of the Edit Phonebook Entry dialog box. The first option, None, is to use no logon script. This option works when connecting to a Windows NT server and some ISPs.

In some cases, particularly SLIP accounts, a terminal window needs to be opened or a script written to automate the process of logging on. The second option, Pop Up a Terminal Window, opens a terminal window after dialing to enable you to log on manually. This is an excellent way to learn what prompts the remote system has so that you can write a script later.

The final option, Run This Script, enables you to use a script, either from the Script.INF file in the WINNT\SYSTEM32\RAS directory or from a .SCP file in the same directory.


TIP: You also can get the options to run a script or pop up a terminal window before dialing by clicking the Before Dialing button.

Security

The Security tab enables you to determine how passwords will be sent to the server, despite what the dialog box shown in Figure 15.23 states.

Fig. 15.23

Security settings control how logon is attempted.

Normally, the Accept Any Authentication Including Clear Text option is used, enabling the client to send the user name and password in unencrypted form. In some cases, this is unadvisable, such as when establishing a PPTP connection, as described in the "Point-to-Point Tunneling Protocol" section.

If the connection is to a non-Microsoft server and clear text is unacceptable, use the Accept Only Encrypted Authentication option. This enables any Windows NT-supported encryption to be used to protect the password.

The best option when calling a Microsoft server is to use Accept Only Microsoft Encrypted Authentication. This uses the Microsoft modified Challenge Handshake Authentication Protocol (CHAP) to establish a connection and enables the entire data stream to be encrypted.

These options normally are unnecessary because few people are concerned with a tap on their phone that's capable of decoding modem data.


NOTE: For more information on Windows NT Security, consult Chapters 26, "Securing NT Server" and 53, "Securing a Server on the Internet."

X.25

Windows NT still supports a wide variety of X.25 packet switching networks. These networks provide low-speed--normally 9,600 baud--connections that do not have a distance charge, but rather a charge for each packet sent. X.25 was the predecessor to frame relay and is still used in developing countries but is no longer widely used in the U.S.

If you need to connect Windows NT to an X.25 packet network, the network provider can tell you what to put in these fields.

When you've completed changes to all the tabs in the Edit Phonebook Entry dialog box, click OK to save your changes and return to the Dial-Up Networking dialog box.

Multi-Link

Multi-link is the process of combining more than one channel of data or modem into a single stream for use. This process used to be called inverse multiplexing because multiplexing is the process of taking one line and making several channels. Multi-link is actually an implementation of Multi-link PPP as defined in the Internet RFC 1990.

Multi-link is new to Windows NT 4.0 and not widely supported in the industry yet, except for use with ISDN. (For example, none of the Internet service providers in the Indianapolis area support Multi-link PPP for analog modems.) Due to the limited support of Multi-link PPP for analog modems, it might only be useful when working with Windows NT servers at your corporation.

Multi-link PPP provides a simple, cost-effective way to get higher bandwidth for dial-up applications. By using multiple modems, you can double or triple the normal bandwidth available to a dial-up application. Setting up a server for Multi-link PPP is as easy as selecting the Enable Multi-link check box in the Network Configuration dialog box.

Creating a Multi-Link Dial-Up Entry

Using Multi-link on a client is almost as easy as setting up a normal dial-up connection. It can be done by following these steps:

1. Start Dial-Up Networking by choosing Start, Programs, Accessories, Dial-Up Networking.

2. Click New in the Dial-Up Networking dialog box to show the New Phonebook Entry dialog box.

3. On the Basic tab, enter an Entry Name such as My Multi-link server.

4. Select Multiple Lines in the Dial Using combo box.

5. Click Configure to show the Multiple Line Configuration dialog box.

6. Select the modems to use.

7. Select the first modem in the Modem or Device list box; then click the Phone Numbers button to display the Phone Numbers dialog box.


NOTE: Entering phone numbers for multiple lines must be done one line at a time.
8. Enter the phone number, and click Add.

9. Click OK to return to the Multiple Line Configuration dialog box.

10. Select the next modem, and repeat steps 8-10 to add phone numbers to each additional line.

11. When finished selecting lines, click OK to return to the New Phonebook Entry dialog box (see Figure 15.24). Notice that the Phone Number text box has been disabled.

12. Click OK to return to Dial-Up Networking.

Fig. 15.24

The Phone Number text box is disabled for Multi-link entries.

Dialing a Multi-Link Capable Server

After the entry has been created, select the Multi-link entry from the Dial-Up Networking dialog box, and click Dial.

Windows NT prompts you for a username, password, and domain for the connection. You have the option of saving the password for future use. When you click OK, Windows NT starts dialing all the modems simultaneously. After one of the lines has successfully connected, Windows NT displays a Connected, bundling additional lines message, indicating that it's waiting for additional lines to connect so that they can be bundled. Windows NT doesn't activate the connection until all the lines of a Multi-link have connected.

If the server supports Multi-link and all the modems connect successfully, you won't see any difference from a normal line, except that more than one modem will be in use. If the server doesn't support Multi-link, however, you'll get an error. This error means that the remote system doesn't support Multi-link. The error message isn't much help; it just says that the link was disconnected by the remote system. At this point, just hang up and create a normal Dial-Up Networking entry for the server.

Point-to-Point Tunneling Protocol (PPTP)

Also new to RAS in Windows NT 4.0 is the Point-to-Point Tunneling Protocol (PPTP) which enables secure, encrypted connections over the Internet or other public network. These connections aren't limited to carrying TCP/IP traffic; they can carry IPX and NetBEUI traffic, as well, enabling virtual private networks to be built on top of existing networks.

Virtual private networks (VPNs) are connections made on top of existing networks for the purpose of reducing the cost of maintaining a fully private network. A private network can consist of dedicated 56K lines, T1 lines, frame relay, satellite links, or other connectivity technologies. Unfortunately, all these technologies are relatively expensive to establish and particularly difficult to maintain.

Most of these technologies' costs are driven by the length of distance between the sites being connected. The further the sites are from one another, the more expensive they become. A company with offices in New York and Los Angeles can expect to pay an extremely high price for a T1 line between the two sites. Another complication is that when multiple sites are involved, you need to consider the impact of one of the lines going down. We live in the real world in which construction sometimes cuts cables and prevents data from getting through. If multiple sites depend on a cable for communications, then all the sites lose their capability to communicate with the sites on the other side of the link. This leads many network administrators to put redundant links between sites, ensuring that a single cable failure cannot take down the entire network. Each additional link, however, adds communications cost and hardware.

If, in addition to maintaining this private network, a company decides to connect to the Internet at each site, there are duplicated costs because the connection to the Internet requires its own hardware and communications resources. The promise of a VPN is that it prevents the need for redundant links and removes distance from the cost equation.

VPNs normally have a lower cost because you need only one link to the rest of the sites. This link is used for external traffic, such as traffic to the Internet and internal traffic to other sites. This reduces hardware costs and prevents a single communications line failure from disconnecting multiple sites. If the communications link goes down, then that site is cut off from the rest of the network, but all the other sites are unaffected.

The downsides to a VPN are that it sends internal, and potentially confidential, information over a public network and that the amount of bandwidth available varies.

To resolve the problem of sending private information over a public network, the data is normally encrypted. In the case of Windows NT Server's PPTP protocol, a 40-bit RSA encryption method is used. This prevents someone from easily gaining access to the confidential information.

This leaves the problem of variable bandwidth. When transmitting data over a public network, it's impossible to ensure that the bandwidth your company needs will be available. This means that even though you have T1 lines (capable of transmitting 1.544Mbps), you can't ensure that this amount of bandwidth will be available between your sites. The public network might be saturated and unable to accommodate this much additional traffic.


TIP: The best way to make sure that bandwidth is available is to use the same ISP for all your sites. This way, you have a single vendor to deal with when you're not getting the bandwidth you need.

Windows NT's PPTP protocol is the product of the PPTP Forum, a collaborative effort between Microsoft and several hardware vendors. Microsoft's implementation is focused on allowing secure access between corporate, host, network, and dial-up users. Windows NT RAS enables a client computer to dial into a PPTP-enabled terminal server or front-end processor (FEP) and establish a secure connection to the corporate network. Unfortunately, no FEPs support PPTP at this time. Both U.S. Robotics and 3Com have promised PPTP support in future releases of their software.

Installing PPTP

Before using PPTP, the protocol must be installed and configured in the Network applet:

1. Open Control Panel by choosing Start, Settings, Control Panel.

2. Double-click Network to open the Network applet.

3. Click the Protocols tab to see all the protocols on the system.

4. Click Add to show the Select Network Protocol dialog box.

5. Select Point-to-Point Tunneling Protocol, and click OK to display the PPTP Configuration dialog box (see Figure 15.25).

Fig. 15.25

The PPTP Configuration dialog box enables you to specify how many simultaneous connections you need.

6. Enter the Number of Virtual Private Networks that you need to serve (if installing on the server) or want to simultaneously connect to (if installing on the workstation), and click OK. This displays the Setup Message dialog box, which notifies you Remote Access Services (RAS) setup will now be invoked. Please configure the PPTP ports in RAS setup to enable you to use RAS over PPTP.

7. Click OK to show the Remote Access Setup dialog box with all configured modems and devices listed.

8. Click Add to show the Add RAS Device dialog box (see Figure 15.26).

9. Select the first VPN device that was added by the PPTP Setup, and click OK to return to the Remote Access Setup dialog box.

Fig. 15.26

PPTP devices appear as RAS-capable devices.

10. Click Configure to show the Configure Port Usage dialog box (see Figure 15.27). Select Dial Out and Receive Calls for a server and Dial Out Only for a workstation.

Fig. 15.27

Configuring the PPTP device for dial-out and dial-in ensures that it can be used for whatever purpose when needed.

11. Repeat steps 8-10 until all the VPN devices have been added. Click Continue in the Remote Access Setup dialog box to return to the Network applet.

12. Click Close to close the Network applet and show the Network Settings Change dialog box.

13. Click Yes to reboot Windows NT and make PPTP operational.

Adding a New PPTP Entry

After the PPTP protocol is installed, you must create a Dial-Up Networking entry for it:

1. Select My Computer and then Dial-Up Networking, or choose Start, Programs, Accessories, Dial-Up Networking.

2. In the Dial-Up Networking dialog box, click New.

3. Enter the name of the phone book entry.

4. Leave the I Know All About Phonebook Entries and Would Rather Edit the Properties Directly check box blank if you want to have Windows NT prompt you through filling out the parameters. Click Next to proceed to the Server dialog box.

5. Check the I Am Calling the Internet option, and make sure that both the Send My Plain Text Password If That's the Only Way to Connect and The Non-Windows NT Server I Am Calling Expects Me to Type Login Information After Connecting, or to Know TCP/IP Addresses Before Dialing options are cleared. Click Next to proceed to the Modem or Adapter dialog box (see Figure 15.28).

6. Select one of the RASPPTPM adapters from the list of available ports. Click Next to show the Phone Number dialog box (see Figure 15.29).

Fig. 15.28

Select an RASPPTM device to select a PPTP connection.

Fig. 15.29

The phone number is really an IP address.

7. Enter the IP address of the server acting as a PPTP server. Despite the fact that this dialog box is asking for a phone number, it really needs the IP address for the server.

8. Click Next to show the New Phonebook Entry Wizard dialog box.

9. Click Finish to show the Dial-Up Networking dialog box.

If you would rather enter the settings manually:

1. Check the I Know All About Phonebook Entries and Would Rather Edit the Properties Directly check box, and click Finish.

2. Select a RASPPTPM port from the list in the Dial Using combo box.

3. Enter the IP address of the PPTP server in the Phone Number field, and click OK to save the new connection.

Connecting to a PPTP Server

To connect to a PPTP server, you need to have created two dial-up connections. The first connection connects to the Internet or to a RAS server to establish connectivity with the network. The second connection establishes security and the tunnel through the Internet.

Each connection has its own security and logon, so you can log on to your ISP with one username and password and log on to the corporate network with another.

Administering a Server

After you've configured a server to accept calls and have created the Dial-Up Networking entries on the client to connect to the server, you're ready to add access to users and monitor the server.

Setting User Access

Windows NT requires that users logging on via Remote Access have permissions set up on the server. This can be done two ways--the first is with User Manager.

Using User Manager to Allow Remote Access. You can start User Manager by choosing Start, Programs, Administrative Tools (common), User Manager. User Manager appears, as shown in Figure 15.30, with a listing of users and groups.

Fig. 15.30

User Manager lists both users and groups defined on the server.

Select the user you want to allow to access the network remotely, and double-click. The User Properties dialog box appears (see Figure 15.31).

Click the Dialin access button in the lower-right corner of this dialog box to open the Dial-Up Access dialog box (see Figure 15.32).

Dial-up access can be set to No Call Back, Set By Caller, or a preset number.

Using Remote Access Admin to Enable Remote Access. Another way to enable a user to access a server remotely, and the only method that was available until Windows NT 4.0, is the Remote Access Admin utility. You can run it by choosing Start, Programs, Administrative Tools (common), Remote Access Admin. This utility starts with a listing of all the servers in the domain, what ports they have defined, and how many are active (see Figure 15.33).

Fig. 15.31

The User Properties dialog box enables all the user's properties to be changed, except the username.

Fig. 15.32

Dialing in properties for the user is simple.

Fig. 15.33

The Remote Access Admin utility shows the status of all the servers.

To change a user's dial-up permission, choose User, Permissions. This displays the Remote Access Permissions dialog box (see Figure 15.34). This dialog box lists all the users in the domain and what their access is set to.

Fig. 15.34

Remote Access Permissions lists all users and their permissions.

To change the permission of a user, select the user in the User list box. Her permissions are displayed in the lower half of the dialog box.

You can grant or revoke remote access by checking or unchecking the Grant Dialin Permission to User check box (refer to Figure 15.32). The user can have her call back set to No Call Back, Set by Caller, or a preset number.

Monitoring Ports

From time to time, you need to perform maintenance on the system and need to kick users off the system. This is easy when all the users are in the same building as you. You can just phone them or walk by their desks and ask them to get off the system. It becomes much more difficult when the users aren't local.

When you start Remote Access Admin, you're shown all the servers in your domain, as well as how many ports are defined and how many are in use. Reviewing the active ports in Remote Access Admin is a quick and easy way to tell whether or not someone is logged on.

Refer to Figure 15.33, where you can see that there's only one server named BEAST with six ports defined and one in use. By choosing Server, Communication Ports, a detailed list of ports appears (see Figure 15.35).

In this list of ports, you see who is connected to each port and when they started their connections. In Figure 15.35, the Administrator has been connected to VPN1 since 2/2/97 at 8:34 p.m. You can see even more detail about a port by selecting it in the Port list and clicking Port Status to access the Port Status dialog box (see Figure 15.36).

The Port Status dialog box shows the connection status and speed, as well as details on the information that has been transmitted and the errors that have occurred. The Port Status dialog box also displays the address of the remote user for every protocol.

Fig. 15.35

All the communications ports for a server are listed.

Fig. 15.36

The Port Status dialog box shows all the details of the connection, including names and addresses.

In Figure 15.36, the connection speed is listed as 10000000 because this connection is across a local EtherNet at 10Mbps. Click OK to return to the Communications Ports dialog box.

In addition to seeing the details of a port, you can also send a message to a single port or to all ports. This enables you to try to notify connected users that you need to take down the system. In practice, however, the messages don't always work. It's best to try to call the users if you know how to contact them. After you've informed a user that you need the system, he can disconnect by simply selecting his port and clicking Disconnect User.


Previous chapterNext chapterContents


Macmillan Computer Publishing USA

© Copyright, Macmillan Computer Publishing. All rights reserved.