<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[gOxiA=苏繁=SuFan Blog]]></title> 
<link>https://sufan.maytide.net/index.php</link> 
<description><![CDATA[gOxiA,苏繁,sufan,Microsoft MVP]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[gOxiA=苏繁=SuFan Blog]]></copyright>
<item>
<link>https://sufan.maytide.net/read.php/1712.htm</link>
<title><![CDATA[[Azure]HOWTO：在 Windows Azure 虚机上配置 SSTP VPN]]></title> 
<author>gOxiA &lt;sufan_cn@msn.com&gt;</author>
<category><![CDATA[Microsoft Cloud]]></category>
<pubDate>Thu, 23 Jan 2014 09:56:33 +0000</pubDate> 
<guid>https://sufan.maytide.net/read.php/1712.htm</guid> 
<description>
<![CDATA[ 
	<p><a href="http://goxia.maytide.net/ftpupfiles/Tips_BF61/windowsazure_logo_1.png"><img title="windowsazure_logo_1" border="0" alt="windowsazure_logo_1" src="http://goxia.maytide.net/ftpupfiles/Tips_BF61/windowsazure_logo_1_thumb.png" width="195" height="30" /></a></p>&nbsp;&nbsp;<p><font color="#fd3f0d" size="4"><strong>HOWTO：在 Windows Azure 虚机上配置 SSTP VPN</strong></font></p>&nbsp;&nbsp;<p>&#160;&#160;&#160;&#160;&#160;&#160;&#160; VPN（虚拟专用网）大家并不会感到陌生，在 Windows Azure 上启用 VPN 服务的意义就更没必要多解释什么，大家自己心里知道就好!</p>&nbsp;&nbsp;<p>&#160;&#160;&#160;&#160;&#160;&#160;&#160; 目前 <a href="http://goxia.maytide.net/" target="_blank">gOxiA</a> 在 <a href="http://www.windowsazure.com/" target="_blank">Windows Azure</a> 的虚拟机上经过实践，基于 SSTP 的 VPN 是能够正常运作的，所以今天的内容也仅向大家介绍如何在 Windows Azure 虚拟机上配置 SSTP VPN。有关 VPN 常用协议的具体资料可以访问 <a href="http://technet.microsoft.com/zh-cn/library" target="_blank">TechNet Library</a> 上 <a href="http://technet.microsoft.com/zh-cn/library/cc771298(v=WS.10).aspx" target="_blank">VPN 隧道协议</a> 的文章。</p>&nbsp;&nbsp;<p>&#160;&#160;&#160;&#160;&#160;&#160;&#160; 要启用基于 SSTP 协议的 VPN 服务，需要准备一张证书，申请证书比较简单的办法就是用 SelfSSL 工具创建一个自签名证书，并将证书安装到 Windows Azure 虚拟机系统的计算机账户上，同时还要将证书导入到客户端“受信任的根证书颁发机构”中。这一配置过程就不再复述，创建自签名证书可参考下面的命令行：</p>&nbsp;&nbsp;<p><div class="code">selfssl.exe /N:cn=name.cloudapp.net /V:3650</div></p>&nbsp;&nbsp;<p>&#160;&#160;&#160;&#160;&#160;&#160;&#160; 接下来还要准备一台虚拟机，并在 Endpoint（端点）配置中创建 TCP 443 映射。</p>&nbsp;&nbsp;<p>&#160;&#160;&#160;&#160;&#160;&#160;&#160; 准备工作就绪，现在打开服务器管理器，添加角色和功能；勾选“Remote Access”，在后续的角色服务选择中复选“DirectAccess and VPN（RAS）”和“Routing”。</p>&nbsp;&nbsp;<p><a href="http://goxia.maytide.net/ftpupfiles/Azure_E7E7/image.png"><img title="image" style="border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px" border="0" alt="image" src="http://goxia.maytide.net/ftpupfiles/Azure_E7E7/image_thumb.png" width="634" height="450" /></a></p>&nbsp;&nbsp;<p><a href="http://goxia.maytide.net/ftpupfiles/Azure_E7E7/image_3.png"><img title="image" style="border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px" border="0" alt="image" src="http://goxia.maytide.net/ftpupfiles/Azure_E7E7/image_thumb_3.png" width="634" height="450" /></a></p>&nbsp;&nbsp;<p>&#160;&#160;&#160;&#160;&#160;&#160;&#160; 稍等片刻完成安装，Windows Server 2012 系统会要求重启系统，Windows Server 2012 R2 可直接开始进行初始配置。在“Configure Remote Access”中选择“Deploy VPN Only”，完成之后向导会自动打开 RRAS 控制台。</p>&nbsp;&nbsp;<p><a href="http://goxia.maytide.net/ftpupfiles/Azure_E7E7/image_4.png"><img title="image" style="border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px" border="0" alt="image" src="http://goxia.maytide.net/ftpupfiles/Azure_E7E7/image_thumb_4.png" width="634" height="358" /></a></p>&nbsp;&nbsp;<p><a href="http://goxia.maytide.net/ftpupfiles/Azure_E7E7/image_5.png"><img title="image" style="border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px" border="0" alt="image" src="http://goxia.maytide.net/ftpupfiles/Azure_E7E7/image_thumb_5.png" width="604" height="498" /></a></p>&nbsp;&nbsp;<p>&#160;&#160;&#160;&#160;&#160;&#160;&#160; 在 RRAS 控制台选中当前服务器，鼠标右键点击，执行“Configure and Enable Routing and Remote Access”，选择 Custom 进行自定义配置，在服务列表中只选择“VPN access”和“NAT”，之后跟随向导完成后续步骤，启动 RRAS 服务。</p>&nbsp;&nbsp;<p><a href="http://goxia.maytide.net/ftpupfiles/Azure_E7E7/image_6.png"><img title="image" style="border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px" border="0" alt="image" src="http://goxia.maytide.net/ftpupfiles/Azure_E7E7/image_thumb_6.png" width="518" height="434" /></a></p>&nbsp;&nbsp;<p>&#160;&#160;&#160;&#160;&#160;&#160;&#160; 回到 RRAS 控制台界面进入当前服务器属性，切换到“Security”选项卡，选择之前导入的自签名证书。</p>&nbsp;&nbsp;<p><a href="http://goxia.maytide.net/ftpupfiles/Azure_E7E7/image_7.png"><img title="image" style="border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px" border="0" alt="image" src="http://goxia.maytide.net/ftpupfiles/Azure_E7E7/image_thumb_7.png" width="417" height="585" /></a></p>&nbsp;&nbsp;<p>&#160;&#160;&#160;&#160;&#160;&#160;&#160; 再切换至“IPv4”选项卡，启用静态地址池，即“Static address pool”，并手工输入一个地址范围，如：192.168.2.1~192.168.2.20，最后确认完成整个设置。</p>&nbsp;&nbsp;<p><a href="http://goxia.maytide.net/ftpupfiles/Azure_E7E7/image_8.png"><img title="image" style="border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px" border="0" alt="image" src="http://goxia.maytide.net/ftpupfiles/Azure_E7E7/image_thumb_8.png" width="418" height="587" /></a></p>&nbsp;&nbsp;<p>&#160;&#160;&#160;&#160;&#160;&#160;&#160; 至此， SSTP VPN 的配置我们已经接近完成，现在 RRAS 控制台依次展开列表，选中 IPv4 下的 NAT，右键点击执行“New Interface”，进行网卡的添加。</p>&nbsp;&nbsp;<p><a href="http://goxia.maytide.net/ftpupfiles/Azure_E7E7/image_9.png"><img title="image" style="border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px" border="0" alt="image" src="http://goxia.maytide.net/ftpupfiles/Azure_E7E7/image_thumb_9.png" width="512" height="358" /></a></p>&nbsp;&nbsp;<p>&#160;&#160;&#160;&#160;&#160;&#160;&#160; 添加网卡时选择名为以太网开头的网卡（Ethernet）非 Internal，并在随后弹出的属性设置中，为 NAT 选择“Public interface connected to the Internet”，并复选“Enable NAT on this interface”。</p>&nbsp;&nbsp;<p><a href="http://goxia.maytide.net/ftpupfiles/Azure_E7E7/image_10.png"><img title="image" style="border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px" border="0" alt="image" src="http://goxia.maytide.net/ftpupfiles/Azure_E7E7/image_thumb_10.png" width="418" height="504" /></a></p>&nbsp;&nbsp;<p>&#160;&#160;&#160;&#160;&#160;&#160;&#160; 服务器端的配置告一段落，现在回到客户端计算机添加 VPN 连接，VPN 类型为 SSTP（安全套接字隧道协议），并允许“Microsoft CHAP Version 2（MS-CHAP v2）”协议。</p>&nbsp;&nbsp;<p><a href="http://goxia.maytide.net/ftpupfiles/Azure_E7E7/image_11.png"><img title="image" style="border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px" border="0" alt="image" src="http://goxia.maytide.net/ftpupfiles/Azure_E7E7/image_thumb_11.png" width="439" height="618" /></a></p>&nbsp;&nbsp;<p>&#160;&#160;&#160;&#160;&#160;&#160;&#160; 现在启动 VPN 连接，便可无限畅游国际互联网。连接 VPN 用户请确认是否允许进行远程连接。如果遇到其他错误，可参考“<a title="Troubleshooting common VPN related errors" href="http://blogs.technet.com/b/rrasblog/archive/2009/08/12/troubleshooting-common-vpn-related-errors.aspx">Troubleshooting common VPN related errors</a>”。</p><br/>Tags - <a href="https://sufan.maytide.net/go.php/tags/microsoft/" rel="tag">microsoft</a> , <a href="https://sufan.maytide.net/go.php/tags/windows/" rel="tag">windows</a> , <a href="https://sufan.maytide.net/go.php/tags/azure/" rel="tag">azure</a> , <a href="https://sufan.maytide.net/go.php/tags/vpn/" rel="tag">vpn</a> , <a href="https://sufan.maytide.net/go.php/tags/sstp/" rel="tag">sstp</a>
]]>
</description>
</item><item>
<link>https://sufan.maytide.net/read.php/1712.htm#blogcomment4991</link>
<title><![CDATA[[评论] [Azure]HOWTO：在 Windows Azure 虚机上配置 SSTP VPN]]></title> 
<author>春秋七草 &lt;blogcn@live.n&gt;</author>
<category><![CDATA[评论]]></category>
<pubDate>Sun, 06 Jul 2014 05:59:14 +0000</pubDate> 
<guid>https://sufan.maytide.net/read.php/1712.htm#blogcomment4991</guid> 
<description>
<![CDATA[ 
	貌似在 Windows 7 上 VPN 连接不上
]]>
</description>
</item>
</channel>
</rss>