

Decide whether to authenticate to the IP-HTTPS server by using a certificate that is issued by a certification authority (CA), or by using a self-signed certificate that is issued automatically by the DirectAccess server. IP-HTTPS is a transition protocol that is used by DirectAccess clients to tunnel IPv6 traffic over IPv4 networks. Plan for allowing DirectAccess traffic through edge firewalls.ĭecide whether you want to use Kerberos or certificates for client authentication, and plan your website certificates.

Taskĭecide where to place the DirectAccess server (at the edge, or behind a Network Address Translation (NAT) device or firewall), and plan IP addressing, routing, and force tunneling. These planning tasks do not need to be completed in a specific order. This topic describes the infrastructure planning steps. The first step of planning for an advanced DirectAccess deployment on a single server is to plan the infrastructure that is required for the deployment. Applies To: Windows Server 2012 R2, Windows Server 2012
