SlideShare a Scribd company logo
Load Balancing

SSTP VPN
Using the KEMP LoadMaster

Load Balancer
RICHARD
HICKS
Richard M.
Hicks
Consulting
Founder and Principal Consultant
Microsoft Most Valuable
Professional (MVP)
• Cloud and Datacenter
• Enterprise Security
20+ Year Industry Veteran
Enterprise Mobility and Security
Infrastructure Expert
WINDOWS ROUTING

AND REMOTE ACCESS

SERVICES
WINDOWS RRAS
Routing
and
Remote
Access 

Services
(RRAS)
Feature

of the
Windows
Server 2016
operating
system
Mature,
robust,

and 

stable
First
introduced
in
Windows
2000
Support for
modern
VPN
protocols
RRAS BENEFITS
Easy to deploy
As a feature of the Windows Server
2016 operating system, RRAS is easy
to install and configure.
Cost effective
RRAS and Windows 10 VPN

does not require any additional

per-user licensing to implement.
Flexible deployment
RRAS can be deployed 

on existing physical or virtual
infrastructure.
Easy to manage
RRAS requires no specialized
knowledge and can be implemented
and supported using existing
Windows administrator skill sets.
PROTOCOL 

SUPPORT
PROTOCOL SUPPORT
Internet Key Exchange version 2 (IKEv2)
+
Secure Sockets Tunneling Protocol (SSTP)
+
Layer Two Tunneling Protocol over IPsec (L2TP/IPsec)
+
Point-to-Point Tunneling Protocol
IKEV2
Industry
standard
VPN
protocol in
wide use.
Broad
client
support.
Uses UDP
for
transport
(ports 500
and 4500).
Commonly
blocked

by edge
firewalls.
Difficult
to scale
out.
SSTP
Microsoft
proprietary
VPN
protocol.
Supported
since
Windows
Vista.
Uses TCP
for
transport
(port 443).
Firewall
friendly
protocol
that
provides
ubiquitous
access.
Easily
scalable.
L2TP/IPSEC AND PPTP
Requires
client-side
certificates for
highest
assurance.
Can use pre-
shared keys
(not
recommended)
Difficult to
implement
and support.
Numerous
known security
vulnerabilities.
L2TP/IPsec PPTP
L2TP/IPsec and PPTP are legacy VPN protocols and are
considered obsolete. Their use should be avoided at all costs.
WHY SSTP?
FIREWALL FRIENDLY
SSTP uses
Transport
Layer Security
(TLS).
Operates
on
standard
HTTPS port
443.
Commonly
available.
Easy to
implement
and
support.
HIGHLY SCALABLE
Easy to load balance.
Includes native support for full TLS

termination and offload.
All encryption/decryption can be performed on

dedicated appliance.
• Improves performance
• Reduces server resource utilization
• Increases concurrent user support per server
LOAD BALANCING SSTP
VIRTUAL SERVICE
Define Virtual IP
Address (VIP)
Specify TCP port 443
Enter a Service Name
Choose persistence
options
REAL SERVERS
Provide IP address of
first VPN server
Specify TCP port 443
Define the weight

and connection limit (optional)
Repeat steps above for each
additional VPN server
TLS OFFLOADING - GEO
Modify existing SSTP
virtual service
Enable SSL Acceleration
Choose an 

SSL certificate
Select a cipher set
TLS OFFLOADING - RRAS
Edit the properties of
the RRAS server
Open the Security tab
Select the option to use
HTTP
Restart the RRAS
service
TRY LOADMASTER AND ALWAYS-ON-VPN
Always-on-VPN Free trial Try in Azure

More Related Content

PPTX
Adapting to evolving user, security, and business needs with aruba clear pass
PPTX
Wireless penetration testing
PPTX
WAF ASM / Advance WAF - Brute force lior rotkovitch f5 sirt v5 clean
PDF
ClearPass Policy Manager 6.3 User Guide
PPTX
Access Management with Aruba ClearPass
PPT
Module 5 Sniffers
PPTX
Spoofing Techniques
PDF
Adapting to evolving user, security, and business needs with aruba clear pass
Wireless penetration testing
WAF ASM / Advance WAF - Brute force lior rotkovitch f5 sirt v5 clean
ClearPass Policy Manager 6.3 User Guide
Access Management with Aruba ClearPass
Module 5 Sniffers
Spoofing Techniques

What's hot (20)

PPTX
Advanced Aruba ClearPass Workshop
PPT
intrusion detection system (IDS)
PPT
Presentation, Firewalls
PDF
Nuove normativa sulla accessibilità applicabili a qualsiasi sito web
PPTX
Wi fi call flows
PDF
Azure hands on lab
PPTX
Part 3 - DNS Configuration (IFD)
PPTX
PPTX
Wifi Security
PPTX
Campus_Network_Design_with_ArubaOS-CX_-_Leading_Practices
PPTX
Large scale, distributed access management deployment with aruba clear pass
PDF
AWS 네트워크 보안을 위한 계층별 보안 구성 모범 사례 – 조이정, AWS 솔루션즈 아키텍트:: AWS 온라인 이벤트 – 클라우드 보안 특집
PPT
Fortinet FortiOS 5 Presentation
PDF
Mitigating GNSS jamming and spoofing using ML and AI
PDF
DNS Hizmetine Yönetlik DoS/DDoS Saldırıları
PDF
IBM Cloud: Direct Link Guide
PPTX
Rootconf_phishing_v2
PPTX
Asm bot mitigations v3 final- lior rotkovitch
PPSX
Cloud Forensics
Advanced Aruba ClearPass Workshop
intrusion detection system (IDS)
Presentation, Firewalls
Nuove normativa sulla accessibilità applicabili a qualsiasi sito web
Wi fi call flows
Azure hands on lab
Part 3 - DNS Configuration (IFD)
Wifi Security
Campus_Network_Design_with_ArubaOS-CX_-_Leading_Practices
Large scale, distributed access management deployment with aruba clear pass
AWS 네트워크 보안을 위한 계층별 보안 구성 모범 사례 – 조이정, AWS 솔루션즈 아키텍트:: AWS 온라인 이벤트 – 클라우드 보안 특집
Fortinet FortiOS 5 Presentation
Mitigating GNSS jamming and spoofing using ML and AI
DNS Hizmetine Yönetlik DoS/DDoS Saldırıları
IBM Cloud: Direct Link Guide
Rootconf_phishing_v2
Asm bot mitigations v3 final- lior rotkovitch
Cloud Forensics
Ad

Similar to Load Balancing SSTP VPN with KEMP LoadMaster (20)

PDF
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
PDF
2500 controller
PDF
CV_MCMiranda_EN_NC
PDF
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
PDF
VMworld 2014: Introduction to NSX
DOCX
RizwanJamal-Resume
PDF
GAMO VMware vCloud Air
PDF
Fortinet Service specifications shortlist
PDF
Inteligentní řízení WAN konektivity
PDF
Ip tunneling and vpns
PPTX
New NSX Pitch Deck 2023 030302020202.pptx
PPTX
Cisco Generic Session with the products q
RTF
KennethBaughResume_2015
PPTX
VMworld 2016: Advanced Network Services with NSX
PPTX
The Data Center Network Evolution
PDF
Implementing Docker Load Balancing in Microservices Infrastructure
PDF
Ip tunnelling and_vpn
PPTX
A consolidated virtualization approach to deploying distributed cloud networks
PDF
Understanding Cisco Next Generation SD-WAN Solution
PPTX
Citrix Cloud Master Class June 2014
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
2500 controller
CV_MCMiranda_EN_NC
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
VMworld 2014: Introduction to NSX
RizwanJamal-Resume
GAMO VMware vCloud Air
Fortinet Service specifications shortlist
Inteligentní řízení WAN konektivity
Ip tunneling and vpns
New NSX Pitch Deck 2023 030302020202.pptx
Cisco Generic Session with the products q
KennethBaughResume_2015
VMworld 2016: Advanced Network Services with NSX
The Data Center Network Evolution
Implementing Docker Load Balancing in Microservices Infrastructure
Ip tunnelling and_vpn
A consolidated virtualization approach to deploying distributed cloud networks
Understanding Cisco Next Generation SD-WAN Solution
Citrix Cloud Master Class June 2014
Ad

More from Kemp (20)

PPTX
State of Application Experience [AX] Report 2019
PPTX
Internet of Things, OWASP & WAF
PPTX
2019 CRN Channel Chiefs – Tim Quinn
PPTX
Cloud Hosting for Federal, State & Local Government with GovDataHosting
PPTX
Dell EMC Elastic Cloud Storage - Kemp at Network Field Day, DellTechWorld
PDF
TCO Calculator for Load Balancers - Private, Public and Multicloud
PDF
Application Delivery Fabric for Next Gen Enterprise
PDF
Redundancy and Failover with Always-on-VPN and KEMP GSLB
PDF
Advanced Application Monitoring and Management in Microsoft Azure with KEMP360
PDF
DirectAccess Load Balancing Tips and Tricks
PDF
Enhanced Multisite Site Selection for Windows 10 and DirectAccess with KEMP L...
PDF
Top 15 Exchange Questions that Senior Admin ask - Jaap Wesselius
PDF
Simplifying Application Delivery Infrastructure in Azure for MSP's
PPTX
What to expect with Microsoft Exchange 2016?
PDF
Advanced Load Balancer/Traffic Manager and App Gateway for Microsoft Azure
PPTX
Microsoft DirectAccess Remote Access (VPN) with Windows 10 and Server 2012
PDF
Load Balancers vs IIS ARR or a Web Application Proxy (WA) for HA
PDF
Dell and KEMP - Partnering for scale
PPTX
Soluciones de nube híbrida con KEMP LoadMaster y Microsoft Azure
PDF
High Availability & Web Publishing for Skype for Business
State of Application Experience [AX] Report 2019
Internet of Things, OWASP & WAF
2019 CRN Channel Chiefs – Tim Quinn
Cloud Hosting for Federal, State & Local Government with GovDataHosting
Dell EMC Elastic Cloud Storage - Kemp at Network Field Day, DellTechWorld
TCO Calculator for Load Balancers - Private, Public and Multicloud
Application Delivery Fabric for Next Gen Enterprise
Redundancy and Failover with Always-on-VPN and KEMP GSLB
Advanced Application Monitoring and Management in Microsoft Azure with KEMP360
DirectAccess Load Balancing Tips and Tricks
Enhanced Multisite Site Selection for Windows 10 and DirectAccess with KEMP L...
Top 15 Exchange Questions that Senior Admin ask - Jaap Wesselius
Simplifying Application Delivery Infrastructure in Azure for MSP's
What to expect with Microsoft Exchange 2016?
Advanced Load Balancer/Traffic Manager and App Gateway for Microsoft Azure
Microsoft DirectAccess Remote Access (VPN) with Windows 10 and Server 2012
Load Balancers vs IIS ARR or a Web Application Proxy (WA) for HA
Dell and KEMP - Partnering for scale
Soluciones de nube híbrida con KEMP LoadMaster y Microsoft Azure
High Availability & Web Publishing for Skype for Business

Recently uploaded (20)

PPTX
Database Information System - Management Information System
PPTX
Module 1 - Cyber Law and Ethics 101.pptx
PPTX
newyork.pptxirantrafgshenepalchinachinane
PPTX
June-4-Sermon-Powerpoint.pptx USE THIS FOR YOUR MOTIVATION
PPT
250152213-Excitation-SystemWERRT (1).ppt
DOCX
Unit-3 cyber security network security of internet system
PDF
Sims 4 Historia para lo sims 4 para jugar
PDF
Exploring VPS Hosting Trends for SMBs in 2025
PPT
Ethics in Information System - Management Information System
PPTX
t_and_OpenAI_Combined_two_pressentations
PPTX
Internet___Basics___Styled_ presentation
DOC
Rose毕业证学历认证,利物浦约翰摩尔斯大学毕业证国外本科毕业证
PPTX
artificialintelligenceai1-copy-210604123353.pptx
PPTX
Introduction to cybersecurity and digital nettiquette
PPTX
Funds Management Learning Material for Beg
PPTX
artificial intelligence overview of it and more
PDF
💰 𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓 💰
PDF
Introduction to the IoT system, how the IoT system works
PPTX
presentation_pfe-universite-molay-seltan.pptx
PDF
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
Database Information System - Management Information System
Module 1 - Cyber Law and Ethics 101.pptx
newyork.pptxirantrafgshenepalchinachinane
June-4-Sermon-Powerpoint.pptx USE THIS FOR YOUR MOTIVATION
250152213-Excitation-SystemWERRT (1).ppt
Unit-3 cyber security network security of internet system
Sims 4 Historia para lo sims 4 para jugar
Exploring VPS Hosting Trends for SMBs in 2025
Ethics in Information System - Management Information System
t_and_OpenAI_Combined_two_pressentations
Internet___Basics___Styled_ presentation
Rose毕业证学历认证,利物浦约翰摩尔斯大学毕业证国外本科毕业证
artificialintelligenceai1-copy-210604123353.pptx
Introduction to cybersecurity and digital nettiquette
Funds Management Learning Material for Beg
artificial intelligence overview of it and more
💰 𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓 💰
Introduction to the IoT system, how the IoT system works
presentation_pfe-universite-molay-seltan.pptx
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...

Load Balancing SSTP VPN with KEMP LoadMaster