70-649 · Question #292
Your network contains two servers named Server1 and Server2 that run Windows Server 2008 R2. Network Access Protection (NAP) is deployed on Server1. Server2 has the Routing and Remote Access service…
The correct answer is C. Extensible authentication protocol (EAP). To deploy NAP with VPN, you must configure the following: Install and configure Routing and Remote Access as a VPN server. Configure your server running NetworkPolicy Server (NPS) as the primary RADIUS server in Routing and Remote Access. In NPS, configure VPN servers as RADIUS…
Question
Your network contains two servers named Server1 and Server2 that run Windows Server 2008 R2. Network Access Protection (NAP) is deployed on Server1. Server2 has the Routing and Remote Access service (RRAS) role service installed. You need to configure Server2 to use NAP VPN enforcement. Which authentication method should you enable on Server2?
Options
- AEncrypted authentication (CHAP)
- BAllow machine certificate authentication for IKEv2
- CExtensible authentication protocol (EAP)
- DMicrosoft encrypted authentication version 2 (MS-CHAP v2)
How the community answered
(51 responses)- A16% (8)
- B8% (4)
- C73% (37)
- D4% (2)
Explanation
To deploy NAP with VPN, you must configure the following: Install and configure Routing and Remote Access as a VPN server. Configure your server running NetworkPolicy Server (NPS) as the primary RADIUS server in Routing and Remote Access. In NPS, configure VPN servers as RADIUS clients. Also configure connection request policy, network policy,and NAP health policy. You can configure these policies individually using the NPS console, or you can use theNew Network Access Protection wizard. Enable the NAP Remote Access and EAP enforcement clients on NAP-capable client computers. Enable the NAP service on NAP-capable client computers. Configure the Windows Security Health Validator (WSHV) or install and configure other system health agents(SHAs) and system health validators (SHVs), depending on your NAP deployment. If you are using PEAP-TLS or EAP-TLS with smart cards or certificates, deploy a public key infrastructure (PKI)with Active Directory?Certificate Services (AD CS). If you are using PEAP-MS- CHAP v2, issue server certificates with either AD CS or purchase server certificatesfrom a trusted root certification authority (CA).
Topics
Community Discussion
No community discussion yet for this question.