
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 134
theOnlineDocumentationprovidedbyMicrosoft,
“InWindows2000,authorizationisgrantedbasedonthedialuppropertiesofauser
accountandremoteaccesspolicies.Remoteaccesspoliciesareasetofconditions
andconnectionsettingsthatgivenetworkadministratorsmoreflexibilitywhen
authorizingconnectionattempts…Withremoteaccesspolicies,youcangrantordeny
authorizationbytimeofdayordayoftheweek,bytheWindows2000grouptowhich
theremoteaccessuserbelongs,bythetypeofconnectionbeingrequested(dialup
networkingorVPNconnection),andsoon.You canconfiguresettingsthatlimit the
maximumsessiontime,specifytheauthenticationandencryptionstrengths,set
BandwidthAllocationProtocol(BAP)policies,andsoon.”
31
Forclientendauthentication,smartcardshouldbemandatory.Thisispossible,
accordingtoMicrosoft,whenEAP isdeployed:
“TheExtensibleAuthenticationProtocol(EAP)isanextensiontothePointtoPoint
Protocol(PPP)thatallowsarbitraryauthenticationmethodsusingcredentialand
informationexchangesofarbitrarylengths…ByusingEAP,supportforanumberof
specificauthenticationschemesknownasEAPtypesmaybeadded,includingtoken
cards,onetime passwords,publickeyauthenticationusingsmartcards,certificates,
andothers.”
32
BasicTesting:
n Dialinfromavalidphonenumberwithavaliduseraccount.Waitforthecall
backandtrytologon.Theattemptshouldsucceed.
n Dialinfromanonvalidphonenumberwithavaliduseraccount.Waitforthe
callbackandtrytologon.Theattemptshouldfail.
n Dialinfromavalidphonenumberwithanonvaliduseraccount.Waitforthe
callbackandtrytologon.Theattemptshouldfail.
n InspecttheRASlogfile.
31
http://www.microsoft.com/windows2000/techinfo/reskit/enus/default.asp?url=/WINDOWS2000/techi
nfo/reskit/enus/deploy/dgcf_inc_bhah.asp
32
http://www.microsoft.com/windowsxp/home/using/productdoc/en/default.asp?url=/WINDOWSXP/ho
me/using/productdoc/en/auth_eap.asp
Comentarios a estos manuales