After some Googling and noodling, I have a bit more information to share about DirectAccess, Microsoft’s latest solution for remote user connectivity to head-office networks. DirectAccess does indeed require IPv6, although it can tunnel IPv6 packets across IPv4 networks. DirectAccess also uses IPsec to perform both computer and user authentication, as well as session encryption. Typically, the client will connect to a DirectAccess server at corporate HQ; this machine must be running 2008 R2.
The computer certificate is used to authenticate the computer, permitting propagation of Group Policy Objects. User credentials let the user create a separate tunnel to gain access to resources on the corporate network. Microsoft distinguishes between the more secure “end-to-end” connection, which requires IPv6 and IPsec and Server 2008 (regular or R2) throughout the network, and an “edge-to-edge” connection in which the IPsec protection ends at the IPsec gateway and communication between that gateway and internal application servers is unencrypted. (My suspicion is that “edge-to-edge” is going to be plenty good enough for most remote access situations because we generally assume that our internal networks are not being eavesdropped on.)
Other benefits include compatibility with Network Access Protection (NAP) and efficient traffic management which ensures that remote users don’t have to get to Internet destinations through the DirectAccess gateway. DirectAccess seems to be for Windows 7 only, although one would think that it wouldn’t be that hard to implement it for Vista, since Vista also has built-in support for IPv6. DirectAccess might be very convenient for some companies; it would be a shame if its benefits are kept from Vista in the name of Windows 7 “synergy.”
Recent posts:
Microsoft’s New “Direct”-ion
BitLocker Extends Its Reach
Virtual Desktop Interface




