| About This Book |
|
xv | |
| Intended Audience |
|
xv | |
| Prerequisites |
|
xvi | |
| Reference Materials |
|
xvi | |
| About the CD-ROM |
|
xvi | |
| Features of This Book |
|
xvi | |
| Notes |
|
xvii | |
| Conventions |
|
xvii | |
| Chapter and Appendix Overview |
|
xviii | |
| Finding the Best Starting Point for You |
|
xx | |
| Where to Find Specific Skills in This Book |
|
xxi | |
| Getting Started |
|
xxiv | |
| Hardware Requirements |
|
xxiv | |
| Software Requirements |
|
xxv | |
| Setup Instructions |
|
xxv | |
| The Microsoft Certified Professional Program |
|
xxxiv | |
| Microsoft Certification Benefits |
|
xxxv | |
| Requirements for Becoming a Microsoft Certified Professional |
|
xxxvi | |
| Technical Training for Computer Professionals |
|
xxxvii | |
| Technical Support |
|
xxxviii | |
|
Designing a Windows 2000 Network |
|
|
1 | (22) |
|
|
|
1 | (1) |
|
|
|
1 | (1) |
|
Network Services Overview |
|
|
2 | (7) |
|
|
|
2 | (1) |
|
|
|
2 | (1) |
|
Dynamic Host Configuration Protocol |
|
|
3 | (1) |
|
Windows Internet Name Service |
|
|
4 | (1) |
|
|
|
4 | (2) |
|
Network Address Translator |
|
|
6 | (1) |
|
|
|
7 | (1) |
|
|
|
8 | (1) |
|
Developing a Network Implementation Plan |
|
|
9 | (5) |
|
Operating System Considerations |
|
|
9 | (2) |
|
|
|
11 | (1) |
|
|
|
12 | (1) |
|
Interaction with Legacy Systems |
|
|
12 | (1) |
|
Network Protocol Considerations |
|
|
12 | (1) |
|
|
|
13 | (1) |
|
Common Protocols Supported by Windows 2000 |
|
|
14 | (9) |
|
Transmission Control Protocol/Internet Protocol |
|
|
14 | (4) |
|
|
|
18 | (1) |
|
|
|
19 | (1) |
|
|
|
19 | (1) |
|
|
|
19 | (1) |
|
Infrared Data Association |
|
|
19 | (1) |
|
|
|
20 | (1) |
|
|
|
21 | (2) |
|
|
|
23 | (30) |
|
|
|
23 | (1) |
|
|
|
23 | (1) |
|
|
|
24 | (7) |
|
|
|
24 | (2) |
|
Architectural Overview of the TCP/IP Protocol Suite |
|
|
26 | (3) |
|
Transmission Control Protocol |
|
|
29 | (1) |
|
|
|
29 | (1) |
|
|
|
30 | (1) |
|
|
|
30 | (1) |
|
Internet Protocol Addressing |
|
|
31 | (6) |
|
|
|
31 | (2) |
|
|
|
33 | (1) |
|
IP Address Conversion from Binary to Decimal |
|
|
33 | (1) |
|
|
|
34 | (1) |
|
|
|
35 | (1) |
|
|
|
36 | (1) |
|
Microsoft TCP/IP Installation and Cofiguration |
|
|
37 | (8) |
|
|
|
37 | (1) |
|
Practice: Installing the TCP/IP Protocol |
|
|
37 | (1) |
|
|
|
38 | (3) |
|
Testing TCP/IP with Ipconfig and PING |
|
|
41 | (2) |
|
Configuring Packet Filters |
|
|
43 | (1) |
|
Practice: Implementing IP Packet Filters |
|
|
43 | (1) |
|
|
|
44 | (1) |
|
Basic Concepts of IP Routing |
|
|
45 | (8) |
|
|
|
45 | (2) |
|
Static and Dynamic IP Routing |
|
|
47 | (1) |
|
Practice: Updating a Windows 2000-Based Routing Table |
|
|
47 | (3) |
|
|
|
50 | (1) |
|
|
|
51 | (2) |
|
|
|
53 | (26) |
|
|
|
53 | (1) |
|
|
|
53 | (1) |
|
|
|
54 | (7) |
|
Interoperability with NetWare |
|
|
54 | (1) |
|
|
|
55 | (1) |
|
|
|
56 | (4) |
|
|
|
60 | (1) |
|
Using Gateway Service for NetWare |
|
|
61 | (6) |
|
Gateway Service for NetWare Overview |
|
|
61 | (1) |
|
Understanding Gateway Service for NetWare and Gateways |
|
|
61 | (1) |
|
Installing Gateway Service for NetWare |
|
|
62 | (2) |
|
|
|
64 | (2) |
|
Connecting Directly to NetWare Resources |
|
|
66 | (1) |
|
|
|
66 | (1) |
|
Using Client Service for NetWare |
|
|
67 | (3) |
|
|
|
67 | (1) |
|
Choosing Between Client Service for NetWare and Gateway Service for NetWare |
|
|
67 | (1) |
|
Configuring Client Service for NetWare |
|
|
68 | (1) |
|
|
|
69 | (1) |
|
Installing and Configuring NWLink |
|
|
70 | (9) |
|
Windows 2000 Professional and NetWare Connectivity |
|
|
70 | (1) |
|
|
|
71 | (1) |
|
Frame Type and Network Number |
|
|
72 | (2) |
|
|
|
74 | (1) |
|
Practice: Installing and Configuring NWLink |
|
|
75 | (1) |
|
|
|
76 | (1) |
|
|
|
77 | (2) |
|
Monitoring Network Activity |
|
|
79 | (20) |
|
|
|
79 | (1) |
|
|
|
79 | (1) |
|
Introducing Network Monitor |
|
|
80 | (3) |
|
Understanding Network Monitor |
|
|
80 | (1) |
|
Practice: Installing Network Monitor |
|
|
80 | (2) |
|
|
|
82 | (1) |
|
|
|
83 | (8) |
|
|
|
83 | (1) |
|
|
|
83 | (3) |
|
|
|
86 | (1) |
|
|
|
87 | (2) |
|
Practice: Capturing Frames with Network Monitor |
|
|
89 | (1) |
|
Network Monitor Performance Issues |
|
|
89 | (1) |
|
Detecting Network Monitor |
|
|
89 | (1) |
|
|
|
90 | (1) |
|
Windows 2000 Administration Tools |
|
|
91 | (8) |
|
Windows 2000 Administration Capabilities |
|
|
91 | (1) |
|
|
|
91 | (4) |
|
Simple Network Management Protocol (SNMP) |
|
|
95 | (2) |
|
|
|
97 | (1) |
|
|
|
98 | (1) |
|
|
|
99 | (38) |
|
|
|
99 | (1) |
|
|
|
99 | (1) |
|
Introducing and Enabling IPSec |
|
|
100 | (9) |
|
Internet Protocol Security |
|
|
100 | (1) |
|
|
|
101 | (1) |
|
|
|
101 | (3) |
|
|
|
104 | (1) |
|
|
|
104 | (3) |
|
|
|
107 | (1) |
|
|
|
108 | (1) |
|
|
|
109 | (10) |
|
Prerequisites for Implementing IPSec |
|
|
109 | (1) |
|
|
|
109 | (1) |
|
Configuring IPSec Policies |
|
|
109 | (1) |
|
|
|
110 | (1) |
|
|
|
111 | (1) |
|
|
|
112 | (3) |
|
|
|
115 | (1) |
|
|
|
116 | (1) |
|
|
|
117 | (1) |
|
|
|
118 | (1) |
|
Customizing IPSec Policies and Rules |
|
|
119 | (10) |
|
|
|
119 | (1) |
|
IP Filters and Filter Specifications |
|
|
120 | (1) |
|
Security Methods and Negotiation Policies |
|
|
121 | (1) |
|
|
|
122 | (1) |
|
IPSec Through NAT and Proxies |
|
|
122 | (1) |
|
Other IPSec Considerations |
|
|
123 | (2) |
|
|
|
125 | (1) |
|
Practice: Building a Custom IPSec Policy |
|
|
125 | (3) |
|
|
|
128 | (1) |
|
|
|
129 | (8) |
|
IPSec Management and Troubleshooting Tools |
|
|
129 | (2) |
|
|
|
131 | (1) |
|
Practice: Using Network Monitor to View Clear Text Traffic |
|
|
131 | (1) |
|
Practice: Using Network Monitor to View Encrypted Traffic |
|
|
132 | (1) |
|
Practice: Using Diagnostic Aids |
|
|
133 | (1) |
|
|
|
134 | (1) |
|
|
|
135 | (2) |
|
Resolving Network Host Names |
|
|
137 | (14) |
|
|
|
137 | (1) |
|
|
|
137 | (1) |
|
|
|
138 | (2) |
|
Windows 2000 Naming Schemes |
|
|
138 | (1) |
|
|
|
139 | (1) |
|
|
|
140 | (6) |
|
|
|
140 | (1) |
|
|
|
140 | (1) |
|
|
|
141 | (4) |
|
|
|
145 | (1) |
|
|
|
146 | (5) |
|
Understanding the Hosts File |
|
|
146 | (1) |
|
Advantage of Using a Hosts File |
|
|
147 | (1) |
|
Practice: Working with the Hosts File and DNS |
|
|
147 | (1) |
|
|
|
148 | (1) |
|
|
|
149 | (2) |
|
Implementing Domain Name System (DNS) |
|
|
151 | (34) |
|
|
|
151 | (1) |
|
|
|
151 | (1) |
|
|
|
152 | (6) |
|
|
|
152 | (1) |
|
|
|
152 | (1) |
|
|
|
153 | (1) |
|
|
|
154 | (1) |
|
|
|
155 | (1) |
|
|
|
156 | (1) |
|
|
|
157 | (1) |
|
Name Resolution and DNS Files |
|
|
158 | (6) |
|
|
|
158 | (1) |
|
|
|
158 | (1) |
|
|
|
159 | (1) |
|
|
|
160 | (1) |
|
|
|
160 | (1) |
|
|
|
161 | (1) |
|
|
|
162 | (1) |
|
|
|
162 | (1) |
|
|
|
163 | (1) |
|
Planning a DNS Implementation |
|
|
164 | (8) |
|
|
|
164 | (1) |
|
Registering with the Parent Domain |
|
|
164 | (1) |
|
Practice: Implementing DNS |
|
|
165 | (6) |
|
|
|
171 | (1) |
|
|
|
172 | (5) |
|
Practice: Installing the DNS Server Service |
|
|
172 | (2) |
|
Troubleshooting DNS with NSLOOKUP |
|
|
174 | (2) |
|
|
|
176 | (1) |
|
|
|
177 | (8) |
|
Configuring DNS Server Properties |
|
|
177 | (2) |
|
Adding DNS Domains and Zones |
|
|
179 | (1) |
|
Practice: Configuring a DNS Server |
|
|
180 | (1) |
|
|
|
181 | (1) |
|
Configuring Reverse Lookup |
|
|
182 | (1) |
|
|
|
182 | (1) |
|
|
|
183 | (2) |
|
Using Windows 2000 Domain Name Service |
|
|
185 | (14) |
|
|
|
185 | (1) |
|
|
|
185 | (1) |
|
|
|
186 | (6) |
|
|
|
186 | (3) |
|
Configuring Zones for Dynamic Update |
|
|
189 | (1) |
|
Practice: Enabling Dynamic Updates |
|
|
190 | (1) |
|
|
|
191 | (1) |
|
|
|
192 | (7) |
|
Overview of DNS Servers and Caching |
|
|
192 | (1) |
|
Implementing a Caching-Only Server |
|
|
192 | (2) |
|
Monitoring DNS Server Performance |
|
|
194 | (1) |
|
Practice: Testing a Simple Query on a DNS Server |
|
|
194 | (2) |
|
|
|
196 | (1) |
|
|
|
197 | (2) |
|
Implementing Windows Internet Name Service (WINS) |
|
|
199 | (28) |
|
|
|
199 | (1) |
|
|
|
199 | (1) |
|
|
|
200 | (6) |
|
Name Resolution with NetBIOS |
|
|
200 | (3) |
|
|
|
203 | (1) |
|
|
|
204 | (1) |
|
|
|
205 | (1) |
|
The WINS Resolution Process |
|
|
206 | (6) |
|
Resolving NetBIOS Names with WINS |
|
|
206 | (1) |
|
|
|
207 | (1) |
|
|
|
208 | (1) |
|
|
|
209 | (1) |
|
Name Query and Name Response |
|
|
210 | (1) |
|
|
|
211 | (1) |
|
|
|
212 | (8) |
|
|
|
212 | (1) |
|
Considerations for WINS Servers |
|
|
213 | (1) |
|
|
|
213 | (1) |
|
|
|
214 | (2) |
|
Practice: Configuring a WINS Client |
|
|
216 | (1) |
|
|
|
217 | (2) |
|
Managing and Monitoring WINS |
|
|
219 | (1) |
|
|
|
219 | (1) |
|
Configuring WINS Replication |
|
|
220 | (7) |
|
|
|
220 | (1) |
|
Configuring a WINS Server as a Push or Pull Partner |
|
|
220 | (1) |
|
Configuring Database Replication |
|
|
221 | (1) |
|
Practice: Performing WINS Database Replication |
|
|
222 | (2) |
|
Backing Up the WINS Database |
|
|
224 | (1) |
|
|
|
225 | (1) |
|
|
|
226 | (1) |
|
Implementing Dynamic Host Configuration Protocol (DHCP) |
|
|
227 | (34) |
|
|
|
227 | (1) |
|
|
|
227 | (1) |
|
Introducing and Installing DHCP |
|
|
228 | (9) |
|
|
|
228 | (1) |
|
|
|
229 | (4) |
|
|
|
233 | (1) |
|
|
|
234 | (2) |
|
|
|
236 | (1) |
|
|
|
236 | (1) |
|
|
|
237 | (8) |
|
|
|
237 | (1) |
|
Installing and Configuring a DHCP Server |
|
|
238 | (5) |
|
Implementing Multiple DHCP Servers |
|
|
243 | (1) |
|
|
|
244 | (1) |
|
Integrating DHCP with Naming Services |
|
|
245 | (4) |
|
|
|
245 | (3) |
|
|
|
248 | (1) |
|
Using DHCP with Active Directory |
|
|
249 | (2) |
|
Windows 2000 Integrated IP Management |
|
|
249 | (1) |
|
Rogue DHCP Server Detection Feature |
|
|
250 | (1) |
|
|
|
250 | (1) |
|
|
|
251 | (10) |
|
|
|
251 | (1) |
|
Troubleshooting DHCP Clients |
|
|
252 | (3) |
|
Troubleshooting DHCP Servers |
|
|
255 | (2) |
|
Moving the DHCP Server Database |
|
|
257 | (1) |
|
|
|
258 | (1) |
|
|
|
259 | (2) |
|
Providing Your Clients Remote Access Service (RAS) |
|
|
261 | (42) |
|
|
|
261 | (1) |
|
|
|
261 | (1) |
|
Introducing Remote Access Service |
|
|
262 | (8) |
|
Overview of Remote Access Service |
|
|
262 | (1) |
|
Routing and Remote Access Features |
|
|
263 | (2) |
|
Enabling Routing and Remote Access |
|
|
265 | (1) |
|
Practice: Installing a Routing and Remote Access Server |
|
|
266 | (1) |
|
Remote Access Versus Remote Control |
|
|
267 | (2) |
|
|
|
269 | (1) |
|
Configuring a Routing and Remote Access Server |
|
|
270 | (9) |
|
Allowing Inbound Connections |
|
|
270 | (1) |
|
Creating a Remote Access Policy (RAP) |
|
|
271 | (3) |
|
Practice: Creating a New Remote Access Policy |
|
|
274 | (1) |
|
Configuring a Remote Access Profile |
|
|
275 | (1) |
|
Practice: Creating a Policy Filter |
|
|
276 | (1) |
|
Configuring Bandwidth Allocation Protocol (BAP) |
|
|
277 | (1) |
|
|
|
278 | (1) |
|
Implementing IP Routing on a Remote Access Server |
|
|
279 | (7) |
|
|
|
279 | (1) |
|
Practice: Enabling and Configuring a Routing and Remote Access Server |
|
|
279 | (1) |
|
Updating the Routing Tables |
|
|
280 | (2) |
|
Implementing Demand-Dial Routing |
|
|
282 | (3) |
|
|
|
285 | (1) |
|
Supporting Virtual Private Networks |
|
|
286 | (6) |
|
|
|
286 | (2) |
|
Integrating VPN in a Routed Environment |
|
|
288 | (1) |
|
Integrating VPN Servers with the Internet |
|
|
288 | (2) |
|
Practice: Creating VPN Interfaces |
|
|
290 | (1) |
|
|
|
291 | (1) |
|
Supporting Multilink Connections |
|
|
292 | (2) |
|
|
|
292 | (1) |
|
|
|
292 | (1) |
|
|
|
293 | (1) |
|
Using Routing and Remote Access with DHCP |
|
|
294 | (2) |
|
Routing and Remote Access and DHCP |
|
|
294 | (1) |
|
|
|
294 | (1) |
|
Practice: Configuring the DHCP Relay Agent to Work over Routing and Remote Access |
|
|
295 | (1) |
|
|
|
295 | (1) |
|
Managing and Monitoring Remote Access |
|
|
296 | (7) |
|
Logging User Authentication and Accounting Requests |
|
|
296 | (2) |
|
|
|
298 | (1) |
|
|
|
299 | (1) |
|
|
|
300 | (1) |
|
|
|
300 | (1) |
|
|
|
301 | (1) |
|
|
|
302 | (1) |
|
Supporting Network Address Translation (NAT) |
|
|
303 | (24) |
|
|
|
303 | (1) |
|
|
|
303 | (1) |
|
|
|
304 | (10) |
|
Network Address Translation |
|
|
304 | (1) |
|
Public and Private Addresses |
|
|
305 | (2) |
|
|
|
307 | (2) |
|
NAT Processes in Windows 2000 Routing and Remote Access |
|
|
309 | (3) |
|
Additional NAT Routing Protocol Components |
|
|
312 | (1) |
|
|
|
313 | (1) |
|
Installing Internet Connection Sharing |
|
|
314 | (6) |
|
Internet Connection Sharing |
|
|
314 | (3) |
|
Internet Connection Sharing and NAT |
|
|
317 | (1) |
|
Troubleshooting Connection Sharing (NAT) |
|
|
318 | (1) |
|
|
|
319 | (1) |
|
Installing and Configuring NAT |
|
|
320 | (7) |
|
Network Address Translation Design Considerations |
|
|
320 | (4) |
|
Virtual Private Networks and NATs |
|
|
324 | (1) |
|
|
|
325 | (1) |
|
|
|
326 | (1) |
|
Implementing Certificate Services |
|
|
327 | (22) |
|
|
|
327 | (1) |
|
|
|
327 | (1) |
|
|
|
328 | (5) |
|
|
|
328 | (2) |
|
Enterprise and Stand-Alone CAs |
|
|
330 | (1) |
|
|
|
331 | (1) |
|
|
|
332 | (1) |
|
Installing and Configuring Certificate Authority |
|
|
333 | (9) |
|
|
|
333 | (1) |
|
|
|
334 | (1) |
|
|
|
334 | (3) |
|
Practice: Installing a Stand-Alone Subordinate CA |
|
|
337 | (2) |
|
|
|
339 | (1) |
|
Certificate and Key Recovery |
|
|
339 | (2) |
|
|
|
341 | (1) |
|
|
|
342 | (7) |
|
|
|
342 | (1) |
|
|
|
342 | (1) |
|
|
|
342 | (1) |
|
|
|
342 | (1) |
|
How a Certificate Is Issued |
|
|
343 | (1) |
|
|
|
343 | (1) |
|
Practice: Revoking a Certificate |
|
|
344 | (1) |
|
|
|
344 | (1) |
|
Practice: Changing a Recovery Policy |
|
|
345 | (1) |
|
|
|
346 | (1) |
|
|
|
347 | (2) |
|
Implementing Enterprise-Wide Network Security |
|
|
349 | (26) |
|
|
|
349 | (1) |
|
|
|
349 | (1) |
|
Implementing Network Security |
|
|
350 | (7) |
|
Planning for Network Security |
|
|
350 | (3) |
|
Planning Distributed Network Security |
|
|
353 | (1) |
|
Internet Connection Issues |
|
|
354 | (1) |
|
|
|
355 | (1) |
|
|
|
356 | (1) |
|
Configuring Routing and Remote Access Security |
|
|
357 | (7) |
|
Overview of Remote Access |
|
|
357 | (1) |
|
Configuring Protocols for Security |
|
|
358 | (1) |
|
Practice: Using Security Protocols for a Virtual Private Network Connection |
|
|
359 | (1) |
|
Creating Remote Access Policies |
|
|
360 | (1) |
|
Using Encryption Protocols |
|
|
361 | (2) |
|
|
|
363 | (1) |
|
Monitoring Security Events |
|
|
364 | (11) |
|
Monitoring Your Network Security |
|
|
364 | (1) |
|
Using Event Viewer to Monitor Security |
|
|
365 | (1) |
|
Practice: Recording Failed Logon Attempts |
|
|
365 | (2) |
|
Practice: Viewing the Security Log |
|
|
367 | (1) |
|
|
|
368 | (1) |
|
The IPSec Monitor Utility |
|
|
369 | (1) |
|
Monitoring Security Overhead |
|
|
370 | (1) |
|
|
|
371 | (1) |
|
|
|
372 | (3) |
| Appendix A Questions and Answers |
|
375 | (14) |
| Glossary |
|
389 | (26) |
| Index |
|
415 | |