{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-250-review-accepted-vpn-protocols-after-installing-or-upgrading-rras/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-250-review-accepted-vpn-protocols-after-installing-or-upgrading-rras/",
        "slug": "dse-20260908-250-review-accepted-vpn-protocols-after-installing-or-upgrading-rras",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-250-review-accepted-vpn-protocols-after-installing-or-upgrading-rras/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-250-review-accepted-vpn-protocols-after-installing-or-upgrading-rras.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-250-review-accepted-vpn-protocols-after-installing-or-upgrading-rras/"
        },
        "title": "Review accepted VPN protocols after installing or upgrading RRAS",
        "summary": "Why should a new RRAS deployment and an upgraded server be checked separately?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:13:01+00:00",
        "modified_at": "2026-09-08T18:29:34+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 2,
        "word_count": 232,
        "potentially_affected": "Administrators configuring Windows Server Routing and Remote Access as a VPN server.",
        "dse_recommendation": "Have the remote-access owner list the protocols intended to remain available and the clients that require them.",
        "primary_source": {
            "name": "How to install and configure Remote Access (RAS) as a VPN server",
            "url": "https://learn.microsoft.com/en-us/windows-server/remote/remote-access/get-started-install-ras-as-vpn",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft&#8217;s setup procedure configures IKEv2 and a static address pool for authorized VPN clients. Beginning with Windows Server 2025, new RRAS setups do not accept PPTP or L2TP by default, although those protocols can be enabled. An in-place upgrade preserves existing protocol behavior, so a server previously accepting PPTP or L2TP can continue doing so after the upgrade. <a href=\"https://learn.microsoft.com/en-us/windows-server/remote/remote-access/get-started-install-ras-as-vpn\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Record whether the server is newly configured or upgraded from an existing RRAS installation. Inspect its actual protocol settings rather than inferring them from the operating-system version. Review the client population and approved VPN design before changing accepted connections.</p>\n<h2>DSE recommendation</h2>\n<p>Have the remote-access owner list the protocols intended to remain available and the clients that require them. Review the current port configuration against that decision, along with the assigned client address pool. Schedule removal of an unapproved protocol with its affected users identified and an alternative connection tested. Keep server protocol decisions separate from user-authorization policy and client-tunnel deployment.</p>\n<h2>Verification</h2>\n<p>Test a permitted protocol from a representative client and confirm the assigned address is within the intended pool. Test that a deliberately disabled protocol is not accepted. Repeat this review after an in-place upgrade, preserving the before-and-after configuration so retained legacy behavior is visible to the service owner.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/remote/remote-access/get-started-install-ras-as-vpn\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: How to install and configure Remote Access (RAS) as a VPN server</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft’s setup procedure configures IKEv2 and a static address pool for authorized VPN clients. Beginning with Windows Server 2025, new RRAS setups do not accept PPTP or L2TP by default, although those protocols can be enabled. An in-place upgrade preserves existing protocol behavior, so a server previously accepting PPTP or L2TP can continue doing so after the upgrade. Microsoft Learn.\nApplicability\nRecord whether the server is newly configured or upgraded from an existing RRAS installation. Inspect its actual protocol settings rather than inferring them from the operating-system version. Review the client population and approved VPN design before changing accepted connections.\nDSE recommendation\nHave the remote-access owner list the protocols intended to remain available and the clients that require them. Review the current port configuration against that decision, along with the assigned client address pool. Schedule removal of an unapproved protocol with its affected users identified and an alternative connection tested. Keep server protocol decisions separate from user-authorization policy and client-tunnel deployment.\nVerification\nTest a permitted protocol from a representative client and confirm the assigned address is within the intended pool. Test that a deliberately disabled protocol is not accepted. Repeat this review after an in-place upgrade, preserving the before-and-after configuration so retained legacy behavior is visible to the service owner.\nOfficial references\nMicrosoft Learn: How to install and configure Remote Access (RAS) as a VPN server. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft’s setup procedure configures IKEv2 and a static address pool for authorized VPN clients. Beginning with Windows Server 2025, new RRAS setups do not accept PPTP or L2TP by default, although those protocols can be enabled. An in-place upgrade preserves existing protocol behavior, so a server previously accepting PPTP or L2TP can continue doing so after the upgrade. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/remote/remote-access/get-started-install-ras-as-vpn).\n\n## Applicability\n\nRecord whether the server is newly configured or upgraded from an existing RRAS installation. Inspect its actual protocol settings rather than inferring them from the operating-system version. Review the client population and approved VPN design before changing accepted connections.\n\n## DSE recommendation\n\nHave the remote-access owner list the protocols intended to remain available and the clients that require them. Review the current port configuration against that decision, along with the assigned client address pool. Schedule removal of an unapproved protocol with its affected users identified and an alternative connection tested. Keep server protocol decisions separate from user-authorization policy and client-tunnel deployment.\n\n## Verification\n\nTest a permitted protocol from a representative client and confirm the assigned address is within the intended pool. Test that a deliberately disabled protocol is not accepted. Repeat this review after an in-place upgrade, preserving the before-and-after configuration so retained legacy behavior is visible to the service owner.\n\n## Official references\n\n[Microsoft Learn: How to install and configure Remote Access (RAS) as a VPN server](https://learn.microsoft.com/en-us/windows-server/remote/remote-access/get-started-install-ras-as-vpn). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-250-review-accepted-vpn-protocols-after-installing-or-upgrading-rras/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-250-review-accepted-vpn-protocols-after-installing-or-upgrading-rras/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-250-review-accepted-vpn-protocols-after-installing-or-upgrading-rras/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Review accepted VPN protocols after installing or upgrading RRAS",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-250-review-accepted-vpn-protocols-after-installing-or-upgrading-rras/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-250-review-accepted-vpn-protocols-after-installing-or-upgrading-rras/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-250-review-accepted-vpn-protocols-after-installing-or-upgrading-rras/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-250-review-accepted-vpn-protocols-after-installing-or-upgrading-rras/",
                "headline": "Review accepted VPN protocols after installing or upgrading RRAS",
                "description": "Why should a new RRAS deployment and an upgraded server be checked separately?",
                "abstract": "Why should a new RRAS deployment and an upgraded server be checked separately?",
                "articleBody": "Source facts\nMicrosoft’s setup procedure configures IKEv2 and a static address pool for authorized VPN clients. Beginning with Windows Server 2025, new RRAS setups do not accept PPTP or L2TP by default, although those protocols can be enabled. An in-place upgrade preserves existing protocol behavior, so a server previously accepting PPTP or L2TP can continue doing so after the upgrade. Microsoft Learn.\nApplicability\nRecord whether the server is newly configured or upgraded from an existing RRAS installation. Inspect its actual protocol settings rather than inferring them from the operating-system version. Review the client population and approved VPN design before changing accepted connections.\nDSE recommendation\nHave the remote-access owner list the protocols intended to remain available and the clients that require them. Review the current port configuration against that decision, along with the assigned client address pool. Schedule removal of an unapproved protocol with its affected users identified and an alternative connection tested. Keep server protocol decisions separate from user-authorization policy and client-tunnel deployment.\nVerification\nTest a permitted protocol from a representative client and confirm the assigned address is within the intended pool. Test that a deliberately disabled protocol is not accepted. Repeat this review after an in-place upgrade, preserving the before-and-after configuration so retained legacy behavior is visible to the service owner.\nOfficial references\nMicrosoft Learn: How to install and configure Remote Access (RAS) as a VPN server. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:13:01+00:00",
                "dateModified": "2026-09-08T18:29:34+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-250-review-accepted-vpn-protocols-after-installing-or-upgrading-rras/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-250-review-accepted-vpn-protocols-after-installing-or-upgrading-rras/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Review accepted VPN protocols after installing or upgrading RRAS"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 232,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "How to install and configure Remote Access (RAS) as a VPN server",
                    "url": "https://learn.microsoft.com/en-us/windows-server/remote/remote-access/get-started-install-ras-as-vpn"
                }
            }
        ]
    }
}