# Review accepted VPN protocols after installing or upgrading RRAS

> Why should a new RRAS deployment and an upgraded server be checked separately?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-250-review-accepted-vpn-protocols-after-installing-or-upgrading-rras/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:13:01+00:00
- Modified: 2026-09-08T18:29:34+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Why should a new RRAS deployment and an upgraded server be checked separately?

## Potentially affected

Administrators configuring Windows Server Routing and Remote Access as a VPN server.

## DSE recommendation

Have the remote-access owner list the protocols intended to remain available and the clients that require them.

## Article

## Source facts

Microsoft’s setup procedure configures IKEv2 and a static address pool for authorized VPN clients. Beginning with Windows Server 2025, new RRAS setups do not accept PPTP or L2TP by default, although those protocols can be enabled. An in-place upgrade preserves existing protocol behavior, so a server previously accepting PPTP or L2TP can continue doing so after the upgrade. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/remote/remote-access/get-started-install-ras-as-vpn).

## Applicability

Record whether the server is newly configured or upgraded from an existing RRAS installation. Inspect its actual protocol settings rather than inferring them from the operating-system version. Review the client population and approved VPN design before changing accepted connections.

## DSE recommendation

Have the remote-access owner list the protocols intended to remain available and the clients that require them. Review the current port configuration against that decision, along with the assigned client address pool. Schedule removal of an unapproved protocol with its affected users identified and an alternative connection tested. Keep server protocol decisions separate from user-authorization policy and client-tunnel deployment.

## Verification

Test a permitted protocol from a representative client and confirm the assigned address is within the intended pool. Test that a deliberately disabled protocol is not accepted. Repeat this review after an in-place upgrade, preserving the before-and-after configuration so retained legacy behavior is visible to the service owner.

## Official references

[Microsoft Learn: How to install and configure Remote Access (RAS) as a VPN server](https://learn.microsoft.com/en-us/windows-server/remote/remote-access/get-started-install-ras-as-vpn). Source reviewed September 8, 2026.

## Primary reference

- Name: How to install and configure Remote Access (RAS) as a VPN server
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/remote/remote-access/get-started-install-ras-as-vpn
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Review accepted VPN protocols after installing or upgrading RRAS,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-250-review-accepted-vpn-protocols-after-installing-or-upgrading-rras/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
