What you need to know
Why should a new RRAS deployment and an upgraded server be checked separately?
Potentially affected
Administrators configuring Windows Server Routing and Remote Access as a VPN server.
DSE recommendation
Have the remote-access owner list the protocols intended to remain available and the clients that require them.
Source facts
Microsoft’s setup procedure configures IKEv2 and a static address pool for authorized VPN clients. Beginning with Windows Server 2025, new RRAS setups do not accept PPTP or L2TP by default, although those protocols can be enabled. An in-place upgrade preserves existing protocol behavior, so a server previously accepting PPTP or L2TP can continue doing so after the upgrade. Microsoft Learn.
Applicability
Record whether the server is newly configured or upgraded from an existing RRAS installation. Inspect its actual protocol settings rather than inferring them from the operating-system version. Review the client population and approved VPN design before changing accepted connections.
DSE recommendation
Have the remote-access owner list the protocols intended to remain available and the clients that require them. Review the current port configuration against that decision, along with the assigned client address pool. Schedule removal of an unapproved protocol with its affected users identified and an alternative connection tested. Keep server protocol decisions separate from user-authorization policy and client-tunnel deployment.
Verification
Test a permitted protocol from a representative client and confirm the assigned address is within the intended pool. Test that a deliberately disabled protocol is not accepted. Repeat this review after an in-place upgrade, preserving the before-and-after configuration so retained legacy behavior is visible to the service owner.
Official references
Microsoft Learn: How to install and configure Remote Access (RAS) as a VPN server. Source reviewed September 8, 2026.
Review the official source
How to install and configure Remote Access (RAS) as a VPN server · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE