You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows Server 2019单网卡环境下DirectAccess公网IP配置失败求助

Windows Server 2019单网卡环境下DirectAccess公网IP配置失败求助

Hi there, let's break down why you're hitting that "invalid public IP" error and walk through the steps to get your single-NIC DirectAccess setup working on Windows Server 2019. I've helped folks with similar home lab setups before, so let's take this step by step.

First, why you're seeing the "invalid public IP" error

The most common reasons for this in your setup are:

  • Your public IP is dynamic (not static) and DirectAccess can't validate it reliably
  • Your server is behind a router, so you haven't set up proper port forwarding to let external traffic reach it
  • The DirectAccess wizard can't reach or verify your public IP from the server or external network

Step 1: Confirm your public IP details

First things first:

  • Make sure your ISP provided a static public IP (201.114.X.X in your example). DirectAccess relies on a fixed public IP to work consistently—dynamic IPs require extra dynamic DNS setup which complicates things for a single-NIC setup.
  • Verify the public IP is active: Use a device outside your home network (like a phone on cellular data) to check your public IP via a tool like whatismyip.com and confirm it matches what your ISP gave you.

Step 2: Configure your home router correctly

Since your server is behind a router (edge network), you need to route external DirectAccess traffic to your server's internal IP (192.168.1.100):

  • Log into your router's admin panel and set up port forwarding for these ports to 192.168.1.100:
    • UDP 500 (for IKEv1)
    • UDP 4500 (for IPsec NAT-T)
    • TCP 443 (for HTTPS/IPsec)
  • Enable IPsec Passthrough (sometimes labeled VPN Passthrough) in your router settings—this ensures IPsec traffic can pass through to your server.
  • Disable any strict NAT filtering or firewall modes that might block incoming VPN/DirectAccess traffic.

Step 3: Fix the DirectAccess configuration wizard

Now let's get past that stuck screen:

  1. Open the Remote Access Management Console (Server Manager → Remote Access → Configure Remote Access).
  2. Choose "DirectAccess and VPN (RAS)" then "Deploy DirectAccess only".
  3. On the Network Topology page, select Behind an edge device (with a single network adapter) and click Next.
  4. On the Public Name or IP Address page:
    • Enter your static public IP (201.114.X.X) directly into the field.
    • Click the Validate button—this checks if the wizard can reach and confirm the IP is valid.
    • If validation fails: Double-check your router's port forwarding rules, ensure your public IP is static, and use an external port checker tool (from outside your home network) to verify TCP 443 is open on your public IP.

Step 4: Additional checks to avoid post-setup issues

  • DNS Configuration: Make sure your server's network adapter is set to use itself as the DNS server (192.168.1.100)—since it's both a DC and DNS server, this is critical for DirectAccess to resolve internal resources.
  • Group Policy: Confirm the DirectAccess client GPO is applied to your laptops/PCs. Open Group Policy Management and check that the GPO (named something like DirectAccess Client Settings) is linked to the OU containing your domain-joined devices.
  • Firewall Rules: Verify Windows Defender Firewall on the server has enabled the Remote Access and IPsec inbound rules—these should be enabled automatically when you install the Remote Access role, but it's worth double-checking via wf.msc.

If you still run into issues

  • If your public IP is dynamic: Switch to a dynamic DNS service (like No-IP) and enter the dynamic DNS domain name instead of the IP in the DirectAccess wizard. The wizard will validate the domain's DNS resolution instead of the IP.
  • Check for blocked ports: Some ISPs block UDP 500/4500. Reach out to your ISP to confirm these ports are allowed on your line.
  • Ensure no extra IPs on the server: Make sure your server's single network adapter only has the 192.168.1.100 IP—extra IPs can confuse the DirectAccess wizard.

备注:内容来源于stack exchange,提问作者Assist IT

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.23 11:02:38