Once you perform the setup in the DirectAccess console, you need to configure firewall rules to enable NAP for DirectAccess. When you run the DirectAccess setup through the console, it creates 6 firewall rules, 3 for the client and 3 for the server. You will need to modify these rules for your configuration. These rules can’t be configured through the Windows Firewall with Advanced Security snap-in; instead you need to configure the rules via the command line.
- On the DA server policy , on the rule named “DirectAccess Policy-DaServerToCorp” you need to set the following:
- Auth1 Health cert = yes
- Apply Authorization = yes
- Auth 1 Cert mapping = yes
- On the DA server policy, on the rule named “DirectAccess Policy-DaServerToDnsDc” you need to include the IPv6 address of the HRA server to endpoint1.
- On the DA client policy, on the rule named “DirectAccess Policy-ClientToDnsDc” you need to include the IPv6 address of the HRA server to endpoint2.
- On the client and DA server, if you don’t need a tunnel for management server you can remove “DirectAccess Policy-ClientToMgmt” and “DirectAccess Policy-DaServerToMgmt.”










