Load Balancing DirectAccess

Load Balancing Direct Access ImageDirectAccess in Windows Server 2012 R2 is a paradigm shift in the way secure remote access is provided for managed Windows clients. DirectAccess is made up of Windows platform technologies that are used to provide seamless, transparent, and always on remote corporate network connectivity. DirectAccess connectivity is established automatically any time the user has access to the public Internet. The user experience is exactly the same outside the network as it is inside, allowing them to access on-premises data and applications in a familiar manner.

High Availability Challenges

As more organizations begin to adopt DirectAccess in Windows Server 2012 R2, users are becoming increasingly dependent on this remote access technology to stay productive when they are away from the office. To ensure the highest levels of availability, network engineers should identify and eliminate any potential single points of failure in the solution.

DirectAccess High Availability Features

DirectAccess includes several features designed to eliminate single points of failure. DirectAccess includes support for high availability arrays using Windows Network Load Balancing (WNLB) and third-party external load balancers. DirectAccess also includes support for geographic redundancy with multisite configuration.

Windows Network Load Balancing

WNLB suffers from many serious drawbacks and should be avoided in production environments. WNLB uses layer two broadcasts for heartbeat communication, which generates an excessive amount of noise on the wire. WNLB also lacks application awareness, which may result in network traffic being delivered to a host that is not capable of handling those requests. In addition, WNLB provides limited granularity and control for traffic distribution.

 KEMP Load Balancers and DirectAccess

The KEMP LoadMaster load balancer is an excellent solution for providing high availability for Windows Server 2012 R2 DirectAccess. Using the LoadMaster to provide load balancing for DirectAccess server arrays provides numerous benefits over WNLB, including better service health checks and granular traffic delivery. In addition, the LoadMaster GEO feature can be leveraged to provide more accurate site selection for clients in a multisite configuration. Also, the LoadMaster can be configured to provide essential high availability for the Network Location Service (NLS), eliminating potential service disruptions caused by NLS system outages.

Getting started with the KEMP LoadMaster load balancer is simple. You can download a fully functional 30 day free trial here. Performing the initial configuration on the LoadMaster is easy. You’ll find a quick overview for the basic setup at the end of this blog post. Once you’ve completed the installation and configuration of your LoadMaster, be sure to download the Windows Server 2012 R2 DirectAccess Deployment Guide here. This guide includes detailed, prescriptive guidance for configuring the KEMP LoadMaster load balancer for DirectAccess.


DirectAccess is a compelling remote access solution that can be used to provide secure remote access with unrivaled ease of use. As users become more reliant on DirectAccess for their productivity, building a scalable and highly available DirectAccess solution is critical. Avoid using WNLB and implement the KEMP LoadMaster load balancer to provide load balancing and high availability for DirectAccess and network location servers, as well as geographic redundancy. This will ensure the best experience for users and administrators alike.

Richard Hicks

Richard Hicks

Richard Hicks is a network and information security expert specializing in Microsoft technologies. He is a Microsoft Enterprise Security MVP and the founder and principal consultant for Richard M. Hicks Consulting. Richard has deployed secure remote access solutions for some of the largest organizations in the world. Learn more about DirectAccess by visiting http://directaccess.richardhicks.com.

More Posts

Follow Me:
TwitterFacebookLinkedInGoogle Plus