On the Windows RRAS server, open the Remote Access Management console (rrasmgmt.msc) and perform the following steps:

  1. Right-click the VPN server and select Properties.
  2. Select the Security tab.
  3. Select the public SSL certificate in the SSL Certificate Binding box.
  4. Select the option to Use HTTP.
  5. Click Ok.
  6. Click Yes when prompted to restart the service.
  7. Repeat these steps on each RRAS server in the cluster.

Note: It is assumed that the public SSL certificate is installed on the RRAS server when performing the steps above. In some cases, installing the public SSL certificate on the RRAS server may not be possible. In this scenario the administrator must manually configure the RRAS server to support SSL offload for SSTP. For further details, refer to the following page: Always On VPN SSTP Load Balancing and SSL Offload.