Configure DirectAccess to use a Load-Balanced NLS
- Last Updated: August 5, 2025
- 1 minute read
- LoadMaster
- LoadMaster GA
- Documentation
Note: Clients on the internal network will lose connectivity to the domain if the NLS is unavailable. If enabling load balancing for NLS for an existing DirectAccess deployment, it is recommended that the NLS be reachable by clients and have a valid SSL certificate available during the transition. As the NLS hostname will be changing when this happens, a hostname mismatch will occur on the original NLS during the cutover, causing clients to fail the NLS check. This issue can be addressed by assigning a multi-SAN certificate to the NLS that includes both the original NLS name and the new load-balanced name prior to implementing this change.
To configure DirectAccess to use a load-balanced NLS, follow the steps below:
- In the internal DNS, create a DNS record with a hostname that resolves to the virtual IP address configured for the NLS Virtual Service.
- In the Remote Access Management console, click DirectAccess and VPN under the Configuration node in the navigation tree.
- In the Step 3
Infrastructure Servers box, click Edit.
- Enter the new NLS URL and click Validate.
- Ensure that connectivity to the URL is validated successfully before proceeding.
- Save and apply the configuration.