Hello Customers,
In this post, I will go through the steps to configure to deploy Network Policy Server (NPS) based RADIUS server to authenticate and authorize the remote access connections coming from RRAS based VPN server. I will try to go through different policy parameters in order to point you to various important policy options in NPS server role. However for your deployment, you may be adding/deleting more these depending upon your requirements.
Radius server is used to perform AAA i.e. authentication, authorization and accounting of the remote access user. This post gives details on Network Policy server (NPS) role acting as RADIUS server – installed on a different machine from the one running RRAS server.
Let us try to configure NPS server role as a RADIUS server on a Windows server 2008 R2 machine. To do that, you need to first install the NPS server role:
To configure NPS based Radius server to authenticate VPN based remote access connection, follow these steps:
Note: This needs to be configured only if the RADIUS Client and NPS server are running on separate machines.
For this example scenario where RADIUS server is authentication the connection locally, skip this configuration.
Right click New – to create a new CRP. The specific fields in Connection Request policy of interest are: -
For this example scenario where RADIUS server is authentication the connection locally, select “Authenticate requests on this server”.
For this example scenario, let the authentication methods be set at the policy level.
Right click New – to create a new network policy. A network access policy has different fields, however some of the common fields are given below: -
Note: The mandatory ones that are required for remote access connection to pass through are highlighted in bold: -
Note: This list MUST match the authentication methods configured inside RRAS server.
References: For further details on Radius configuration, please refer to this article. For further details on remote access policy configuration, please refer to this document.
Remote Access Deployment – Part 1: Configuring Remote Access Clients
Remote Access Deployment – Part 2: Configuring RRAS as a VPN server
With Regards,
Samir Jain
Senior Program Manager
Windows Networking
[This posting is provided “AS IS” with no warranties, and confers no rights.]