a little bit complex question about RADIUS and groups



Hi,

i need a few thougths from another point of view.
for suere, expirience or a complete solution are although welcome.

we now have several different opinions , even form microsoft itsself.

for some reason (token) we need to use radius to authenticate vpn-user.

ISA 2004 SP2 in AD 2003

Computer are partly not domain-members and they are geographicly dispersd,
so we fireclient wouldn´t be a prefered solution.

up to here, everything is fine.

now we need to give different users different rights, preferd is based on
groups.

opinions up to now:
a) great, runs
b) fine, should be running - but theres no way to give the
token(radius)-user different rules in isa - we need to (however) add user
who connect without token, so that we can use AD-groups for them
c) works but.... , needs per AD-group (aka RADIUS-rule) one IAS (aka RRAS) -
so that based on different IP´s and portforwarding different RRAS-services
are used
d) maybe working, if you get a authentification somehow, maybe via a
webpublishing (?!??)
e) doesn´t work
f) don´t work

base for all tougths:
http://www.microsoft.com/technet/isa/2004/plan/isaradiusremote.mspx
http://www.microsoft.com/technet/isa/2004/plan/owa_radius.mspx#_Appendix_B:_Best
http://technet2.microsoft.com/WindowsServer/en/library/fc353fbb-4df4-4b36-b14a-20cbbad434941033.mspx?mfr=true
http://www.microsoft.com/technet/isa/2004/help/FW_VPNRadius.mspx?mfr=true


short version:
VPN-User are RADIUS authetificated
in addition isa-rules(paketfilter) are need , based on user or (better)
groupbased rulse


cheers,
Ralf





.



Relevant Pages

  • RE: App FW for isa2K4 2K6
    ... A1 - use ISA 2006. ... user base? ... A3 - you can find lots of opinions on this (and several other unrelated ... On Behalf Of Security ...
    (Focus-Microsoft)
  • Re: ISA and Public DNS
    ... Alberto, Italy ... > Anyone have any opinions about running a public DNS sever on the same box ... Can ISA make itself a DMZ in some form? ...
    (microsoft.public.isa)
  • ISA and Public DNS
    ... Anyone have any opinions about running a public DNS sever on the same box ... I only have a single W2K3 license and would love to make this ... Can ISA make itself a DMZ in some form? ...
    (microsoft.public.isa)

Loading