Re: Locking down IAS and NAS

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Thomas K (thomas_at_kuborn.be)
Date: 02/25/05


Date: Fri, 25 Feb 2005 17:25:10 +0100

Hey Timo,

I think you're right that you cannot use "NAS-PORT" as a policy-match
condition :(

I think you could use authentication-type as an alternate criteria. AFAIK,
PAP will be used to authenticate telnet/ssh while VPN will use some other
auth type...

Cheers,

/T

"Timo" <timo@theglens.net> wrote in message
news:1109341242.272664.130590@o13g2000cwo.googlegroups.com...
> Hey Tom
>
> Thanks for replying. I didnt know about the Cisco VSA but that is nice
> tidbid to know about. I was more hoping that MS IAS would support the
> RFC2865 section 5.5 NAS-Port.
>
> You say " Sure, IAS support radius attribute 'nas-port' by default."
>
> But when I go into the Policy Conditions and try and add a NAS-Port
> attribute its not there. NAS-IP-Address really isnt gonna help
> because I need to differenciate between different services on the same
> box , IP addr. Basically I need to give permission to some users to be
> able to use the VPN router & Client , they authenticate via RADIUS, Im
> hoping that I can get the RADIUS box to send an Access-Reject when
> those same users to be able to login to the VPN router w\ telnet or
> SSH. Any ideas .
>
> Thanks again.
>
>
> Timo
>



Relevant Pages

  • OpenBSD VPN server with active directory auth
    ... I know OpenBSD vpn does not auth with LDAP directly. ... I heard Active Directory uses kerberos authentication too, ...
    (comp.unix.bsd.openbsd.misc)
  • Re: VPN PPC 2003 Premium problem
    ... There's no documentation with a clear information of the ... entire VPN authentication process of PPC 2003. ... an answer that PAP isn't supported to L2TP auth. ...
    (microsoft.public.pocketpc.developer)
  • Re: Cant auth. on remote server using cable ISP dhcp settings
    ... > Maybe I'm missing something here, but are you using a VPN client or TSWeb, ... >> laptop cannot log on to any of the websites. ... so I configured my home dhcp to pass me the same as I get ... >> ping by fqdn and get a response, but it just dies on the auth part. ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: Locking down IAS and NAS
    ... Couldn't you easily change the VPN authentication protocol to something ... > Your right that telnet and ssh are using PAP but the VPN is as well. ...
    (microsoft.public.internet.radius)
  • VPN IPSEC/L2TP + PAP auth. Need definitive answer!
    ... I'm trying to stablish a VPN session between a PPC2003 Ipaq and a VPN server ... checkbox to use PAP in L2TP, and it works in the same setup), but the PPC ... Neither I can find a definitve answer if some ...
    (microsoft.public.pocketpc.developer.networking)