70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network, Enhanced Chapter 11: Internet Authentication Service.

Slides:



Advertisements
Similar presentations
11 TROUBLESHOOTING Chapter 12. Chapter 12: TROUBLESHOOTING2 OVERVIEW  Determine whether a network communications problem is related to TCP/IP.  Understand.
Advertisements

Module 10: Troubleshooting Network Access. Overview Troubleshooting Network Access Resources Troubleshooting LAN Authentication Troubleshooting Remote.
1 Routing and Remote Access Service (Week 15, Friday 4/21/2006) © Abdou Illia, Spring 2006.
Module 5: Configuring Access for Remote Clients and Networks.
1 Objectives Configure Network Access Services in Windows Server 2008 RADIUS 1.
1 Configuring Virtual Private Networks for Remote Clients and Networks.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 11: Planning Network Access.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 5: Planning, Configuring, And Troubleshooting DHCP.
MCDST : Supporting Users and Troubleshooting a Microsoft Windows XP Operating System Chapter 14: Troubleshooting Remote Connections.
Hands-On Microsoft Windows Server 2003 Administration Chapter 11 Administering Remote Access Services.
11 ADMINISTERING MICROSOFT WINDOWS SERVER 2003 Chapter 2.
70-270, MCSE/MCSA Guide to Installing and Managing Microsoft Windows XP Professional and Windows Server 2003 Chapter Twelve Implementing Terminal.
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
Chapter 16 AAA. AAA Components  AAA server –Authenticates users accessing a device or network –Authorizes user to perform specific activities –Performs.
Hands-On Microsoft Windows Server 2003 Networking Chapter 1 Windows Server 2003 Networking Overview.
Hands-On Microsoft Windows Server Connecting Through Terminal Services Terminal server – Enables clients to run services and software applications.
Using RADIUS Within the Framework of the School Environment Charles Bolen Systems Engineer December 6, 2011.
Virtual Private Network (VPN) © N. Ganesan, Ph.D..
Overview of Routing and Remote Access Service (RRAS) When RRAS was implemented in Microsoft Windows NT 4.0, it added support for a number of features.
Chapter 11: Dial-Up Connectivity in Remote Access Designs
Hands-On Microsoft Windows Server 2008 Chapter 8 Managing Windows Server 2008 Network Services.
Implementing RADIUS AAA Phil & Rick. Content Terms and Concepts Access Control What is AAA? Benefits of AAA What is RADIUS? Microsoft IAS Overview Installation.
Using RADIUS Within the Framework of the School Environment Ed Register Consultant April 6, 2011.
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 10: Remote Access.
1 Microsoft Windows NT 4.0 Authentication Protocols Password Authentication Protocol (PAP) Challenge Handshake Authentication Protocol (CHAP) Microsoft.
VPN Scenarios © N. Ganesan, Ph.D.. Chapter Objectives.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 9 Network Policy and Access Services in Windows Server 2008.
Virtual Private Networks (Tunnels). When Are VPN Tunnels Used? VPN with PPTP tunnel Used if: All routers support VPN tunnels You are using MS-CHAP or.
Guide to MCSE , Enhanced 1 Activity 10-1: Restarting Windows Server 2003 Objective: to restart Windows Server 2003 Start  Shut Down  Restart Configure.
Course 6421A Module 7: Installing, Configuring, and Troubleshooting the Network Policy Server Role Service Presentation: 60 minutes Lab: 60 minutes Module.
Configuring Routing and Remote Access(RRAS) and Wireless Networking
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 9: Securing Network Traffic Using IPSec.
Module 8: Configuring Virtual Private Network Access for Remote Clients and Networks.
Module 9: Planning Network Access. Overview Introducing Network Access Selecting Network Access Connection Methods Selecting a Remote Access Policy Strategy.
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 12: Routing.
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 7: Domain Name System.
Module 10: Configuring Windows XP Professional to Operate in Microsoft Networks.
70-411: Administering Windows Server 2012
Objectives Configure routing in Windows Server 2008 Configure Routing and Remote Access Services in Windows Server 2008 Network Address Translation 1.
1 Chapter Overview Using the New Connection Wizard to configure network and Internet connections Using the New Connection Wizard to configure outbound.
1 Week 6 – NPS and RADIUS Install and Configure a Network Policy Server Configure RADIUS Clients and Servers NPS Authentication Methods Monitor and Troubleshoot.
20411B 8: Installing, Configuring, and Troubleshooting the Network Policy Server Role Presentation: 60 minutes Lab: 60 minutes After completing this module,
1 Chapter 12: VPN Connectivity in Remote Access Designs Designs That Include VPN Remote Access Essential VPN Remote Access Design Concepts Data Protection.
Module 11: Remote Access Fundamentals
MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # ) Chapter Four Windows Server 2008 Remote Desktop Services,
Hands-On Microsoft Windows Server Introduction to Remote Access Routing and Remote Access Services (RRAS) –Enable routing and remote access through.
5.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 5: Planning.
Module 11: Implementing ISA Server 2004 Enterprise Edition.
MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # ) Chapter Five Windows Server 2008 Remote Desktop Services,
Working with Users and Groups Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Introducing User Account Control Configure and troubleshoot.
Windows Server 2003 La migrazione da Windows NT 4.0 a Windows Server 2003 Relatore: MCSE - MCT.
1 Week #5 Routing and NAT Network Overview Configuring Routing Configuring Network Address Translation Troubleshooting Routing and Remote Access.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 10: Planning and Managing IP Security.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 4: Planning and Configuring Routing and Switching.
Working with Users and Groups Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Introducing User Account Control Configure and troubleshoot.
1 Chapter 13: RADIUS in Remote Access Designs Designs That Include RADIUS Essential RADIUS Design Concepts Data Protection in RADIUS Designs RADIUS Design.
1 Welcome to Designing a Microsoft Windows 2000 Network Infrastructure.
Pass Microsoft Installing and Configuring Windows Server 2012 exam in just 24 HOURS! 100% REAL EXAM QUESTIONS ANSWERS Microsoft Installing.
KAPLAN SCHOOL OF INFORMATION SYSTEMS AND TECHNOLOGY IT375 Window Enterprise Administration Course Name – IT Introduction to Network Security Instructor.
远程访问策略是如何处理的 Are there policies to process? START Does connection attempt match policy conditions? Yes 拒绝尝 试的连接 Is the Ignore User Dialin Properties attribute.
Chapter 1 Introduction to Networking
Module 9: Configuring Network Access
Administering Windows Server 2012
Microsoft Windows NT 4.0 Authentication Protocols
Module Overview Installing and Configuring a Network Policy Server
Configuring and Troubleshooting Routing and Remote Access
100% Exam Passing Guarantee & Money Back Assurance
Implementing TMG Server Publishing
Lesson #10 MCTS Cert Guide Microsoft Windows 7, Configuring Chapter 10 Configuring Network and Firewall Settings.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 4: Planning and Configuring Routing and Switching.
Presentation transcript:

70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network, Enhanced Chapter 11: Internet Authentication Service

Guide to MCSE , Enhanced 2 Objectives Understand and describe the purpose of the RADIUS protocol Describe the function of RADIUS servers, clients, and proxies Configure a RADIUS server using the Internet Authentication Service Configure a RADIUS proxy using the Internet Authentication Service

Guide to MCSE , Enhanced 3 Objectives (continued) Configure RRAS as a RADIUS client Troubleshoot RADIUS

Guide to MCSE , Enhanced 4 RADIUS Overview RADIUS: remote authentication dial-in user service Designed to centralize the authentication process for large distributed networks Originally intended for dial-up networks Can be used for VPN servers, switches, and wireless access points Two mandatory server roles: RADIUS client RADIUS server

Guide to MCSE , Enhanced 5 RADIUS Overview (continued) The RADIUS client accepts authentication information from users or devices and forwards the information to a RADIUS server The RADIUS server accepts authentication information from a RADIUS client Windows Server 2003 can act as either a RADIUS server or RADIUS client

Guide to MCSE , Enhanced 6 RADIUS Overview (continued) Install IAS to use Windows Server 2003 as a RADIUS Server RADIUS proxies act as intermediaries between RADIUS clients and RADIUS servers

Guide to MCSE , Enhanced 7 Radius Overview (continued)

Guide to MCSE , Enhanced 8 Radius Overview (continued)

Guide to MCSE , Enhanced 9 Outsourcing Dial-up Requirements You can use IAS to outsource dial-up requirements and allow roaming users to continue logging on using Active Directory user name and passwords A user dials into ISP, ISP forwards request to RADIUS proxy, RADIUS proxy forwards request to RADIUS server, RADIUS server passes information to domain controller for authentication

Guide to MCSE , Enhanced 10 Outsourcing Dial-up Requirements (continued)

Guide to MCSE , Enhanced 11 Configuring IAS as a RADIUS Server IAS is standard component of Windows Server 2003 Installed through Add or Remove Programs Must be configured using IAS snap-in before being used IAS must be registered with Active Directory if Active Directory is used on the network IAS server will not respond to any requests from RADIUS clients not listed in the IAS configuration

Guide to MCSE , Enhanced 12 Configuring IAS as a RADIUS Server (continued)

Guide to MCSE , Enhanced 13 Configuring IAS as a RADIUS Server (continued)

Guide to MCSE , Enhanced 14 Configuring IAS as a RADIUS Server (continued)

Guide to MCSE , Enhanced 15 Configuring IAS as a RADIUS Server (continued)

Guide to MCSE , Enhanced 16 Activity 11-1: Configuring IAS as a Radius Server Objective: Install IAS so your server can act as a RADIUS server Install IAS through Add or Remove Programs Add RADIUS clients Enter a password in the shared secret box

Guide to MCSE , Enhanced 17 Configuring RRAS as a RADIUS Client The RRAS server acts as a RADIUS client if it passes authentication requests You may specify that a RADIUS server be used for authentication when configuring RRAS You must specify the name or IP address of the RADIUS server and shared secret when configuring RRAS as a RADIUS server

Guide to MCSE , Enhanced 18 Configuring RRAS as a RADIUS Client (continued)

Guide to MCSE , Enhanced 19 Configuring RRAS as a RADIUS Client (continued)

Guide to MCSE , Enhanced 20 Activity 11-2: Configuring a RRAS Client Objective: Configure a RRAS server to use IAS for authentication Use Routing and Remote Access control Add new RADIUS server to the list Enter shared secret

Guide to MCSE , Enhanced 21 Activity 11-3: Testing RADIUS Objective: Create a VPN connection to your RRAS server to test RADIUS authentication Create a new VPN network connection Select anyone’s use If RADIUS is configured successfully, your RRAS server should contact the IAS service on your partner’s computer

Guide to MCSE , Enhanced 22 Configuring IAS as a RADIUS Proxy Windows Server 2003 can act as a RADIUS proxy Windows Server 2003 can act as both RADIUS proxy and RADIUS server at the same time Connection request policies determine how a RADIUS request is handled

Guide to MCSE , Enhanced 23 Remote RADIUS Server Groups Server groups are required for IAS to act as a RADIUS proxy RADIUS requests and logging information are forwarded to remote RADIUS server groups Server groups allow for load balancing and fault tolerance Weight setting is used to configure load balancing Priority is assigned to provide fault tolerance

Guide to MCSE , Enhanced 24 Remote RADIUS Server Groups (continued)

Guide to MCSE , Enhanced 25 Activity 11-4: Creating a Remote RADIUS Server Group Objective: Create a remote RADIUS server group that can be used when IAS is configured as a RADIUS proxy Use the New Remote RADIUS Server Group Wizard Group name is Engineering Enter shared secret

Guide to MCSE , Enhanced 26 Connection Request Policies Constructed similarly to a remote access policy No permissions Conditions are a subset of the conditions found in remote access policies Conditions include Day-And-Time-Restrictions, Client-IP-Addresses, and Client-Vendor Profile has very different options than profile in remote access policy

Guide to MCSE , Enhanced 27 Connection Request Policies (continued)

Guide to MCSE , Enhanced 28 Connection Request Policies (continued)

Guide to MCSE , Enhanced 29 Activity 11-5: Creating a Connection Request Policy Objective: Create a new connection request policy to configure your server as a RADIUS proxy Add a new connection request policy Use New Connection Request Policy Wizard Use proxy name EngineeringProxy

Guide to MCSE , Enhanced 30 Troubleshooting RADIUS Most remote access problems are not related to RADIUS Before troubleshooting RADIUS, ensure users can obtain remote access without RADIUS Use log files whenever possible

Guide to MCSE , Enhanced 31 Troubleshooting RADIUS (continued)

Guide to MCSE , Enhanced 32 Troubleshooting RADIUS (continued)

Guide to MCSE , Enhanced 33 Troubleshooting RADIUS (continued)

Guide to MCSE , Enhanced 34 Activity 11-6: Logging IAS Information to a File Objective: Enable IAS event logging Ensure that all accounting requests are logged Ensure that all valid and nonvalid authentication requests are logged Ensure all interim accounting requests are logged

Guide to MCSE , Enhanced 35 Summary RADIUS may be used to centralize remote access authentication and logging RADIUS is composed of the RADIUS clients, RADIUS servers, and RADIUS proxies RADIUS clients forward authentication requests to RADIUS servers, RADIUS servers then authenticate the requests and authorize the connections A RADIUS proxy can be used as an intermediary between RADIUS clients and servers in large environments IAS allows Windows Server 2003 to act as a RADIUS server

Guide to MCSE , Enhanced 36 Summary (continued) RRAS can act as a RADIUS client when configured as a remote access server IAS can also be configured as a RADIUS proxy Connection request policies are used on each request to determine whether IAS acts as a RADIUS server or a RADIUS proxy Connection request policies are composed of a condition and a profile IAS can log information to a file or SQL server