Cisco AAA with RADIUS against Active Directory through the NPS role in Windows Server 2012 R2

  Рет қаралды 79,300

Blue Team Security

Blue Team Security

8 жыл бұрын

In this video I demonstrate setting up Active Directory authentication for a Cisco router IOS. This will be using AAA and RADIUS through the Network Policy Server (NPS) role in Windows Server 2012 R2 to authenticate users in Active Directory on Cisco IOS devices.

Пікірлер: 31
@mattr5664
@mattr5664 5 жыл бұрын
oh man you are a life saver. I was only getting it partly working with a bunch of other walkthroughs. Yours worked right off the bat. Thank you! Windows Server 2016 - C9300 on 16.8.1a
@carlmarkley3817
@carlmarkley3817 Жыл бұрын
Outstanding, I had all the right pieces in place but they were not lined up correctly on my Server 2019 and Cisco Catalysis 9300. All set now, thanks for putting this out there.
@bsiko1
@bsiko1 4 жыл бұрын
Thank you so much it's worked for me
@fredh3603
@fredh3603 7 жыл бұрын
Hi, thanks for the tutorial. I tested this with a Windows Server 2012R2, which is currently also being used as our MAB-server. My iOS device is an old Cisco1721 using iOS 12.4(25d). I am sitting in an AD-forest and assume my testingdevice is too old. I wonder if the command "domain-stripping" could add the domain automatically to the username. Can you confirm this thought? _____ Oh, also I'm not sure if you mentioned, but the local account is only being used when the Cisco IOS device cannot pass the authentication to the radius OR the radius cannot pass it to the active direcotry.
@networklabs1
@networklabs1 4 жыл бұрын
Nice video mate
@BurninBosmer
@BurninBosmer 6 жыл бұрын
Is it possible to then limit who can log into the router, such as only a certain group in AD/LDAP?
@carlosarjonaquijano2791
@carlosarjonaquijano2791 3 ай бұрын
To connect a user through the wireless network, what type of radius authentication must the switch have?
@xbyrxlyr
@xbyrxlyr 2 жыл бұрын
Great video, but the splash screen at the end made me shard a little.
@martynjones973
@martynjones973 Жыл бұрын
Great video thank you, do you have one on Cisco ICE 👍👍👍
@andresparamo6734
@andresparamo6734 2 жыл бұрын
Has anyone configured a cisco switch with radius from DUO using their auth proxy? Would the cisco side of this tutorial be the same?
@andresparamo6734
@andresparamo6734 2 жыл бұрын
Great tutorial! Quick question for you for anyone that might know. Do you know if after enabling aaa for authentication is the option still available to login with the local credentials that were created on the router/switch?
@jaysonpatricio
@jaysonpatricio 2 жыл бұрын
got same question when radius server is down, local credential should work but he did not mention it here
@jhilling
@jhilling 4 жыл бұрын
How are you making this work using MS-CHAP? My previous setup on 2012 required me to use "Unencrypted authentication (PAP, SPAP).
@Lonje
@Lonje 2 жыл бұрын
i am also interested to know
@DishantPandya
@DishantPandya 7 жыл бұрын
I configured everything exactly as shown in here but still there's a problem authenticating.
@Chris-Christopher-
@Chris-Christopher- 3 жыл бұрын
@Nehemiah Brayan, when tried it I got a virus and my entire family got cancer. My kids are dead because of instaportal. Do not use instaportal.
@badisdolor8456
@badisdolor8456 3 жыл бұрын
just for the nps server ?? how can i add one in my lab ?
@anasa.ghannam9302
@anasa.ghannam9302 4 ай бұрын
it doesn't work mate, the syslog said: invalid_group_handle , anyone can help please))
@jozamaymen
@jozamaymen 4 жыл бұрын
don't forget to use (BAP percentage of capacity), sometime the radius won't work without it.
@mdhumayun
@mdhumayun 5 жыл бұрын
It is working if I unchecked all button except Unencrypted authentication (PAP, SPAP) on Authentication Methods under Network policies :)
@tusredesti9017
@tusredesti9017 5 жыл бұрын
Same here, i do a equal action.
@jonbiong
@jonbiong 5 жыл бұрын
Thanks, this solved it.
@trancechannel6633
@trancechannel6633 4 жыл бұрын
Which part bro in this video
@saadabdulla9934
@saadabdulla9934 3 жыл бұрын
Solved my issue, thanks.
@Lonje
@Lonje 2 жыл бұрын
mine too. i wonder how he made it work using the other authentication protocols.
@jaysonpatricio
@jaysonpatricio 2 жыл бұрын
how about the failover if the NPS(radius is down) the local admin should work right?
@Chrishall1982x
@Chrishall1982x Жыл бұрын
yes
@luileliomatsenguane440
@luileliomatsenguane440 6 жыл бұрын
Hi, where do you defined acouch-adm?
@dbacky
@dbacky 4 жыл бұрын
That is the user (Adam Couch, acouch-adm@BTSLAB.COM) that is added to the Network Admins security group at the 2:32 mark in the video.
@jugsonmunganga891
@jugsonmunganga891 4 жыл бұрын
the acouch-adm account comes from where ?????
@dbacky
@dbacky 4 жыл бұрын
That is the user (Adam Couch, acouch-adm@BTSLAB.COM) that is added to the Network Admins security group at the 2:32 mark in the video.
Windows NPS (RADIUS) with Cisco and Meraki Wireless
32:37
Network Lunchbox
Рет қаралды 19 М.
Comfortable 🤣 #comedy #funny
00:34
Micky Makeover
Рет қаралды 12 МЛН
What it feels like cleaning up after a toddler.
00:40
Daniel LaBelle
Рет қаралды 93 МЛН
AAA and RADIUS vs TACACS+
7:19
Doctor Networks
Рет қаралды 59 М.
Securing RADIUS with EAP-TLS [Windows Server 2019]
39:18
OsbornePro TV
Рет қаралды 64 М.
Wireless Radius Authentication with Windows Server 2016
18:08
Tech Pub
Рет қаралды 134 М.
28. Configuring RADIUS Authentication for VPN with NPS
20:52
MSFT WebCast
Рет қаралды 77 М.
Cisco AAA with Windows Server 2016 RADIUS Configuration 3 of 3
16:49
Port Security vs Port Based Authentication (802.1x) Whats the Difference?
13:12
Comfortable 🤣 #comedy #funny
00:34
Micky Makeover
Рет қаралды 12 МЛН