cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
512
Views
0
Helpful
3
Replies

Radius authentication

paulnigel
Level 1
Level 1

Hi forum,

Is there a way to use Radius to authenticate users(based on windows user accounts) when they are connected to the switches before granting them access to the windows environment?

3 Replies 3

darpotter
Level 5
Level 5

Hi

The most obvious solution would seem to be 802.1x port security. The switch then doesnt give any network access until the AAA server gives back a result.

You could use vlans from ACS so that authenticated users get onto the network where the windows servers reside, and everyone else gets dumped to somewhere else.

The switch needs a pre-configured username/password so that PCs without 802.1x configured can still be authenticated to receive the non-windows vlan assignment.

This stuff is all part of the NAC framework, although you dont need all the extra complexity of posture validation and stuff.

Darran

Hi Darran,

Thanks for your reply. I will explore the areas you mentioned.

Thanks much & Best regards,

Paul

jason.nadeau
Level 1
Level 1

Disregard above entry is correct.