cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
2983
Views
0
Helpful
5
Replies

Integrate RADIUS Authentication with Windows Server NPS

Ivan Rivai
Level 1
Level 1

Hello.

I'm using Windows Server 2012 R2 and Cisco Switch Catalyst 2960X.

Firstly, I've deployed 802.1x and NAP. So basically I want to authenticate radius login to the switches,L3s, and routers. For now, i have different radius server using freeradius but i want to place the radius in the windows server, to make it centralize. I've tried following the tutorial here :

https://www.freeccnaworkbook.com/blog/ccna-security/cisco-ios-radius-authentication-with-windows-server-2012-nps

But that's the condition where 802.1X has not been deployed.

So my question is, can the network devices authenticate 2 different authentications? 

Thank you.

Best regards,

Ivan

5 Replies 5

pieterh
VIP
VIP

the tutorial you refer to is for management access to the device, (this is not NAC)

Yes for DOT1x authentication you can use a different radius server than for management access.

Try this link (there may be a more recent, this is 2011)

Hello, thank you for your reply.

Can I actually use 1 radius server for both 802.1x auth and for management access auth?

Thank you.

Yes you can.

The server (group) referenced in 
     aaa authentication login ...
     aaa authentication enable .....
is for management

The server (group) referenced in
     aaa authentication dot1x .....
     aaa authorization network .....
is for 802.1x

yeah i've tried using this, but the auth failed.

I tried using another server, which is also a windows server, installed the NPS role, and it works. So i'm assuming the server can not take 2 different authentication requests?

compare the policies you created on the two servers, there must be a difference.

with a single authentication server you need two policies for the same device.

Review Cisco Networking for a $25 gift card