cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1175
Views
0
Helpful
1
Replies

LeapProxy method to Authenticate Wireless Users with AD

rashidsiddiqui
Level 1
Level 1

Hi Friends,

Recently i came across the settings on ACS, known as LeapProxy, where, NPS (Network Policy Server) was installed on AD (Active Directory), and we enabled Radius server feature on NPS. Please refer the attachment.

We are using PEAP method for Authentication. How it is integrated is like following,

  1. Users with the help of a supplicent connect to wireless, and Opt for PEAP method.
  2. WLC is integrated with ACS.
  3. On ACS we have defined AD server as LeapProxy Server.
  4. Request is forwarded to LeapProxy's Radius server.
  5. Radius Server forwards to AD.

Now the question i have, "How NPS/Radius server is forwarding the request to AD?". NPS/Radius server is on the same AD machine. In NPS/Radius we do not have any AD credentials. Although it worked, but i am not getting the data flow details.

1 Accepted Solution

Accepted Solutions

Nicolas Darchis
Cisco Employee
Cisco Employee

To my opinion, NPS, since it's a Windows Server 2008, has to be installed on a Domain Controller or member Server of the domain. So it does have connectivity and credentials to AD since it's running on a machine with access to the domain.

However this is a 100% Microsoft question I'd say and if you have more concerns, you're better off trying a Microsoft forum :-)

View solution in original post

1 Reply 1

Nicolas Darchis
Cisco Employee
Cisco Employee

To my opinion, NPS, since it's a Windows Server 2008, has to be installed on a Domain Controller or member Server of the domain. So it does have connectivity and credentials to AD since it's running on a machine with access to the domain.

However this is a 100% Microsoft question I'd say and if you have more concerns, you're better off trying a Microsoft forum :-)

Review Cisco Networking for a $25 gift card