IAS

From: Chris Wheeler (cwheeler@netimage.net)
Date: 06/19/02


From: "Chris Wheeler" <cwheeler@netimage.net>
Date: Wed, 19 Jun 2002 07:46:09 -0700


Dan,
Are you using the NT/W2K user/group accounts to
authenicate the users to the PIX/routers?
Do you know where I can find good documentation on this
type of setup? I want users who go out to the Internet
to get Authenticated via the IAS when they hit the PIX.

Thanks,

Chris

>-----Original Message-----
>I have a regular NT infrastructure with several W2K
>servers thrown in. I loaded IAS on one of my W2K
servers
>as a RADIUS server. I am authenticating user logins to
my
>Cisco routers and PIX.
>
>My question is, PIX seems to be sending requests in
PAP.
>I need to fully understand the use of the session keys
in
>the RADIUS client/server relationship to ensure that I
am
>not doing cleartext. If there is a way to specify that
>client requests from my PIX be sent in CHAP or MS-CHAP,
I
>would appreciate that.
>
>Also, I added a special user to my NT domain, after
>setting up the RADIUS server and sucessfully
>authenticating an existing user. After forcing a domain
>sync and waiting about 4 hours, the new user is still
not
>recognized. Where does the IAS pull its info from? The
>PDC/BCD of the domain, or does it go into BCD emulation
>with its own database?
>
>Please send all responses directly to me, if you could,
at
>danl@ascinet.com
>.
>



Relevant Pages

  • Re: IAS
    ... Search for RADIUS and or AAA. ... > to get Authenticated via the IAS when they hit the PIX. ... I am authenticating user logins to ... >>setting up the RADIUS server and sucessfully ...
    (microsoft.public.win2000.security)
  • Re: Vasco Radius
    ... you can use a third party RADIUS server for authenticating VPN users ... invoming VPN connections in the Using RADIUS Authentication for ISA Server ... > or use Configure VPN Client Access on the isa 2004 server with IAS on the ...
    (microsoft.public.isa.vpn)
  • Locking down IAS and NAS
    ... Ive got large W2K3 IAS setup authenticating all kinds of logins. ... Currently IAS autheticates users logging into Cisco Routers and ... Swithces via telnet or SSH to admin the box, ...
    (microsoft.public.internet.radius)
  • IAS BT STREAM STATIC ROUTES
    ... I have a BT ipstream setup to 4 remote offices, ... authenticating to IAS succesfully, ... also provided bt home to home users connections ...
    (microsoft.public.internet.radius)
  • Dynamic IP Pool with IAS and Third-party NAS
    ... I am needing to set up a Radius server that is capable of ... providing both static and dynamic IP addresses to clients that are ... authenticating to a third-party NAS at an ISP. ... provide a dynamic address from a pool. ...
    (microsoft.public.internet.radius)