How do I deal with remote non domain PC's



Hey guys,

Got a MS question for you and hopefully you are able to point me in the
right direction.
We are using PIX VPN and are using MS IAS / RADIUS Server for
authentication. Clients are connecting with MS PPTP client.
To prevent remote non domain pc's from signing on as Anonymous to a
member file server, what would you use to authenticate? PKI
environment/Certificates or is IAS enough?

My problem is now that IAS gets them though the first door but if they
need to access other MS file servers they are being re-prompted for
credentials.

If anybody knows some How To documents for this implementation would be
much appreciated

Another thing is that in a couple of weeks we are going to integrate
the AS400 using Kerberos Authentication for single signon purpouses

Should I wait for this because it changes authentication big time
throughout the network? I could imagine this breaking things again.


Jan

.



Relevant Pages

  • How do I deal with remote non domain PCs
    ... authentication. ... Clients are connecting with MS PPTP client. ... member file server, what would you use to authenticate? ... environment/Certificates or is IAS enough? ...
    (microsoft.public.internet.radius)
  • Re: RADIUS (IAS) and Cisco Concentrator? (PDF Attachment)
    ... The order the radius statements in IOS will determine the order the ... IAS servers are checked. ... RADIUS client what policy to use? ... I'm not sure what this is, but if it refers to a secure authentication ...
    (microsoft.public.windows.server.active_directory)
  • RE: check group membership in Connection Request Policy
    ... The access request does not contain a valid user password, ... Authentication is done at the VPN3000, ... So what data does the VPN3000 send to the IAS? ... a custom IAS extension would be really a solution. ...
    (microsoft.public.internet.radius)
  • Re: 802.1X/EAP authentication issue with XP client
    ... I also tried adjusting the IAS remote access policy framed MTU param ... client, same scenario, is not getting a successful authentication. ... or system event logs. ...
    (microsoft.public.internet.radius)
  • Re: RADIUS (IAS) and Cisco Concentrator? (PDF Attachment)
    ... so I simple copy the settings to another IAS server and register in AD then the new one will be a failover? ... Registering IAS with AD effectively tells AD not to accept External Authentication requests from other sources. ... You can have multiple IAS servers registered at the same time, so you can tell your Concentrator to follow a chain of servers if the first one doesn't respond. ... At the bottom of the properties window, select "Grant remote access permission" and then click OK. ...
    (microsoft.public.windows.server.active_directory)