Networking Forums

Networking Forums > Computer Networking > Windows Networking > RADIUS: remote access policies

Reply
Thread Tools Display Modes

RADIUS: remote access policies

 
 
RB
Guest
Posts: n/a

 
      02-16-2007, 02:42 PM
I am trying to set up 'Port based authentication' via 802.1X with cisco 4500
switch and policies defined on IAS.
I am not able to set "Remote Access Policy" to authenticate domain\user
connecting from domain\computer only.
when domain\computer is connected to LAN it should be member of VLAN1 and
when domain\user is logged on to domain it should be member of VLAN2.

If I have 'RA Policy' which contains for example
... AND
Windows-Groups matches "domain\domain users" AND
Windows-Groups matches "domain\domain computers"

this policy will be never applied. When computer starts it is authenticated
only as member of "domain\domain computers" (is not member of "domain\domain
users") and when domain\user logs on, user authentication runs only (is not
member of "domain\domain computers").

I want set this policy to disable connect with domain\user account on
non-domain computer.

any idea?

thx

RB


 
Reply With Quote
 
 
 
 
James McIllece [MS]
Guest
Posts: n/a

 
      02-21-2007, 07:05 PM
=?Utf-8?B?UkI=?= <(E-Mail Removed)> wrote in
news:16792973-1DF4-48A6-9437-(E-Mail Removed):

> I am trying to set up 'Port based authentication' via 802.1X with
> cisco 4500 switch and policies defined on IAS.
> I am not able to set "Remote Access Policy" to authenticate
> domain\user connecting from domain\computer only.
> when domain\computer is connected to LAN it should be member of VLAN1
> and when domain\user is logged on to domain it should be member of
> VLAN2.
>
> If I have 'RA Policy' which contains for example
> .. AND
> Windows-Groups matches "domain\domain users" AND
> Windows-Groups matches "domain\domain computers"
>
> this policy will be never applied. When computer starts it is
> authenticated only as member of "domain\domain computers" (is not
> member of "domain\domain users") and when domain\user logs on, user
> authentication runs only (is not member of "domain\domain computers").
>
> I want set this policy to disable connect with domain\user account on
> non-domain computer.
>
> any idea?
>
> thx
>
> RB
>
>
>


Hi there --

I queried the product team on this and received the following response:

"Unfortunately, this cannot be accomplished. The shortcoming however is
with the current authentication methods, not with IAS. There are no RADIUS
servers that provide quite this capability. As far as IAS is concerned, we
treat the below (remote access policy) statement as an OR rather than an
AND. When an authentication attempt is being passed to the RADIUS server
for validation, it can only be a user authentication OR a machine
authentication, it can ‘t be both at the same time.

Also, with IAS we do not keep any system state information, so we don’t
track whether a particular machine has authenticated prior to a user
attempt."


--
James McIllece, Microsoft

Please do not send email directly to this alias. This is my online account
name for newsgroup participation only.

This posting is provided "AS IS" with no warranties, and confers no rights.
 
Reply With Quote
 
RB
Guest
Posts: n/a

 
      02-23-2007, 01:36 PM
thx for response

RB

"James McIllece [MS]" wrote:

> =?Utf-8?B?UkI=?= <(E-Mail Removed)> wrote in
> news:16792973-1DF4-48A6-9437-(E-Mail Removed):
>
> > I am trying to set up 'Port based authentication' via 802.1X with
> > cisco 4500 switch and policies defined on IAS.
> > I am not able to set "Remote Access Policy" to authenticate
> > domain\user connecting from domain\computer only.
> > when domain\computer is connected to LAN it should be member of VLAN1
> > and when domain\user is logged on to domain it should be member of
> > VLAN2.
> >
> > If I have 'RA Policy' which contains for example
> > .. AND
> > Windows-Groups matches "domain\domain users" AND
> > Windows-Groups matches "domain\domain computers"
> >
> > this policy will be never applied. When computer starts it is
> > authenticated only as member of "domain\domain computers" (is not
> > member of "domain\domain users") and when domain\user logs on, user
> > authentication runs only (is not member of "domain\domain computers").
> >
> > I want set this policy to disable connect with domain\user account on
> > non-domain computer.
> >
> > any idea?
> >
> > thx
> >
> > RB
> >
> >
> >

>
> Hi there --
>
> I queried the product team on this and received the following response:
>
> "Unfortunately, this cannot be accomplished. The shortcoming however is
> with the current authentication methods, not with IAS. There are no RADIUS
> servers that provide quite this capability. As far as IAS is concerned, we
> treat the below (remote access policy) statement as an OR rather than an
> AND. When an authentication attempt is being passed to the RADIUS server
> for validation, it can only be a user authentication OR a machine
> authentication, it can ‘t be both at the same time.
>
> Also, with IAS we do not keep any system state information, so we don’t
> track whether a particular machine has authenticated prior to a user
> attempt."
>
>
> --
> James McIllece, Microsoft
>
> Please do not send email directly to this alias. This is my online account
> name for newsgroup participation only.
>
> This posting is provided "AS IS" with no warranties, and confers no rights.
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
IAS Remote Access Policies Antonio Cardoso Windows Networking 0 11-28-2005 09:30 AM
IAS W3k : Remote Access Policies attribute... Zul J Wireless Networks 0 08-09-2005 11:33 AM
Question on Remote Access policies Ewan Windows Networking 6 06-18-2005 03:06 PM
Remote Access Policies error in Routing & Remote Access Mark Windows Networking 1 06-28-2004 03:57 AM
Routing and Remote Access and Using Timeout Policies Adam Prince Windows Networking 0 11-21-2003 01:00 PM



1 2 3 4 5 6 7 8 9 10 11