Solved

RADIUS TESTING GUI TOOL

Posted on 2011-03-04
14
540 Views
Last Modified: 2012-06-27
Ive been looking online and found various types of Radius testing tools.  Does anyone have any recommendations on a freeware download tool that i can use to ensure my configurations ive followed are correct?

currently ive setup:

1 master dc, ad, dns, dhcp & sp2
- completed radius configurations
- installed and configured IAS
- created and added a single user account - the test client pc, happens to be plugged into the same local switch although the client would be logging on from a remote position but assuming this is ok anyway, but not sure if 'radius or ias' are being used!!??

i havent activated 'Routing & Remote Access' which im assuming is what i would need to do next if the 'test client pc' was actually logging on remotely, so the client would not only be using 'radius, ias, but a vpn' connection aswell.
0
Comment
Question by:mikey250
  • 9
  • 4
14 Comments
 
LVL 11

Accepted Solution

by:
Tasmant earned 500 total points
ID: 35036339
You can only authenticate against IAS/Radius in some situations: Remote Access or 802.1X Wired or Wireless configuration. It's always based on network authentication to gain access to the network.
If you expect to use Radius when you enter your credentials in the Windows Logon screen, then you're wrong.

You can use Radius after you entered your credentials in the Windows Logon prompt to realize a network authentication (802.1x wireless or wired). But your credentials on the client are not validated by a DC, but used in cache. PEAP MSCHAPv2 authentication.
You can enable network authentication for the computer before you enter user credentials, EAP TLS authentication. You will need a CA to deploy computer certificates.

If you want to test, you should enable Remote access and simulate a VPN between your client and RAS Server. If the connection is successfull then your IAS configuration will be good. Else, you need to review.
0
 

Author Comment

by:mikey250
ID: 35036452
"If you expect to use Radius when you enter your credentials in the Windows Logon screen, then you're wrong."

as per your comment above, what i mean is a user will logon as normal although radius is configured although im not sure why after your comment above and then IAS does the AAA part.

if a user is local to a domain do i need to configure anything other than adding user to the domain as a normal user?
0
 
LVL 11

Assisted Solution

by:Tasmant
Tasmant earned 500 total points
ID: 35036657
If the user is local to the computer, then the authentication is against the local SAM Database.
If the user is stored in Active Directory (ie domain account), then the authentication is against the Domain Controllers, using Kerberos protocol by default (else NTLM).

You cannot change this behavior.
AAA is a way to forward authentication request from a system (switch, wireless AP, router, VPN box) to be able to authenticate against Active Directory (instead using multiple repository, by example adding local accounts to a router). IAS will ask to DCs to validate the credentials, and by example check is the user is member of a group configured in a rule. IAS has rules to define which acess the user will gain (by example VLAN guest access, or VLAN production access).

But IAS is never used when you enter credentials with the logon screen.
IAS will be used if you set up a VPN connection, or do network authentication with wired or wireless 802.1X
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 

Author Comment

by:mikey250
ID: 35036789
"If the user is local to the computer, then the authentication is against the local SAM Database."  - ok so if a standalone server was set up and all pc's, servers were connected and NOT on a DC then the authentication is against the Local SAM Database.

"If the user is stored in Active Directory (ie domain account), then the authentication is against the Domain Controllers, using Kerberos protocol by default (else NTLM)."  -  ok.

when configuring the IAS i selected MD5 and Ethernet which appears to be wrong from what you have advised so I need to change this accordingly.

Although I have routers but not connected as yet i will select vpn in the 'routing and remote access' part and see if it will still function on my local switch anyway.  then if it works i will have to plug host pc on the other end of a router.

I have no vlans at this time.
0
 
LVL 11

Assisted Solution

by:Tasmant
Tasmant earned 500 total points
ID: 35037204
you could use this guide, it's an excellent help to figure how to setup IAS.
http://www.microsoft.com/downloads/en/confirmation.aspx?familyid=05951071-6b20-4cef-9939-47c397ffd3dd&displaylang=en

The most secure connections are PEAP/MsCHAP v2 (you use the user credentials, and there is only one certificate needed on the IAS), or i you prefer the best secure is EAP/TLS but you would deploy certificate for computers and/or users.
0
 

Author Comment

by:mikey250
ID: 35037711
im going through your url now!! i have no certificates as just testing how to do things so will ignore the EAP/TLS part.  ive selected everything in list anyway, ie peap/mschap, md5 and smartcard anyway.but peap/mschap is at top of list.  it said the access part was Ethernet so ive selected this although i did not think so.  either way i will go through and test just the parts that im looking at.

i haven't connected my router yet so am hoping things will work anyway as if the user was connected remotely anyway.
0
 

Author Comment

by:mikey250
ID: 35038033
my test client pc although local for the time being, ive got the vpn working and i can see the username logged on via 'routing & remote access'.
0
 

Author Comment

by:mikey250
ID: 35038064
i downloaded a program to test the 'radius server' and kept getting some 'error binding issue'.  now that i have read your comments and confirmed the vpn is working.  I then ran the software i downloaded again and NOW NO MORE 'ERROR BINDING ERROR' shows!!

As you said in your 1st thread  -

"If you want to test, you should enable Remote access and simulate a VPN between your client and RAS Server. If the connection is SUCCESSFUL then your IAS configuration will be good.

so is that it as far as getting this link up and running?
0
 

Author Comment

by:mikey250
ID: 35038130
i did NOT realise that although my my dhcp allocated an address, that when a vpn is connected it would allocated an additional address but not show it in dhcp at all.

the only way to notice is when i open 'Routing & Remote Access' is when i locate the vpn and properties and within there it shows the other ip address given to the vpn user.

The reason for this is because ive logged on as another user and then created a vpn for another as im using to test.  Otherwise i realise this would not normally happen.
0
 
LVL 11

Assisted Solution

by:Tasmant
Tasmant earned 500 total points
ID: 35055328
When you create a VPN connection on your client, you will get a specific IP address for your VPN tunnel.
So if you run ipconfig /all you should see your client with 2 IPs.
More, if you launch route /print, you should by default see that the gateway for default route 0.0.0.0 is pointing to your VPN IP.
For the DHCP, it's the RAS service which book a pool of 10 IPs by default to be able to allocate them to clients. When the 10 IPs allocated is reached, another pool is booked.
0
 

Author Comment

by:mikey250
ID: 35058718
yes i did get a specific ip address.
Yes 2 ip's - 1 ip is the allocated address given from the dhcp and all the normally dhcp lease configurations as expected, ie master dc,dns,dhcp.

OK - i did NOT realise that RAS service books a pool of 10 IP's as YES this is what I saw and YOU say when fully allocated another pool is created - ok!!!!!!!

Ive had another expert say that IT MAY BE BECAUSE of some Browser service, but I was not sure.

thanks for that advice!!!!!!!!
0
 

Author Comment

by:mikey250
ID: 35254921
Hi i keep having intermitant problems with my internet dongle it should be ok now as sometimes i can create a new thread and sometimes my internet connection would cut me off during closure of another.  i am going to allocate the points accordingly anyway.
0
 

Author Comment

by:mikey250
ID: 35255029
hi my internet my down the other day although it appeared to be intermittant and although i created another thread i went to close other threads but lost my internet connection.  my internet connection should be ok now so i wish to allocated points accordingly and go through the other threads i have!!
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

It is only natural that we all want our PCs to be in good working order, improved system performance, so that is exactly how programs are advertised to entice. They say things like:            •      PC crashes? Get registry cleaner to repair it!    …
On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question