Solved

How to configure two NPS servers for redundacy on a Cisco switch with 802.1x

Posted on 2013-05-24
10
551 Views
Last Modified: 2013-09-18
Hi,

We are configuring 802.1X for some of our switches.We are going to use dynamic VLAN assigments through Microsoft NPS radius server.

For redundacy we would like to configure all the switches with 2 NPS Microsoft servers in case one of the 2 goes down or is being patch.

That being said, can someone help us out to understand how could we get that configured?
0
Comment
Question by:llarava
  • 4
  • 3
10 Comments
 
LVL 20

Expert Comment

by:rauenpc
Comment Utility
If you're just asking how the redundancy works:
You just need to have both NPS servers configured the same, and on the switches you define two radius server hosts. When you make the AAA commands that reference radius or a server group, as long as both servers are configured as radius or are both part of the server group you will be able to deal with failures/patching/reboots/etc.

Or do you need the entire config to deal with the dynamic LAN and redundancy for 802.1x?
0
 

Author Comment

by:llarava
Comment Utility
All the switches will be configued with 802.1x the goal is to do dynamic vlan assignment with NPS servers. So basically we would like to have all the switches work with 2 nps servers in case of failure or patches. Can we just configure the switch to use both nps servers? If so, how do we do it?
0
 
LVL 76

Accepted Solution

by:
arnold earned 500 total points
Comment Utility
You can usually define multiple servers to which radius auth/authorization/accounting packets can be sent.

Rauenpc, pointed it out. Are you looking for a specific directive exampe?

http://packetlife.net/blog/2010/sep/27/basic-aaa-configuration-ios/
0
 

Author Comment

by:llarava
Comment Utility
I would like to know how do I configure the switch to be able to work with both nps servers in case one goes down or we have to patch it.
0
Backup Your Microsoft Windows Server®

Backup all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

 

Author Comment

by:llarava
Comment Utility
The goal is to configure 801.x with dynamic vlan assignments for wired and wireless for windows 7 supplicants.
0
 
LVL 76

Expert Comment

by:arnold
Comment Utility
You define two or more tacacs-servers.  Te order of the listing will be the order of attempts should it not respond it will be labeled as dead, and the requests will be sent to the other.
There is a configuration setting tht deals how long a server labeled as dead will not be rechecked. After that time has passed, it will be added back into the pool.

Note, an erroneous response will not get a radius service labeled as dead, a radius server is only labeled as dead when there is no response.

Which switch do you have?  Does the switch lacks the option to define multiple servers?
0
 
LVL 76

Expert Comment

by:arnold
Comment Utility
The only requirement to have a switch work with an Is:
1) the switch must be a client of the NPS
2) they must reference the same secret.

As far as functionality, the NPS policy must be configured to properly respond to the request dealing with including the reply items that will set the VLAN, etc. on the switch.
0
 

Author Closing Comment

by:llarava
Comment Utility
-
0

Featured Post

Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Know what services you can and cannot, should and should not combine on your server.
PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now