Solved

NPS and an ASA

Posted on 2013-06-04
7
420 Views
Last Modified: 2013-06-06
I have a Cisco ASA5500 that is using a Windows Server 2008 R2 machine as a RADIUS server to authenticate users for VPN and TSWeb access. The RADIUS server also services other Cisco equipment with AAA authentication. I have no problems with this setup.

However, since all 3 are on the same NPS server, the rules interfere with security. If a user has permissions to access TSWeb but not VPN, they are still granted access because they fall into one of the rules. I was hoping to be able to sort the requests based on the UDP Port that they came in on but I have been unable to handle that from the Microsoft side of things. At this point the only available option I see is have a different server for each type of access but that seems insane.

After several hours of searching the Internet for the answer, I turn to the Experts. I will provide any additional information necessary, just ask.
0
Comment
Question by:NHEC_Networking
7 Comments
 
LVL 16

Assisted Solution

by:btassure
btassure earned 250 total points
ID: 39221350
RADIUS isn't great for that level of granularity.

Active Directory AA and LDAP are more suited to group based authentication.

What version of ASA are you using?

Have you considered other options than RADIUS?
0
 
LVL 25

Accepted Solution

by:
RobMobility earned 250 total points
ID: 39221379
Hi,

You may be able to control access using Cisco Dynamic Access Policies - this will evaluate a user against criteria such as tunnel group, AnyConnect version and LDAP/RADIUS AD user group - you could use this to control access.

Easiest to set in ASDM

Regards,


RobMobility
0
 
LVL 42

Expert Comment

by:kevinhsieh
ID: 39221908
You need to adjust your NPS policies to include the type of device. I can elaborate later once i get onto the office. I use NPS for RD gateway, 802.1x wired, 802.1x Wireless, and ASA VPN without issue. I found radius to work better than LDAP.
0
Do email signature updates give you a headache?

Do you feel like you are constantly making changes to email signatures? Are the images not formatting how you want them to? Want high-quality HTML signatures on all devices, including on mobiles and Macs? Then, let Exclaimer solve all your email signature problems today.

 

Author Comment

by:NHEC_Networking
ID: 39221955
Kevinhsieh - The problem is that I use TSWeb (handled by the ASA), VPN (handled by the ASA) and CLI. All of which are generated by the ASA.

Btassure and RobMobility - I am working on getting LDAP setup on the ASA but I'm running into issues. I will continue to troubleshoot those and get back to you, this option looks  promising. Thank you
0
 
LVL 25

Expert Comment

by:RobMobility
ID: 39222019
Hi,

You should be able to use Radius Attributes for Dynamic Access Policies as well.

Try LDAP over SSL and make sure your LDAP service account is a Domain Admin - other permissions do not appear to work.

Kind regards,


RobMobility.
0
 

Author Comment

by:NHEC_Networking
ID: 39222029
I was able to make LDAP work. Now I just need to work out the DAPs and applying them. This is great progress so far. Thank you for your assistance!
0
 
LVL 25

Expert Comment

by:RobMobility
ID: 39225939
Hi,

I use Dymanic Access Policies to control access between multiple user groups and multiple end-points.

It's quite flexible in this respect.

Regards,


RobMobility.
0

Featured Post

What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

Join & Write a Comment

Suggested Solutions

Let’s list some of the technologies that enable smooth teleworking. 
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

8 Experts available now in Live!

Get 1:1 Help Now