NPS and an ASA

Posted on 2013-06-04
Medium Priority
Last Modified: 2013-06-06
I have a Cisco ASA5500 that is using a Windows Server 2008 R2 machine as a RADIUS server to authenticate users for VPN and TSWeb access. The RADIUS server also services other Cisco equipment with AAA authentication. I have no problems with this setup.

However, since all 3 are on the same NPS server, the rules interfere with security. If a user has permissions to access TSWeb but not VPN, they are still granted access because they fall into one of the rules. I was hoping to be able to sort the requests based on the UDP Port that they came in on but I have been unable to handle that from the Microsoft side of things. At this point the only available option I see is have a different server for each type of access but that seems insane.

After several hours of searching the Internet for the answer, I turn to the Experts. I will provide any additional information necessary, just ask.
Question by:NHEC_Networking
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 16

Assisted Solution

btassure earned 1000 total points
ID: 39221350
RADIUS isn't great for that level of granularity.

Active Directory AA and LDAP are more suited to group based authentication.

What version of ASA are you using?

Have you considered other options than RADIUS?
LVL 25

Accepted Solution

RobMobility earned 1000 total points
ID: 39221379

You may be able to control access using Cisco Dynamic Access Policies - this will evaluate a user against criteria such as tunnel group, AnyConnect version and LDAP/RADIUS AD user group - you could use this to control access.

Easiest to set in ASDM


LVL 42

Expert Comment

ID: 39221908
You need to adjust your NPS policies to include the type of device. I can elaborate later once i get onto the office. I use NPS for RD gateway, 802.1x wired, 802.1x Wireless, and ASA VPN without issue. I found radius to work better than LDAP.
Get real performance insights from real users

Key features:
- Total Pages Views and Load times
- Top Pages Viewed and Load Times
- Real Time Site Page Build Performance
- Users’ Browser and Platform Performance
- Geographic User Breakdown
- And more


Author Comment

ID: 39221955
Kevinhsieh - The problem is that I use TSWeb (handled by the ASA), VPN (handled by the ASA) and CLI. All of which are generated by the ASA.

Btassure and RobMobility - I am working on getting LDAP setup on the ASA but I'm running into issues. I will continue to troubleshoot those and get back to you, this option looks  promising. Thank you
LVL 25

Expert Comment

ID: 39222019

You should be able to use Radius Attributes for Dynamic Access Policies as well.

Try LDAP over SSL and make sure your LDAP service account is a Domain Admin - other permissions do not appear to work.

Kind regards,


Author Comment

ID: 39222029
I was able to make LDAP work. Now I just need to work out the DAPs and applying them. This is great progress so far. Thank you for your assistance!
LVL 25

Expert Comment

ID: 39225939

I use Dymanic Access Policies to control access between multiple user groups and multiple end-points.

It's quite flexible in this respect.



Featured Post

Bringing Advanced Authentication to the SMB Market

WatchGuard announces the acquisition of advanced authentication provider, Datablink, with one mission – to bring secure authentication to SMB, mid-market, and distributed enterprises with a cloud-based solution, ideal for resale via their established channel & MSSP community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

OpenVPN is a great open source VPN server that is capable of providing quick and easy VPN access to your network on the cheap.  By default the software is configured to allow open access to your network.  But what if you want to restrict users to on…
A safe way to clean winsxs folder from your windows server 2008 R2 editions
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
Suggested Courses

801 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question