How to configure NAC as RADIUS to authorize AD users
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎01-18-2018 08:21 PM
Hello, everybody,
please, give me a link to some manuals.
I want to use one of two existing NAC installations as RADIUS to authorize AD users for an external system (Fortigate FG-600 firewall).
So, the questions are:
1) How to configure NAC to send authorization requests to AD domain controllers?
2) How to configure NAC be RADIUS server
Many thanks in advance,
Ilya
please, give me a link to some manuals.
I want to use one of two existing NAC installations as RADIUS to authorize AD users for an external system (Fortigate FG-600 firewall).
So, the questions are:
1) How to configure NAC to send authorization requests to AD domain controllers?
2) How to configure NAC be RADIUS server
Many thanks in advance,
Ilya
7 REPLIES 7
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎01-19-2018 05:46 AM
Hi, Stephan,
thank you...
Unfortunately, the article is unavaiable...
thank you...
Unfortunately, the article is unavaiable...
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎01-18-2018 08:31 PM
Hello,
NAC is a RADIUS server but default.
To leverage AD you can proxy RADIUS to an NPS server or you can setup NAC to use LDAP/NTLM Authentication and authenticate users directly to AD (with no proxy to NPS).
Which are you looking to do?
You can see topics on this via the "Help" in NetSight or via our website where you download NAC/NetSight software.
*Note that Fortinet is not a supported Firewall if you are looking to authenticate VPN users through NAC...we only support Cisco ASA, Juniper SA, and Enterasys XSR. This information is in the Release Notes. You can likely use NAC for mgmt access to the Fortinet, however.
Regards,
Scott Keene
NMS/NAC Support
Extreme GTAC
NAC is a RADIUS server but default.
To leverage AD you can proxy RADIUS to an NPS server or you can setup NAC to use LDAP/NTLM Authentication and authenticate users directly to AD (with no proxy to NPS).
Which are you looking to do?
You can see topics on this via the "Help" in NetSight or via our website where you download NAC/NetSight software.
*Note that Fortinet is not a supported Firewall if you are looking to authenticate VPN users through NAC...we only support Cisco ASA, Juniper SA, and Enterasys XSR. This information is in the Release Notes. You can likely use NAC for mgmt access to the Fortinet, however.
Regards,
Scott Keene
NMS/NAC Support
Extreme GTAC
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎01-18-2018 08:31 PM
Hi, Scott,
thanks for your reply.
Could you please explain what is a difference between proxying RADIUS requests to NPS and authenticate users directly to AD? What is an easiest way?
I do not need to authenticate VPN users, just wired and wifi users to allow them Internet access.
Thank you very much!
thanks for your reply.
Could you please explain what is a difference between proxying RADIUS requests to NPS and authenticate users directly to AD? What is an easiest way?
I do not need to authenticate VPN users, just wired and wifi users to allow them Internet access.
Thank you very much!
