IAS and 802.1x/MAC authentication to replace VMPS


hello,

 

sorry not find forum directly ias , seemed closest fit.

 

i'm researching how move our network vmps (a soon-to-be end-of-lifed cisco mac address based wired switch port authentication , vlan assignment mechanism) combination of 802.1x , mac authentication , see if microsoft ias radius would fit bill.  i've read ias on technet , see using remote access policies, should able map mac addresses vlan assignments.  question is, does know of an automation tool can take flat file of mac address vlan mappings , create necessary ias remote access policies mac address vlan mappings?  have thousands of changing mac addresses , hundreds of vlans need keep track of , have system in place generate flat file of mac address vlan mappings. i've looked @ cisco acs server , it's not scalable wanted see how ias (or whatever new radius server microsoft running these days) work before delving freeradius has it's own issues when trying communicate ad via samba since dont allow ntlm on our network.

 

any or suggestions appreciated!

 

thanks,

 

mark

hi mark,

 

you can review this forum post review of methods used incorporate mac addresses network policy server (nps) policies [microsoft's new radius server in windows server 2008]: http://forums.microsoft.com/technet/showpost.aspx?postid=2470343&siteid=17, sounds may understand possible.

 

as dynamically creating policies flat file, guessing need scripted. i'm not aware of automation tool can you.

 

since can use pattern matching when creating authentication (connection request) and authorization (network) policies in nps, calling-station-id condition can used match multiple clients if wish, , make vlan assignment - eliminating need create policy each individual mac address. since nps configuration in xml format, importing changes not complicated.

 

i hope helps!

 

-greg

 

p.s. couple other forums may provide migration forum (http://forums.microsoft.com/technet/showforum.aspx?forumid=574&siteid=17) , network infrastructure severs forum (http://forums.microsoft.com/technet/showforum.aspx?forumid=1510&siteid=17).



Windows Server  >  Network Access Protection



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group