{"id":2054,"date":"2017-03-29T18:28:47","date_gmt":"2017-03-29T18:28:47","guid":{"rendered":"http:\/\/microsoftgeek.com\/?p=2054"},"modified":"2018-09-06T23:18:18","modified_gmt":"2018-09-06T23:18:18","slug":"configure-a-radius-server-on-windows-server-to-authenticate-cisco-vpn-users","status":"publish","type":"post","link":"https:\/\/microsoftgeek.com\/?p=2054","title":{"rendered":"Configure a Radius server on Windows Server to authenticate Cisco VPN users"},"content":{"rendered":"<p>A <strong>Virtual Private Network (VPN)<\/strong> allows to connect to a private network through the Internet, from anywhere in the world.<\/p>\n<p>It may be very helpful to business users willing to access from outside the internal resources of their company.<\/p>\n<p>In this post we\u2019ll see how you can allow <strong>Active Directory<\/strong> users to perform the login to a <strong>VPN<\/strong>, configured on a <strong>Cisco<\/strong> router.<\/p>\n<p>The setup includes a <em>Cisco 1801<\/em> router, configured with a <strong>Road Warrior VPN<\/strong>, and a server with <strong>Windows Server 2012 R2<\/strong> where we installed and activated the domain controller and <strong>Radius<\/strong> server role.<br \/>\n<span id=\"more-3751\"><\/span><\/p>\n<p>To facilitate the management of the users with the permission to access through VPN, we are going to create a specific group called <em>VpnAuthorizedUsers:<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-172\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/1.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"1238\" height=\"652\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-173\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/2.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"779\" height=\"549\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-174\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/3.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"776\" height=\"541\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Assign the user who needs the VPN access to the group\u00a0<em>VpnAuthorizedUsers<\/em>:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-175\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/4.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"775\" height=\"540\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-176\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/5.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"775\" height=\"542\" \/><\/p>\n<p>Launch <em>Server Manager<\/em> and select <em>Add Roles and Features:<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-177\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/6.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"869\" height=\"578\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-178\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/7.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"797\" height=\"563\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Select the server where to install the role:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-179\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/8.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"795\" height=\"564\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Select the role <em>Network Policy and Access Services:<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-180\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/9.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"794\" height=\"561\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Install the required features:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-181\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/10.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"413\" height=\"436\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-182\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/11.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"788\" height=\"560\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-183\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/12.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"790\" height=\"559\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Select <em>Network Policy Server:<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-184\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/13.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"791\" height=\"557\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Press <em>Install<\/em> to start the installation of the role:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-185\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/14.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"791\" height=\"559\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Press <em>Close<\/em> to exit from the wizard:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-186\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/15.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"796\" height=\"561\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Procced with the configuration of the Radius server selecting <em>NAP<\/em>, then right-click on the server name and press <em>Network Policy Server:<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-187\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/16.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"926\" height=\"602\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Right-click on <em>NPS<\/em> and select <em>Register server in Active Directory:<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-188\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/17.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"577\" height=\"454\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Collapse the <em>Radius<\/em> menu and right-click on <em>RADIUS Clients:<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-189\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/18.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"728\" height=\"475\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Specify the name and the IP address of the peripheral that will forward the authentication requests to the Radius. Also specify a password for the connection:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-190\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/19.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"459\" height=\"582\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Expande <em>Policies<\/em> and right-click on <em>Connection Request Policies:<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-222\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/19a.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"828\" height=\"559\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Specify a policy name:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-191\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/20.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"688\" height=\"598\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Add a <em>Client Friendly Name<\/em> condition:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-192\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/21.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"687\" height=\"598\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Specify the same name used for the <em>Radius Clients:<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-193\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/22.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"691\" height=\"600\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-194\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/23.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"692\" height=\"603\" \/><\/p>\n<p>Click <em>Next:<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-195\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/24.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"692\" height=\"602\" \/><\/p>\n<p>Select the attribute <em>User-Name<\/em> and click <em>Next:<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-196\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/25.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"691\" height=\"602\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-3682\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/26.png\" sizes=\"auto, (max-width: 692px) 100vw, 692px\" srcset=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/26.png 692w, http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/26-300x261.png 300w, http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/26-680x591.png 680w\" alt=\"\" width=\"692\" height=\"601\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Right-click on <em>Network Policies:<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-198\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/27.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"681\" height=\"459\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Specify the policy name:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-199\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/28.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"687\" height=\"601\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Specify the <em>UserGroups<\/em> condition:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-200\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/29.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"691\" height=\"603\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Add the group <em>VpnAuthrizedUsers<\/em> that you\u2019ve precedently created:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-201\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/30.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"690\" height=\"598\" \/><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-202\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/31.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"686\" height=\"592\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-203\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/32.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"689\" height=\"600\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Enable the <em>PAP,SPAP<\/em> access:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-204\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/33.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"692\" height=\"600\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Press <em>NO<\/em> at the following dialog:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-205\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/34.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"689\" height=\"598\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-206\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/35.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"692\" height=\"599\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-207\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/36.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"691\" height=\"601\" \/><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-208\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/37.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"687\" height=\"600\" \/><\/p>\n<p>Once the Road Warrior VPN has been configured on the Cisco router, you have to enable the authentication of the VPN users through Radius.<\/p>\n<p>The <em>local<\/em> command allow local users of the router to connect even if the Radius server is offline:<\/p>\n<p><em>conf t<\/em><br \/>\n<em>aaa authentication login vpnuser group radius local<\/em><\/p>\n<p>Be sure the crypto map command has the same name of <em>aaa authentication:<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-210\" src=\"http:\/\/thesolving.com\/wp-content\/uploads\/2017\/01\/39.png\" alt=\"Radius Windows Server 2012 R2 Vpn Cisco\" width=\"447\" height=\"80\" \/><\/p>\n<p>Access in configuration mode <em>(Configure \u00a0terminal)<\/em> and specify the radius parameter with the IP address and the password specified at the beginning of the tutorial:<\/p>\n<p><em>radius-server host 10.0.0.1 auth-port 1812 acct-port 1813 key password xxxxxxxxx<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A Virtual Private Network (VPN) allows to connect to a private network through the Internet, from anywhere in the world. It may be very helpful to business users willing to access from outside the internal resources of their company. In this post we\u2019ll see how you can allow Active Directory users to perform the login [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[48],"tags":[],"class_list":["post-2054","post","type-post","status-publish","format-standard","hentry","category-microsoft-windows-server-2012"],"_links":{"self":[{"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/posts\/2054","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2054"}],"version-history":[{"count":3,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/posts\/2054\/revisions"}],"predecessor-version":[{"id":2057,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/posts\/2054\/revisions\/2057"}],"wp:attachment":[{"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2054"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2054"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2054"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}