Security for IAS (Radius)
hi all,
recently have built ias server provide authentication , access procurve switches network admins have raised concerned person domain admin or local admin of ias server can provide access domain user , thats both operation level , admin level.
i change solution little bit , need expert's suggestion on:
· if raise separate forest altogether , establish 1 way trust user domain on ias server member of new forest , user user forest can be added defined connection request policy.
· second option standalone server adam , ias in case need have separate user ids logon switches , password sync can’t maintained, not sure solution hence need details help.
regards
yogesh malhotra
yogesh malhotra http://flickr/photos/yogeshmalhotra
having fact want restrict administrative access ias/nsp server, option have have server in a separate security boundary if not trusting domains admins. still have "problem" local admins , there no way skip that dependency!
i vote first option having ias/nps server in a separate forest where can restrict group membership of users account forest local security groups in resource forest. there no need synchronize or replicate user names or passwords!
/hasain
Windows Server > Security
Comments
Post a Comment