Security for IAS (Radius)


hi all,

recently have built ias server provide authentication , access procurve switches network admins have raised concerned person domain admin or local admin of ias server can provide access domain user , thats both operation level , admin level.

i change solution little bit , need expert's suggestion on:

·     if raise separate forest altogether , establish 1 way trust user domain on ias server member of new forest , user user forest can be added defined connection request policy.

·     second option standalone server adam , ias in case need have separate user ids logon switches , password sync can’t maintained, not sure solution hence need details help.

regards

yogesh malhotra

 

 


yogesh malhotra http://flickr/photos/yogeshmalhotra

having fact want restrict administrative access ias/nsp server, option have have server in a separate security boundary if not trusting domains admins. still have "problem" local admins , there no way skip that dependency! 

i vote first option having ias/nps server in a separate forest where can restrict group membership of users account forest local security groups in resource forest. there no need synchronize or replicate user names or passwords! 

/hasain



Windows Server  >  Security



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client