Showing posts with label Server 2008. Show all posts
Showing posts with label Server 2008. Show all posts
Saturday, 24 November 2012
Resetting secure channel between DCs
This summary is not available. Please
click here to view the post.
Friday, 23 November 2012
Windows 2008 RADIUS Server for Cisco Router
Introduction
RADIUS (Remote Authentication Dial-In User
Service) is a security protocol which is used for centralized network
access control for computers to connect and use network devices and
services. RADIUS uses a client/server system where the RADIUS client
will run on the networking devices (in our case it is Cisco router)
and send the authentication request to the central RADIUS server (in
our case it is NPS) that contain all the user authentication and
network service access information. Refer Figure1 to see how the
RADIUS works. AAA (Authentication, Authorization, and Accounting)
is a network security service where you can set up access control on
your router or access servers. AAA uses protocols such as RADIUS ,
TACACS+, or Kerberos to administer its security functions.
Microsoft NPS (Network Policy
Server) is a feature in Windows Server 2008 that centrally manage and
enforce the network access policies that determine whether the user
can or cannot access the network. The NPS is using the RADIUS
protocol to communicate with the servers and network devices for
authentication. This service is mainly used for the Remote user who
connect with VPN or wireless access points to access the network
resources. Using an NPS server you can create network policies
centrally and can be used in all the networking devices in your
network.
Figure 1:
This guide will show you the quick steps to configure a
Microsoft NPS server for RADIUS authentication for Cisco router
logins. Below are the tasks we are going to accomplish.
1.
Configure Microsoft NPS server as RADIUS Server
2.
Configure Cisco for RADIUS authentication.
Prerequisites
1. Windows Server 2008R2
2. Active Directory Domain Services
3. NPS Server must be a member of a domain
Configure Microsoft NPS server as RADIUS Server
1. Go to Server Manger > Roles > Add
Roles and select 'Network Policy and Access Services' click
Next
2. Read the description and click Next
3. Select Network Policy Server and click Next
4. Confirm the Installation by clicking Finish
5. Now go to Start > Administrative Tools >
Network Policy Server.
Now click Action and click Register Server
in Active Directory to register the NPS in Active Directory.
6. Confirm that you want to authorize this computer (NPS) to read users' dial-in properties of the domain by clicking OK
7. Now you will see the confirmation screen and click OK
8. Now on the left panel under the RADIUS Clients and
Servers right click RADIUS Clients and click New RADIUS
Client.
9. Now specify the policy name and connection type.
Here I am mentioning the policy name as 'Cisco Router Access'
and Type of network access server is 'Unspecified'.
10. On the Specify Conditions page add a Windows
group and specify a group from Active Directory.
Here I am adding Network Support group from the
Active Directory.
11. On the Specify Access Permission page, select Access granted only and click Next.
12. Now select Unencrypted authentication [PAP, SPAP]
on the Configure Authentication Methods.
13. On the Configure settings page in Standard Section add Service-Type parameter with the value NAS Prompt.
14. On the Configure settings
page in Vendor Specific section
add Cisco-AV-Pair parameter
with value: shell:priv-lvl=15
. This particular example causes a user logging in from a network
access server to have immediate access to EXEC commands.
15. On the Completing New Network Policy page
review the settings and click Finish
Below you can see the screen-shot of the network policy
that we have created.
2.
Configuring Cisco Router for RADIUS authentication
The below configuration will enable the RADIUS
Authentication on your Cisco Router.
Enable AAA on the router by using the below command in
global configuration mode.
Cisco(config)#aaa
new-model
Cisco(config)#aaa group server radius NPS
Cisco(config-sg-radius)#server
172.17.0.52 auth-port 1812 acct-port 1813
Where 172.17.0.52 is the IP address of the RADIUS Server.
Cisco(config)#aaa authentication login ciscoauth local group NPS
Cisco(config)#aaa
authorization exec ciscoauth local group NPS if-authenticated
Cisco(config)#aaa
authorization network ciscoauth local group NPS
Cisco(config)#aaa
accounting exec default start-stop group NPS
Cisco(config)#aaa
accounting system default start-stop group NPS
Cisco(config)#aaa session-id common
Cisco(config)#ip radius source-interface GigabitEthernet0/0 (User facing Interface)
Cisco(config)#radius-server
host 172.17.0.52 auth-port 1812 acct-port 1813 key sharedkey
Cisco(config)#line vty 0 4
Cisco(config-line)#
authorization exec ciscoauth
Cisco(config-line)#login
authentication ciscoauth
Cisco(config-line)#transport
input telnet rlogin ssh
There we finish our configuration. Now you can test it by logging into the router as a user who is a member of the Network support group.
Thursday, 1 November 2012
How to setup a Windows Server 2008R2 Domain Controller
Introduction
Prerequisites
3. Now the Active Directory Domain Services Installation wizard will open up. Tick the Use advanced mode installation check box and click next.
7. On the Domain NETBIOS name wizard leave it as default and click Next. In our example it is MATHEW
Domain is one of the most important concept in a Windows
network. A domain is a collection of user and computer accounts that
are grouped together so that they can be centrally managed using a
Domain controller. A domain controller is a server which hold the
'Active Directory Domain Service (AD DS)' role in a network. Once
you promote a Windows server as a domain controller it can be used
for controlling and managing the whole domain in a centralized
location. The domain controller will provide a single sign-on to
various servers and services inside a domain. Also users and
computers can be granted with access permissions. Group policy is one
of the most important feature in AD DS that controls the working
environment of user accounts and computer accounts. Group policy
provides centralized management and configuration of operating
systems, applications and user's setting in active directory
environment. While you setup a domain controller, a DNS server will
also get configured along with the AD DS. DNS server is one of the
most important service in a network that will serve the computers
with its name resolution functionality.
Visit http://technet.microsoft.com/en-us/library/cc786438(v=ws.10).aspx and http://technet.microsoft.com/en-us/library/dd578336(v=ws.10).aspx for more details about Domain Controllers and Active Directory Services.
Prerequisites
- Server should be configured with a static IP address.
- Appropriate DNS configuration should be there, if there is no DNS server in your network put the loop-back address as the DNS server address in TCP/IP configuration.
-
Computer must be connected in a network.
Promoting
Windows Server 2008R2 as Domain controller
1. Log on to windows server 2008R2 computer as an
administrator.
Click
Start
> Run
Type
'dcpromo'
and click OK
2. Now AD DS binaries will start installing on your
server. Wait for the installation to get finished.
3. Now the Active Directory Domain Services Installation wizard will open up. Tick the Use advanced mode installation check box and click next.
6.
On this windows you can name the domain that you are going to create.
In this example I am naming it as 'mathew.com'
Type the fully
qualified domain name that you wish to use and click Next.
7. On the Domain NETBIOS name wizard leave it as default and click Next. In our example it is MATHEW
8. On
the forest functional level wizard choose the functional level that
you wish to use and click next. In this example I am choosing
'Windows Server 2008
R2'. You can see the
details about each functional level available on the box below. Click
Next.
To
know more about functional levels visit http://technet.microsoft.com/en-us/library/understanding-active-directory-functional-levels(v=ws.10).aspx
9.
On the Additional Domain Controller Option tick
the DNS
server option and
click Next. Here
you can find that the Global catalog option is ticked and grayed out.
This is because Global catalog is installed by default while you
configure first domain controller in a network.
10.
Safely ignore the DNS warning wizard and click Yes
to continue.
14. Once you click Next the wizard will configure Active Directory Domain Services on your Server. It is better to tick the Reboot on completion check box to reboot the server automatically to finish the Installation.
3. Default Domain Policy of after the fresh Installation of AD DS.
You can find the screen-shots of the default domain policy after the installation of AD DS. Refer Figure 1 and Figure 2:
11.
Now the wizard will ask you to choose a location for Database, Log
Files and SYSVOL. The best practice is to choose a location which is
other than the System volume to store these files. Click Next
12.
Choose a Directory services restore mode administrator password. Make
sure that you are providing a password other than the administrator
password. This password is used for recovering AD in case of any
disaster. Click Next
13. On
the Summary window review the settings and
Click next.
14. Once you click Next the wizard will configure Active Directory Domain Services on your Server. It is better to tick the Reboot on completion check box to reboot the server automatically to finish the Installation.
15.
After the reboot go to
Start > Administrative Tools > Active Directory Users and
computers where you
will find the domain that you have created. In our example you can
find 'mathew.com' in
Active
Directory Users and computers.
Additional
Information
1. To find
out the roles Installed along with AD DS
You
can use the command 'netdom
query fsmo' to find
out the roles installed along with the Active Directory Domain
Services. Below is the screen-shot which shows the output of the
command.
You can visit "How to transfer FSMO Roles in 2008R2" to know more about fsmo roles and how to transfer these
roles to another DC in the same domain.
2. DNS
Server Snap-In after the fresh installation
Here you can find the DNS Manager snap-in after a fresh
Installation.
To know more about DNS Server Role visit http://technet.microsoft.com/en-us/library/cc753635(v=ws.10).aspx
3. Default Domain Policy of after the fresh Installation of AD DS.
You can find the screen-shots of the default domain policy after the installation of AD DS. Refer Figure 1 and Figure 2:
Figure 1:
Figure 2:
To know more about group policy visit http://technet.microsoft.com/en-us/library/bb742376.aspx
While we configure a Domain Controller in a network it is better to configure an additional domain controller to improve the reliablility and availability of the network services. The Additional Domain Controller will serve the client machines in case of any failure of the Primary Domain Controller. I will explian how to configure an Additional Domain Controller latter in my Blogs.
While we configure a Domain Controller in a network it is better to configure an additional domain controller to improve the reliablility and availability of the network services. The Additional Domain Controller will serve the client machines in case of any failure of the Primary Domain Controller. I will explian how to configure an Additional Domain Controller latter in my Blogs.
Thursday, 18 October 2012
Step-by-Step guide to transfer FSMO roles in Windows Server 2008
The FSMO role holder is known as the Primary Domain
Controller in a Domain. FSMO, also called Flexible Single Master Role
will decide which DC should hold the Operation Master Role in a
domain. During the installation of Domain Controller the FSMO role
is automatically installed on the first server. If you have only one
DC you don't want to do anything with the FSMO roles. But in a
multiple server environment you may need to transfer the FSMO roles
in some situations.There are totally five roles associated with FSMO.
- This document will help you to transfer the FSMO roles to another DC.
The following are the five FSMO Roles :
- Schema Master Role
- Domain Naming Master
- RID Master
- PDC Master
- Infrastructure Master
You can use the command 'netdom query fsmo' to
find out which DC is holding the FSMO roles.
This is an IMPORTANT thumb rule that you have to
consider while transferring FSMO roles:
DO
NOT place the Infrastructure Master Role in a DC where Global Catalog
is configured unless all the Domain Controllers are configured as
Global Catalog.
I will show how to manage Global Catalog in a DC latter
in this guide.
Some
Prerequisites
You have to follow this prerequisites before transferring
FSMO roles.
- There should be a good connectivity between DC's.
- Proper Replication between DC's (You can use repadmin.exe to check the replication status and problems)
- Proper DC health (You can use dcdiag.exe to check the health of the DC)
- The DC that you are going to transfer should be configured as a NTP Time server (Refer http://yadhutony.blogspot.in/2012/10/ntp-time-server-configuration-in.html for configuration details)
To transfer the FSMO roles you can either use GUI or
ntdsutil.exe in CLI. In our scenario I am going to use GUI to
transfer the roles.
Best
Practises
- Schema Master and Domain Naming Master in one machine, which also hold the Global catalog
- PDC,RID (Infrastructure) in one machine.
- Do not place Infrastructure master role in a DC where Global catalog is enabled unless all the DC's are enabled with Global catalog
Scenario
>In our test scenario we have three DC's
The FQDN of the DC's are :
1. dc001.tony.com 2. dc002.tony.com 3.
dc003.tony.com.
>Currently dc003.tony.com is the Operation
master which hold all the FSMO roles in the domain tony.com.
>I am going to transfer the FSMO roles from
dc003.tony.com to dc002.tony.com.
A.) Schema
Master Role
We need to use Schema master snap-in to transfer the
schema master role. To install the schema master snap-in you need to
follow the below steps:
Register Schmmgmt.dll
1.Open
command prompt and type regsvr32
schmmgmt.dll
3.On the File,
menu click Add/Remove Snap-in
4.Click
Add
5.Click
Active
Directory Schema,
click Add,
click Close,
and then click OK
Transferring
Schema Master Role
1. Go to Schema master snap-in
2. Right-click Active Directory Schema and click
Change Domain Controllers.
3. Now select the “domain controller” that you
wanted to transfer the schema master role and click OK. In my
case I need to transfer it to dc002.tony.com
4. Right-click Active Directory Schema and click
Operation master > Change Schema master > Change
Now the Schema Master Role is transferred to the
preferred DC tony002.tony.com as you can see from the below
screenshot.
B.)
Transfer Domain Naming Master Role
1. Go to Active Directory Domain and Trust
2. Right-click the Active Directory Domain and Trust
and click Change Active Directory Domain Controller
3. Now select the “domain controller” that you
wanted to transfer the naming master role and click OK.
4. Right-click the Active Directory Domain and Trust
and click Operation Master> Domain Naming Operation
Master > Change.
Now the Naming Master Role is transferred to the
preferred DC dc002.tony.com
C.)
Transfer RID , PDC and Infrastructure Master
We can transfer these three roles using a single
snap-in, Active Directory Users and Computers
1. Go to Active Directory Users and Computers
2. Right-click Active Directory Users and Computers >
All Tasks >Change Domain Controller
3. Now select the “domain controller” that you
wanted to transfer the operation master (RID, PDC, Infrastructure)
role and click OK.
4. Right-click the Active Directory Domain and Trust
and click Operation Master
Click RID tab > Click Change
5. Click PDC tab> Click Change
6. Click Infrastructure Master tab > Click
Change
As soon as I try to change the Infrastructure master
role I got a warning like “The Infrastructure master role should
not be transferred to a GC server” Since all my DC's hold
Global catalog I can safely ignore this warning and proceed. In your
case DO NOT move Infrastructure master role unless all the DC's hold
GC, else remove Global catalog and transfer Infrastructure master
role.
Click Yes
By following the above steps you can successfully
transfer the FSMO roles from one DC to another.
Also you can make sure that all the FSMO roles got
transferred by running netdom query fsmo. See the result below:
Administering
Global Catalog in a DC
Global Catalog server hold the complete information
about all the objects of its own domain. To know more about global
catalog you can visit: http://technet.microsoft.com/en-us/library/cc730749.aspx
Here I am going to explain you how to enable or remove a
Global Catalog Server.
1. Click Active Directory Sites and Services
2. In the console tree, double-click Sites,
and then double-click “sitename”
3. Double-click Servers, click your domain
controller, right-click NTDS Settings, and then click
Properties.
4. On the General tab, click to select the
Global catalog check box to assign the role
of global catalog to the server.
5. If the check box was already ticked untick
it to remove the global catalog from the server.
6. Restart the Domain Controller.
Subscribe to:
Posts (Atom)





