Showing posts with label Windows Server 2008R2. Show all posts
Showing posts with label Windows Server 2008R2. Show all posts

Friday, 23 November 2012

Windows 2008 RADIUS Server for Cisco Router



Introduction

RADIUS (Remote Authentication Dial-In User Service) is a security protocol which is used for centralized network access control for computers to connect and use network devices and services. RADIUS uses a client/server system where the RADIUS client will run on the networking devices (in our case it is Cisco router) and send the authentication request to the central RADIUS server (in our case it is NPS) that contain all the user authentication and network service access information. Refer Figure1 to see how the RADIUS works. AAA (Authentication, Authorization, and Accounting) is a network security service where you can set up access control on your router or access servers. AAA uses protocols such as RADIUS , TACACS+, or Kerberos to administer its security functions.

Microsoft NPS (Network Policy Server) is a feature in Windows Server 2008 that centrally manage and enforce the network access policies that determine whether the user can or cannot access the network. The NPS is using the RADIUS protocol to communicate with the servers and network devices for authentication. This service is mainly used for the Remote user who connect with VPN or wireless access points to access the network resources. Using an NPS server you can create network policies centrally and can be used in all the networking devices in your network.

Figure 1:

This guide will show you the quick steps to configure a Microsoft NPS server for RADIUS authentication for Cisco router logins. Below are the tasks we are going to accomplish.

1. Configure Microsoft NPS server as RADIUS Server

2. Configure Cisco for RADIUS authentication.

Prerequisites

1. Windows Server 2008R2

2. Active Directory Domain Services

3. NPS Server must be a member of a domain

Configure Microsoft NPS server as RADIUS Server

1. Go to Server Manger > Roles > Add Roles and select 'Network Policy and Access Services' click Next

2. Read the description and click Next
 
3. Select Network Policy Server and click Next

4. Confirm the Installation by clicking Finish

5. Now go to Start > Administrative Tools > Network Policy Server.
Now click Action and click Register Server in Active Directory to register the NPS in Active Directory.

6. Confirm that you want to authorize this computer (NPS) to read users' dial-in properties of the domain by clicking OK

7. Now you will see the confirmation screen and click OK
 
8. Now  on the left panel under the RADIUS Clients and Servers right click RADIUS Clients and click New RADIUS Client.
9. Now specify the policy name and connection type. Here I am mentioning the policy name as 'Cisco Router Access' and Type of network access server is 'Unspecified'.
 
10. On the Specify Conditions page add a Windows group and specify a group from Active Directory.
Here I am adding Network Support group from the Active Directory. 

11. On the Specify Access Permission page, select Access granted only and click Next.

12. Now select Unencrypted authentication [PAP, SPAP] on the Configure Authentication Methods.

13. On the Configure settings page in Standard Section add Service-Type parameter with the value NAS Prompt.
 
14. On the Configure settings page in Vendor Specific section add Cisco-AV-Pair parameter with value: shell:priv-lvl=15 . This particular example causes a user logging in from a network access server to have immediate access to EXEC commands.

15. On the Completing New Network Policy page review the settings and click Finish

Below you can see the screen-shot of the network policy that we have created.

2. Configuring Cisco Router for RADIUS authentication

The below configuration will enable the RADIUS Authentication on your Cisco Router.

Enable AAA on the router by using the below command in global configuration mode.

Cisco(config)#aaa new-model

Cisco(config)#aaa group server radius NPS
Cisco(config-sg-radius)#server 172.17.0.52 auth-port 1812 acct-port 1813

Where 172.17.0.52 is the IP address of the RADIUS Server.

Cisco(config)#aaa authentication login ciscoauth local group NPS
Cisco(config)#aaa authorization exec ciscoauth local group NPS if-authenticated
Cisco(config)#aaa authorization network ciscoauth local group NPS
Cisco(config)#aaa accounting exec default start-stop group NPS
Cisco(config)#aaa accounting system default start-stop group NPS

Cisco(config)#aaa session-id common

Cisco(config)#ip radius source-interface GigabitEthernet0/0  (User facing Interface)
Cisco(config)#radius-server host 172.17.0.52 auth-port 1812 acct-port 1813 key sharedkey

Cisco(config)#line vty 0 4
Cisco(config-line)# authorization exec ciscoauth
Cisco(config-line)#login authentication ciscoauth
Cisco(config-line)#transport input telnet rlogin ssh

There we finish our configuration. Now you can test it by logging into the router as a user who is a member of the Network support group.

Thursday, 1 November 2012

How to setup a Windows Server 2008R2 Domain Controller

Introduction

Domain is one of the most important concept in a Windows network. A domain is a collection of user and computer accounts that are grouped together so that they can be centrally managed using a Domain controller. A domain controller is a server which hold the 'Active Directory Domain Service (AD DS)' role in a network. Once you promote a Windows server as a domain controller it can be used for controlling and managing the whole domain in a centralized location. The domain controller will provide a single sign-on to various servers and services inside a domain. Also users and computers can be granted with access permissions. Group policy is one of the most important feature in AD DS that controls the working environment of user accounts and computer accounts. Group policy provides centralized management and configuration of operating systems, applications and user's setting in active directory environment. While you setup a domain controller, a DNS server will also get configured along with the AD DS. DNS server is one of the most important service in a network that will serve the computers with its name resolution functionality.

Prerequisites
  • Server should be configured with a static IP address.
  •  Appropriate DNS configuration should be there, if there is no DNS server in your network put the loop-back address as the DNS server address in TCP/IP configuration.
  • Computer must be connected in a network.
Promoting Windows Server 2008R2 as Domain controller
1. Log on to windows server 2008R2 computer as an administrator.
Click Start > Run

Type 'dcpromo' and click OK



2. Now AD DS binaries will start installing on your server. Wait for the installation to get finished.


3. Now the Active Directory Domain Services Installation wizard will open up. Tick the Use advanced mode installation check box and click next.

4. On the Operating system compatibility windows, read the information and click Next.


5. On 'Choose a Deployment Configuration' window select 'Create a new domain in a new forest' since we are going to configure the first domain server in this network, click Next



6. On this windows you can name the domain that you are going to create. In this example I am naming it as 'mathew.com' Type the fully qualified domain name that you wish to use and click Next.



7. On the Domain NETBIOS name wizard leave it as default and click Next. In our example it is MATHEW
 
8. On the forest functional level wizard choose the functional level that you wish to use and click next. In this example I am choosing 'Windows Server 2008 R2'. You can see the details about each functional level available on the box below. Click Next.




9. On the Additional Domain Controller Option tick the DNS server option and click Next. Here you can find that the Global catalog option is ticked and grayed out. This is because Global catalog is installed by default while you configure first domain controller in a network.


 
10. Safely ignore the DNS warning wizard and click Yes to continue.
 
11. Now the wizard will ask you to choose a location for Database, Log Files and SYSVOL. The best practice is to choose a location which is other than the System volume to store these files. Click Next
 
12. Choose a Directory services restore mode administrator password. Make sure that you are providing a password other than the administrator password. This password is used for recovering AD in case of any disaster. Click Next

13. On the Summary window review the settings and Click next.

14. Once you click Next the wizard will configure Active Directory Domain Services on your Server. It is better to tick the Reboot on completion check box to reboot the server automatically to finish the Installation.

15. After the reboot go to Start > Administrative Tools > Active Directory Users and computers where you will find the domain that you have created. In our example you can find 'mathew.com' in Active Directory Users and computers.

Additional Information
1. To find out the roles Installed along with AD DS
You can use the command 'netdom query fsmo' to find out the roles installed along with the Active Directory Domain Services. Below is the screen-shot which shows the output of the command.
 
You can visit "How to transfer FSMO Roles in 2008R2"  to know more about fsmo roles and how to transfer these roles to another DC in the same domain.

2. DNS Server Snap-In after the fresh installation



Here you can find the DNS Manager snap-in after a fresh Installation.



3. Default Domain Policy of after the fresh Installation of AD DS.

You can find the screen-shots of the default domain policy after the installation of AD DS. Refer Figure 1 and Figure 2:
Figure 1:

Figure 2:
To know more about group policy visit http://technet.microsoft.com/en-us/library/bb742376.aspx 

While we configure a Domain Controller in a network it is better to configure an additional domain controller to improve the reliablility and availability of the network services. The Additional Domain Controller will serve the client machines in case of any failure of the Primary Domain Controller. I will explian how to configure an Additional Domain Controller latter in my Blogs.

Thursday, 18 October 2012

Step-by-Step guide to transfer FSMO roles in Windows Server 2008

The FSMO role holder is known as the Primary Domain Controller in a Domain. FSMO, also called Flexible Single Master Role will decide which DC should hold the Operation Master Role in a domain. During the installation of Domain Controller the FSMO role is automatically installed on the first server. If you have only one DC you don't want to do anything with the FSMO roles. But in a multiple server environment you may need to transfer the FSMO roles in some situations.There are totally five roles associated with FSMO.
  • This document will help you to transfer the FSMO roles to another DC.
The following are the five FSMO Roles :
  1. Schema Master Role
  2. Domain Naming Master
  3. RID Master
  4. PDC Master
  5. Infrastructure Master
You can use the command 'netdom query fsmo' to find out which DC is holding the FSMO roles.

This is an IMPORTANT thumb rule that you have to consider while transferring FSMO roles:

DO NOT place the Infrastructure Master Role in a DC where Global Catalog is configured unless all the Domain Controllers are configured as Global Catalog.

I will show how to manage Global Catalog in a DC latter in this guide.

Some Prerequisites

You have to follow this prerequisites before transferring FSMO roles.
  1. There should be a good connectivity between DC's.
  2. Proper Replication between DC's (You can use repadmin.exe to check the replication status and problems)
  3. Proper DC health (You can use dcdiag.exe to check the health of the DC)
  4. The DC that you are going to transfer should be configured as a NTP Time server (Refer http://yadhutony.blogspot.in/2012/10/ntp-time-server-configuration-in.html for configuration details)
To transfer the FSMO roles you can either use GUI or ntdsutil.exe in CLI. In our scenario I am going to use GUI to transfer the roles. 

Best Practises
  1. Schema Master and Domain Naming Master in one machine, which also hold the Global catalog
  2. PDC,RID (Infrastructure) in one machine.
  3. Do not place Infrastructure master role in a DC where Global catalog is enabled unless all the DC's are enabled with Global catalog
Also visit http://support.microsoft.com/kb/223346 for more details.

Transfering FSMO Roles

Scenario

>In our test scenario we have three DC's
The FQDN of the DC's are :
1. dc001.tony.com 2. dc002.tony.com 3. dc003.tony.com.
 
>Currently dc003.tony.com is the Operation master which hold all the FSMO roles in the domain tony.com.

>I am going to transfer the FSMO roles from dc003.tony.com to dc002.tony.com.
A.) Schema Master Role
 
We need to use Schema master snap-in to transfer the schema master role. To install the schema master snap-in you need to follow the below steps:
Register Schmmgmt.dll  
1.Open command prompt and type regsvr32 schmmgmt.dll

2.Click Start, click Run, type mmc, and then click OK
3.On the File, menu click Add/Remove Snap-in
 
4.Click Add

5.Click Active Directory Schema, click Add, click Close, and then click OK

Transferring Schema Master Role
1. Go to Schema master snap-in
 
2. Right-click Active Directory Schema and click Change Domain Controllers.
 
3. Now select the “domain controller” that you wanted to transfer the schema master role and click OK. In my case I need to transfer it to dc002.tony.com


4. Right-click Active Directory Schema and click Operation master > Change Schema master > Change 

 
 
Now the Schema Master Role is transferred to the preferred DC tony002.tony.com as you can see from the below screenshot.


B.) Transfer Domain Naming Master Role

1. Go to Active Directory Domain and Trust
2. Right-click the Active Directory Domain and Trust and click Change Active Directory Domain Controller

 
3. Now select the “domain controller” that you wanted to transfer the naming master role and click OK.


4. Right-click the Active Directory Domain and Trust and click Operation Master> Domain Naming Operation Master > Change.
Now the Naming Master Role is transferred to the preferred DC dc002.tony.com
  
 
C.) Transfer RID , PDC and Infrastructure Master

We can transfer these three roles using a single snap-in, Active Directory Users and Computers
1. Go to Active Directory Users and Computers
 
2. Right-click Active Directory Users and Computers > All Tasks >Change Domain Controller
3. Now select the “domain controller” that you wanted to transfer the operation master (RID, PDC, Infrastructure) role and click OK.


4. Right-click the Active Directory Domain and Trust and click Operation Master
Click RID tab > Click Change
  

5. Click PDC tab> Click Change

 
6. Click Infrastructure Master tab > Click Change

 
As soon as I try to change the Infrastructure master role I got a warning like “The Infrastructure master role should not be transferred to a GC server” Since all my DC's hold Global catalog I can safely ignore this warning and proceed. In your case DO NOT move Infrastructure master role unless all the DC's hold GC, else remove Global catalog and transfer Infrastructure master role.

 
Click Yes

By following the above steps you can successfully transfer the FSMO roles from one DC to another.
Also you can make sure that all the FSMO roles got transferred by running netdom query fsmo. See the result below:


  Administering Global Catalog in a DC

Global Catalog server hold the complete information about all the objects of its own domain. To know more about global catalog you can visit: http://technet.microsoft.com/en-us/library/cc730749.aspx

Here I am going to explain you how to enable or remove a Global Catalog Server.

1. Click Active Directory Sites and Services

2. In the console tree, double-click Sites, and then double-click “sitename”

3. Double-click Servers, click your domain controller, right-click NTDS Settings, and then click Properties.

4. On the General tab, click to select the Global catalog check box to assign the role of global catalog to the server.

5. If the check box was already ticked untick it to remove the global catalog from the server.


6. Restart the Domain Controller.