Windows NPS as RADIUS Server for 802.1X and VPN - 夜莺博客

Windows NPS as RADIUS Server for 802.1X and VPN

If your identity lives in Active Directory and you do not want another platform to operate, Windows Network Policy Server is a perfectly serviceable RADIUS server for wired 802.1X, wireless and VPN access. It ships with Windows Server, integrates with AD groups natively and returns the standard attributes switches need. The catch is terminology: everything that a network engineer calls a policy is two objects in NPS, and the wizard creates them differently depending on whether you start from the VPN or the 802.1X path.

Objects you need before policies make sense

  1. Install the role: Network Policy and Access Services (NPAS), then open Network Policy Server from Server Manager > Tools.
  2. RADIUS clients - every authenticating device (switch, WLAN controller, VPN server) must be registered with its source IP address and a shared secret. Devices are not clients in the AD sense; the NAS is the RADIUS client. A mismatch here produces requests that NPS drops with no useful log line.
  3. Certificate - for PEAP or EAP-TLS, NPS needs a server certificate issued by a CA the clients trust. A self-signed default certificate is the standard reason end users see certificate warnings.
  4. AD groups - define who gets which access, so policies reference group membership instead of individual accounts.

Create policies with the wizard, then refine

NPS console > NPS (Local) > Standard Configuration
  RADIUS server for 802.1X Wireless or Wired Connections
    > Configure 802.1X using a wizard
       - Type of 802.1X connection: Secure Wireless + Secure Wired
       - RADIUS clients: the switches and controllers
       - Authentication method: PEAP / Microsoft: Protected EAP
       - User groups: Domain Users / Domain Computers

The wizard creates a connection request policy (decides which requests this NPS handles and where to authenticate them) and a network policy (decides whether access is granted and with which attributes). Requests must satisfy both, in that order.

Returning a VLAN to the switch

Network policy > Properties > Settings > RADIUS Attributes > Standard
  Tunnel-Medium-Type = 802 (Ethernet)
  Tunnel-Type        = Virtual LANs (VLAN)
  Tunnel-Pvt-Group-ID = 20          # the VLAN the port should move to

# voice devices get their own policy, matching the vendor attribute
Condition: NAS-Port-Type = Ethernet, plus group = Voice-Devices
Attributes: Tunnel-Pvt-Group-ID = 30
            Cisco AV-Pair: device-traffic-class=voice

The Tunnel-Pvt-Group-ID is the VLAN number the switch applies dynamically - the same mechanism Cisco ISE uses with its authorization profiles, described in Cisco ISE Policy Sets for Wired 802.1X: Setup Guide. Add the Cisco AV-Pair only for multi-domain or multi-auth ports where the phone and the attached PC must be distinguished.

Policy design rules

  • Order network policies from most specific to most general; the first match wins and processing stops.
  • Keep a catch-all deny at the end. A missing deny silently grants access with an empty policy result, which on a switch means "use the port's static VLAN".
  • Separate machine authentication (certificate or computer account) from user authentication; mixed-domain deployments rarely work with a single policy.
  • Log both authentication and accounting - the accounting log is how you reconstruct who connected to which port.

Verification

# NPS side
Event Viewer > Custom Views > Server Roles > Network Policy and Access Services
# or text logs, configured under NPS > Accounting

# switch side
show authentication sessions interface Gi1/0/1 details
show dot1x all summary

On the switch, the session details should show the method (dot1x or mab), the returned VLAN and the policy name. If NPS logs a reason code 65 (access denied) the server rejected the group; reason codes in the 20s point to credential or certificate problems. Where a dedicated NAC platform is an option, compare the operational trade-offs in ClearPass vs Cisco ISE: NAC Platform Comparison and the open-source alternative in FreeRADIUS EAP-TLS for Wired 802.1X with Cisco Switches before standardising.

原文链接:https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-np-configure