Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Authentication to RADIUS Server hosted at another location

Status
Not open for further replies.

pipkins

IS-IT--Management
Jul 16, 2003
10
0
0
GB
Hello,

I have two sites connected via a 'route-based' VPN. In the first site is a NetScreen 5XP and the second a NetScreen 25 both running ScreenOS 4.0.

I am configuring both NetScreen devices to utilise a RADIUS server for admin authentication. This works fine if the RADIUS server is connected to the local trusted network.

However, I want either NetScreen device to use the RADIUS server located in the alternate location, if it cannot communicate with its own local RADIUS server.

I have noted that when attempting to communicate with the remote RADIUS server, network traffic is not sent via the VPN, but unencrypted with a source address of the 'untrusted' interface.

Does anybody know how to setup this configuration, and I would assume that this also applies to the NetScreen attempting to communicate with DNS, NTP or authentication servers in a remote site ?

Thanks in advance.
 
Quick question for you Pipkins,

have you declared the radius server with a name or ip.
If it is ip then it should correctly route the information over the tunnel.

Remember to open port 1645 for it and all should be well.

If you are using domain names for the radius server you will need a wins server to get it running on the remote lan.

Regards

Njetscreamer
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top