Jump to content

Recommended Posts

Posted

Hi

 

I'm wanting to set up a secondary RADIUS NPS server for failover/redundancy /load balancing and know that I will also need certificates on the clients to allow authentication against the different server name.

 

However, when setting up the second server do I set it up as another ROOT CA or SUBORDINATE CA?

 

Also, if i'm putting both radius servers into the wireless APs will it only use the secondary one if the primary is unreachable?

 

If I don't have an NPS proxy, but just the 2 servers, can I still configure load balancing between the 2 from within the NPS configuration?

 

Thanks.

Posted

Hey @ITGURU

 

Certificate services and NPS are completely separate things, so no need to setup your 2nd RADIUS server as a certificate authority.

 

Yep - the APs will only contact box #2 if #1 is unavailable without an NPS proxy.

 

How many authenticating devices will you have? A single radius server can handle a lot (and doesn't need a particularly impressive spec), so I would think redundancy would be fine.

Posted
Hey @ITGURU

 

Certificate services and NPS are completely separate things, so no need to setup your 2nd RADIUS server as a certificate authority.

 

Yep - the APs will only contact box #2 if #1 is unavailable without an NPS proxy.

 

How many authenticating devices will you have? A single radius server can handle a lot (and doesn't need a particularly impressive spec), so I would think redundancy would be fine.

 

Hi

I just assumed that if the client is connecting to a different server it would need a certificate with the second servers name in, so it can authenticate to that one also?

Potentially I have 300 wireless devices in AD, but cannot say how many would be in used at any one time.

Posted
It'll need a certificate, but you can just issue one from your existing CA server.

 

300 is small fry for an NPS box.

 

Is there a step by step for doing the certificate side? So that in the event of the primary server going off, clients can continue to authenticate through the second one?

Posted

Assuming you've already got a cert services server setup, you'd do this from your 2nd NPS box:

 

1. Click Start --> Run and type MMC to open management console.

2. Click File > Add/Remove Snap In

3. On the drop down menu select Console Root and then click Add.

4. Select the Certificates snap in and then click Add.

5. Click Computer Account > Next make sure Local Computer is selected.

6. Expand the Certificate (Local Computer) and click on Personal store

7. Right click on Certificates and select All Tasks --> Request New Certificate.

8. Make sure Server or Computer is selected and then click Next.

9. Give a friendly name to the certificate and also provide a description for what the certificate is going to be

used for and click Next

10. The final box will give you a summary of the details entered and issue a certificate.

 

Ant

Posted
Assuming you've already got a cert services server setup, you'd do this from your 2nd NPS box:

 

1. Click Start --> Run and type MMC to open management console.

2. Click File > Add/Remove Snap In

3. On the drop down menu select Console Root and then click Add.

4. Select the Certificates snap in and then click Add.

5. Click Computer Account > Next make sure Local Computer is selected.

6. Expand the Certificate (Local Computer) and click on Personal store

7. Right click on Certificates and select All Tasks --> Request New Certificate.

8. Make sure Server or Computer is selected and then click Next.

9. Give a friendly name to the certificate and also provide a description for what the certificate is going to be

used for and click Next

10. The final box will give you a summary of the details entered and issue a certificate.

 

Ant

 

Much appreciated - i'll give that a go once got the second server up and running! :-)

Posted
Much appreciated - i'll give that a go once got the second server up and running! :-)

 

All working if I stop the primary server! However, just realised the second server certificate is only for 365 days. How do I use the template I duplicated on the primary server with the same validity period?

 

then how do I revoke the old one? Just right click and revoke from the issued certificates on the first server?

 

thanks.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...