- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- Re: How to configure C2S VPN with AzureAD and 2FA
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
White Paper - How to configure C2S VPN with AzureAD and 2FA
Hi Folks,
Well this is my first post here, figured I would create a quick document for a few of my customers but there has been a wider interest in it as well.
- Create new public DNS domain
- Added domain as a “Custom domain name” in AzureAD
- Created 2019 AD domain on prem
- Installed NPS onto AD server
- ** STOP AND TEST RADIUS **
- Installed Azure AD Connect and began AD sync to cloud
- Installed “Network Policy Server extension for Azure” on top of NPS
- Test
The way I have it setup is the gateway sends a RADIUS request to MS NPS, NPS auths’s against AD, if successful NPS will send it to AzureAD for OTP creation, MS will then send the OTP via SMS or email to the end user.
For the full list of White Papers, go here.
This is tested with a 750 running latest code as the gateway, SecureClient on the user PC and Capsule VPN on windows10
happy to answer questions or provide more info if needed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Tagging @_Val_, we probably need to treat this as a whitepaper.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, master, it is a white paper now
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello everyone,
can someone explain me the option on the Radius settings?
"Ask user for password (will be used to automatically answer the first challenge)".
we are planning to do the same config on SMB devices too and there I dont have this option.
Thanks in advance.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
can someone please explain me this option on the Radius setting.
"Ask user for password (will be used to automatically answer the first challenge)".
Im trying to setup a SMB device and dont have this option.
thanks in advance
