lợi ích của việc ứng dụng radius trong vpn là bạn có thể quản lý account...

Upload: letranganh

Post on 29-Oct-2015

53 views

Category:

Documents


0 download

TRANSCRIPT

Li ch ca vic ng dng Radius trong VPN l bn c th qun l account ngi dng. Account dng connect VPN c khi to trong domain Win2K3 nn s gip cho Admin d dng qun l... lm c iu ny, Router phi h tr VPN v Radius, s knh ti a ca VPN ph thuc vo Router h tr.

Cu hnh trn Windows Server 2003:1- Nng cp Server 2003 ln Domain Controller.

2- Ci t service IAS (Internet Authentication Service) trong Control Panel >> Add Remove Program >> Add Remove Windows Components >> Networking Service >> Details >> Internet Authentication Service.

3. Kch hot RADIUS trong Programs/Administrative Tools.

4. Right-click Clients chn New RADIUS Client

5. Nhp tn RADIUS Server trong mc Friendly name: g tn l VPNRadius. Client address: nhp da ch IP ca Router.

6. Ti Client-Vendor >> chn RADIUS Standard.Share secret v Confirm shared secret l password chng thc gia router v RADIUS server (VD: 123456).

7. Nhp double click vo profile VPNRadius va mi to, chn Grant remote access permission.

8. To mi 1 Policy trong Right Click ti mc Remote Access Policy >> New Remote Access Policy.

9. Chn Use the wizard to set up a typical policy for a common scenario, t tn miu t cho Policy trong mc Policy name >> Next.

10. Chn VPN.

11. Chn Group v nhp add thm vo Group cho php thc hin kt ni VPN.

12. Chn kiu chng thc MS-Chapv2.

13. Nhp Next.

14. Finish.

15. Vo Radius, nhp chut phi vo Internet Authentication Service, chn Register server in Active Directory.

16. Ti domain, nhp chut phi vo username anphat, chn properties, Tab Dial-in, chn Allow access.

17. Add username anphat vo Group Wifi.

18. Cu hnh trn Router Draytek Vigor 2800:- Truy cp vo trang cu hnh ca router (Router Draytek Vigor 2800) >> Applications >> RADIUS.- Check Enable kch hot tnh nng RADIUS.- Server IP Address l IP ca RADIUS Server.- Shared Secret l password mnh t mc Share Secret trong qu trnh xy dng RADIUS Server (123456).

19. To new connection trn my tnh client, connect v mng LAN ca cng ty.