Discussion:
NPS, Radius, and multiple domains
(too old to reply)
Perseus109
2012-03-22 18:49:45 UTC
Permalink
Just had a quick question and I was hoping one of you might have an
idea. I have added a second two way trust domain (domain B) to our
forest and I need for the users in that domain to be able to VPN in
through our Watchguard firewall useing the Radius server I have
already set up and working for domainA. I have tried adding the user
from the second domain to the existing permission group in domainA, as
well as creating a second group on domainB and adding that in the NPS
policy. The first method gives an authentication error showing that
they used domainA for the domain instead of domainB. The later method
prevents all users from being able to log in at all. Any idea what I
am missing?
Peter Foldes
2012-03-22 20:15:40 UTC
Permalink
Did you give permission from User A to user B
--
Peter
Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.
This posting is provided "AS IS" with no warranties, and confers no rights.
http://www.microsoft.com/protect
Post by Perseus109
Just had a quick question and I was hoping one of you might have an
idea. I have added a second two way trust domain (domain B) to our
forest and I need for the users in that domain to be able to VPN in
through our Watchguard firewall useing the Radius server I have
already set up and working for domainA. I have tried adding the user
from the second domain to the existing permission group in domainA, as
well as creating a second group on domainB and adding that in the NPS
policy. The first method gives an authentication error showing that
they used domainA for the domain instead of domainB. The later method
prevents all users from being able to log in at all. Any idea what I
am missing?
Perseus109
2012-03-23 12:38:51 UTC
Permalink
The way the NPS has a security group it checks in domainA. I tried
adding the domainB user to that group but it would not autheniticate
and the logs for NPS show that it looked like the user used doaminA
instead of domainB.
Post by Peter Foldes
Did you give permission from User A to user B
--
Peter
Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.
This posting is provided "AS IS" with no warranties, and confers no rights.http://www.microsoft.com/protect
Loading...