Dynamic VLAN assignment using RADIUS. Network Diagram



Similar documents
Residence Wired Connection Installation Manual

Wireless Network Configuration Guide

How to configure 802.1X authentication with a Windows XP or Vista supplicant

Step by step guide for connecting PC to wired LAN at dormitories of University of Pardubice

How to Configure a BYOD Environment with the Unified AP in Standalone Mode

How To - Implement Clientless Single Sign On Authentication with Active Directory

Windows XP Exchange Client Installation Instructions

Windows Vista: Connecting to the wireless network at Hood College

SCADA Security. Enabling Integrated Windows Authentication For CitectSCADA Web Client. Applies To: CitectSCADA 6.xx and 7.xx VijeoCitect 6.xx and 7.

VoIP Intercom with Allworx 6x Server Setup Guide

HOW TO CONNECT TO FTP.TARGETANALYSIS.COM USING FILEZILLA. Installation

IIS, FTP Server and Windows

Connecting to UNOSECURE using Windows 7

Installing T-HUB on multiple computers

If you are unable to set up your Linksys Router by using one of the above options, use the steps below to manually configure your router.

educ Office Remove & create new Outlook profile

Installation Guides - Information required for connection to the Goldfields Institute s (GIT) Wireless Network

How to connect to NAU s WPA2 Enterprise implementation in a Residence Hall:

eduroam wireless setup guide for Windows 7, XP and Vista

Airnet-Student is a new and improved wireless network that is being made available to all Staffordshire University students.

Remote Terminal Service (RTS) User Guide (Version 2.1)

Manually Configuring Windows Vista for Wireless PittNet

Keri USB-A Connection and Configuration

DESLock+ Basic Setup Guide Version 1.20, rev: June 9th 2014

Network Connect Installation and Usage Guide

Integration with IP Phones

Connecting to eduroam using Windows 8

Intel Entry Storage System SS4200-E Active Directory Implementation and Troubleshooting

Windows Server 2008 R2 Initial Configuration Tasks

This document is intended to make you familiar with the ServersCheck Monitoring Appliance

V310 Support Note Version 1.0 November, 2011

Integrating with IBM Tivoli TSOM

How to Access Coast Wi-Fi

University Computing & Telecommunications Virtual Private Networking: How To/Self- Help Guide Windows 8.1 Operating System.

This document is intended to make you familiar with the ServersCheck Monitoring Appliance

Layer 2 / Layer 3 switches and multi-ssid multi-vlan network with traffic separation

Network Security Solutions Implementing Network Access Control (NAC)

NAC Guest. Lab Exercises

Remote Desktop How-To. How to log into your computer remotely using Windows XP, etc.

Application Note 8: TrendView Recorders DCOM Settings and Firewall Plus DCOM Settings for Trendview Historian Server

Paxera Uploader Basic Troubleshooting

Optimum Business SIP Trunk Set-up Guide

How To - Implement Clientless Single Sign On Authentication in Single Active Directory Domain Controller Environment

Installing VPN for PC v1.3

The FlexiSchools Online Order Management (FOOM) Installation Guide

Symphony Network Troubleshooting

CONFIGURATION OF SATO LAN and WiFi INTERFACES

Snom 720 and Elastix Server

SchoolBooking SSO Integration Guide

University of Central Florida UCF VPN User Guide UCF Service Desk

Microsoft XP Professional Remote Desktop Connection

Configure Outlook 2013 to connect to Hosted Exchange

Network Monitoring User Guide Pulse Appliance

Note: This case study utilizes Packet Tracer. Please see the Chapter 5 Packet Tracer file located in Supplemental Materials.

Installation Notes for Outpost Network Security (ONS) version 3.2

Steps to be taken when you are unable to get the license in Tally.ERP 9

Creating a Gateway to Client VPN between Sidewinder G2 and a Mac OS X Client

Set Up Setup with Microsoft Outlook 2007 using POP3

PT Activity: Configure Cisco Routers for Syslog, NTP, and SSH Operations

User Guide Microsoft Exchange Remote Test Instructions

Arkay Remote Data Backup Client Quick Start Guide

client configuration guide. Business

Florida Atlantic University VPN Client Installation Guide

TECHNICAL BULLETIN. Configuring Wireless Settings in an i-stat 1 Wireless Analyzer

Abstract. Avaya Solution & Interoperability Test Lab

Introduction. What is a Remote Console? What is the Server Service? A Remote Control Enabled (RCE) Console

How to remotely access your Virtual Desktop from outside the college using VMware View Client. How to guide

Windows XP Home Network Setup: Step-by-Step

How to configure MAC authentication on a ProCurve switch

Installing Logos SSL Certificates on Mobile Devices

NETVIGATOR Wireless Modem Setup Guide. (TG789Pvn)

DPS Telecom Your Partners in Network Alarm Management

Connecting to Remote Desktop Windows Users

Configuring Windows 7 to Use Encrypted (WPA-E) Wireless Services a...

For paid computer support call

How To Set Up Hopkins Wireless On Windows 7 On A Pc Or Mac Or Ipad (For A Laptop) On A Network Card (For Windows 7) On Your Computer Or Ipa (For Mac Or Mac) On An Ipa Or

Internet access system through the Wireless Network of the University of Bologna (last update )

Elastix Server VoIP Intercom Setup Guide

Automatic Setup... 1 Manual Setup... 2 Installing the Wireless Certificates... 18

Technology Services Group Procedures. IH Anywhere guide. 0 P a g e

The FlexiSchools Online Order Management System Installation Guide

VoIP Intercom and Elastix Server

Massey University Wireless Network Client Configuration Windows 7

UCO_SECURE Wireless Connection Guide: Windows 8

Use 802.1x EAP-TLS or PEAP-MS-CHAP v2 with Microsoft Windows Server 2003 to Make a Secure Network

Remote Access: Internet Explorer

Device Interface IP Address Subnet Mask Default Gateway

RAPID BROADBAND INSTALLATION RAPID BROADBAND SUPPORT CONTACT DETAILS. AND TROUBLESHOOTING GUIDE. Tel:

Microsoft Office 365 with MailDefender

Configuring an IP (SIP) Polycom Soundstation on the Avaya IP Office

extranet.airproducts.com Windows XP Client Configuration

PowerLink for Blackboard Vista and Campus Edition Install Guide

VThis A PP NOTE DELIVERING MEDIA TO SEACHANGE BMS/BMC SERVERS

Massey University Wireless Network - Client Configuration Windows XP (Service Pack 2)

How to Use Remote Access Using Internet Explorer

Remote Access Enhancements

Configuring an IPsec VPN to provide ios devices with secure, remote access to the network

HOW TO RETRIEVE FILES FROM THE TARGET ANALYTICS FTP SITE

Transcription:

Dynamic VLAN assignment using RADIUS This document describes how to dynamically assign clients to VLANs using RADIUS. This is useful is you have multiple clients using the same physical network and need to assign them to different VLANs depending on their logon credentials. This process removes the need to manually assign ports into VLANs. This applies to Netgear managed switches running firmware version 8.0.1.2 or later. Equipment used: FreeRADIUS for Windows GSM7224v2 1 management PC 2 client PCs for testing (2 x Win XP Pro SP3) DHCP provided by DHCP server on VLAN2 Network Diagram

Switch Configuration The starting configuration for the switch is to have all ports in VLAN1 with a management IP address on the switch of 192.168.0.254. Go to Switching -> VLAN -> Basic -> VLAN Configuration Add VLAN2 with the settings as shown on the left Press Add Go to Security -> Port Authentication -> Advanced -> Port Authentication Select Ports 0/1 and 0/2 Set the Control Mode for these 2 ports to Force Authorized Press Apply This is done so that the RADIUS server and the management PC do not have get locked out from the switch Go to Security -> Port Authentication - > Advanced -> 802.1X Configuration Set Administrative Mode and VLAN Assignment Mode to Enable Press Apply

Go to Security -> Management Security -> Authentication List -> Dot1x Authentication List Select the option for dot1xlist and choose Radius for the first Field Press Apply Go to Security -> Management Security -> RADIUS -> Server Configuration Add Radius Server IP Address as 192.168.0.253 Set Secret Configured to Yes Set Secret to 123456 Press Add

RADIUS Server Configuration Download and install FreeRADIUS for Windows. Once installed, the system tray. icon will appear in the Right click on the FreeRADIUS icon and choose Edit Radius Clients.conf in this file we need to add an entry for our RADIUS client, the GSM7224v2. To do this, add the following code and save the file: client 192.168.0.253/24 { secret = 1232456 shortname = gsm7224v2 } Next, right click on the FreeRADIUS icon and choose Edit Users in this file we need to add some users together with what VLAN we want these users to be assigned to. To do this, add the following code and save the file: user1 user2 User-Password == "password1" Tunnel-Type = "VLAN", Tunnel-Medium-Type = "IEEE-802", Tunnel-Private-Group-Id = "2" User-Password == "password2" Tunnel-Type = "VLAN", Tunnel-Medium-Type = "IEEE-802", Tunnel-Private-Group-Id = "2" Finally, restart FreeRADIUS by right clicking on the icon and choosing Restart Service.

Client configuration Since we are using FreeRADIUS, the network cards on client PC1 and client PC2 need to be configured for MD5. To do this right click on the Local Area Connection and choose Properties. Go to the Authentication tab and choose MD5 as shown: Note: If you do not see the Authentication tab, it will be because the Wired AutoConfig service in Windows has not started. Start it in services.msc

Testing Connect PC1 and PC2 to any port on the switch other than ports 0/1 and 0/2. Once connected, Windows will prompt for credentials. For credentials, use: PC1 Username: user1 Password: password1 PC2 Username: user2 Password: password2 Once successfully authenticated, PC1 and PC2 will become members of VLAN2 even though the ports to which they are connected were originally members of VLAN1. To test, verify the following: 1: PC1 can successfully ping PC2. 2: PC1 and PC2 cannot ping the management PC Notes To assist with any troubleshooting, check the FreeRADIUS logs in C:\FreeRADIUS.net\var\log\radius\radius.log The RADIUS statistics on the GSM7224v2 are also helpful these can be found under Security -> Management Security -> RADIUS -> Server Configuration -> Statistics