Question
SOLVED: IPSec VPN, Radius. Distinguishing user groups
Hi, After successfully configuring various types of VPN I' m left with a puzzle. In the organization we have several different types of user (administrative, technical and so on). They are split into differet AD groups (VPN-Admin, VPN-Tech). So far so good. I need to allow access based on these groups VPN-Admin should be allowed only access to 172.16.1.0/24 VPN-Tech should be allowed access to 172.16.1.0/12 Am I right in assuming this would entail configuring 2 distinct RADIUS connetions to the same NPS server? They could be evaluated differently based on NAS IP/Called Station ID (i.e. one would be called VPN-Admin and one VPN-Tech). The NPS CRP would then evaluate this field and grant/deny access based on user membership. Also there would need to be created equally many VPN Phase 1/2 definitions and policies. It seems quite complex, and if I' m somehow missing something that makes assigning user rights simpler, please let me know. Sincerely Mikkel
