06.27
Setting up Windows 2003:
Install ISA:
Goto Add/Remove Windows Components,
Click onĀ “Networking Services”.
Tick Internet Authentication Service.
* Note, May need Install CD
Setup VPN users group:
Open Active Directory
Create a new Group “VPN Users” as a Global, Security Group.
Add Users who you want VPN access to this group.
Configure IAS:
Goto Internet Authentication Service (IAS)
Right Click “RADIUS Clients” > New RADIUS Client.
Give it a sensible name like “Snapgear” > Enter its IP address > Next.
Client vendor set to “RADIUS Standard” > Enter a shared secret to use.
Back at the main console > Select “Remote Access Policies” > “Create a New Remote Access Policy”
Select Use Wizard, Call it “VPN Users Access” > Select VPN > Select Group and Add “VPN Users”
Tick MS-CHAP v2
Finish the Wizard
Configure Snapgear:
Goto PPTP VPN Server > Enable PPTP Server
Set Authentication Scheme to MC-CHAPv2
Use Strong Encryption
Set Authentication Database to RADIUS.
Goto Users > RADIUS
Set the Server to the AD Server, Leave Server Port, Type in the Password we set earlier.
We are Finished
If you have SEP installaed on the same server its a good idea to change the port to 1813 as it will conflict with the 1812 port assigned by SEP and make sure you change it under the RADIUS user in the SG