{"id":19040,"date":"2024-02-14T16:20:02","date_gmt":"2024-02-14T15:20:02","guid":{"rendered":"https:\/\/www.boc.de\/watchguard-info-portal\/?p=19040"},"modified":"2024-03-01T13:21:47","modified_gmt":"2024-03-01T12:21:47","slug":"howto-redundantes-authpoint-radius-microsoft-netzwerkrichtlinienserver-setup-mit-der-watchguard-firebox","status":"publish","type":"post","link":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/2024\/02\/howto-redundantes-authpoint-radius-microsoft-netzwerkrichtlinienserver-setup-mit-der-watchguard-firebox\/","title":{"rendered":"HOWTO: Redundantes AuthPoint Radius (Microsoft Netzwerkrichtlinienserver) Setup mit der WatchGuard Firebox"},"content":{"rendered":"<h5>Problemstellung<\/h5>\n<p>Da Microsoft f\u00fcr IKEv2 oder L2TP MS-CHAPv2 voraussetzt, m\u00fcssen die Radius Anfragen von dem AuthPoint Gateway an einen Microsoft NPS weitergeleitet werden. Leider Kann in AuthPoint kein NPS Failover konfiguriert werden. F\u00fcr SSLVPN oder IPSEC wird kein NPS ben\u00f6tigt!<\/p>\n<h5>L\u00f6sungsvorschlag<\/h5>\n<p>Die Firebox bietet die M\u00f6glichkeit mit einem Loopback Interface und einer SNAT Load Balancing Action, die Radius Anfragen auf mehrere Server zu verteilen.<br \/>\nUm die Erreichbarkeit der Server zu pr\u00fcfen, sendet die Firebox alle 10 Sekunden ein ICMP Paket an die Server. Wenn einer der Radius Server nicht mehr auf die ICMP Pakete antwortet werden die Anfragen an den verbliebenen Server gesendet, bis der Server wieder auf die ICMP Pakete antwortet.<br \/>\nDieses Setup bietet leider keine Redundanz, wenn der Radius Dienst nicht mehr ordnungsgem\u00e4\u00df funktioniert.<\/p>\n<h4><!--more--><\/h4>\n<h4>1. Loopback Interface<\/h4>\n<p>Alle Radius Anfragen werden zun\u00e4chst an das Loopback Interface der Firebox geschickt. Anschlie\u00dfend werden die Anfragen durch das SNAT Loadbalancing der Firebox an die Radius Server verteilt. <strong><br \/>\n(Policy Manager) -&gt; Network -&gt; Configuration -&gt; Loopback<br \/>\n<\/strong><\/p>\n<h4><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19048 size-full\" src=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-05_12h05_24.png\" alt=\"\" width=\"785\" height=\"614\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-05_12h05_24.png 785w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-05_12h05_24-300x235.png 300w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-05_12h05_24-768x601.png 768w\" sizes=\"(max-width: 785px) 100vw, 785px\" \/><\/h4>\n<h4>2. SNAT Action\u00a0mit Server Loadbalancing und Firewall Regel<strong><br \/>\n<\/strong><\/h4>\n<p>In der SNAT Action w\u00e4hlen wir das Server Load Balancing aus und tragen die IP-Adressen der Radius Server ein.<br \/>\n<strong>(Policy Manager) -&gt; Setup -&gt; Actions -&gt; SNAT<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19049 size-full\" src=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-05_12h02_28.png\" alt=\"\" width=\"375\" height=\"374\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-05_12h02_28.png 375w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-05_12h02_28-300x300.png 300w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-05_12h02_28-150x150.png 150w\" sizes=\"(max-width: 375px) 100vw, 375px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19050 size-full\" src=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-05_12h22_45.png\" alt=\"\" width=\"353\" height=\"390\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-05_12h22_45.png 353w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-05_12h22_45-272x300.png 272w\" sizes=\"(max-width: 353px) 100vw, 353px\" \/><\/p>\n<p>In unserem Setup nehmen wir die vordefinierte Radius-RFC Paketfilter Regel<br \/>\n<strong>(Policy Manager) -&gt; Add Policy -&gt; Packet Filters -&gt; Radius-RFC<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19153 size-full\" src=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-14_11h32_53.png\" alt=\"\" width=\"642\" height=\"432\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-14_11h32_53.png 642w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-14_11h32_53-300x202.png 300w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-14_11h32_53-272x182.png 272w\" sizes=\"(max-width: 642px) 100vw, 642px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19118 size-full\" src=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-13_10h57_56.png\" alt=\"\" width=\"565\" height=\"775\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-13_10h57_56.png 565w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-13_10h57_56-219x300.png 219w\" sizes=\"(max-width: 565px) 100vw, 565px\" \/><\/p>\n<h4>3. AuthPoint Radius-Client Ressource<\/h4>\n<p>In der MS-CHAPv2 Konfiguration tragen wir die IP-Adresse des Loopback Interfaces ein.<strong><br \/>\n(Watchguard Cloud) -&gt; Konfigureiren -&gt; Ressourcen\u00a0<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19055 size-full\" src=\"https:\/\/www.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-05_12h57_15.png\" alt=\"\" width=\"952\" height=\"928\" srcset=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-05_12h57_15.png 952w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-05_12h57_15-300x292.png 300w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-05_12h57_15-768x749.png 768w, https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-content\/uploads\/2024\/02\/2024-02-05_12h57_15-800x780.png 800w\" sizes=\"(max-width: 952px) 100vw, 952px\" \/><\/p>\n<h5><strong>Fazit<\/strong><\/h5>\n<p>Im Moment gibt es leider keine M\u00f6glichkeit redundante Radius Server im AuthPoint Portal zu konfigurieren.<br \/>\nMit dem Server Loadbalancing der Firebox haben wir aber eine gute M\u00f6glichkeit redundante Radius Server in das AuthPoint Setup zu implementieren.<\/p>\n<h5><strong>Quellen im WatchGuard Help Center<\/strong><\/h5>\n<ul>\n<li><a href=\"https:\/\/www.watchguard.com\/help\/docs\/help-center\/en-US\/Content\/en-US\/Fireware\/networksetup\/net_loopback_c.html\" target=\"_blank\" rel=\"noopener noreferrer\">Configure a Loopback Interface<\/a><\/li>\n<li><a href=\"https:\/\/www.watchguard.com\/help\/docs\/help-center\/en-US\/Content\/en-US\/Fireware\/nat\/server_load_balancing_config_c.html\" target=\"_blank\" rel=\"noopener noreferrer\">Configure Server Load Balancing<\/a><\/li>\n<li><a href=\"https:\/\/www.watchguard.com\/help\/docs\/help-center\/en-US\/Content\/en-US\/Fireware\/nat\/nat_loopback_static_c.html\" target=\"_blank\" rel=\"noopener noreferrer\">NAT Loopback and Static NAT (SNAT)<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Problemstellung Da Microsoft f\u00fcr IKEv2 oder L2TP MS-CHAPv2 voraussetzt, m\u00fcssen die Radius Anfragen von dem AuthPoint Gateway an einen Microsoft NPS weitergeleitet werden. Leider Kann in AuthPoint kein NPS Failover konfiguriert werden. F\u00fcr SSLVPN oder IPSEC wird kein NPS ben\u00f6tigt! L\u00f6sungsvorschlag Die Firebox bietet die M\u00f6glichkeit mit einem Loopback Interface und einer SNAT Load Balancing Action, die Radius Anfragen auf mehrere Server zu verteilen. Um &hellip; <a href=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/2024\/02\/howto-redundantes-authpoint-radius-microsoft-netzwerkrichtlinienserver-setup-mit-der-watchguard-firebox\/\" class=\"more-link\">Weiterlesen <span class=\"screen-reader-text\">HOWTO: Redundantes AuthPoint Radius (Microsoft Netzwerkrichtlinienserver) Setup mit der WatchGuard Firebox<\/span> <span class=\"meta-nav\">&raquo;<\/span><\/a><\/p>\n","protected":false},"author":14,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[362],"tags":[439,290,598,913,455,1034,1036,679,96,1041,1037,532,518,575],"class_list":["post-19040","post","type-post","status-publish","format-standard","hentry","category-howto","tag-authpoint","tag-failover","tag-firebox","tag-loadbalancing","tag-mfa","tag-microsoft-netzwerkrichtlinienserver","tag-multi-faktor","tag-nps","tag-radius","tag-redundanz","tag-server","tag-snat","tag-watchguard","tag-watchguard-authpoint"],"_links":{"self":[{"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/posts\/19040"}],"collection":[{"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/comments?post=19040"}],"version-history":[{"count":44,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/posts\/19040\/revisions"}],"predecessor-version":[{"id":19182,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/posts\/19040\/revisions\/19182"}],"wp:attachment":[{"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/media?parent=19040"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/categories?post=19040"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/tags?post=19040"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}