Page 1 of 1

SE + NPS in AD environment

Posted: Sun Nov 07, 2021 4:31 pm
by marantz
Hi guys,

At 1st I want to thank all folks working on this project. It looks amazing. Keep up the good work!

I have set up SE with network policy server and AD. As far as I use asteriks to manage users it works great. We have couple thousands users and adding them 1 by 1 to SE including setting magane access lists would be extremely painful process.

Is there any chance to Softether actually read/use IP filters in network policy server?

Re: SE + NPS in AD environment

Posted: Mon Nov 08, 2021 2:55 am
by eddiewu
Try setting up nps as radius server and use radius authentication on se.

Re: SE + NPS in AD environment

Posted: Mon Nov 08, 2021 3:31 pm
by marantz
As said above I did it and it works great. The problem is SE can't recognize nps IP filters.

Re: SE + NPS in AD environment

Posted: Wed Nov 24, 2021 2:54 pm
by dr.cryo
I got exactly the same problem to solve. Since I cannot (don't want) use VLANs to separate traffic and keep ACLs on router (that's why ACLs are on SE), I'm looking for a way, how to achieve traffic separation.
One way, as Marantz mentioned, could be to accept IP-filter RADIUS/NPS parameter. Second way could be, since ACLs are stored on Hub level, somehow decide which Hub to use by the RADIUS/NPS response.
Is any of the above two supported or easily achievable? Thanks in advance for your replies.

Re: SE + NPS in AD environment

Posted: Sat Nov 27, 2021 8:50 pm
by marantz
I came accross the same idea to arrange users access level by using few hubs. No luck there since I couldnt force NPS to work with specific hub.
I stuck on this for a long time.