{"id":42118,"date":"2019-03-18T00:00:00","date_gmt":"2019-03-17T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/nastrojka-802-1x-na-kommutatorah-cisco-s-pomoshhyu-otkazoustojchivogo-nps-windows-radius-with-ad"},"modified":"2020-02-18T13:44:55","modified_gmt":"2020-02-18T10:44:55","slug":"nastrojka-802-1x-na-kommutatorah-cisco-s-pomoshhyu-otkazoustojchivogo-nps-windows-radius-with-ad","status":"publish","type":"post","link":"https:\/\/prohoster.info\/nl\/blog\/administrirovanie\/nastrojka-802-1x-na-kommutatorah-cisco-s-pomoshhyu-otkazoustojchivogo-nps-windows-radius-with-ad","title":{"rendered":"Configuratie van 802.1X op Cisco-switches met behulp van failover NPS (Windows RADIUS met AD)","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Configuratie van 802.1X op Cisco-switches met behulp van failover NPS (Windows RADIUS met AD)\" src=\"\/wp-content\/uploads\/2019\/03\/1bbe235a78ff2e13e771f7086c6885f3.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nLaten we in de praktijk kijken naar het gebruik van Windows Active Directory + NPS (2 servers voor failover) + standaard 802.1x voor toegangcontrole en authenticatie van gebruikers - domeincomputers - apparaten. Je kunt de theorie over de standaard in Wikipedia vinden via de link: <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/IEEE_802.1X\">IEEE 802.1X<\/a><\/noindex><\/p>\n<p>Aangezien mijn 'laboratorium' beperkt is in middelen, combineer ik de rollen van NPS en domeincontroller, maar ik raad je aan om zulke kritieke services toch te scheiden.<\/p>\n<p>Ik ken geen standaardmethoden voor het synchroniseren van configuraties (beleid) van Windows NPS, daarom zullen we PowerShell-scripts gebruiken, die worden uitgevoerd door de taakplanner (de auteur is mijn voormalige collega). Voor de authenticatie van domeincomputers en van apparaten die niet kunnen in <b>802.1x<\/b> (telefoons, printers etc.), zal er een groepsbeleid worden ingesteld en zullen er beveiligingsgroepen worden gemaakt.<\/p>\n<p>Aan het einde van het artikel zal ik enkele nuances van het werken met 802.1x bespreken - hoe je niet-beheerde switches, dynamische ACL's enzovoorts kunt gebruiken. Ik zal informatie delen over opgevangen 'bugs'...<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\nLaten we beginnen met de installatie en configuratie van failover NPS op Windows Server 2012R2 (op 2016 is het vergelijkbaar): via Server Manager -&gt; Add Roles and Features Wizard kiezen we alleen Network Policy Server.<\/p>\n<p><img decoding=\"async\" alt=\"Configuratie van 802.1X op Cisco-switches met behulp van failover NPS (Windows RADIUS met AD)\" src=\"\/wp-content\/uploads\/2019\/03\/8ee1c9024d59ac338571e9cd67225075.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nof met PowerShell:<\/p>\n<pre><code class=\"actionscript\">Install-WindowsFeature NPAS -IncludeManagementTools<\/code><\/pre>\n<p><\/p>\n<blockquote><p>Een kleine verduidelijking - aangezien voor <b>Protected EAP (PEAP)<\/b> je absoluut een certificaat nodig hebt dat de autenticiteit van de server bevestigt (met de bijbehorende rechten voor gebruik), dat op de clientcomputers vertrouwd zal zijn, moet je waarschijnlijk ook de rol <b>Certification Authority<\/b>installeren. Maar laten we aannemen dat <b>CA<\/b> al is ge\u00efnstalleerd...<\/p><\/blockquote>\n<p> We doen hetzelfde op de tweede server. Laten we een map voor het script C:Scripts op beide servers aanmaken en een netwerkmmap op de tweede server <b>SRV2NPS-config$<\/b><\/p>\n<p>Op de eerste server maken we een PowerShell-script aan <i>C:ScriptsExport-NPS-config.ps1<\/i> met de volgende inhoud:<\/p>\n<pre><code class=\"actionscript\">Export-NpsConfiguration -Path \"SRV2NPS-config$NPS.xml\"<\/code><\/pre>\n<p>\nDaarna stellen we een taak in de Taakplanner in: \"<i>Export-NpsConfiguration<\/i>\u201d<\/p>\n<pre><code class=\"bash\">powershell -executionpolicy unrestricted -f \"C:ScriptsExport-NPS-config.ps1\"<\/code><\/pre>\n<p>\n<i>Voer uit voor alle gebruikers \u2014 Voer uit met de hoogste rechten<br \/>\nDagelijks \u2014 Herhaal de taak elke 10 minuten gedurende 8 uur.<\/i><\/p>\n<p>Op de reserve NPS stellen we de import van de configuratie (beleid) in:<br \/>\nwe cre\u00ebren een PowerShell-script:<\/p>\n<pre><code class=\"bash\">echo Import-NpsConfiguration -Path \"c:NPS-configNPS.xml\" &gt;&gt; C:ScriptsImport-NPS-config.ps1<\/code><\/pre>\n<p>\nen het om de uitvoering ervan elke 10 minuten:<\/p>\n<pre><code class=\"bash\">powershell -executionpolicy unrestricted -f \"C:ScriptsImport-NPS-config.ps1\"<\/code><\/pre>\n<p>\n<i>Voer uit voor alle gebruikers \u2014 Voer uit met de hoogste rechten<br \/>\nDagelijks \u2014 Herhaal de taak elke 10 minuten gedurende 8 uur.<\/i><\/p>\n<p>Laten we nu, ter controle, op een van de servers(!) een paar switches toevoegen als RADIUS-clients (IP en Shared Secret) en twee verbindingsverzoekbeleid: <b>WIRED-Connect<\/b> (Voorwaarde: \u201cType poort NAS \u2013 Ethernet\u201d) en <b>WiFi-Enterprise<\/b> (Voorwaarde: \u201cType poort NAS \u2013 IEEE 802.11\u201d), evenals een netwerkbeleid <b><i>Access Cisco Network Devices<\/i><\/b> (Netwerkbeheerders):<\/p>\n<pre><code class=\"xml\">Voorwaarden:\nGroepen Windows - domainsg-network-admins\nBeperkingen:\nAuthenticatiemethoden - Authenticatie in platte tekst (PAP, SPAP)\nParameters:\nRADIUS-attributen: Standaard - Service-Type - Login\nLeverancier-afhankelijk - Cisco-AV-Pair - Cisco - shell:priv-lvl=15<\/code><\/pre>\n<p><b class=\"spoiler_title\">Aan de kant van de switches zijn de volgende instellingen:<\/b><\/p>\n<pre><code class=\"plaintext\">aaa new-model\naaa local authentication attempts max-fail 5\n!\n!\naaa group server radius NPS\n server-private 192.168.38.151 auth-port 1812 acct-port 1813 key %shared_secret%\n server-private 192.168.10.151 auth-port 1812 acct-port 1813 key %shared_secret%\n!\naaa authentication login default group NPS local\naaa authentication dot1x default group NPS\naaa authorization console\naaa authorization exec default group NPS local if-authenticated\naaa authorization network default group NPS\n!\naaa session-id common\n!\nidentity profile default\n!\ndot1x system-auth-control\n!\n!\nline vty 0 4\n exec-timeout 5 0\n transport input ssh\n escape-character 99\nline vty 5 15\n exec-timeout 5 0\n logging synchronous\n transport input ssh\n escape-character 99<\/code><\/pre>\n<p>Na de configuratie, na 10 minuten, zouden alle clientsbeleidparameters ook op de reserve NPS moeten verschijnen en kunnen we ons aanmelden op de switches met behulp van een Active Directory-account, lid van de groep domainsg-network-admins (die we eerder hebben aangemaakt).<\/p>\n<p>Laten we verder gaan met de configuratie van Active Directory \u2013 we maken groeps- en wachtwoordbeleid aan, we cre\u00ebren de benodigde groepen.<\/p>\n<p>Groepsbeleid <i><b>Computers-8021x-Instellingen<\/b><\/i>:<\/p>\n<p><b><\/p>\n<pre><code class=\"plaintext\">Computerconfiguratie (Ingeschakeld)\n   Beleid\n     Windows-instellingen\n        Beveiligingsinstellingen\n          Systeemdiensten\n     Wired AutoConfig (Opstartmodus: Automatisch)\nWired-netwerk (802.3) Beleid<\/code><\/pre>\n<p><\/b><br \/>\n<b class=\"spoiler_title\">NPS-802-1x<\/b><\/p>\n<pre><code class=\"plaintext\">Naam\tNPS-802-1x\nBeschrijving\t802.1x\nGlobale instellingen\nINSTELLING\tWAARDE\nGebruik Windows bedrade LAN-netwerkdiensten voor clients\tIngeschakeld\nGedeelde gebruikersreferenties voor netwerkauthenticatie\tIngeschakeld\nNetwerkprofiel\nBeveiligingsinstellingen\nGebruik IEEE 802.1X-authenticatie voor netwerktoegang inschakelen\tIngeschakeld\nGebruik IEEE 802.1X-authenticatie voor netwerktoegang handhaven\tUitgeschakeld\nIEEE 802.1X-instellingen\nComputerauthenticatie\tAlleen computer\nMaximale authenticatiefouten\t10\nMaximale EAPOL-Startberichten verzonden\t \nGehouden periode (seconden)\t \nStartperiode (seconden)\t \nAuthenticatieperiode (seconden)\t \nNetwerkauthenticatiemethode-eigenschappen\nAuthenticatiemethode\tBeschermde EAP (PEAP)\nValidatie servercertificaat\tIngeschakeld\nVerbind met deze servers\t \nVraag de gebruiker niet om nieuwe servers of vertrouwde certificeringsinstanties te autoriseren\tUitgeschakeld\nVersnel snel opnieuw verbinden\tIngeschakeld\nVerbreken als de server geen cryptobinding TLV presenteert\tUitgeschakeld\nHandhaven van netwerktechniekbescherming\tUitgeschakeld\nAuthenticatiemethode-configuratie\nAuthenticatiemethode\tBeveiligd wachtwoord (EAP-MSCHAP v2)\nGebruik automatisch mijn Windows-inlognaam en wachtwoord (en domein indien van toepassing)\tIngeschakeld<\/code><\/pre>\n<p><img decoding=\"async\" alt=\"Configuratie van 802.1X op Cisco-switches met behulp van failover NPS (Windows RADIUS met AD)\" src=\"\/wp-content\/uploads\/2019\/03\/f0f5e0c83441367a09d56fca217ec587.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nLaten we een beveiligingsgroep aanmaken <b><i>sg-computers-8021x-vl100<\/i><\/b>, waar we computers zullen toevoegen die we willen toewijzen aan VLAN 100 en we instellen filters voor het eerder gemaakte groepsbeleid voor deze groep:<\/p>\n<p><img decoding=\"async\" alt=\"Configuratie van 802.1X op Cisco-switches met behulp van failover NPS (Windows RADIUS met AD)\" src=\"\/wp-content\/uploads\/2019\/03\/45d9763098d1f1e3f105188ab0941ac9.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nOm te controleren of het beleid succesvol is toegepast, kunt u \"Netwerkcentrum en delen (Netwerk- en internetinstellingen) - Wijzig adapterinstellingen (Adapterinstellingen configureren) - Adaptereigenschappen\" openen, waar we het tabblad \"Authenticatie\" kunnen zien:<\/p>\n<p><img decoding=\"async\" alt=\"Configuratie van 802.1X op Cisco-switches met behulp van failover NPS (Windows RADIUS met AD)\" src=\"\/wp-content\/uploads\/2019\/03\/407b1a154f0fed84e71574e1225d68a2.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nWanneer we er zeker van zijn dat het beleid succesvol wordt toegepast, kunnen we verder gaan met het configureren van het netwerkbeleid op NPS en de poorten van de toegangsswitch.<\/p>\n<p>Laten we een netwerkbeleid aanmaken <b><i>neag-computers-8021x-vl100<\/i><\/b>:<\/p>\n<pre><code class=\"xml\">Voorwaarden:\n  Windows Groepen - sg-computers-8021x-vl100\n  NAS Poort Type - Ethernet\nBeperkingen:\n  Authentieke Methoden - Microsoft: Protected EAP (PEAP) - Ongecodeerde authenticatie (PAP, SPAP)\n  NAS Poort Type - Ethernet\nInstellingen:\n  Standaard:\n   Framed-MTU 1344\n   TunnelMediumType 802 (bevat alle 802-media plus Ethernet canonieke indeling)\n   TunnelPrivateGroupId  100\n   TunnelType  Virtuele LAN's (VLAN)<\/code><\/pre>\n<p>\n<img decoding=\"async\" alt=\"Configuratie van 802.1X op Cisco-switches met behulp van failover NPS (Windows RADIUS met AD)\" src=\"\/wp-content\/uploads\/2019\/03\/3e279c0b6111caec20fc91743a75f1aa.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nStandaardinstellingen voor de poort van de switch (ik merk op dat het type authenticatie \"multi-domein\" is - Data &amp; Voice, en dat er ook authenticatie op basis van MAC-adres mogelijk is. Gedurende de \"overgangsperiode\" is het zinvol om de volgende parameters te gebruiken:<\/p>\n<pre><code class=\"actionscript\">\nauthentication event fail action authorize vlan 100\nauthentication event no-response action authorize vlan 100\n<\/code><\/pre>\n<p>\nvlan-id is niet van \"quarantaine\", maar diezelfde, waar de gebruikerscomputer succesvol moet worden geautoriseerd - totdat we zeker weten dat alles correct functioneert. Deze parameters kunnen ook in andere scenario's worden gebruikt, bijvoorbeeld wanneer er een unmanaged switch op deze poort is aangesloten en u wilt dat alle apparaten die zijn aangesloten en niet zijn geauthenticeerd, in een bepaalde VLAN (\"quarantaine\") komen.<\/p>\n<p><b class=\"spoiler_title\">instellingen van de switchpoort in 802.1x modus host-mode multi-domain<\/b><\/p>\n<pre><code class=\"actionscript\">default int range Gi1\/0\/39-41\nint range Gi1\/0\/39-41\nshu\ndes PC-IPhone_802.1x\nswitchport mode access\nswitchport nonegotiate\nswitchport voice vlan 55\nswitchport port-security maximum 2\nauthentication event fail action authorize vlan 100\nauthentication event no-response action authorize vlan 100\nauthentication host-mode multi-domain\nauthentication port-control auto\nauthentication violation restrict\nmab\ndot1x pae authenticator\ndot1x timeout quiet-period 15\ndot1x timeout tx-period 3\nstorm-control broadcast level pps 100\nstorm-control multicast level pps 110\nno vtp\nlldp receive\nlldp transmit\nspanning-tree portfast\nno shu\nexit<\/code><\/pre>\n<p>U kunt controleren of de computer\/telefoon succesvol is geauthenticeerd met het commando:<\/p>\n<pre><code class=\"actionscript\">sh authentication sessions int Gi1\/0\/39 det<\/code><\/pre>\n<p>\nLaten we nu een groep aanmaken (bijvoorbeeld, <i>sg-fgpp-mab<\/i> ) in Active Directory voor telefoons en voeg er \u00e9\u00e9n apparaat aan toe voor tests (in mijn geval is dat <b><i>Grandstream GXP2160<\/i><\/b> met het MAC-adres <b>000b.82ba.a7b1<\/b> en de bijbehorende gebruikersaccount <b>domein 00b82baa7b1<\/b>). <\/p>\n<p>Voor de gemaakte groep verlagen we de vereisten van het wachtwoordbeleid (met behulp van <noindex><a rel=\"nofollow\" href=\"https:\/\/blogs.technet.microsoft.com\/canitpro\/2013\/05\/29\/step-by-step-enabling-and-using-fine-grained-password-policies-in-ad\/\">Fine-Grained Password Policies<\/a><\/noindex> via Active Directory Administrative Center -&gt; domein -&gt; Systeem -&gt; Wachtwoordinstellingencontainer) met de volgende parameters <b><i>Password-Settings-for-MAB<\/i><\/b>:<\/p>\n<p><img decoding=\"async\" alt=\"Configuratie van 802.1X op Cisco-switches met behulp van failover NPS (Windows RADIUS met AD)\" src=\"\/wp-content\/uploads\/2019\/03\/289eedad27d4dc8c4d406f09e3496ac1.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nwaardoor we het gebruik van het MAC-adres van apparaten als wachtwoorden toestaan. Daarna kunnen we een netwerkbeleid voor 802.1x authenticatie met de methode mab cre\u00ebren, dat we neag-devices-8021x-voice noemen. De parameters zijn als volgt:<\/p>\n<ul>\n<li>NAS Port Type \u2013 Ethernet<\/li>\n<li>Windows Groups \u2013 sg-fgpp-mab<\/li>\n<li>EAP Types: Onversleutelde authenticatie (PAP, SPAP)<\/li>\n<li>RADIUS Attributen \u2013 Verkoper Specifiek: Cisco \u2013 Cisco-AV-Pair \u2013 Attribuutwaarde: device-traffic-class=voice<\/li>\n<\/ul>\n<p>\nna succesvolle authenticatie (vergeet niet de poort van de switch in te stellen), laten we informatie van de poort zien:<\/p>\n<p><b class=\"spoiler_title\">sh authentication se int Gi1\/0\/34<\/b><\/p>\n<pre><code class=\"plaintext\">----------------------------------------\n            Interface:  GigabitEthernet1\/0\/34\n          MAC Address:  000b.82ba.a7b1\n           IP Address:  172.29.31.89\n            User-Name:  000b82baa7b1\n               Status:  Authz Success\n               Domain:  VOICE\n       Oper host mode:  multi-domain\n     Oper control dir:  both\n        Authorized By:  Authentication Server\n      Session timeout:   N\/A\n         Idle timeout:  N\/A\n    Common Session ID:  0000000000000EB2000B8C5E\n      Acct Session ID:  0x00000134\n               Handle:  0xCE000EB3\n\nRunnable methods list:\n       Method   State\n       dot1x    Failed over\n       mab      Authc Success<\/code><\/pre>\n<p>Nu, zoals beloofd, bekijken we een paar niet zo voor de hand liggende situaties. Bijvoorbeeld, we moeten computers van gebruikers aansluiten via een niet-beheerde switch. In dit geval zullen de poortinstellingen als volgt zijn:<\/p>\n<p><b class=\"spoiler_title\">poortinstellingen van de switch in modus 802.1x host-mode multi-auth<\/b><\/p>\n<pre><code class=\"actionscript\">interface GigabitEthernet1\/0\/1\ndescription *SW \u2013 802.1x \u2013 8 mac*\nshu\nswitchport mode access\nswitchport nonegotiate\nswitchport voice vlan 55\nswitchport port-security maximum 8  ! verhoog het aantal toegestane MAC-adressen\nauthentication event fail action authorize vlan 100\nauthentication event no-response action authorize vlan 100\nauthentication host-mode multi-auth  ! \u2013 authenticatiemodus\nauthentication port-control auto\nauthentication violation restrict\nmab\ndot1x pae authenticator\ndot1x timeout quiet-period 15\ndot1x timeout tx-period 3\nstorm-control broadcast level pps 100\nstorm-control multicast level pps 110\nno vtp\nspanning-tree portfast\nno shu<\/code><\/pre>\n<p>P.S. een heel vreemde bug opgemerkt \u2013 als een apparaat via zo'n switch was aangesloten en vervolgens in een beheerde switch werd gestoken, zal het niet werken totdat we de switch opnieuw opstarten(!) Tot nu toe heb ik geen andere manieren gevonden om dit probleem op te lossen.<\/p>\n<p>Een ander punt met betrekking tot DHCP (indien ip dhcp snooping wordt gebruikt) \u2013 zonder dergelijke opties:<\/p>\n<pre><code class=\"actionscript\">ip dhcp snooping vlan 1-100\nno ip dhcp snooping information option<\/code><\/pre>\n<p>\nOm de een of andere reden kan ik het ip-adres niet correct verkrijgen... hoewel dit misschien een eigenaardigheid van onze DHCP-server is.<\/p>\n<p>Mac OS &amp; Linux (waar 802.1x native wordt ondersteund) proberen zich te authenticeren met de gebruiker, zelfs als authenticatie op mac-adres is ingesteld. <\/p>\n<p>In het volgende deel van het artikel zullen we de toepassing van 802.1x voor Wireless bekijken (afhankelijk van de groep waartoe het gebruikersaccount behoort, zullen we hen 'in de juiste netwerk (vlan) plaatsen', hoewel ze verbinding maken met hetzelfde SSID).<\/p>\n<p>Bron: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/443942\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u043d\u0430 \u043f\u0440\u0430\u043a\u0442\u0438\u043a\u0435 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435 Windows Active Directory + NPS (2 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f \u043e\u0442\u043a\u0430\u0437\u043e\u0443\u0441\u0442\u043e\u0439\u0447\u0438\u0432\u043e\u0441\u0442\u0438) + \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442 802.1x \u0434\u043b\u044f \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u2013 \u0434\u043e\u043c\u0435\u043d\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u043e\u0432 \u2013 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432. \u041e\u0437\u043d\u0430\u043a\u043e\u043c\u0438\u0442\u044c\u0441\u044f \u0441 \u0442\u0435\u043e\u0440\u0438\u0435\u0439 \u043f\u043e \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u0443 \u043c\u043e\u0436\u043d\u043e \u0432 Wikipedia, \u043f\u043e \u0441\u0441\u044b\u043b\u043a\u0435: IEEE 802.1X \u0422\u0430\u043a \u043a\u0430\u043a \u201c\u043b\u0430\u0431\u043e\u0440\u0430\u0442\u043e\u0440\u0438\u044f\u201d \u0443 \u043c\u0435\u043d\u044f \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0430 \u043f\u043e \u0440\u0435\u0441\u0443\u0440\u0441\u0430\u043c, \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u0438\u043c \u0440\u043e\u043b\u0438 NPS \u0438 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440\u0430 \u0434\u043e\u043c\u0435\u043d\u0430, \u043d\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-42118","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.3 - aioseo.com -->\n\t<meta name=\"description\" content=\".\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/nl\/blog\/administrirovanie\/nastrojka-802-1x-na-kommutatorah-cisco-s-pomoshhyu-otkazoustojchivogo-nps-windows-radius-with-ad\" \/>\n\t\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.3\" \/>\n\t\t<meta property=\"og:locale\" content=\"nl_NL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 802.1X \u043d\u0430 \u043a\u043e\u043c\u043c\u0443\u0442\u0430\u0442\u043e\u0440\u0430\u0445 Cisco \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u043e\u0442\u043a\u0430\u0437\u043e\u0443\u0441\u0442\u043e\u0439\u0447\u0438\u0432\u043e\u0433\u043e NPS (Windows RADIUS with AD) | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\".\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/nl\/blog\/administrirovanie\/nastrojka-802-1x-na-kommutatorah-cisco-s-pomoshhyu-otkazoustojchivogo-nps-windows-radius-with-ad\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-03-17T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T10:44:55+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Configuratie van 802.1X op Cisco-switches met behulp van betrouwbare NPS (Windows RADIUS met AD) | ProHoster","description":".","canonical_url":"https:\/\/prohoster.info\/nl\/blog\/administrirovanie\/nastrojka-802-1x-na-kommutatorah-cisco-s-pomoshhyu-otkazoustojchivogo-nps-windows-radius-with-ad","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"nl_NL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 802.1X \u043d\u0430 \u043a\u043e\u043c\u043c\u0443\u0442\u0430\u0442\u043e\u0440\u0430\u0445 Cisco \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u043e\u0442\u043a\u0430\u0437\u043e\u0443\u0441\u0442\u043e\u0439\u0447\u0438\u0432\u043e\u0433\u043e NPS (Windows RADIUS with AD) | ProHoster","og:description":".","og:url":"https:\/\/prohoster.info\/nl\/blog\/administrirovanie\/nastrojka-802-1x-na-kommutatorah-cisco-s-pomoshhyu-otkazoustojchivogo-nps-windows-radius-with-ad","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-03-17T21:00:00+00:00","article:modified_time":"2020-02-18T10:44:55+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"42118","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 07:20:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 00:05:22","updated":"2026-01-22 07:20:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/posts\/42118","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/comments?post=42118"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/posts\/42118\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/media?parent=42118"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/categories?post=42118"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/tags?post=42118"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}