Nebula VPN - Configure L2TP-VPN with a RADIUS/AD-Server using Nebula

The Nebula Cloud platform offers the option to allow L2TP VPN users to authenticate wired/wireless networks over RADIUS 802.1x and (or) AD servers, connecting to local domain controllers in the network.

Table of Contents:

  1.  Scenario
  2. Setting up Authentication in Nebula Control Center
  3. Setting up the RADIUS / AD Server
  4. Setting up L2TP in Nebula Control Center
  5. Client configuration and verification


1. Scenario

Prerequisite: Client VPN IP addresses cannot overlap LAN subnet
Scenario: Setup L2TP VPN connection with Radius/AD servers in Windows server 2008
Preparation: NSG100 *1, NSW100 *1, RADIUS Server *1 and AD Server *1 in Windows server 2008, iPhone 6S+ *1 and Laptop x1

1.JPG

2. Setting up Authentication in Nebula Control Center

1. Navigate to

Site-wide > Configure > Firewall > Firewall settings

 

2. Enter information under my RADIUS server

mceclip1.png

In order to use My RADIUS server option, user is required to configure the Radius server and Active Directory roles in the domain controller.

Setting up the RADIUS / AD Server

RADIUS:
1. Add new RADIUS Client
Server Manager > Role > Network Policy and Access Services > NPS(local) > RADIUS Clients and Servers > RADIUS Client > New RADIUS Client > Enter information in red > OK

4.JPG

2. Add new RADIUS Client

5.JPG

 3. Enter Policy name (eg: USG) > Next

6.JPG

4. Select Client IPv4 Address > Add > Enter WAN NSG100 IP (eg: 10.214.30.67) > OK

7.JPG

 

AD
1. Add new AD user
Server Manager >Role > Active Directory Domain Services > Active Directory Users and Computers > zyxel.cso.com > Users > New > User

8.JPG

2. Enter user logon name (eg: james@zyxel.cso.com) > Next

9.JPG

 3. Enter password > Next > Finish

10.JPG

4. Setting up L2TP in Nebula Control Center

1. Navigate to

Site-wide > Configure > Firewall > Remote Access VPN

and set up the Client setup to your needs. Don't forget to select the RADIUS-Server in the "Authentication" field. 

 

 

5. Client configuration and verification

In this example, we look at generic iPhone settings for the client setup:
1. iPhone > Setting > General > VPN > Add VPN Configuration > Type > L2TP

12.JPG

2. iPhone > Setting > Toggle on VPN14.JPG

 3. iPhone > Setting > General > VPN

14.JPG

4. L2TP Connection Result on NCC via 

GATEWAY > Monitor > Event log > Category > Enter Auth > Search 

Event log displays L2TP client login information15.JPG

5. L2TP Connection Result on Event viewer in Windows Server 2008
Server Manager > Diagnostics > Custom views >Event Viewer> ServerRoles > Network Policy and Access Services

16.JPG


6. Scenario Result for authorizing L2TP Client over Authentication Server - L2TP Client IP 10.20.20.1 can access LAN host 10.214.30.16

Articles in this section

Was this article helpful?
0 out of 0 found this helpful
Share

Comments

0 comments

Please sign in to leave a comment.