Configure Microsoft NPS radius to authenticate on‑prem AD users for Firebox SSLVPN mobile VPN

LDAP is the preferred method for authenticating SSLVPN users against an on‑premises Active Directory server. However, it is also possible to use a Windows NPS RADIUS server to authenticate AD users. The configuration is almost the same as when you set up IKEv2 Mobile VPN to authenticate on‑prem AD users. The only differences are: Install…

How to configure Windows IKEv2 VPN client automatically use your Windows logon credentials with a WatchGuard Firebox and RADIUS

When the Windows IKEv2 VPN client uses automatic logon, it sends credentials as DOMAIN\username. The Firebox matches the DOMAIN part with the RADIUS server name. If the names don’t match (for example, lowercase or different spelling), authentication fails. Windows VPN Client Configuration Firebox Configuration

Configure Microsoft NPS to authenticate on‑prem AD users for Firebox IKEv2 mobile VPN

IKEv2 with MS‑CHAPv2 cannot authenticate directly against LDAP, so a RADIUS server is required. The simplest option is Microsoft NPS, which is included with Windows Server. (FreeRADIUS works too, but this guide focuses on NPS.) Install NPS on a Windows Server You can install NPS on any Windows Server, including a Domain Controller. Server ManagerManage…

Guide how to configure a Linux machine to do SSLVPN and IKEv2 mobilevpn to a WatchGuard Firebox device.

SSLVPN (OpenVPN) – Easiest & works on most distros. WatchGuard SSLVPN is just OpenVPN under the hood, so Linux support is excellent. Step 1 — Download the SSLVPN .ovpn file from the Firebox Step 2 — Import the client.ovpn file into NetworkManager All other settings come from the .ovpn file and normally require no changes.…

Close