6. Install and Configure NPS Servers
Install NPS
- Logon to your NPS server
- Open powershell as administrator and issue the following command:
Install-WindowsFeature NPAS -IncludeManagementTools
- Open NPS console
- Right click the NPS Server and select Register in Active Directory
- Click OK
- In NPS expand RADIUS Clients and Servers
- Right-click on RADIUS Clients > New
- Check the box for Enable this RADIUS Client
- Friendly name: name of the VPN server
- IP: 10.0.8.6 (BackDMZ)
- Shared tab - ensure Manual is checked and enter the Shared Secret from the VPN server
- In NPS console under Standard Configuration, ensure RADIUS server for Dial-Up or VPN Connections is selected
- Select Configure VPN or Dial-UP
- Select Virtual Private Network (VPN) Connects > Next
- Clear Microsoft Encrypted Authentication version 2 (MS-CHAPv2) check box
- Check Extensible Authentication Protocol
- Set Type to Microsoft: Protected EAP (PEAP)
- Select Configure
- Remove Secured password (EAP-MSCHAP v2)
- Add Smart Card or other certificate > Next
- Under User Groups, select Add > AOVPN Users AD group
- IP Filters > Next
- Encryption settings > Next
- Realm Name > Next > Finish