Options

Linux or Windows for Radius server

saddayzsaddayz Member Posts: 29 ■□□□□□□□□□
Hello,

I'm planning to implement two (Main and Backup) Radius servers for Cisco (Nexus, ASR and ISR and maybe IOS) devices. Now i'm thinking which platform would be more suitable to use: Windows or linux (free radius) for it. The main requirements that it'd support a synchronization of databases between each other. Also it'd be nice to have Radius accounting (to log to server any command, that has been entered by user (but is not mandatory)). So i'm thinking which platform to use. Also, my company have AD (Active Dir) environment. So maybe it's good idea to run it on windows with AD ?

Or maybe you can recommend any whitepapers? Thanks!

Comments

  • Options
    --chris----chris-- Member Posts: 1,518 ■■■■■□□□□□
    saddayz wrote: »
    Hello,

    I'm planning to implement two (Main and Backup) Radius servers for Cisco (Nexus, ASR and ISR and maybe IOS) devices. Now i'm thinking which platform would be more suitable to use: Windows or linux (free radius) for it. The main requirements that it'd support a synchronization of databases between each other. Also it'd be nice to have Radius accounting (to log to server any command, that has been entered by user (but is not mandatory)). So i'm thinking which platform to use. Also, my company have AD (Active Dir) environment. So maybe it's good idea to run it on windows with AD ?

    Or maybe you can recommend any whitepapers? Thanks!

    I have zero experience with Linux / Free Radius and have only setup and used a M$ AD/Radius system. I don't use any accounting features, so I can't comment there either. Only thing I can say is in 400+ days it has not failed or needed someone to fiddle with it to make it work.
  • Options
    saddayzsaddayz Member Posts: 29 ■□□□□□□□□□
    Thank you, do you also Use more than one radius server?

    Which Microsoft tool do you use for running the Radius system ? And on which windows version does it run.
    Thanks.
  • Options
    --chris----chris-- Member Posts: 1,518 ■■■■■□□□□□
    Yes, one in prod and one in DR. Both running on server 2012, very straight forward to setup. https://msdn.microsoft.com/en-us/library/cc732912(v=ws.11).aspx
  • Options
    saddayzsaddayz Member Posts: 29 ■□□□□□□□□□
    thank you,


    Btw maybe you know do the AAA accounting (specifically logging of users commands entered) with MS Radius implementation ?


    And the other question about AAA configuration on CISCO nodes:


    DO the "aaa authorization exec default group radius local" is mandatory to be able to get to exec mode ?


    Thank you
Sign In or Register to comment.