angyal.dk
  1. You are here:  
  2. Home
  3. Windows Server administration

L2TP/IPSec Remote Access VPN with Active Directory authentication by RADIUS and Duo Security MFA

Details
Category: Windows Server administration
Published: 05 December 2021
  • vpn
  • l2tp
  • ipsec
  • nps
  • radius

In this article, we'll describe how to deploy an L2TP/IPSec Remote Access VPN (Virtual Private Network) on a Ubiquiti EdgeRouter 4, using RADIUS (Remote Authentication Dial-In User Service) for central user authentication through Windows Network Policy Services, and Duo Security Multifactor Authentication (MFA).

What can I use it for?

Enterprise users who are on business trips or working from home can use a Virtual Private Network to connect their devices to company resources, such as file servers and enterprise applications (e.g., CRM, ERP). In this scenario, we will utilize the Layer Two Tunneling Protocol (L2TP) over Internet Protocol Security (IPSec) encryption to offer VPN services to our users. Since L2TP doesn't have integrated encryption, the data transmitted between users' devices and the VPN server will be encrypted with a 256-bit encryption key. We will use the Network Policy Server (NPS) service in Windows Server 2019 to authenticate users in our on-premises Active Directory.

As an extra security layer, we will utilize Duo Security MFA push notifications on smartphones to approve login requests.

Read more: L2TP/IPSec Remote Access VPN with Active Directory authentication by RADIUS and Duo Security MFA

Main Menu

  • Home
  • Search

IT Topics

  • Windows Server administration
  • Notions

Tags

vpn l2tp ipsec nps radius
  • Forgot your password?
  • Forgot your username?