<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Networks Archives - Jim Dolby</title>
	<atom:link href="https://jim.dolby.id.au/tips/networks/feed" rel="self" type="application/rss+xml" />
	<link>https://jim.dolby.id.au/./tips/networks</link>
	<description>A Geek and still proud of it!</description>
	<lastBuildDate>Sat, 20 Jun 2020 23:38:06 +0000</lastBuildDate>
	<language>en-AU</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
<site xmlns="com-wordpress:feed-additions:1">195341223</site>	<item>
		<title>Securing your devices using DNS</title>
		<link>https://jim.dolby.id.au/tips/security/securing-your-devices-using-dns.html</link>
		
		<dc:creator><![CDATA[YTS_Jim]]></dc:creator>
		<pubDate>Sat, 20 Jun 2020 23:38:01 +0000</pubDate>
				<category><![CDATA[Networks]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[home]]></category>
		<guid isPermaLink="false">https://www.securetech.com.au/?p=311</guid>

					<description><![CDATA[<p>We have long wondered why some of the more harmful webpages are not blocked more easily using DNS, and we finally found a system that does it for us.  Securing your devices using DNS may sound like an odd concept, but read on to find out more</p>
<p>The post <a href="https://jim.dolby.id.au/tips/security/securing-your-devices-using-dns.html">Securing your devices using DNS</a> appeared first on <a href="https://jim.dolby.id.au">Jim Dolby</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>We have long wondered why some of the more harmful webpages are not blocked more easily using DNS, and we finally found a system that does it for us.  Securing your devices using DNS may sound like an odd concept, but read on to find out more.  You can now improve your Internet Security &amp; Privacy In a Few Easy Steps</p>



<p>dns9.<a href="http://quad9.net/">quad9.net</a> is a great free service that blocks many bad things from talking to your computers and other devices. Alot of the viruses people get come from either webpages or email and use DNS to talk to their command and control (C&amp;C) server(s). Quad9 provides Internet Security &amp; Privacy<br>In a Few Easy Steps</p>



<p>dns9.<a href="http://quad9.net/">quad9.net</a> will allow you to block all harmful webpages and many other things without you even being aware of it.</p>



<p>If your unsure what DNS is, its the Domain Name System. in other words, its the domain name of the site (such as securetech.com.au) which resolves into an IP address of &#8220;208.113.162.199&#8221;. which one is easier to remember?</p>



<p></p>
<p>The post <a href="https://jim.dolby.id.au/tips/security/securing-your-devices-using-dns.html">Securing your devices using DNS</a> appeared first on <a href="https://jim.dolby.id.au">Jim Dolby</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">311</post-id>	</item>
		<item>
		<title>ASTARO &#8211; Adding Win 2k3 as a Authentication server</title>
		<link>https://jim.dolby.id.au/tips/networks/astaro-adding-win-2k3-as-a-authentication-server.html</link>
					<comments>https://jim.dolby.id.au/tips/networks/astaro-adding-win-2k3-as-a-authentication-server.html#respond</comments>
		
		<dc:creator><![CDATA[YTS_Jim]]></dc:creator>
		<pubDate>Sun, 26 Feb 2012 20:19:13 +0000</pubDate>
				<category><![CDATA[Networks]]></category>
		<guid isPermaLink="false">https://www.securetech.com.au/?p=157</guid>

					<description><![CDATA[<p>How to setup ASTARO (now sophos) UTM to authenticate with windows server 2003 through RADIUS. Step-by-step guide to getting it running. Step 1 &#8211; Add a usergroup to Authenticate against Open Computer Management (Start/All Programs/Administrative Tools/Computer Management), Add a new Usergroup and give it a descriptive and helpful name (I suggest something like &#8220;Gateway Users&#8221;). [&#8230;]</p>
<p>The post <a href="https://jim.dolby.id.au/tips/networks/astaro-adding-win-2k3-as-a-authentication-server.html">ASTARO &#8211; Adding Win 2k3 as a Authentication server</a> appeared first on <a href="https://jim.dolby.id.au">Jim Dolby</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>How to setup ASTARO (now sophos) UTM to authenticate with windows server 2003 through <a href="https://en.wikipedia.org/wiki/RADIUS">RADIUS</a>. Step-by-step guide to getting it running.</p>



<h3 class="wp-block-heading">Step 1 &#8211; Add a usergroup to Authenticate against</h3>



<figure class="wp-block-image"><img fetchpriority="high" decoding="async" width="401" height="439" data-attachment-id="158" data-permalink="https://jim.dolby.id.au/tips/networks/astaro-adding-win-2k3-as-a-authentication-server.html/attachment/win_all_user_groups" data-orig-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_all_User_groups.jpg" data-orig-size="401,439" data-comments-opened="0" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Win_all_User_groups" data-image-description="" data-image-caption="" data-large-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_all_User_groups.jpg" src="https://www.securetech.com.au/wp-content/uploads/2019/08/Win_all_User_groups.jpg" alt="Screenshot of &quot;Firewall Users&quot; usergroup" class="wp-image-158" srcset="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_all_User_groups.jpg 401w, https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_all_User_groups-274x300.jpg 274w" sizes="(max-width: 401px) 100vw, 401px" /></figure>



<ul class="wp-block-list"><li>Open Computer Management (<em><strong>Start/All Programs/Administrative Tools/Computer Management</strong></em>),</li><li>Add a new Usergroup and give it a descriptive and helpful name (I suggest something like &#8220;Gateway Users&#8221;).</li></ul>



<h3 class="wp-block-heading">Step 2 &#8211; Add users to your group</h3>



<figure class="wp-block-image"><img decoding="async" width="399" height="462" data-attachment-id="159" data-permalink="https://jim.dolby.id.au/tips/networks/astaro-adding-win-2k3-as-a-authentication-server.html/attachment/win_server_user_properties_memberof" data-orig-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_server_user_properties_memberof.jpg" data-orig-size="399,462" data-comments-opened="0" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Win_server_user_properties_memberof" data-image-description="" data-image-caption="" data-large-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_server_user_properties_memberof.jpg" src="https://www.securetech.com.au/wp-content/uploads/2019/08/Win_server_user_properties_memberof.jpg" alt="Screenshot showing user is a member of firewall users group" class="wp-image-159" srcset="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_server_user_properties_memberof.jpg 399w, https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_server_user_properties_memberof-259x300.jpg 259w" sizes="(max-width: 399px) 100vw, 399px" /></figure>



<ul class="wp-block-list"><li>Within Computer Management (System Tools/Local Users and Groups/Users), create users (if necessary)</li><li>Right click on a user and select&nbsp;<strong>Properties</strong></li><li>Under the&nbsp;<em><strong>Member Of</strong></em>&nbsp;tab, add the group that you created in Step 1 (eg &#8220;Gateway Users&#8221;)</li><li>Do Not close&nbsp;<strong>Properties</strong>&nbsp;dialog box, go to step 3.</li></ul>



<h3 class="wp-block-heading">Step 3 &#8211; Configure Dial-in access</h3>



<figure class="wp-block-image"><img decoding="async" width="379" height="110" data-attachment-id="160" data-permalink="https://jim.dolby.id.au/tips/networks/astaro-adding-win-2k3-as-a-authentication-server.html/attachment/win_server_remote_access_permissions" data-orig-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_server_Remote_access_permissions.jpg" data-orig-size="379,110" data-comments-opened="0" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Win_server_Remote_access_permissions" data-image-description="" data-image-caption="" data-large-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_server_Remote_access_permissions.jpg" src="https://www.securetech.com.au/wp-content/uploads/2019/08/Win_server_Remote_access_permissions.jpg" alt="Screenshot showing user properties Remote Access Permission to allow VPN access" class="wp-image-160" srcset="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_server_Remote_access_permissions.jpg 379w, https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_server_Remote_access_permissions-300x87.jpg 300w" sizes="(max-width: 379px) 100vw, 379px" /></figure>



<ul class="wp-block-list"><li>Within&nbsp;<strong>Properties</strong>&nbsp;dialog box, click on the&nbsp;<em><strong>Dial-in</strong></em>&nbsp;tab.</li><li>choose &#8220;Allow Access&#8221; under Remote Access Permission (Dial-in or VPN)</li><li>Save and close the&nbsp;<em>Properties</em>&nbsp;dialog box.</li></ul>



<h3 class="wp-block-heading">Step 4 &#8211; Alter Group Policy for password encryption</h3>



<figure class="wp-block-image"><img loading="lazy" decoding="async" width="798" height="568" data-attachment-id="161" data-permalink="https://jim.dolby.id.au/tips/networks/astaro-adding-win-2k3-as-a-authentication-server.html/attachment/win_server_gpedit_reversable_encryption" data-orig-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_Server_GPEdit_reversable_encryption.jpg" data-orig-size="798,568" data-comments-opened="0" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Win_Server_GPEdit_reversable_encryption" data-image-description="" data-image-caption="" data-large-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_Server_GPEdit_reversable_encryption.jpg" src="https://www.securetech.com.au/wp-content/uploads/2019/08/Win_Server_GPEdit_reversable_encryption.jpg" alt="Alter Group Policy to allow storing passwords using reversible encryption." class="wp-image-161" srcset="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_Server_GPEdit_reversable_encryption.jpg 798w, https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_Server_GPEdit_reversable_encryption-300x214.jpg 300w, https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_Server_GPEdit_reversable_encryption-768x547.jpg 768w" sizes="auto, (max-width: 798px) 100vw, 798px" /></figure>



<ul class="wp-block-list"><li>Within Active Directory Users and Computers, right click on your domain name and chose&nbsp;<strong>properties</strong></li><li>Within the Domain Properties dialog box click&nbsp;<em><strong>Group Management</strong></em>&nbsp;tab</li><li>Highlight the&nbsp;<em><strong>Default Domain Policy</strong></em>&nbsp;and select &#8220;edit&#8221;</li><li>In the GPO Editor, navigate to&nbsp;<em><strong>Computer Configuration/Windows Settings/Security Settings/Account Policies/Password Policy</strong></em></li><li>Make sure&nbsp;<strong>Store passwords using reversible encryption</strong>&nbsp;is enabled</li><li>Save and close all dialog boxes</li></ul>



<h3 class="wp-block-heading">Step 5 &#8211; Add a client to the IAS RADIUS server</h3>



<figure class="wp-block-image"><img loading="lazy" decoding="async" width="400" height="444" data-attachment-id="162" data-permalink="https://jim.dolby.id.au/tips/networks/astaro-adding-win-2k3-as-a-authentication-server.html/attachment/win_2k3_ias_radius_client_new" data-orig-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_IAS_Radius_Client_new.jpg" data-orig-size="400,444" data-comments-opened="0" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Win_2k3_IAS_Radius_Client_new" data-image-description="" data-image-caption="" data-large-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_IAS_Radius_Client_new.jpg" src="https://www.securetech.com.au/wp-content/uploads/2019/08/Win_2k3_IAS_Radius_Client_new.jpg" alt="Create a new RADIUS client" class="wp-image-162" srcset="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_IAS_Radius_Client_new.jpg 400w, https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_IAS_Radius_Client_new-270x300.jpg 270w" sizes="auto, (max-width: 400px) 100vw, 400px" /></figure>



<ul class="wp-block-list"><li>Open IAS (<em><strong>Start/All Programs/Administrative Tools/Internet Authentication Server</strong></em>)</li><li>Right click on <strong>RADIUS Clients</strong> then chose <em><strong>New RADIUS Client</strong></em></li><li>Gave the Client a friendly name of ASG and an IP address</li><li>Chose RADIUS Standard Vendor-Client and input a shared secret<br>(note: will need to input this on the ASG, so write it down)</li></ul>



<h3 class="wp-block-heading">Step 6 &#8211; Create a new Remote Access Policy</h3>



<figure class="wp-block-image"><img loading="lazy" decoding="async" width="500" height="393" data-attachment-id="163" data-permalink="https://jim.dolby.id.au/tips/networks/astaro-adding-win-2k3-as-a-authentication-server.html/attachment/win_2k3_new_rap_1" data-orig-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_1.jpg" data-orig-size="500,393" data-comments-opened="0" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Win_2k3_New_RAP_1" data-image-description="" data-image-caption="" data-large-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_1.jpg" src="https://www.securetech.com.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_1.jpg" alt="Create a new custom Remote Access Policy" class="wp-image-163" srcset="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_1.jpg 500w, https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_1-300x236.jpg 300w" sizes="auto, (max-width: 500px) 100vw, 500px" /></figure>



<figure class="wp-block-image"><img loading="lazy" decoding="async" width="499" height="393" data-attachment-id="164" data-permalink="https://jim.dolby.id.au/tips/networks/astaro-adding-win-2k3-as-a-authentication-server.html/attachment/win_2k3_new_rap_2" data-orig-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_2.jpg" data-orig-size="499,393" data-comments-opened="0" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Win_2k3_New_RAP_2" data-image-description="" data-image-caption="" data-large-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_2.jpg" src="https://www.securetech.com.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_2.jpg" alt="Create a new Remote Access Policy with these policy conditions" class="wp-image-164" srcset="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_2.jpg 499w, https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_2-300x236.jpg 300w" sizes="auto, (max-width: 499px) 100vw, 499px" /></figure>



<figure class="wp-block-image"><img loading="lazy" decoding="async" width="380" height="156" data-attachment-id="165" data-permalink="https://jim.dolby.id.au/tips/networks/astaro-adding-win-2k3-as-a-authentication-server.html/attachment/win_2k3_new_rap_4" data-orig-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_4.jpg" data-orig-size="380,156" data-comments-opened="0" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Win_2k3_New_RAP_4" data-image-description="" data-image-caption="" data-large-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_4.jpg" src="https://www.securetech.com.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_4.jpg" alt="Add the name that was used in step 5" class="wp-image-165" srcset="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_4.jpg 380w, https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_4-300x123.jpg 300w" sizes="auto, (max-width: 380px) 100vw, 380px" /></figure>



<figure class="wp-block-image"><img loading="lazy" decoding="async" width="500" height="394" data-attachment-id="166" data-permalink="https://jim.dolby.id.au/tips/networks/astaro-adding-win-2k3-as-a-authentication-server.html/attachment/win_2k3_new_rap_5" data-orig-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_5.jpg" data-orig-size="500,394" data-comments-opened="0" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Win_2k3_New_RAP_5" data-image-description="" data-image-caption="" data-large-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_5.jpg" src="https://www.securetech.com.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_5.jpg" alt="Finish creating a new Remote Access Policy" class="wp-image-166" srcset="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_5.jpg 500w, https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_5-300x236.jpg 300w" sizes="auto, (max-width: 500px) 100vw, 500px" /></figure>



<figure class="wp-block-image"><img loading="lazy" decoding="async" width="401" height="463" data-attachment-id="167" data-permalink="https://jim.dolby.id.au/tips/networks/astaro-adding-win-2k3-as-a-authentication-server.html/attachment/win_2k3_new_rap_6" data-orig-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_6.jpg" data-orig-size="401,463" data-comments-opened="0" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Win_2k3_New_RAP_6" data-image-description="" data-image-caption="" data-large-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_6.jpg" src="https://www.securetech.com.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_6.jpg" alt="Edit the Dial-in profile" class="wp-image-167" srcset="https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_6.jpg 401w, https://jim.dolby.id.au/wp-content/uploads/2019/08/Win_2k3_New_RAP_6-260x300.jpg 260w" sizes="auto, (max-width: 401px) 100vw, 401px" /></figure>



<ul class="wp-block-list"><li>Within IAS, right click on&nbsp;<strong>Remote Access Policies</strong>&nbsp;and Choose&nbsp;<em><strong>New Remote Access Policy</strong></em></li><li>In the wizard, Choose&nbsp;<em><strong>Set Up Custom Policy</strong></em>&nbsp;and give the policy a descriptive name</li><li>Select the&nbsp;<em><strong>NAS-Identifier</strong></em>&nbsp;policy condition and give the NAS ID of&nbsp;<strong>pptp</strong>&nbsp;(lowercase)</li><li>Select the&nbsp;<em><strong>Windows-Groups</strong></em>&nbsp;policy condition as well and add the group specified in Step 1</li><li>Choose&nbsp;<em><strong>Grant Remote Access</strong></em></li><li>Edit the profile to include CHAP on the Authentication tab (You can include PAP as well, but this is an insecure method)</li><li>Save and close all configurations on the Active Directory server</li></ul>



<h3 class="wp-block-heading">Step 7 &#8211; Configure the ASG</h3>



<figure class="wp-block-image"><img loading="lazy" decoding="async" width="984" height="505" data-attachment-id="168" data-permalink="https://jim.dolby.id.au/tips/networks/astaro-adding-win-2k3-as-a-authentication-server.html/attachment/asg_authentication_server" data-orig-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/ASG_Authentication_server.jpg" data-orig-size="984,505" data-comments-opened="0" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="ASG_Authentication_server" data-image-description="" data-image-caption="" data-large-file="https://jim.dolby.id.au/wp-content/uploads/2019/08/ASG_Authentication_server.jpg" src="https://www.securetech.com.au/wp-content/uploads/2019/08/ASG_Authentication_server.jpg" alt="Configure ASTARO Secure Gateway (ASG)" class="wp-image-168" srcset="https://jim.dolby.id.au/wp-content/uploads/2019/08/ASG_Authentication_server.jpg 984w, https://jim.dolby.id.au/wp-content/uploads/2019/08/ASG_Authentication_server-300x154.jpg 300w, https://jim.dolby.id.au/wp-content/uploads/2019/08/ASG_Authentication_server-768x394.jpg 768w" sizes="auto, (max-width: 984px) 100vw, 984px" /></figure>



<ul class="wp-block-list"><li>Navigate to&nbsp;<em><strong>Definitions &amp; Users/Authentication Servers/Servers</strong></em></li><li>Add the server, service port (keep default unless absolutely certain) and shared secret from Step 5</li><li>Save the configuration</li></ul>



<p>You are now done with the configuration. In a few minutes, at most, you should be able to use the UTM to authenticate with windows using the RADIUS server facilities. If there is an issue where authentication continually fails, most likely there is a setting on the AD server that needs to be adjusted.</p>



<h3 class="wp-block-heading">Advanced Settings</h3>



<p>If you wanted to get fancy, you could do the following:</p>



<p>Setup a Group for each part of the ASTARO Secure Gateway components (such as Proxy, VPN, Webadmin, etc)</p>



<p>Setup a Remote Access Policy which mimicks the above, while adding &#8220;NAS-Identifier&#8221; as an extra step. ASTARO sends a unique identifier for each part, so you can setup groups within windows to authorise access to whatever you want, and then you no longer need to edit users at the ASG Web Admin.</p>



<p>This requires setting up &#8220;Automatic User Creation&#8221; (<em><strong>Definitions &amp; Users/Authentication Servers/Global Settings</strong></em>).</p>



<h3 class="wp-block-heading">Troubleshooting</h3>



<p>Use the Test feature of the Edit Authentication Server Page to check if the UTM authenticates with windows and therefor the user is getting authorisation. </p>



<p>Use the Event viewer on the server to check the &#8220;System&#8221; Logs, Failed Logon events will show further details here (as long as ASG is setup with the correct server details.</p>



<p><a href="https://web.archive.org/web/20120317181602/http://technet.microsoft.com/en-us/library/cc782585.aspx">http://technet.microsoft.com/en-us/library/cc782585.aspx</a> is a good place to start for troubleshooting various items on the windows side.</p>



<p>This article was originally found at &#8220;<a href="https://web.archive.org/web/20120317181602/https://support.astaro.com/support/index.php/RADIUS">https://support.astaro.com/support/index.php/RADIUS</a>&#8220;. We have updated it, because the original was a little light on information, and is considered outdated now.</p>



<p>This was created in a hope that others can get more information, and not have to spend as much time as we did, tracking down issues and piecing everything together (not being an expert on RADIUS Authentication).</p>



<p>If you need help with this or other firewalls, please <a href="https://www.securetech.com.au/company/contact-us.html">contact us</a>.</p>
<p>The post <a href="https://jim.dolby.id.au/tips/networks/astaro-adding-win-2k3-as-a-authentication-server.html">ASTARO &#8211; Adding Win 2k3 as a Authentication server</a> appeared first on <a href="https://jim.dolby.id.au">Jim Dolby</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://jim.dolby.id.au/tips/networks/astaro-adding-win-2k3-as-a-authentication-server.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">157</post-id>	</item>
		<item>
		<title>RJ45 Cat 5 cable pin-outs</title>
		<link>https://jim.dolby.id.au/tips/networks/rj45-cat-5-cable-pin-outs.html</link>
		
		<dc:creator><![CDATA[YTS_Jim]]></dc:creator>
		<pubDate>Mon, 05 Jan 2009 05:10:27 +0000</pubDate>
				<category><![CDATA[Networks]]></category>
		<guid isPermaLink="false">https://www.securetech.com.au/?p=21</guid>

					<description><![CDATA[<p>Ethernet RJ45 Socket 10baseT Colour Code T568BPin No Description Colour1_____TX +_______Orange/White2_____TX -_______Orange3_____RX +_______Green/White4________________Blue5________________Blue/White6_____RX -_______Green7________________Brown/White8________________Brown_________________________________ RJ45 Cross Over Cable 10baseTRJ45 Male RJ45 Male1__________32__________63__________16__________2______________________________________ RJ45 100base-T4 Crossover male to maleName______Pin__Pin__NameTX_D1+____1____3____RX_D2+TX_D1-____2____6____RX_D2-RX_D2+____3____1____TX_D1+RX_D2-____6____2____TX_D1-BI_D3+____4____7____BI_D4+BI_D3-____5____8____BI_D4-BI_D4+____7____4____BI_D3+BI_D4-____8____5____BI_D3 It&#8217;s important that each pair is kept as a pair. TX+ &#38; TX- must be inthe pair, and RX+ &#38; RX- must together in another pair etc. [&#8230;]</p>
<p>The post <a href="https://jim.dolby.id.au/tips/networks/rj45-cat-5-cable-pin-outs.html">RJ45 Cat 5 cable pin-outs</a> appeared first on <a href="https://jim.dolby.id.au">Jim Dolby</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Ethernet RJ45 Socket 10baseT Colour Code T568B<br />Pin No Description Colour<br />1_____TX +_______Orange/White<br />2_____TX -_______Orange<br />3_____RX +_______Green/White<br />4________________Blue<br />5________________Blue/White<br />6_____RX -_______Green<br />7________________Brown/White<br />8________________Brown<br />_________________________________</p>
<p>RJ45 Cross Over Cable 10baseT<br />RJ45 Male RJ45 Male<br />1__________3<br />2__________6<br />3__________1<br />6__________2<br />______________________________________</p>
<p>RJ45 100base-T4 Crossover male to male<br />Name______Pin__Pin__Name<br />TX_D1+____1____3____RX_D2+<br />TX_D1-____2____6____RX_D2-<br />RX_D2+____3____1____TX_D1+<br />RX_D2-____6____2____TX_D1-<br />BI_D3+____4____7____BI_D4+<br />BI_D3-____5____8____BI_D4-<br />BI_D4+____7____4____BI_D3+<br />BI_D4-____8____5____BI_D3</p>
<p>It&#8217;s important that each pair is kept as a pair. TX+ &amp; TX- must be in<br />the pair, and RX+ &amp; RX- must together in another pair etc. (Just as<br />the table above shows).</p>


<p>Ethernet RJ45 Socket 10baseT Colour Code T568A</p>
<table>
    <tr>
        <td> &nbsp; &#8216;A&#8217; Colour</td>
        <td> &nbsp; Signals</td>
        <td> &nbsp; Pin#</td>
        <td> &nbsp; &#8216;B&#8217; Colour</td>
    </tr>
    <tr>
        <td> &nbsp; Green / White</td>
        <td> &nbsp; TX+</td>
        <td> &nbsp; 1</td>
        <td> &nbsp; Orange / White</td>
    </tr>
    <tr>
        <td> &nbsp; Green</td>
        <td> &nbsp; TX-</td>
        <td> &nbsp; 2</td>
        <td> &nbsp; Orange</td>
    </tr>
    <tr>
        <td> &nbsp; Orange / White</td>
        <td> &nbsp; RX+</td>
        <td> &nbsp; 3</td>
        <td> &nbsp; Green / White</td>
    </tr>
    <tr>
        <td> &nbsp; Blue</td>
        <td> &nbsp; </td>
        <td> &nbsp; 4</td>
        <td> &nbsp; Blue</td>
    </tr>
    <tr>
        <td> &nbsp; Blue / White</td>
        <td> &nbsp; </td>
        <td> &nbsp; 5</td>
        <td> &nbsp; Blue / White</td>
    </tr>
    <tr>
        <td> &nbsp; Orange</td>
        <td> &nbsp; RX-</td>
        <td> &nbsp; 6</td>
        <td> &nbsp; Green</td>
    </tr>
    <tr>
        <td> &nbsp; Brown / White</td>
        <td> &nbsp; </td>
        <td> &nbsp; 7</td>
        <td> &nbsp; Brown / White</td>
    </tr>
    <tr>
        <td> &nbsp; Brown</td>
        <td> &nbsp; 8</td>
        <td> &nbsp; </td>
        <td> &nbsp; Brown</td>
    </tr>
</table>



<p></p>
<p>The post <a href="https://jim.dolby.id.au/tips/networks/rj45-cat-5-cable-pin-outs.html">RJ45 Cat 5 cable pin-outs</a> appeared first on <a href="https://jim.dolby.id.au">Jim Dolby</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">21</post-id>	</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 
Lazy Loading (feed)

Served from: jim.dolby.id.au @ 2026-05-08 16:22:12 by W3 Total Cache
-->