Community discussions

MikroTik App
 
pakfar
just joined
Topic Author
Posts: 3
Joined: Mon Jan 26, 2015 1:56 pm

Mikrotik & Windows Server 2008 Active Directory

Mon Jan 26, 2015 2:13 pm

Do MikroTik coordinated with Windows Server 2008 Active Directory?
Sync with AD
 
User avatar
hossain2004a
Member Candidate
Member Candidate
Posts: 247
Joined: Mon Dec 22, 2014 7:34 pm
Location: Iran

Re: Mikrotik & Windows Server 2008 Active Directory

Mon Jan 26, 2015 4:32 pm

I think they don't relate to each other so there would be no problem with them, Imaging mikrotik is your Modem and compare it with Win server, there would be no problem?

P.S: I didn't test it yet, but will do in future
 
User avatar
rmmccann
Member Candidate
Member Candidate
Posts: 182
Joined: Tue Sep 25, 2012 11:15 pm
Location: USA

Re: Mikrotik & Windows Server 2008 Active Directory

Mon Jan 26, 2015 9:50 pm

I think they don't relate to each other so there would be no problem with them, Imaging mikrotik is your Modem and compare it with Win server, there would be no problem?

P.S: I didn't test it yet, but will do in future
I think OP is referring to AAA using 2008 Active Directory.

I have been able to set up 802.1x authentication with my 2008 R2 Active Directory domain and Mikrotik wireless and radius. With a little further research I'm sure you could get AAA to handle router logins, hotspot, etc as well.
 
DLNoah
Member Candidate
Member Candidate
Posts: 144
Joined: Fri Nov 12, 2010 5:33 pm

Re: Mikrotik & Windows Server 2008 Active Directory

Mon Jan 26, 2015 11:28 pm

Authentication for Winbox/Telnet router logins via Active Directory will not work, unless you store the password in AD with reversible encryption (WARNING: NOT RECOMMENDED). Winbox/Telnet AAA only supports PAP authentication, which requires a cleartext-password to authenticate.
 
scampbell
Trainer
Trainer
Posts: 487
Joined: Thu Jun 22, 2006 5:20 am
Location: Wellington, NZ
Contact:

Re: Mikrotik & Windows Server 2008 Active Directory

Tue Jan 27, 2015 12:25 am

Authentication for Winbox/Telnet router logins via Active Directory will not work, unless you store the password in AD with reversible encryption (WARNING: NOT RECOMMENDED). Winbox/Telnet AAA only supports PAP authentication, which requires a cleartext-password to authenticate.
There are several links to using AD as a Radius Server for Hotspot, AAA etc

Here is one...... http://wiki.mikrotik.com/wiki/AAA_with_Active_Directory

DLNoah is correct about the reverse encryption - so you need to weigh up if you want to do this.

We use this IAS feature for Hotspot authentication at schools etc.

Note IAS was renamed NPS (Network Policy Server) in Windows Server 2008 :D
 
pakfar
just joined
Topic Author
Posts: 3
Joined: Mon Jan 26, 2015 1:56 pm

Re: Mikrotik & Windows Server 2008 Active Directory

Tue Jan 27, 2015 11:11 am

Authentication for Winbox/Telnet router logins via Active Directory will not work, unless you store the password in AD with reversible encryption (WARNING: NOT RECOMMENDED). Winbox/Telnet AAA only supports PAP authentication, which requires a cleartext-password to authenticate.
There are several links to using AD as a Radius Server for Hotspot, AAA etc

Here is one...... http://wiki.mikrotik.com/wiki/AAA_with_Active_Directory

DLNoah is correct about the reverse encryption - so you need to weigh up if you want to do this.

We use this IAS feature for Hotspot authentication at schools etc.

Note IAS was renamed NPS (Network Policy Server) in Windows Server 2008 :D
I need ppp authentication with AD (user manager sync with AD)
it`s Possible?