Checkpoint architecture & design
Checkpoint architecture & design
2. Tools Used
1. Active Directory (AD): A directory service used for managing user accounts and
authentication.
2. Network Policy Server (NPS): A feature in Windows Server that implements the RADIUS role.
1. On the DC1 VM, open the Network Policy Server from the Server Manager tools menu.
2. Navigate to RADIUS Clients and Servers > RADIUS Clients, then add a new RADIUS client.
o Address: 10.1.0.254
1. Expand Policies > Network Policies and create a new policy named:
pfSense Network Security Appliance Administration.
2. Add the condition: Windows Groups, then link the localadmin group from AD.
5. Add the Class RADIUS attribute and assign the value T LocalAdmin. This attribute
communicates group membership to pfSense.
1. Open http://10.1.0.254 in the browser on DC1 to access the pfSense web interface.
2. Navigate to System > User Manager > Authentication Servers, then add a new server:
o Type: RADIUS
1. In the pfSense interface, go to the Groups tab and add a new group:
E. Verify Configuration
1. Log out of pfSense and attempt to log in using a user from the LocalAdmin security group.