, 04 2017 . 17:11
+
?
, RADIUS Mikrotik, , . , . .
, .
?
, . ( ) :
- AUTHSRV.DOM1.LOCAL (win2003), .
- Mikrotik, .
- DOM1.LOCAL (win2008) DOM2.LOCAL (win2003).
- DOM2.LOCAL allow_internet, , Mikrotik.
- AUTHSRV.DOM1.LOCAL allow_internet, DOM2.LOCAL\allow_internet.
- , , AUTHSRV\allow_internet.
.
?
.
DOM1.LOCAL DOM3.LOCAL (win2003).
DOM3.LOCAL allow_internet, .
AUTHSRV\allow_internet .
, . :
= - . , , , , .
.. , - , .
DOM3.LOCAL DOM1.LOCAL . - ( RDP).
DOM2.LOCAL .
RADIUS ,
DC.DOM3.LOCAL DOM3*. -RADIUS .
. ,
DOM3.LOCAL mixed-, - /Dial-in (VPN ) ,
DOM2.LOCAL.
DOM3.LOCAL native
(VPN ) ( ) :
Set objOU = GetObject("LDAP://dc=DOM3,dc=local")
objOU.Filter = Array("user")
For Each objUser In objOU
objUser.PutEx 1,"msNPAllowDialin", vbnull
objUser.SetInfo
Next
.
https://habrahabr.ru/post/334904/
:
author v0rdych
radius
windows domain mixed-mode
dial-in policy