Monday, 2014-03-24

*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid00:00
*** coolacid has quit (Read error: Connection reset by peer)00:02
*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid00:03
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid13:19
*** nowen has quit (Ping timeout: 265 seconds)13:29
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid13:33
*** nowen has quit (Client Quit)13:34
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid13:34
*** nowen has quit (Client Quit)13:36
*** nowen1 (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid13:36
*** nowen1 has quit (Ping timeout: 240 seconds)13:40
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid13:44
*** nowen1 (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid16:25
*** nowen has quit (Ping timeout: 264 seconds)16:28
*** jimmy____ (40813d32@gateway/web/freenode/ip.64.129.61.50) has joined #wikid16:35
jimmy____Hello Gents.16:35
nowen1ji16:35
nowen1hi16:35
*** nowen1 is now known as nowen16:36
jimmy____I am trying to set up wikid and I have a few questions regarding this setup16:36
nowenok16:36
jimmy____I am not sure if I need to setup a RADIUS server..16:37
nowendepends on what you're trying to do16:37
jimmy____I'm ptying to place the 2 Factor auth for VPN access.16:38
jimmy____trying**16:38
nowenyour VPN can talk radius directly to the WiKID Enterprise server16:38
jimmy____So far I have the wikid server setup.16:38
nowenif you want to have your directory included for authorization, you will need a separate radius server16:38
jimmy____And I would like to auth through windows AD16:39
nowenthen you need to install and configure NPS, the MS radius plugin16:39
jimmy____I read the info in configuring NPS16:39
jimmy____which means that I do not have to configure anything on the switch side? Cisco ASA16:40
nowenThe CIsco will be set up to talk radius to NPS.16:40
nowenCisco >> NPS/AD >> WIKID >> NPS/AD >> Cisco16:41
nowenthe users will enter their AD username and WiKID OTP16:42
nowenNPS uses the AD username for authorization, then proxies the creds to WiKID16:42
nowenNPS can be a bit of a pain16:44
jimmy____I dont know if it's just NPS.. i'm finding this entire setup a pain :(16:44
nowenwell, it's a lot of moving parts. the key is to start simple16:45
nowencan you get the cisco using AD creds via NPS?16:45
jimmy____it's just that my unfimilarity with this causing me to walk around in the dark :(16:45
nowenI hear ya16:45
jimmy____As of yet I have not done anything besides setup the Wikid server.16:46
jimmy____My other quesiton was either to go about installing a RADIUS server is really required.16:46
nowenI think NPS is your only choice for a radius server, but i could be wrong.16:48
jimmy____ugh..16:50
nowenThe ASA might be able to do it16:50
nowenthat's a question for #cisco ;-)16:50
jimmy____http://www.wikidsystems.com/support/wikid-support-center/how-to/how-to-add-two-factor-authentication-to-a-cisco-5500-adsm-6.2 that's the link to the ASA 550016:50
jimmy____Im sure if I do that I could skip setting up the NPS, right?16:51
nowenyes, but I think that doesn't include routing the auth through AD.  It would prove that you have radius set up correctly on the ASA16:52
jimmy____I see. I guess I would have to give NPS a try.. see where that takes me..16:56
nowenI'm sorry.16:58
jimmy____No worries... I'm sure if I wasn't this handi capped.. I would have got something out of this by now =]16:59
nowenI wish NPS was better.  It would make a lot of things easier.17:00
jimmy____what is the problem with NPS that you would know of?17:07
nowenmostly,  I would say bad verbiage.17:07
nowenit's hard to know what is what17:07
nowenI've just seen a lot of people struggle with it17:07
nowenthat being said, I tested our tutorial and it worked17:08
nowenalso, it's impossible to get good support from MS17:08
jimmy____I was looking at your tutorial, that seems pretty straight forward..17:08
*** nowen has quit (Quit: Leaving.)17:09
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid17:10
nowenI did not mean to do that ;-)17:10
jimmy____ok, I was curious if my questions did scare you off... ;)17:11
nowenmy suggestion is to start simple - cisco to nps, test with AD creds, then nps to wikid, test with OTP17:11
jimmy____ok, is there a tutorial for cisco to nps?17:12
nowenjust look for how to add a radius server to the cisco17:13
jimmy____gotcha17:13
jimmy____just to clarify NPS should be configured on the DC17:13
nowenI think that is simplest17:14
*** vladp (6d65ec17@gateway/web/freenode/ip.109.101.236.23) has joined #wikid17:18
vladphi nick17:18
vladpdo you have a momnent ?17:18
vladp*moment17:18
jimmy____thanks nowen.17:31
nowennp jimmy____17:32
nowenhi vladp17:32
nowensure17:32
vladpTo import a postgresql database wikid simple dump and then import to the new server and run /opt/WiKID/conf/templates/wikid-firstboot.sh17:33
nowenwhat are you trying to do? Upgrade postgres version?17:34
vladpimport postgresql database to a new server17:35
nowenok17:35
nowenwill the new server replace the old one?17:36
vladpno, it'll be setup on a different datacenter17:39
vladpand i wanted to keep the database for users to not generate tokens again17:40
nowenok - I recommend you set up the new server, create new certs, etc.  Then dump and import the data17:40
nowenif the IP address is changing, that might be an issue17:40
vladpactually i think I'll need to generate new domains17:40
vladpwith the new Ip17:41
nowenwe can re-direct users to your new IP using DNS17:41
nowenbut our dns will be in the middle17:41
nowenhow many users do you have?17:41
vladp100+ anyway we wil use this in case the other datacenter is having netwrk issues17:43
vladpso we will need to authenticate users against another domain which will be in this datacenter17:43
nowenis this all for your sys admins? or is it external?17:46
vladpall internal17:46
nowenwell, we can re-direct users via dns.  we would create an entry for yourdomainID.wikidsystems.net and point it to your new IP18:02
nowenwhen the old IP fails, the token will try our dns18:03
*** jimmy____ has parted #wikid (None)18:18
nowenbrb18:33
*** nowen1 (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid18:34
*** nowen has quit (Ping timeout: 252 seconds)18:37
*** nowen1 is now known as nowen18:52
*** vladp has quit (Quit: Page closed)20:18
*** nowen has quit (Quit: Leaving.)22:12

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!