Microsoft Always on VPN AD groups to different ip

Indrek 1 Reputation point
2021-01-28T14:28:35.43+00:00

Hi,

is there a way to force user groups at NPS authentication/RRAS to certain DHCP or static IP pool with Microsoft Always on VPN ?

AD group "A" users direct to pool etc 10.0.10.10 - 10.0.10.50

AD group "B" users direct to pool etc 10.0.20.10 - 10.0.20.50

If there is, then how would it be done. ( I dont want the static IP in user dial-in options ).

Windows Server Infrastructure
Windows Server Infrastructure
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Infrastructure: A Microsoft solution area focused on providing organizations with a cloud solution that supports their real-world needs and meets evolving regulatory requirements.
524 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Gloria Gu 3,896 Reputation points
    2021-01-29T02:18:02.777+00:00

    @Indrek Hi,

    Thank you for posting in Q&A!

    This issue has been discussed before, however please kindly note that the goal "assign a dhcp address (several scopes on a 2019 MS DHCP) to an always on vpn user based on network policies on the NPS server" cannot be achieved.

    You can refer to the early thread discussing the same issue for more details:
    https://social.technet.microsoft.com/Forums/en-US/59c0605e-849b-4599-ab86-34dd575746bc/always-on-vpn-with-server-2019-nps-radius-auth-and-selectable-dhcp-subnet-selection-?forum=winserverNIS

    Hope you have a nice day : )
    Gloria

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.
    https://learn.microsoft.com/en-us/answers/articles/67444/email-notifications.html

    0 comments No comments

  2. Indrek 1 Reputation point
    2021-01-29T06:29:56.63+00:00

    Hi @Gloria Gu

    So there is no way to direct AD different groups admin,partners,normal user etc to different IP pool/VLAN with Always on VPN RRAS service ?

    0 comments No comments