Launch Network Policy Server

  1. In Server Manager click "Tools"
  2. Select Network Policy Server


Create a RADIUS Client

  1. Expand "Radius Clients and Servers"

 2. Right Click "Radius Clients" and select "New" from the menu



3. Enter a Friendly name, e.g, "RRAS"

4. Enter the RRAS’s IP in the IP address filed, e.g. "127.0.0.1", if on the same machine,

5. Enter the Shared secret password


6. Click "OK"

Create a Remote RADIUS Server Group

  1. Right Click "Remote RADIUS Server Group" and select "New" from the menu

2. Enter a group name e.g. "DualShield MFA"


3. Click "Add" and Enter the name or IP address of the DualShield Radius Server 



4. Click Verify

5. The IP Address will move down to the IP address box


6. Click OK

7. Select "Authentication/Accounting" tab on the Radius Clients Context Menu, enter the Shared secret password



8. Select "Load Balancing" tab, and copy the timing settings as below..

9. Click OK.

Create a Connection Request Policy

  1. Expand "Policies"
  2.  Right Click "Connection Request Policies" and select "New" from the menu
  3. Enter a Policy name, e.g. "DualShield Radius Connection Policy"
  4. Change type of network access server to "Remote Access Server (VPN-Dial up)" and click "Next"



  5. Add a new condition "Day and Time Restrictions" and select "Permitted" to allow a certain time of connection.



  6. Select "Forward requests to the following remote RADIUS server group for authentication" and select the newly server group "DualShield Radius Server Group"



  7. Click "Next", "Next" and "Finish".
  8. Make sure Dualshield is at the top of the list biy right-clicking and selcting Move Up and processing order is number 1.  Also, disable other connection request policies by right-clicking and selecting Disabled from the menu.


Create a Network Policy

  1. Right Click "Network Policies" and select "New" from the menu
  2. Enter a policy name, e.g. "DualShield Radius Network Policy"
  3. Change type of network access server to "Remote Access Server (VPN-Dial up)" and click "Next"



  4. Add a new condition "Day and Time Restrictions" and select "Permitted" to allow certain time of connection and press "OK" and "Next"



  5. Specify Access Permission and click "Next"



  6. Select the authentication methods e.g.  MS-CHAP v2



  7. Click "No" to the warning message.
  8. Click "Next", "Next", "Next" and "Finish"