locked
Advanced Threat Analytics for VPN using NPS RRS feed

  • Question

  • We have ATA (Version1.9.7312.32791) and Lightweight Gateways on Domain controllers. NPS running on this DC. Cisco ASA VPN use NPS tot authenticate users. 

    How to collect\transfer NPS (on DC) accounting to ATA? What ip address need to use for "Remote RADIUS server group"

    C:\Windows\system32>netstat -a | FINDSTR 1813
      UDP    0.0.0.0:1813           *:*
      UDP    1XX.XX.0.64:1813       *:*




    • Edited by Danila.Elezov Wednesday, April 11, 2018 10:23 AM details
    Wednesday, April 11, 2018 8:23 AM

All replies

  • Hi,

    In order to integrate VPN with ATA, please follow the steps described in our documentation:

    https://docs.microsoft.com/en-us/advanced-threat-analytics/vpn-integration-install-step

    Thanks,

    Tali

    Wednesday, April 11, 2018 9:11 AM
  • Added more details
    Wednesday, April 11, 2018 10:22 AM