Centralize Remote-Access Authentication with RADIUS

assignmentId netplus-radius-aaa · N10-009:4.1 · APNET:3.3 · APNET:2.6
in-memory state · no PII collected

Scenario

Cedar Ridge Outfitters runs a small HQ in Denver and a warehouse in Boise. Both sites now have their own remote-access server, and each one keeps a separate local account list — so a field technician's password has to be reset in two places, and there is no single record of who logged in where. You're the network engineer. Stand up AUTH-HUB-01 as a central RADIUS server so both remote-access servers authenticate field techs against one directory and report accounting to one place.
AUTH-HUB-01 — server roles

Turn on only what this server actually needs. AUTH-HUB-01 should answer authentication requests from the remote-access servers — it is not itself a remote-access endpoint for clients.

RADIUS Authentication Service
Accepts auth/accounting from registered RADIUS clients.
Remote Access Responder
Terminates VPN/dial sessions directly from end clients.

© 2026 <Your Name / Org>. Original clean-room lab for the Network+ / AP Networking Lab Library. No real names collected; use a pseudonymous callsign.

Not submitted.