TL;DR
A network access server (NAS) acts as a gateway that authenticates users before granting access to remote resources like the internet, Voice over Internet Protocol (VoIP) systems, or Virtual Private Networks (VPNs). Common deployments include Internet Service Providers (ISPs), enterprise Virtual Private Network (VPN) connections, and communication platforms. Organizations can strengthen NAS security by leveraging the Okta Remote Authentication Dial-In User Service (RADIUS) Server Agent, which adds Multi-Factor Authentication (MFA) support for devices that do not support Security Assertion Markup Language (SAML).
What is a NAS?
A network access server (NAS) is any device that handles remote logins to establish a point-to-point protocol connection. Some people call these devices media access gateways or remote access servers.
No matter what you call them, these tools handle authentication and ensure that people can tap into the resources they need. You might use them between users and a phone system or users and the internet.
How does a NAS work?
A NAS is a gateway to a wider world of resources for a user. That person must move through the NAS and pass any authentication tests before accessing the resources they need.
You have probably used a NAS even if you didn't realize it. Many years ago, you likely needed to wait for your computer to move through a series of beeps and buzzes before you could reach the internet. That dial-up process was handled by a NAS. (And believe it or not, 2.1 million people still use dial-up systems like this at home right now.)
How does the dial-up connection process work?
A dial-up process looks like this:
- Modem connection: The person starts up the computer, connects the modem, and opens a line of communication.
- Modem to NAS: The modem sends your password and username to the NAS.
- Authentication: Once the NAS verifies your access, a window to the internet opens, and you can reach another server.
The NAS has a simple, but crucial, job here. The user's credentials must be verified to ensure proper access. And the NAS must open a gateway, so the user can read another server. Without a network access server, none of that work gets done.
You may not hear similar beeps and clicks when you log into the internet from a computer at work, but the process remains the same. Your request passes through an NAS to verify and grant access.
If you've ever used a printer on the network, you've probably used a NAS too. Your computer connects to the network access server, which verifies that you're approved to connect, and then you can start your print job.
What are some common examples of network access servers?
We've offered a few examples of NAS deployments. But there a number of functions for network access servers, from connecting directly to the internet to using internet-supported services for direct communication.
Common NAS deployment scenarios
| Deployment Type | Primary Use Case | Authentication Credential Used |
|---|---|---|
| Internet service providers (ISPs) | Serve as the gateway to protected remote resources, enabling ISPs to give their customers access to the internet via modem-like devices such as cable or Digital Subscriber Line (DSL), using point-to-point protocol, point-to-point tunneling protocol, or point-to-point protocol over ethernet connections. | Point-to-point protocol connections (PPP, PPTP, PPPoE) |
| Communication applications (Voice over Internet Protocol (VoIP)) | Authenticate users for VoIP calls and support network management and optimization processes such as load balancing, network resource management, and user sessions. | IP addresses or phone numbers |
| Virtual private network (VPN) | Give remote users access to a private network, allowing employees to securely connect to the business's network and access the resources they need regardless of their location. | Employee credentials authenticated via the internet |
How does Remote Authentication Dial-In User Service (RADIUS) support network access servers?
Most network access server systems work with authentication, authorization, and accounting services using the Remote Authentication Dial-In User Service (RADIUS) protocol. This system typically runs in the background, and it helps to manage network access quickly and efficiently.
How Okta RADIUS Server Agent can help
The Okta RADIUS Server Agent offers a solution to address NAS security vulnerabilities by providing authentication and authorization functionality for devices that do not support SAML.
Why server credentials are at risk
The rapidly evolving security landscape has rendered servers and networks particularly vulnerable to hackers. Due to their sensitive nature and their high level of privileges, server credentials are frequent targets of exploits. Even large organizations have dealt with issues like this recently.
Okta RADIUS can help by providing authentication and authorization functionality.
What does the Okta RADIUS Server Agent do?
To ensure network security, enterprises can leverage the Okta RADIUS Server Agent to support authentication for VPN devices, virtual desktops, and network appliances that don't support SAML.
The Okta RADIUS Server Agent:
- Installs as a Windows service
- Uses MFA to delegate authentication to Okta
- Defaults to port 1812
- Currently supports User Datagram Protocol (UDP) and the Password Authentication Protocol (PAP)
In this way, organizations can rest assured that their VPN connections are secure and their data remains protected.
Frequently asked questions
What is a network access server (NAS)?
A network access server (NAS) is a device that manages remote logins and establishes point-to-point protocol connections. Also called media access gateways or remote access servers, NAS devices handle authentication and control access to resources such as the internet, printers, and private networks.
How does a network access server (NAS) authenticate users?
A NAS verifies a user's credentials — such as a username and password — before granting access to the requested resource. In a dial-up scenario, the modem sends credentials to the NAS, which then opens a gateway to the internet once access is confirmed. Most NAS systems rely on the RADIUS protocol to manage authentication, authorization, and accounting in the background.
What protocols does a network access server (NAS) use for authentication?
Most network access server systems work with authentication, authorization, and accounting services using the Remote Authentication Dial-In User Service (RADIUS) protocol. NAS devices also support protocols such as point-to-point protocol (PPP), point-to-point tunneling protocol (PPTP), and point-to-point protocol over ethernet (PPPoE), as well as User Datagram Protocol (UDP) and the Password Authentication Protocol (PAP).
What are the most common uses of a network access server (NAS)?
Network access servers are commonly used by internet service providers (ISPs) to grant customers internet access, by businesses to support VPN connections for remote employees, and by communication platforms to authenticate VoIP calls using credentials like IP addresses or phone numbers.
How does a network access server (NAS) support Virtual Private Network (VPN) connections?
In enterprise environments, a NAS works alongside client software to authenticate employees connecting to a VPN over the internet. This setup allows remote workers to securely access company resources regardless of their location, which is especially valuable for organizations with flexible or mobile workforces.
What is the Okta Remote Authentication Dial-In User Service (RADIUS) Server Agent and how does it help?
The Okta RADIUS Server Agent is a Windows service that adds multi-factor authentication (MFA) to VPN devices, virtual desktops, and network appliances that do not support Security Assertion Markup Language (SAML). It defaults to port 1812 and supports User Datagram Protocol (UDP) and the Password Authentication Protocol (PAP), delegating authentication to Okta to help keep network connections secure.
Why are server credentials a frequent target for attackers?
Servers and networks have become increasingly vulnerable due to the rapidly evolving security landscape. Because server credentials carry a high level of privileges, they are frequent targets of exploits — a challenge that even large organizations have faced.
Resources
OMG: 2.1 Million People Still Use AOL Dialup. (May 2015). CNN.
VPN Statistics: What the Numbers Tell Us About VPNs. (July 2020). Comparitech.