I've spent my share of time troubleshooting ACS and many hours on tech support.

Version 3.x and 2.x also have their share of critical vulnerabilities some of which are unpatched as of December 10, 2006.Cisco ACS also lacks the ability to act as a relay RADIUS server which limits its ability to serve in a more robust multi-tier RADIUS environment.You need that ability to link to multiple Active Directories or other user directories that are not tied to each other.ACS also costs around 00 per copy whereas Microsoft IAS comes with Windows Server 2003.The complete Tech Republic Ultimate Wireless Security Guide is available as a download in PDF form.Windows Server 2003 comes bundled with a very capable RADIUS (also known as AAA) server that's extremely stable, secure, and robust.

When you search on Internet security databases for Microsoft IAS vulnerabilities, you won't find any.The IAS service just runs for years without the need to patch IAS.If your Windows Server 2003 box is hardened to only accept IAS requests with host-based firewall restrictions on all other ports and you install no other services on a Windows 2003 box, you can literally keep an IAS RADIUS server up for years of zero downtime or reboots.One of IAS' biggest competitors in the Enterprise market is Cisco ACS which people often assume they must use if they're using Cisco networking equipment which simply isn't true.Your Cisco network equipment works perfectly fine so long as you avoid proprietary, less-secure harder-to-deploy protocols, like LEAP or EAP-FAST.Furthermore, the stability of ACS is questionable and there is an endless patch cycle for it since it has been plagued with security vulnerabilities and bugs.