Jump to content

Recommended Posts

Posted

Hi,

 

We are after some help and advice on setting a radius server up. We have cisco 2500 wireless controller with Air 2600 AP’s.

 

We would like to have a radius server to authenticate users and check computers health before they get on to the network. We would also like to have the user log into the Smoothwall when connecting to the internet.

 

We have installed a new server with windows 2008r2 which we would like to use as the radius server. We have everything installed but we are having problems with the certificate side of things. We followed the following article NPS, Wireless LAN Controllers, and Wireless Networks Configuration Example - Cisco

 

When a computer tries to connect to the network we get the following “Windows was unable to connect to SSID” and in event view we get the following “the certificate received from the remote server was issued by an untrusted certificate authority.”

 

I have searched the forum for answers but can’t find much. It seems everyone’s setup is different as you would expect.

 

Thanks

Kenny

Posted

Assuming you've followed the instructions from the link and created an Enterprise CA, but used something that isn't* a Domain Controller to do so.....

 

...have you verified that the client machines are getting the certificate from the CA? Assuming it's a domain-joined windows machine that's had a group policy refresh via a wired connection since you created the CA, they should trust any certificates issued by your new CA.

 

 

 

*migrating CAs is annoying if they're also a DC - it's a classic "shoot yourself in the foot, delayed by X years" move.

Posted

Thanks for reply's.

 

We are using a self-generated certificate and the server isn't a domain controller. The laptops we are trying to connect are not on the domain.

 

I think we are a little confused by the whole thing. We don’t need the laptops to authenticate with the domain control we just need them to log in to Smoothwall via the secure logon page. The wireless is setup on its own vLan and we thought we would use a Radius server to check that anti-virus, windows updates etc. were installed.

 

Any help in point us in the right direction would be appreciated.

 

Kenny

Posted

Ok - As it's a self signed cert the clients will need to know to trust the certificate - otherwise it could be authenticating against anything and how can it know it's safe?

 

So your options are - either use a "proper" certificate, or add the certificate to the clients' certificate store so that it's trusted.

 

Once you've done this you can then use the NAP features to do what you want to do.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...