Kenny_G Posted May 13, 2014 Posted May 13, 2014 Hi, We are after some help and advice on setting a radius server up. We have cisco 2500 wireless controller with Air 2600 AP’s. We would like to have a radius server to authenticate users and check computers health before they get on to the network. We would also like to have the user log into the Smoothwall when connecting to the internet. We have installed a new server with windows 2008r2 which we would like to use as the radius server. We have everything installed but we are having problems with the certificate side of things. We followed the following article NPS, Wireless LAN Controllers, and Wireless Networks Configuration Example - Cisco When a computer tries to connect to the network we get the following “Windows was unable to connect to SSID” and in event view we get the following “the certificate received from the remote server was issued by an untrusted certificate authority.” I have searched the forum for answers but can’t find much. It seems everyone’s setup is different as you would expect. Thanks Kenny
pantscat Posted May 13, 2014 Posted May 13, 2014 What certificate are you using? If it's self generated have you told the clients to trust it?
pete Posted May 13, 2014 Posted May 13, 2014 Assuming you've followed the instructions from the link and created an Enterprise CA, but used something that isn't* a Domain Controller to do so..... ...have you verified that the client machines are getting the certificate from the CA? Assuming it's a domain-joined windows machine that's had a group policy refresh via a wired connection since you created the CA, they should trust any certificates issued by your new CA. *migrating CAs is annoying if they're also a DC - it's a classic "shoot yourself in the foot, delayed by X years" move.
Kenny_G Posted May 14, 2014 Author Posted May 14, 2014 Thanks for reply's. We are using a self-generated certificate and the server isn't a domain controller. The laptops we are trying to connect are not on the domain. I think we are a little confused by the whole thing. We don’t need the laptops to authenticate with the domain control we just need them to log in to Smoothwall via the secure logon page. The wireless is setup on its own vLan and we thought we would use a Radius server to check that anti-virus, windows updates etc. were installed. Any help in point us in the right direction would be appreciated. Kenny
pantscat Posted May 14, 2014 Posted May 14, 2014 Ok - As it's a self signed cert the clients will need to know to trust the certificate - otherwise it could be authenticating against anything and how can it know it's safe? So your options are - either use a "proper" certificate, or add the certificate to the clients' certificate store so that it's trusted. Once you've done this you can then use the NAP features to do what you want to do.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now