Jump to content

Recommended Posts

Posted

I'm setting up Radius for a wireless Trial and It appears to be working OK but its not authenticating correctly. The client can connect and in the WAP I can see that they are connected via 802.1x with the username they used but they can also browse areas of the network that they really shouldn't be able to. I am using a laptop to test this out and the laptop isn't on the domain and it is appearing as though it were a BYOD device.

 

I added the AP into radius as a client and followed the wizard for creating an 802.1x server and that is about as much as I have done.

 

Any help would be appreciated.

Posted
Radius literally just handles the authentication which by the sounds of it is working just fine, if you want to lock down what the client can access once its on you'll want to look at Nap, VLANs, etc. Your wireless system (depending what it is) may provide functionality for this.
  • Thanks 1
Posted
Perhaps its the NAP that I need to configure then. I didn't realise that it would give anyone that auths over 802.1x full access, I thought that NTFS permissions would still apply. The Radius will be used for students/staff and a guest portal will be used for guest access, which is sorted.
Posted

Once they have authenticated through Radius they are just allowed onto the network, they aren't added to a security group, its as if someone has plugged into your wired network. NAP is basically a health check system which gates authenticated users if they don't meet certain conditions, such as up to date antivirus. Provided your network shares don't allow the 'Everyone' security group then users will have to authenticate with a relevant username to gain access.

 

Hope this helps, I would suggest looking at your permissions on your shares, and also your wireless controller to see if you can restrict access with that, typically you can specify which IP's/subnets clients can access, failing that VLANs are extremely useful in this context though I have no experience in that area.

 

Which wireless provider are you using?

  • Thanks 1
Posted
I'm using a Meraki MR18 access point. I think I've sorted it out, I need a holiday or something! On the laptop I was using it had admin credentials but it wasn't on the domain, naturally that shouldn't matter so it let the user browse the network regardless of who authed over radius. Yes I'm a complete muppet and I should be banned from computers. :p:doh:

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...