Jump to content

Recommended Posts

Posted
We've been using Meru Capital Portal with Radius for some time now. However, I can only see the Authenticated User Name in the Meru UI when logged in. I have a WatchGuard firewall and wondering if there is any way to send the Authenticated User Name to the watchguard firewall? My WatchGuard firewall has a valid LDAP server.
Posted

In Meru add a radius Accounting port 1813 in security > radius

then in the ESS profile add the radius profile that you just added as the "Primary RADIUS Accounting Server"

 

Then on your Radius server (NPS?) add the watchguard as a remote radius server. In connection request policies (on NPS) add the watchguard to forward accounting requests.

 

Thus any devices should authenticate to NPS and it should send an accounting request to watchguard.

Posted
In Meru add a radius Accounting port 1813 in security > radius

then in the ESS profile add the radius profile that you just added as the "Primary RADIUS Accounting Server"

 

Then on your Radius server (NPS?) add the watchguard as a remote radius server. In connection request policies (on NPS) add the watchguard to forward accounting requests.

 

Thus any devices should authenticate to NPS and it should send an accounting request to watchguard.

 

Thanks for that. I will give it a try tomorrow. My Radius server is Microsoft NPS.

 

Quick question: When you say that on the Microsoft NPS server add the watchguard as a remote radius server, how do you mean? Because if I go into Watchguard I can add a Radius Server in watchguard which means I can pair watchguard with the NPS but if I am understanding correctly do you mean setup watchguard as a Radius Server? I dont think Watchguard can act as a Radius server but instead connect to a Radius server.

Posted
I'm doing this with smoothwall. I've not setup a watchguard, sorry if I was misleading.

 

Thanks. I've had a look at my Watchguard and cannot seem to setup Watchguard as a Radius Server itself. But instead it allows me to connect to a Radius server just like the Meru does. So I don't think that will help.

 

It's a real shame. Watchguard has a feature to force users to a login page which then authenticates with Active Directory or Radius (whichever is setup) However, seeing as my Meru is on a VLAN port of the watchguard the active directory user detection doesnt seem to work at all. My normal users on the LAN are forced to login but for VLAN users it doesnt work for some reason

  • 6 months later...
Posted

Greetings,

 

I wonder if you might offer me some advice.

 

I have meru controllers and NPS for wireless BYOD. I am having problems in what I can only figure is a misconfig on something. perplexed as one day it worked the next not.

 

I continually get cannot authenticate user from this station. At first when I git this I played with the authentication in NPS and it started working, then seemed to stop and get the same issues again.

 

I expect I have some simple thing wrong.

 

As I have it now...I see the SSID, I connect, I get a DHCP address in that domain, the captive portal page opens with a fortinet prompt screen to enter domain credentials and then I get the user not authenticated from this station. With this I know I am connected, in the vlan, and pulling an address and getting the captive portal...

 

I expect this is a setting on the NPS - but am unsure.

 

In radius clients I have the controller with shared secret specified.

connection request policy enabled , unspecified, condition nas port wireless authenticate requests on this server, no auth methods

 

network policy secure wireless connections grant access, unspecified, condition windows groups, auth methods peap \eap mschapv2, no less secure checked

 

 

Any ideas?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...