Jump to content

Recommended Posts

Posted

We have an existing Wifi Setup with clients being either WPA2 or MAC authenticated onto the network.

 

Existing MAC authentications are being handled by RADIUS server running NPS which is working successfully without Captive Portal as per this guide.

 

Our current issue is that BYOD for 6thForm was setup rather quickly, and used a WPA2 PSK which soon got used by all and sundry, and our 10.57.12.0/23 network soon ran into problems with IPs running out on the DHCP scope.

 

We are trying to setup RADIUS authentication to the same NPS server with a new Network Policy of the following:

Domain\6thFormWifi users

Wireless 802.11 NAS Port Type

IP of 10.57.16.0/24 (our test VLAN and SSID).

 

This is being processed before the MAC auth Network Policy.

 

In testing we get stuck. Either the rules are too tight and any device with a MAC account in AD and user account in the 6thFormWifi user group are allowed on, or only MAC accounts in AD can connect to another SSID with Mac auth on (hidden).

 

Any ideas?

 

Cheers

Mark

Posted

Probably need a bit more detail from you on your setup as to wifi vendor, if the controller will be the authenticator, etc. Couldn't see the guide you mentioned attached or hyperlinked?

 

Maybe have a read at this: http://community.arubanetworks.com/aruba/attachments/aruba/115/6113/1/Using+Microsoft+Windows+2008+Server+With+Aruba.pdf

 

Client MAC auth should be phased out due to MAC spoofing (exceptions would be for devices that don't support 802.1X).

 

Cheers

Posted

Thanks Graeme.

 

Got it working in the end. Created a new group for our Mac Auth devices in AD, then added in Wireless - Other to our Captive Portal Rule.

This seems to have done the trick.

We are using Trapeze controller, with a mix of WLA 332, 522 access points atm.

I am looking at all our devices and Wireless infrastructure at the moment. A lot of the devices are iPads and Phones and are BYOD, so strictly off limits for 802.1X auth.

Thanks.

Mark

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...