neonetman Posted October 3, 2019 Posted October 3, 2019 I've recently started installig out new Unifi wireless system, and am having trouble getting a WPA Enterprise SSID setup to authenticate with an NPS server. I've followed the guide at https://www.gypthecat.com/how-to-configure-windows-2012-nps-for-radius-authentication-with-ubiquiti-unifi but still don't seem t be having any luck, and am tearing my hair out with it.
neonetman Posted October 3, 2019 Author Posted October 3, 2019 really struggling to work out - I just can't get it to authenticate
FragglePete Posted October 3, 2019 Posted October 3, 2019 I got it working with Dynamically Assigned VLANs, - this guide on YouTube helped me get the basics of it sorted: Pete
neonetman Posted October 3, 2019 Author Posted October 3, 2019 This is the entry from the NPS accounting log, but it doesn't seem to tell me much 10/03/2019 15:44:26.512UN01IASdomain\username10.138.2.1017483C22C3FB52044794276-83-C2-2E-3F-B5:MHS319270-C9-4E-6D-89-2FCONNECT 0Mbps 802.11bE84D92CC0B483571140010.138.2.1010AtriumSecure Wireless Connections1domain\usernamedomain\username311 1 10.138.2.100 10/03/2019 14:39:00 25Secure Wireless Connections10
robyholmes Posted October 3, 2019 Posted October 3, 2019 What OS and certificate are you trying to use with this? Windows 7 is very picky about certificates. It needs to be a public trusted one. Windows 10 on the other hand (And iOS) seems to accept a self signed so long as its valid and pre-installed. In the end I pointed UniFi to the BYOD Radius service on our Smoothwall. Works well for our BYOD network, guests just need to click on 'Trust' (iOS) or 'Don't validate' (Android) to get connected. Plus with the Smoothwall passing this auth to the web filter as well you get the right filtering applied.
neonetman Posted October 3, 2019 Author Posted October 3, 2019 I added our Wildcard certificate to the NPS, and am trying to connect using a Win 10 client
robyholmes Posted October 3, 2019 Posted October 3, 2019 I added our Wildcard certificate to the NPS, and am trying to connect using a Win 10 clientDoes your wildcard cert match/cover you server name and internal domain?
neonetman Posted October 3, 2019 Author Posted October 3, 2019 cert is for *.domain.org.uk NPS is on un01.ad.domain.org.uk
robyholmes Posted October 3, 2019 Posted October 3, 2019 cert is for *.domain.org.uk NPS is on un01.ad.domain.org.ukLooks right then. Sorry I'm out of ideas at this point then.
neonetman Posted October 18, 2019 Author Posted October 18, 2019 Thanks for all your help guys - it turns out the POE switches weren't giving enough power to the WAP's, and thet were dropping in and out. Once I've added a power injector in line, and turned off POE on the port everything is working smoothly for this
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now