FN-GM Posted April 22, 2020 Posted April 22, 2020 (edited) Hello, I am currently working on our Radius / NPS setup. I have created the attached Network Policy. I only want this to apply to people connecting to the Wireless Network. I want a separate policy for users who are connecting via VPN - I want to restrict this and not have domain users to have access. Are the conditions in the attached screenshot and or are they or? Does the authentication have to meet both conditions or just one please? Thanks PS: I know I shouldn't use Domain Users. I just did this for illustration. Edited April 22, 2020 by FN-GM
caffrey Posted April 22, 2020 Posted April 22, 2020 I have different policies per user AD group which applies a radius class value based on the AD group they are in, I'm thinking (I may be wrong - I usually am ) You would need to create groups to separate VPN users from wifi users 1
FN-GM Posted April 22, 2020 Author Posted April 22, 2020 Doing it based on AD group alone won't work. I want everyone to access WIFI but only some on VPN. Doing it on groups alone will mean that everyone will also have access to VPN. But if both conditions are required in the screenshot I posted in post 1 I can separate them. I can see if you have a a similar config in your second screenshot. Do both those conditions have to be met to allow the user to connect to WIFI please? Thanks for taking the time to reply.
caffrey Posted April 22, 2020 Posted April 22, 2020 In your screenshot, both conditions have to be met, so it checks for wireless then who's in that security group. If I'm reading your question correctly - just set a deny access policy to the domain users security group ? 1
FN-GM Posted April 22, 2020 Author Posted April 22, 2020 In your screenshot, both conditions have to be met, so it checks for wireless then who's in that security group. Perfect. Thanks If I'm reading your question correctly - just set a deny access policy to the domain users security group ? I want to allow everyone on the wireless. So deny would be the oposite. I don't want to allow everyone on the VPN. So I would use the policy above and another that specifies another group and combine it with another condition to apply for VPN only. That way it the VPN and Wireless policy don't overlap. Thanks for the help.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now