Jump to content

Recommended Posts

Posted

Good Morning,

 

Hopefully a quick one and I am missing something obvious. I am just setting up a Unifi Wireless system. I have a cloud key and 30 APs. They all sit untagged on the wifi management VLAN. I have setup the different wireless vlans as networks in the controller and assigned the VLANs to the different SSIDs. I have also created the RADIUS profile to point to my NPS server which sits in the server VLAN. However, when attempting to connect to any of the new wireless networks it will not connect.

 

Can anyone shed some light on something I may have missed.

 

Cheers

Posted
You need to tagg the vlans on the switch ports that connect to the APs.

 

Including the server vlan? Currently the AP can ping the NPS server without the tag

 

- - - Updated - - -

 

Have you configured the wireless access points as Radius Clients on your NPS server?

AP and Cloud key both been added as RADIUS clients.

Posted (edited)
Including the server vlan? Currently the AP can ping the NPS server without the tag

 

- - - Updated - - -

 

 

AP and Cloud key both been added as RADIUS clients.

 

It depends on the setup but normally I'd have the AP management untagged and all the SSID vlans tagged. You do not need to tag the server vlan.

 

You should only need add the AP not the cloud key as I believe with Unifi the AP is the device that talks to the Radius server. There is no resilience for Unifi cloud controller as such it only dishes out config to devices but can act as a captive portal

Edited by Davit2005
Posted
It depends on the setup but normally I'd have the AP management untagged and all the SSID vlans tagged. You do not need to tag the server vlan.

 

Yeah, I have all the SSID vlans tagged and management vlan untagged for the AP and cloud key ports

Posted
It depends on the setup but normally I'd have the AP management untagged and all the SSID vlans tagged. You do not need to tag the server vlan.

 

^^^ This ^^^

 

I have done this myself today.

 

If you still have trouble - for testing remove the Radius element and use PSK. It will rule this in or out.

  • Thanks 1
Posted (edited)
Yeah, I have all the SSID vlans tagged and management vlan untagged for the AP and cloud key ports

 

Have you configured IP address helpers on the vlan on the layer 3 switch? And have corresponding DHCP scopes. To rule out and test that you could setup a switch port that is untagged on one of the SSID vlans and see if it gets IP address etc.

 

Just try to break it down to little bits, check logs on the NPS server etc.

 

I did have this working at home with Unifi and NPS few years back but it since broke and I haven't bothered fixing it. I may give it another go since I migrated to a new internal domain at home.

Edited by Davit2005
Posted
Cheers guys, so it looks like it was a slight mess up when I created the NPS policy. All working now and connecting. Now I just have to get it to play with Smoothwall
  • Thanks 2
Posted
Cheers guys, so it looks like it was a slight mess up when I created the NPS policy. All working now and connecting. Now I just have to get it to play with Smoothwall

 

Glad you got it sorted :-) .

Posted
Indeed, I don't know why I do any of this work on a Friday. I always miss something. I don't suppose you know a way of confirming if smoothwall is authenticating the correct user? When I go to a blocked page it tells me its blocked for the group but no indication that it has picked up the right user
Posted
Indeed, I don't know why I do any of this work on a Friday. I always miss something. I don't suppose you know a way of confirming if smoothwall is authenticating the correct user? When I go to a blocked page it tells me its blocked for the group but no indication that it has picked up the right user

 

Unfortunately not got any experience with Smoothwall but plenty of people on here use them. See if you can speak to Smoothwall support too.

Posted
With a NPS policy you can add it in as a subnet i.e. 192.168.10.0/24 then anything on that range will work rather than individual AP's. All ours AP's are on DHCP and it works for us as just added 2 new sites to ours this week.
Posted
With a NPS policy you can add it in as a subnet i.e. 192.168.10.0/24 then anything on that range will work rather than individual AP's. All ours AP's are on DHCP and it works for us as just added 2 new sites to ours this week.

 

Only if you're using Windows Server Data Center edition

 

https://docs.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-radius-clients-configure

 

If you are running Windows Server 2016 Datacenter, you can configure RADIUS clients in NPS by IP address range. This allows you to add a large number of RADIUS clients (such as wireless access points) to the NPS console at one time, rather than adding each RADIUS client individually.

 

You cannot configure RADIUS clients by IP address range if you are running NPS on Windows Server 2016 Standard.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...