Jump to content

Recommended Posts

Posted

We have replaced our wireless system to Meraki access points, and we are looking at BYOD options using NPS.

 

Has anyone done this and could be willing to share your settings or config?

Posted (edited)

I've attached the configs/screenshots for both Meraki and NPS.

 

Just as a heads up - If you are running NPS on Windows server 2019 and above, you will need to run the below otherwise you will get some issues with NPS and the windows firewall

 

1. Run sc sidtype IAS unrestricted in terminal/cmd as an administrator on the NPS server.

2. Reboot the server.

 

 

If you are using the config I have attached - All you gotta do is run copy it to your NPS server and the import it via PowerShell or the NPS interface. Then go in and change the following:

 

1. Change the IP address in the RADIUS clients to your schools IP range or IP range of the VLANs that the WAPS uses.

2. Change the shared secret to a random long string (you will need to add this to Cisco Meraki as well).

3. Change the windows group to a group in your active directory (I like creating a group just for BYOD and then adding the all staff group to that group; It give a little more control if students need to use it or if there was a guest account that isn't a staff member etc).

4. In the call station ID, enter the SSID name of your schools BYOD SSID after the : (for example our BYOD SSID is 'WBPS - BYOD' so the value should be '.*.:WBPS - BYOD').

5. If you haven't already - register the NPS with active directory.

 

 

Hope this helps you :)

NPS.zip

Edited by dylanm
  • Thanks 1
Posted
I've attached the configs/screenshots for both Meraki and NPS.

 

Just as a heads up - If you are running NPS on Windows server 2019 and above, you will need to run the below otherwise you will get some issues with NPS and the windows firewall

 

1. Run sc sidtype IAS unrestricted in terminal/cmd as an administrator on the NPS server.

2. Reboot the server.

 

 

If you are using the config I have attached - All you gotta do is run copy it to your NPS server and the import it via PowerShell or the NPS interface. Then go in and change the following:

 

1. Change the IP address in the RADIUS clients to your schools IP range or IP range of the VLANs that the WAPS uses.

2. Change the shared secret to a random long string (you will need to add this to Cisco Meraki as well).

3. Change the windows group to a group in your active directory (I like creating a group just for BYOD and then adding the all staff group to that group; It give a little more control if students need to use it or if there was a guest account that isn't a staff member etc).

4. In the call station ID, enter the SSID name of your schools BYOD SSID after the : (for example our BYOD SSID is 'WBPS - BYOD' so the value should be '.*.:WBPS - BYOD').

5. If you haven't already - register the NPS with active directory.

 

 

Hope this helps you :)

 

Wow! Thank you. :)

 

I'm guessing your not using a splash page?

Posted
Wow! Thank you. :)

 

I'm guessing your not using a splash page?

 

No problem! - Happy to be able to help.

 

We did use the slash page and the members of staff would have had to accept an agreement however it became very annoying for staff as they had to keep agreeing to it - there was no option for a “one off” splash page for each device and it had to have a frequency of days between each acceptance (from memory the maximum amount of days you could set was 90). Therefore we decided to just remove the splash page.

 

There is also an option to have the authenticate users with active directory from the splash page instead of the usual 802.1X way in however we shyed away from this as there wasn’t any encryption (or at least very poor encryption) between Meraki’s servers and our NPS server meaning that all the RADIUS traffic would of been unencrypted / very poorly encrypted across the internet.

 

We do we a splash page/splash page authentication for our guest network and I’m happy to send you the config for it if you want?

Posted
No problem! - Happy to be able to help.

 

We did use the slash page and the members of staff would have had to accept an agreement however it became very annoying for staff as they had to keep agreeing to it - there was no option for a “one off” splash page for each device and it had to have a frequency of days between each acceptance (from memory the maximum amount of days you could set was 90). Therefore we decided to just remove the splash page.

 

There is also an option to have the authenticate users with active directory from the splash page instead of the usual 802.1X way in however we shyed away from this as there wasn’t any encryption (or at least very poor encryption) between Meraki’s servers and our NPS server meaning that all the RADIUS traffic would of been unencrypted / very poorly encrypted across the internet.

 

We do we a splash page/splash page authentication for our guest network and I’m happy to send you the config for it if you want?

 

If you could share that as well, i would be most grateful :)

Posted

Interesting for our BYOD network. Would like it setup with splash screen login and getting access denied.

 

Network access is: Open

Sign on with: My Raduis Server.

 

When testing. I get the splash screen and entering my username and password i get access denied.

 

When i change the Network Access to Enterprise with My Raduis Server and change Splash Page to Click Through it works. (Windows asks for Username and password on the network connections tab)

 

Not sure where i'm going wrong... Any ideas?

Posted

See Attached - Our guest SSID uses sponsored login so the guest put's in their name & email address and then the email address of a member of staff at the school. An approval email gets sent to the member of staff at the school who approves access and job done.

 

Just one thing to be careful of is that if students have a school email address that is using the same domain as the staff. You should block emails from Meraki for these students. This will stop students from being able to join their devices to the WiFi.

 

Meraki - Guest Config.pdf

  • Thanks 1
Posted

Sounds like you want to use the splash page login with sign-on.

 

For that to work, you're going to need to open up some firewall ports (at your school) to enable Meraki's servers to communicate to your NPS server at your school. While you can do this and it will work, just be aware that there is no encryption or at least very poor encryption between Meraki and your NPS server - This RADIUS traffic/data travels across the internet and is not internal all internal...

Meraki has a guide on how to set it up - See here

  • Thanks 1
Posted
See Attached - Our guest SSID uses sponsored login so the guest put's in their name & email address and then the email address of a member of staff at the school. An approval email gets sent to the member of staff at the school who approves access and job done.

 

Just one thing to be careful of is that if students have a school email address that is using the same domain as the staff. You should block emails from Meraki for these students. This will stop students from being able to join their devices to the WiFi.

 

[ATTACH]64104[/ATTACH]

 

Looking at your config, What filtering do you do on your guest network?

Posted
Filtering? Do you mean web filtering?

 

Yes Sorry,

 

In your BYOD settings - How often are your users have to re-authenticae their connection? (Having to re-enter their usernames and passwork to rejoin the wireless network?)

  • 2 weeks later...
Posted

Update.

 

Splash page working for Domain Admins now and forwards on to our XG.

 

Now we add other staff/student groups and they get access denained when trying to log in.

 

Event log i get Error 65:

The Network Access Permission setting in the dial-in properties of the user account in Active Directory is set to Deny access to the user. To change the Network Access Permission setting to either Allow access or Control access through NPS Network Policy, obtain the properties of the user account in Active Directory Users and Computers, click the Dial-in tab, and change Network Access Permission.

 

Which is set to NPS. If i set to allow i get error 66:

 

The user attempted to use an authentication method that is not enabled on the matching network policy.
- But they are part of the groups that i have allowed in.

 

What have i missed?

Posted

Fro when I had Meraki and tried to use a splash page, there were some Meraki IP ranges that had to be whitelisted and allowed unauthenticated traffic through.

 

Meraki do have them listed on their splash page documentation.

 

I’ve moved away from Meraki about 4 years ago so can’t be more help I’m afraid.

Posted
Update - NPS Service crashed wasnted updating the policey, - Error on restart due to a Typo on Called Station ID... Even though it was working before...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...