Moh Posted January 19, 2022 Posted January 19, 2022 We are currently in the process of moving to a Windows Server 2022 NPS server so that we can deploy a signed 802.1x certificate for Android 11 devices as they no longer support having an unsigned/no certificate (presumably this will also impact iOS at some point down the line), using a range of UniFi access points. However, I can't get accounting to work for users that login using RADIUS authentication, either through the guest portal or through a standard WPA-2 enterprise network. It just shows the IP address only on the Smoothwall. I have tried the following: UniFi controller > set to Windows NPS server for RADIUS, accounting set to Smoothwall. Smoothwall > forward RADIUS accounting to NPS server UniFi controller > set to Windows NPS server for RADIUS, accounting set to NPS server. NPS server > forward RADIUS accounting to Smoothwall From what I've researched, it seems to be something to do with Framed-IP-Addresses not working correctly with UniFi? But if we use Smoothwall's RADIUS server, it logs the username correctly. There's been a few topics on here across the years but none of the suggestions in them seem to have worked for me. Everything is up to date as possible (latest WiFi controller, Server 2022 for NPS, Smoothwall on Leeds 55) I'd appreciate any help. Thanks
Moh Posted January 21, 2022 Author Posted January 21, 2022 Got this working now. For anyone interested in the fix: UniFi controller > set to Windows NPS server for RADIUS, accounting set to NPS server, interim update enabled NPS server > forward RADIUS accounting to Smoothwall Smoothwall > add the NPS server as a RADIUS client Ensure that the secret keys match correctly between the NPS server and Smoothwall on both ends (for NPS, you can set a different secret key for the forwarder, then use the same secret key when adding the NPS server onto the Smoothwall as a client).
RobFuller Posted January 22, 2022 Posted January 22, 2022 What signed cert are you using, just wondered if you tried setting up Lets Encrypt?
Moh Posted March 11, 2022 Author Posted March 11, 2022 We ended up implementing eduroam instead which gave us a signed cert + other benefits.
RobFuller Posted March 11, 2022 Posted March 11, 2022 Ah interesting I was considering the same, easy enough process?
Moh Posted March 11, 2022 Author Posted March 11, 2022 It was relatively straightforward, I thought that the most difficult things would be setting up additional VLANs and DHCP scopes on the Smoothwall but the NPS configuration turned out to be more troublesome! We used Jisc to help us with this and it took approx ~3 weeks to get it started and finished.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now