Jump to content

Recommended Posts

Posted

Looking for the most seamless way to setup RADIUS at a school I have just started working at.

 

From research I need:

 

  • PEAP and msChap - is that correct?
  • I would prefer not to setup a PKI infrastructure and / or have to disable certificate validation on clients. In this scenario I believe I need a public cert. Are there any guides on this, does the internal DNS name of the server need to be the same as our FQDN (guessing the cert issuer needs to validate it somehow). if so how do we go about achieving this instead of it using it's internal name.
  • Which suppliers issue NPS valid certs for Radius

 

Any help for the best, hands off approach, would be greatly appreciated.

Posted

It is posable, but your internal domain name needs to be a external domain name, for us, this ment we needed to rename our domain.

We use a Windows NPS server for our RADIUS, Lets Encrypt for the certificate along with a PowerShell to auto renew.

It tuck a bit of work to get it all done (the bigest thing was the internal domain rename) but it has saved us so mutch hassel with WiFi and a number of other things.

 

Domain Name rename:

https://woshub.com/rename-active-directory-domain/

 

I am looking for the site I used to setup NPS, but cant find it at the moment.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...