STK91 Posted July 6 Posted July 6 Good morning We have around 150 staff laptops, at the moment these are connected to our staff wireless via RADIUS. We have EAP-TLS profile at the logon screen and then it should switch to the main staff profile on logon but it hasn't been working properly for a while which causes lot's of issues. I'm considering setting up another SSID, sitting on our admin VLAN which just uses a password (could do MAC filtering) Wondering what others are doing? We've found RADIUS very flaky Thanks
STK91 Posted July 6 Author Posted July 6 Yes - we had to use certificates for the machine profile, when the user logs on it never switches automatically to the user. Wondered whether this was common, it's been very unreliable since it was setup
psydii Posted July 6 Posted July 6 We just use machine auth and ignore user auth for managed devices, managed staff laptops go into a staff managed devices vlan, student devices go into a student managed devices vlan, If a user authenticates with their id they get put into the byod vlan/ with network profile. This works fine because we don't apply per user auth at the firewall/filter so don't need to know in real-time who has what IP. (if we ever need to, we can cross check dhcp an d NPS logs)
FN-GM Posted July 6 Posted July 6 I would advise dropping user auth and switching to machine auth instead. It will fix your issue and stop people joining un-approved devices. 1
psydii Posted July 6 Posted July 6 (edited) What "un-approved devices"? Law says students can't bring those in any more 😄 Edited July 6 by psydii
AlphamaleZed Posted July 6 Posted July 6 We use smoothwall cloud filter so we do not need to use RADIUS and then a hidden wifi with basic Adult and Malicous filter. if you use netsweeper there is a chrome addon.
FN-GM Posted July 6 Posted July 6 11 minutes ago, psydii said: What "un-approved devices"? Law says students can't bring those in any more 😄 Wifi works in the car park 😁
psydii Posted July 6 Posted July 6 Lol. the number of ex students filling up the logs with failed auth just because they've walked past the school is quite something.
soapyfish Posted July 7 Posted July 7 22 hours ago, psydii said: What "un-approved devices"? Law says students can't bring those in any more 😄 Can you link to where this is stated please ?
dmj Posted July 7 Posted July 7 39 minutes ago, soapyfish said: Can you link to where this is stated please ? https://www.legislation.gov.uk/ukpga/2026/21/section/36/enacted 1
Davit2005 Posted July 7 Posted July 7 (edited) On 06/07/2026 at 10:13, STK91 said: Yes - we had to use certificates for the machine profile, when the user logs on it never switches automatically to the user. Wondered whether this was common, it's been very unreliable since it was setup MAC filtering is not as secure (mac addresses can be spoofed), neither is a shared key these days with modern OSs making it very easy to share/show the key 🙂 Some issues can occur if the cert runs out before a new one is put in place 🙂 Edited July 7 by Davit2005
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now