Jump to content

Recommended Posts

Posted
Is there a way using GP to hide the network key in the wireless network properties as ticking show characters reveals the key in plain text. I know only admins can see this but I prefer the way XP did it!
Posted

I know this isn't a direct answer to your question, but if you used a WPA enterprise style setup, you can get authentication based on computer certificates, and therefore no need for keys

 

It's supposed to be the most secure method for wireless networking. I can provide more info if necessary.

Posted
You mean install a radius server?

 

Yeah.... I used to use IAS (Windows Server 2000/2003), and since upgrading to Server 2008 I now use NPS. Both are the same and have a RADIUS server built in.

Posted
Right thanks. This school is moving to Server 2008 soon so will have to take a look at that.

 

You can do it with 2000/2003

Posted
You can do it with 2000/2003

 

At the risk of sounding dumb .. how? I've been looking for a solution but only on the side of all the other jobs .. lol ..

Posted (edited)
At the risk of sounding dumb .. how? I've been looking for a solution but only on the side of all the other jobs .. lol ..

 

So here's the requirements:

 

1. A certificate server on the domain dishing out certificates to all domain computers (well at least the ones you want to use the wireless policy)

2. IAS installed on a domain controller

3. Wireless Access points that support WPA Enterprise (most do now)

 

In IAS:

1. You need to create a wireless access policy. Mine is based on the group 'Domain Computers'. This allows all computers that are a member of that group access. In that policy setting you will see PEAP options where you select your cerificate server

2. You need to add a RADIUS Client (the access point) and configure a shared secret

 

On the Access Point:

1. Configure WPA Enterprise security.. The only settings are, RADUIS Server IP, and the shared secret.

 

Then either through a GPO or directly on the computers configre the wireless profile for that SSID, selecting WPA (or WPA2), but there's an option to choose PEAP authentication. Check the local certificate by running the 'Certificates' mmc snap in and selecting local computer. The certificate should be the one issued by the same server selected in the IAS wireless policy.

 

That's pretty much it. The logs on the server running IAS will help you troubleshoot if you get any issues. Feel free to give me a shout and I will send you screen shots of all my config.

Edited by prad
spelling error
  • Thanks 2
Posted
So here's the requirements:

 

1. A certificate server on the domain dishing out certificates to all domain computers (well at least the ones you want to use the wireless policy)

2. IAS installed on a domain controller

3. Wireless Access points that support WPA Enterprise (most do now)

 

In IAS:

1. You need to create a wireless access policy. Mine is based on the group 'Domain Computers'. This allows all computers that are a member of that group access. In that policy setting you will see PEAP options where you select your cerificate server

2. You need to add a RADIUS Client (the access point) and configure a shared secret

 

On the Access Point:

1. Configure WPA Enterprise security.. The only settings are, RADUIS Server IP, and the shared secret.

 

Then either through a GPO or directly on the computers configre the wireless profile for that SSID, selecting WPA (or WPA2), but there's an option to choose PEAP authentication. Check the local certificate by running the 'Certificates' mmc snap in and selecting local computer. The certificate should be the one issued by the same server selected in the IAS wireless policy.

 

That's pretty much it. The logs on the server running IAS will help you troubleshoot if you get any issues. Feel free to give me a shout and I will send you screen shots of all my config.

 

I'll take a look at that this week and see what I come up with! Many thanks :)

Posted

In Server 2008, they have renamed IAS to Network Protection Server, and it is very Wizardy..

 

I've been fiddling with it, as I want to move from our current IAS servers on Windows 2003, to Server 2008. Not got very far with it, but it all seems to work the same.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...