psycorp Posted March 9, 2011 Posted March 9, 2011 Hi Long story short we have NPS setup with RADIUS client AP's to process wireless connection requests on our 2008 R2 domain. Our Connection request and Network policies at present only contain a NAS Port Type 802.11 condition, which works fine. I am trying to restrict wireless access to computers that are part of the domain but as soon as I add a Machine Group condition which includes the Domain Computers group non of the computers can connect. I have seperately tested adding a User Group condition and this works fine. Any ideas on what could be wrong or I am missing? Cheers
sukh Posted March 9, 2011 Posted March 9, 2011 (edited) Hi Have you created your wireless network policies? Are you trying to restrict on a per user or per machine basis? What desktop clients are you using including SP Level? Have you configured your RADIUS Clients? What Wi-Fi Protected Access (WPA) are you using? WPA, WEP etc... What Authentication methods are you using? EAP-TLS, MS-CHAP v2, PEAP-TLS? Confirm the network connection method for policy, i.e Ethernet, Wireless Access Point etc.... Also, you mention that you use the Domain Computers group as your condition. This will include all computers. I know you are configuring NAP for Wireless but have you tried to create a group for Wireless client, then add that group as a condition add add client to it? Regards Sukh Edited March 9, 2011 by sukh
psycorp Posted March 10, 2011 Author Posted March 10, 2011 Hi Have you created your wireless network policies? Are you trying to restrict on a per user or per machine basis? What desktop clients are you using including SP Level? Have you configured your RADIUS Clients? What Wi-Fi Protected Access (WPA) are you using? WPA, WEP etc... What Authentication methods are you using? EAP-TLS, MS-CHAP v2, PEAP-TLS? Confirm the network connection method for policy, i.e Ethernet, Wireless Access Point etc.... Also, you mention that you use the Domain Computers group as your condition. This will include all computers. I know you are configuring NAP for Wireless but have you tried to create a group for Wireless client, then add that group as a condition add add client to it? Regards Sukh Hi Sukh The background is that we have had the whole system working for quite a while now so yes the wireless policies have been created and the RADIUS clients are configured. Setup is: Wireless access point RADIUS clients using WPA2 encryption XP SP3 and W7 Ent desktop clients Authentication methods are PEAP and MS-CHAP v2 I am trying to restrict access to the wireless network on a per machine basis. I am using the domain computers group simply as an initial test group. As I said in the original post the system works fine until I introduce a Machine Group condition into the Network Policy. Even when this condition includes the Domain Computers group none of our laptops are able to connect. When I remove this condition it works fine again. I have seen this issue reported before in connection with VPN setups but ours is a Wireless LAN system only. Cheers
sukh Posted March 10, 2011 Posted March 10, 2011 Hi Have you created a seperate network policy for the wireless and Confirm the network connection method for policy, i.e Ethernet, Wireless Access Point etc.... "Even when this condition includes the Domain Computers group none of our laptops are able to connect. When I remove this condition it works fine again. " In the condition, when you include the Domain Computers group, none of your laptops are able to connect, is that wired or wireless? Thanks Sukh
psycorp Posted March 10, 2011 Author Posted March 10, 2011 Hi ATM the system authenticates wireless connections only. Cheers
sukh Posted March 10, 2011 Posted March 10, 2011 Hi Have you created a seperate network policy for the wireless and Confirm the network connection method for policy, i.e Ethernet, Wireless Access Point etc.... "Even when this condition includes the Domain Computers group none of our laptops are able
chrisbrown Posted March 10, 2011 Posted March 10, 2011 We had a similar problem, best thing to do was sit and monitor the event logs on the DC. This provided a realtime view of what was happening (and what wasn't)
psycorp Posted March 15, 2011 Author Posted March 15, 2011 Hi I've tracked down the issue so thought I'd post it here for anyone else who might have a similar problem. Our issue was caused by the Authentication Mode in the Security Settings for the Wireless Network Connection that we had setup in Group Policy (Computer Configuration > Windows Settings > Security Settings > Wireless Network (802.11) Policies > "Your Network Policy") Originally the Authentication Mode was set to "User or Computer authentication", when this was changed to "Computer authentication" the Computer Account condition in the Network Policy in NPS was processed correctly and clients could connect. I can only assume that this is a bug as on further testing I found that when the Authentication Mode was set to "User or Computer authentication" NPS would process a User Account condition in the Network Policy correctly, but still refused to process the Computer Account condition properly. Hope this helps someone. Cheers
jbickford Posted September 12, 2012 Posted September 12, 2012 (Computer Configuration > Windows Settings > Security Settings > Wireless Network (802.11) Policies > "Your Network Policy") Originally the Authentication Mode was set to "User or Computer authentication", when this was changed to "Computer authentication" the Computer Account condition in the Network Policy in NPS was processed correctly and clients could connect. Additionally, whether it is by design or not, it may be because NPS is trying to process BOTH 'Domain Users' and 'Domain Computers'. I was able to duplicate my NPS Policy, creating a seperate policy for 'Domain Users' and 'Domain Machines'. Because they are matched in order, when 'Users' fails, 'Machines' picks up and authenticates! Hope that helps someone! (Sorry for updating an old post - it's google's fault!)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now