Jump to content

Recommended Posts

Posted

Hi

 

Long story short we have NPS setup with RADIUS client AP's to process wireless connection requests on our 2008 R2 domain. Our Connection request and Network policies at present only contain a NAS Port Type 802.11 condition, which works fine. I am trying to restrict wireless access to computers that are part of the domain but as soon as I add a Machine Group condition which includes the Domain Computers group non of the computers can connect. I have seperately tested adding a User Group condition and this works fine. Any ideas on what could be wrong or I am missing?

 

Cheers

Posted (edited)

Hi

 

Have you created your wireless network policies?

Are you trying to restrict on a per user or per machine basis?

What desktop clients are you using including SP Level?

Have you configured your RADIUS Clients?

What Wi-Fi Protected Access (WPA) are you using? WPA, WEP etc...

What Authentication methods are you using? EAP-TLS, MS-CHAP v2, PEAP-TLS?

Confirm the network connection method for policy, i.e Ethernet, Wireless Access Point etc....

 

Also, you mention that you use the Domain Computers group as your condition. This will include all computers. I know you are configuring NAP for Wireless but have you tried to create a group for Wireless client, then add that group as a condition add add client to it?

 

 

Regards

Sukh

Edited by sukh
Posted
Hi

 

Have you created your wireless network policies?

Are you trying to restrict on a per user or per machine basis?

What desktop clients are you using including SP Level?

Have you configured your RADIUS Clients?

What Wi-Fi Protected Access (WPA) are you using? WPA, WEP etc...

What Authentication methods are you using? EAP-TLS, MS-CHAP v2, PEAP-TLS?

Confirm the network connection method for policy, i.e Ethernet, Wireless Access Point etc....

 

Also, you mention that you use the Domain Computers group as your condition. This will include all computers. I know you are configuring NAP for Wireless but have you tried to create a group for Wireless client, then add that group as a condition add add client to it?

 

 

Regards

Sukh

 

Hi Sukh

 

The background is that we have had the whole system working for quite a while now so yes the wireless policies have been created and the RADIUS clients are configured. Setup is:

 

Wireless access point RADIUS clients using WPA2 encryption

XP SP3 and W7 Ent desktop clients

Authentication methods are PEAP and MS-CHAP v2

 

I am trying to restrict access to the wireless network on a per machine basis. I am using the domain computers group simply as an initial test group. As I said in the original post the system works fine until I introduce a Machine Group condition into the Network Policy. Even when this condition includes the Domain Computers group none of our laptops are able to connect. When I remove this condition it works fine again. I have seen this issue reported before in connection with VPN setups but ours is a Wireless LAN system only.

 

Cheers

Posted

Hi

 

Have you created a seperate network policy for the wireless and Confirm the network connection method for policy, i.e Ethernet, Wireless Access Point etc....

 

"Even when this condition includes the Domain Computers group none of our laptops are able to connect. When I remove this condition it works fine again. "

 

In the condition, when you include the Domain Computers group, none of your laptops are able to connect, is that wired or wireless?

 

Thanks

Sukh

Posted

Hi

 

Have you created a seperate network policy for the wireless and Confirm the network connection method for policy, i.e Ethernet, Wireless Access Point etc....

 

"Even when this condition includes the Domain Computers group none of our laptops are able

Posted

Hi

 

I've tracked down the issue so thought I'd post it here for anyone else who might have a similar problem. Our issue was caused by the Authentication Mode in the Security Settings for the Wireless Network Connection that we had setup in Group Policy

 

(Computer Configuration > Windows Settings > Security Settings > Wireless Network (802.11) Policies > "Your Network Policy")

 

Originally the Authentication Mode was set to "User or Computer authentication", when this was changed to "Computer authentication" the Computer Account condition in the Network Policy in NPS was processed correctly and clients could connect.

 

I can only assume that this is a bug as on further testing I found that when the Authentication Mode was set to "User or Computer authentication" NPS would process a User Account condition in the Network Policy correctly, but still refused to process the Computer Account condition properly.

 

Hope this helps someone.

 

Cheers

  • 1 year later...
Posted

 

(Computer Configuration > Windows Settings > Security Settings > Wireless Network (802.11) Policies > "Your Network Policy")

 

Originally the Authentication Mode was set to "User or Computer authentication", when this was changed to "Computer authentication" the Computer Account condition in the Network Policy in NPS was processed correctly and clients could connect.

 

 

Additionally, whether it is by design or not, it may be because NPS is trying to process BOTH 'Domain Users' and 'Domain Computers'.

I was able to duplicate my NPS Policy, creating a seperate policy for 'Domain Users' and 'Domain Machines'. Because they are matched in order, when 'Users' fails, 'Machines' picks up and authenticates!

 

Hope that helps someone!

 

(Sorry for updating an old post - it's google's fault!)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...