Jump to content

Recommended Posts

Posted

The majority of our laptops are Windows-based so transparent NTLM authentication is the obvious authentication mechanism to use. This has never really worked on OS X so the two Apple laptops we have simply use browser authentication. Our sixth form users that have Macs also use the browser to authenticate.

 

The odd authentication issue is with our MacBook (we also have an iBook which works fine). The user authenticates, does a bit of whatever and then the laptop will magically authenticate itself using its computer account via transparent NTLM auth. The computer account isn't an account that is authorised for wifi access so the laptop gets quarantined until you re-authenticate. This is slightly annoying!

 

This has been happening for ages but I figured I should probably fix it at some point... I'm now lost for ideas. The system is a BlueSecure BSC-400 fully patched up.

 

Any takers?

Posted

How does NTLM auth work?

 

We use radius on our main DC and Bluesocket transparent 802.1x for our windows machines - I've not implemented it yet but 802.1x works pretty well on 10.6 but 10.5 seems less reliable on our macs, you can have machine > user or just machine credentials authenticate.

Posted
How does NTLM auth work?

 

Magic.

 

It monitors the network traffic from the client and passes the authentication stuff to the controller so that they can authenticate against AD.

 

We use radius on our main DC and Bluesocket transparent 802.1x for our windows machines - I've not implemented it yet but 802.1x works pretty well on 10.6 but 10.5 seems less reliable on our macs, you can have machine > user or just machine credentials authenticate.

 

I don't really want to have to configure another authentication mechanism for one client... especially given that my other Mac clients work as expected.

Posted

@nicklec: They are running a different OS but I cannot for the life of me remember which version. I suspect they handle the AD joining slightly differently... just differently enough to mess things up but I doubt that there is much I can do about that.

 

I have been having a think about this and am wondering if I should add the computer account to a role. This would allow authentication to happen... I'm just wondering if there is a downside.

Posted

Got the Mac in front of me now... its hard disk has seriously died (imagine a very loud clicking thing)... so I have installed a new disk and re-installed everything and the problem still occurs.

 

The role I am testing with (the same one that the staff member uses) does indeed have restricted ports. I read somewhere that noisey Macs can cause the BSC to quarantine the client because it thinks that an attack of some sort is under way. Nothing immediately jumps out of the logs though.

 

@nicklec... What do you mean an 'edge to edge' SSID?

 

BTW - The Mac is running 10.4.11 and is fully patched.

  • 2 weeks later...
Posted
Sorry for slow reply, in the SSID setup 'edge to edge' can be ticked so that the AP just acts as a switch directly to your network so that traffic is not tunneled through the controller.
Posted
Sorry for slow reply, in the SSID setup 'edge to edge' can be ticked so that the AP just acts as a switch directly to your network so that traffic is not tunneled through the controller.

 

I see that now but I'm not too keen on using that setting... it kind of defeats the point of the stupidly expensive BlueSecure box.

 

BTW - My iBook running the same version of the OS has caught the bug too :(

 

It has to be due to me authenticating correctly via the web and then the computer magically authenticating via its computer account :-\

Posted
Well we have 802.1n APs (30something APs) everywhere so 2x GbE links into the BSC is not going to let our domain machines use all the bandwidth; we still use BSC firewall for less intensive devices/users. The BSC is also handling 802.1x, radius authentication and for a few more weeks transparent proxy!
Posted
Well we have 802.1n APs (30something APs) everywhere so 2x GbE links into the BSC is not going to let our domain machines use all the bandwidth; we still use BSC firewall for less intensive devices/users. The BSC is also handling 802.1x, radius authentication and for a few more weeks transparent proxy!

 

I only use 802.11a/g APs and I'm mean so I throttle connections too. I think that I will probably have to switch to 802.11x authentication over the summer break :-\

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...