Jump to content

Possible to bypass Network Policy Server for smartphones?


Recommended Posts

Posted

We have NPS component installed on Server 2008 R2 with a policy to only allow certain Windows laptops (from an AD group) to connect to our wireless network. This works great. However, it also prevents smartphone/tablet devices from connecting as we can't add Android or Apple devices to the AD group. Yet we still require the devices to connect using 802.1x so users can be authenticated. If I remove the condition in NPS so that all devices can connect, smartphones connect fine, but then this allows any device to connect.

 

Is there any way to allow non-Windows devices to not be restricted by the condition in NPS?

Posted
You can add a Windows User group to the NPS policy. For example setup a new AD container for Smartphone users and only add the users that should be allowed to connect their smartphone. You can then log in with the AD username/password
Posted
You can add a Windows User group to the NPS policy. For example setup a new AD container for Smartphone users and only add the users that should be allowed to connect their smartphone. You can then log in with the AD username/password

 

Thanks. The only problem with this is the NPS machine policy in which we have laptops in will still exist, still preventing phones. If I remove this machine policy and use users only, it will allow any user to connect with any device. If I use users only but with MAC filtering, we'll need to add the MAC of hundreds of laptops.

Posted
cant you set up a 2nd wifi ssid etc with its own certificate thats user based allongside the existing one or can the aps/management module only handle 1 ssid/cert?
Posted
I can indeed setup a new SSID. I made a new one and had it set to 802.1x. When connecting on the phone with this new SSID, it prompts for my AD username and password, it tries to get an IP address from our DHCP server, and I think NPS kicks in and prevents the phone connecting. If I go into NPS and remove the condition to only allow laptops, it works. I don't mind having a new SSID but why is NPS still kicking in?
Posted

I use nps to secure my wireless and only allow domain laptops to login to the wireless by having a group to which they are added, I also have a second group which contains users that are permitted to logon to the wireless..

 

My domain laptops are configured to logon via their machine accounts but I log my smartphone on via my user account which is in the second group, this is what I believe you are trying to acheive

 

Ben

Posted
I use nps to secure my wireless and only allow domain laptops to login to the wireless by having a group to which they are added, I also have a second group which contains users that are permitted to logon to the wireless..

 

My domain laptops are configured to logon via their machine accounts but I log my smartphone on via my user account which is in the second group, this is what I believe you are trying to acheive

 

Ben

 

Thanks, that sounds like exactly what I need. I've tried making a new AD group, put my user in it, added it in NPS, made a new WLAN, still won't allow me until I specifically remove the machine condition.

Posted

Set up two network policies. NPS (or Radius, as that's the sub-component you're using) will pick a match from top to bottom.

 

We have two:

 

Member of "AuthBYOD" user group.

Domain Hardware.

 

Meeting either policy lets you in.

 

NPS > Policies > Network Policies

Posted
You don't even need a second policy. Just add the AD user group you want to allow to the existing NPS policy. The smartphone will be allowed in if the username belongs to the group added to NPS.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...