techie211 Posted July 3, 2012 Posted July 3, 2012 Hey ppl, just picking ur brain here. has anyone setup a radius/IAS server for your meru wireless network? What are the advantages/disadvantages if any for setting one up? Any advice and possibly a link to a 'how-to' would help me out greatly. -J
plexer Posted July 3, 2012 Posted July 3, 2012 I use NPS on server 2008 as my radius for wireless. Ben
pantscat Posted July 3, 2012 Posted July 3, 2012 Aye - same here. NPS used for wireless and wired RADIUS... What do you need to know?
techie211 Posted July 3, 2012 Author Posted July 3, 2012 (edited) Aye - same here. NPS used for wireless and wired RADIUS... What do you need to know? thanks for the reply. basically setting it up. Why did you go with NPS and not M$'s built in Radius? or is NPS M$ ver of Radius? I know M$ setup some what but never played around with NPS. Will look into it. thx -J Edited July 3, 2012 by techie211
sparkeh Posted July 3, 2012 Posted July 3, 2012 (edited) thanks for the reply. basically setting it up. Why did you go with NPS and not M$'s built in Radius? or is NPS M$ ver of Radius? I know M$ setup some what but never played around with NPS. Will look into it. thx -J Its MS's version of RADIUS from Network Policy Server Network Policy Server (NPS) is the Microsoft implementation of a Remote Authentication Dial-in User Service (RADIUS) server and proxy in Windows Server 2008. NPS is the replacement for Internet Authentication Service (IAS) in Windows Server 2003. Edited July 3, 2012 by sparkeh 1
pantscat Posted July 3, 2012 Posted July 3, 2012 Network Policy Server (NPS) is built into W2K8. Setting it up is fairly straight forward - in a nutshell: 1. Add your RADIUS clients to NPS (e.g. the devices that are going to be doing the authentication on behalf of the clients. In this case I'm guessing it's your Meru controller) 2. Create a connection request policy (e.g. tell the NPS server that it will handle Radius requests from WiFi or wired clients) 3. Create a network policy - tell the NPS server who is allowed to be authenticated by it - I allow all "Domain Computers" to authenticate to my wireless network. 3a. I have other network policies for wired clients - these policies do clever things like dynamic VLAN assignment based on what AD group the computer account is in. 4. Configure the Meru box to use the NPS server for RADIUS. 5. That's about it! Shout if you need any more specific pointers. 1
twin--turbo Posted July 3, 2012 Posted July 3, 2012 I had a brife flirt with Radius on a SUSE Server and Meru in order to have a captive portal, but we just use local users on the meru for the moment.... Something that may get revisited... Rob
techie211 Posted July 12, 2012 Author Posted July 12, 2012 Network Policy Server (NPS) is built into W2K8. Setting it up is fairly straight forward - in a nutshell: 1. Add your RADIUS clients to NPS (e.g. the devices that are going to be doing the authentication on behalf of the clients. In this case I'm guessing it's your Meru controller) 2. Create a connection request policy (e.g. tell the NPS server that it will handle Radius requests from WiFi or wired clients) 3. Create a network policy - tell the NPS server who is allowed to be authenticated by it - I allow all "Domain Computers" to authenticate to my wireless network. 3a. I have other network policies for wired clients - these policies do clever things like dynamic VLAN assignment based on what AD group the computer account is in. 4. Configure the Meru box to use the NPS server for RADIUS. 5. That's about it! Shout if you need any more specific pointers. hey pantscat, thanks for the info. I'm having a hard time getting the clients to connect to the SSID's. Not sure what else I need to configure. Do you have documentation I can go by that helped you and I may benefit from? any help is appreciated. -Jr
twin--turbo Posted July 13, 2012 Posted July 13, 2012 is this for Captive Portal? if so the client should connect to the SSID and only do radius when a web request is made. Rob
mhowell Posted July 19, 2012 Posted July 19, 2012 Hi techie211, feel free to mail me directly [email protected] and I'll put you in touch with the right people Many thanks mark
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now