oxide54 Posted September 14, 2012 Posted September 14, 2012 hi with NPS can i set a condition for the network policy for membership of a particular domain? basically i have two domains and i want to shunt the switch port to different vlans depeneding on the domain membership of the computer.
SYNACK Posted September 14, 2012 Posted September 14, 2012 Good question, are the machines only on one domain or dual boot into both. If they are single domain only then it may be doable by mac address through managed switches if not through NPS.
oxide54 Posted September 14, 2012 Author Posted September 14, 2012 no they are not dual boot, i don't fancy 500 odd mac address's though. I suppose i could make the machines a member of a group and do it that way but it does seem a little silly, and i can see new machines being joined being forgotten to add to the group its not laziness as such its more I don't want a junior tech moving an pc round having to wait for a network guy to reconfigure the switch port.
SYNACK Posted September 14, 2012 Posted September 14, 2012 They should already be in groups, Domain1\Domain Computers etc. if you can apply VLANs by group through NPS then you it should just work with those groups assuming a trust between the two domains so that the NPS can access both lists.
oxide54 Posted September 14, 2012 Author Posted September 14, 2012 cool forgot about default groups. that will do it.! friday!
oxide54 Posted September 17, 2012 Author Posted September 17, 2012 (edited) okay the NPS server is complaining there is no domain controller for domain rather than the domain of the computer it is actually the local computer name Edited September 17, 2012 by oxide54
SYNACK Posted September 17, 2012 Posted September 17, 2012 okay the NPS server is complaining there is no domain controller for domain rather than the domain of the computer it is actually the local computer name Is the NPS server 'trusted for delegation' in AD?
oxide54 Posted September 17, 2012 Author Posted September 17, 2012 I turned all the conditions of the policy off and it does connect the test machine, but I have to login using a domain user account. I am actually logged into the test machine locally so it prompts for domain credentials which seems a little odd. given there is no condition there for that. I think the machine needs a cert issued, will check in a minute.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now