Jump to content

Recommended Posts

Posted

Hi,

 

I have got Ruckus setup with Radius. Works nearly perfect. I have a slight issue. I have setup Radius to accept connections from Domain Computers under network policies. However when you login the Windows 7 laptop is boots you off the wireless. The only way it will stay on is if you add a group the user is a member of to the network policy.

 

The problem with this is standard users will be able to connect personal devices to the WIFI with the AD credentials.

 

With the Cisco wireless this wasn't required and only Domain Computers is in the list of groups. Is there a way i don't have to add the users groups to the Radius / NPS network policy please?

 

Thanks

Posted

How are you securing the SSID that you are using the radius authentication for?

We have 3 SSID's with Radius authentication setup for our Ruckus, with domain computers connecting to a hidden SSID that is pushed out along with a certificate via GPO, and the other 2 SSID's either a hidden SSID for staff which uses their login details to connect to their VLAN, or a broadcast SSID for the students which uses the captive portal page to validate their logons.

 

In our NPS settings, we have Domain Users and Domain Computers as valid authenticating methods.

Posted
Doing that though will mean users will be able to connect personal devices to the WIFI. Something we don't want on that SSID.
Posted

You could try limiting the Radius authentication to Domain Computers instead of Domain Users in that case.

 

This is why we use a hidden SSID and publish the certificate and SSID details via GPO

Posted

That's what I did, but as soon as a user logs in it boots them off the wireless.

 

Hidden SSID isn't really a way to stop it. It makes it a bit more difficult, but they can still connect if they know what they are doing.

Posted

Have you tried adding the Computer Group as a separate line from the Windows group in the NPS conditions?

 

That way it should check to see if the device is a member of Domain Users AND Domain Computers. If it is in the same line it checks on or the other

  • Thanks 1
Posted
Have you tried adding the Computer Group as a separate line from the Windows group in the NPS conditions?

 

That way it should check to see if the device is a member of Domain Users AND Domain Computers. If it is in the same line it checks on or the other

 

Thanks, will try that.

Posted

Hi,

 

The setting is on the client rather than the NPS setting. You need to set authentication mode to computer only. You can do this on the PC or through group policy if you're already pushing the config through that.

 

David

  • Thanks 1
Posted
Hi,

 

The setting is on the client rather than the NPS setting. You need to set authentication mode to computer only. You can do this on the PC or through group policy if you're already pushing the config through that.

 

David

Setting the authentication mode to computer only on the client is fine for devices that have it deployed via GPO, but not if @FN-GM users have a personal device that should not be connecting to that SSID. In theory the modification to the NPS conditions should limit radius authentication to domain joined stations regardless of the client auth mode.

Posted
Hi,

 

The setting is on the client rather than the NPS setting. You need to set authentication mode to computer only. You can do this on the PC or through group policy if you're already pushing the config through that.

 

David

 

 

Ah ha! found that, bet that works!

Posted

It should work happily, and you could then just remove the user group assignment from NPS to restrict it purely to domain stations.

 

Just remember that if you leave NPS to Domain Users Or Domain Computers, then personal devices can still authenticate if they use their AD credentials so you might want to go down both routes as belt and braces approach depending on how secure you want it.

Posted
It should work happily, and you could then just remove the user group assignment from NPS to restrict it purely to domain stations.

 

Just remember that if you leave NPS to Domain Users Or Domain Computers, then personal devices can still authenticate if they use their AD credentials so you might want to go down both routes as belt and braces approach depending on how secure you want it.

 

If I set it to allow domain computers only then only workstation joined machines will work then if I have it right?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...