Jump to content

psycorp

Members
  • Posts

    7
  • Joined

  • Last visited

Reputation

0 Neutral

About psycorp

Personal Information

  • Occupation
    Network Manager
  • Location
    Birmingham
  1. Ok, thanks Chris. Yes I'm aware of the settings.xml file, I'm still having trouble understanding how it all fits together. Why are there user groups but actual staff users seem to be setup as child objects to the deault eportal users, for instance? Thanks
  2. Hi I'm trying to setup a new user group in eportal to give a small number of teaching staff access to all assessments and registers but I'm finding the group and account hierarchy in eportal a bit confusing. Could anyone explain how to do this, or failing that just give me a clear overview of how the actual users and the default users and user groups all fit together? Thanks
  3. Anyone had any joy setting up IPSec VPN on Smoothwall Guardian with a client such as Shrew VPN. I've got the L2TP to work but the performance is a bit ropey so thought I'd try plain IPSec. However I cant get the client to connect, I'm constantly getting an "Invalid Message from Gateway" during the initial ISAKMP exchange. All setting are as per Smoothwall help files. Help would be greatly appreciated. Thanks
  4. Hi I've tracked down the issue so thought I'd post it here for anyone else who might have a similar problem. Our issue was caused by the Authentication Mode in the Security Settings for the Wireless Network Connection that we had setup in Group Policy (Computer Configuration > Windows Settings > Security Settings > Wireless Network (802.11) Policies > "Your Network Policy") Originally the Authentication Mode was set to "User or Computer authentication", when this was changed to "Computer authentication" the Computer Account condition in the Network Policy in NPS was processed correctly and clients could connect. I can only assume that this is a bug as on further testing I found that when the Authentication Mode was set to "User or Computer authentication" NPS would process a User Account condition in the Network Policy correctly, but still refused to process the Computer Account condition properly. Hope this helps someone. Cheers
  5. Hi ATM the system authenticates wireless connections only. Cheers
  6. Hi Sukh The background is that we have had the whole system working for quite a while now so yes the wireless policies have been created and the RADIUS clients are configured. Setup is: Wireless access point RADIUS clients using WPA2 encryption XP SP3 and W7 Ent desktop clients Authentication methods are PEAP and MS-CHAP v2 I am trying to restrict access to the wireless network on a per machine basis. I am using the domain computers group simply as an initial test group. As I said in the original post the system works fine until I introduce a Machine Group condition into the Network Policy. Even when this condition includes the Domain Computers group none of our laptops are able to connect. When I remove this condition it works fine again. I have seen this issue reported before in connection with VPN setups but ours is a Wireless LAN system only. Cheers
  7. Hi Long story short we have NPS setup with RADIUS client AP's to process wireless connection requests on our 2008 R2 domain. Our Connection request and Network policies at present only contain a NAS Port Type 802.11 condition, which works fine. I am trying to restrict wireless access to computers that are part of the domain but as soon as I add a Machine Group condition which includes the Domain Computers group non of the computers can connect. I have seperately tested adding a User Group condition and this works fine. Any ideas on what could be wrong or I am missing? Cheers
×
×
  • Create New...