Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > IAS for Wireless Authentication

Reply
Thread Tools Display Modes

IAS for Wireless Authentication

 
 
SynEngium
Guest
Posts: n/a

 
      06-24-2009

Hi.
I have setup an IAS server for wireless authentication with these policies:

1) NAS-Port-Type matches "Wireless - Other OR Wireless - IEEE 802.11"
2) Windows-Group matches "domain\Domain Users;domain\Domain Computers"

using PEAP-MS-CHAP-V2

but i have 2 problems:

1 - a computer who is part of the domain but logged on with a local computer
account can still connect to the wireless network.
2 - a computer who is not on the domain can't connect even when providing
the right domain credentials (which also gives me the problem of trying to
connect a windows mobile device since it's not part of the domain)

can someone please tell me what am i doing wrong?

thank you

 
Reply With Quote
 
 
 
 
Anthony [MVP]
Guest
Posts: n/a

 
      06-25-2009

Syn,
When is authentication happening?
At Startup the computer will authenticate. It makes no difference who logs
on afterwards.
At Logon the user will authenticate. it makes no difference what the
computer is.
Anthony,
http://www.airdesk.com



"SynEngium" <> wrote in message
news82050D8-A871-4D81-8686-...
> Hi.
> I have setup an IAS server for wireless authentication with these
> policies:
>
> 1) NAS-Port-Type matches "Wireless - Other OR Wireless - IEEE 802.11"
> 2) Windows-Group matches "domain\Domain Users;domain\Domain Computers"
>
> using PEAP-MS-CHAP-V2
>
> but i have 2 problems:
>
> 1 - a computer who is part of the domain but logged on with a local
> computer
> account can still connect to the wireless network.
> 2 - a computer who is not on the domain can't connect even when providing
> the right domain credentials (which also gives me the problem of trying to
> connect a windows mobile device since it's not part of the domain)
>
> can someone please tell me what am i doing wrong?
>
> thank you
>

 
Reply With Quote
 
SynEngium
Guest
Posts: n/a

 
      06-26-2009

there 2 different scenarios:

1 - if a computer is out of the domain as soon as i try to connect to the
wireless network a username and password are requested. but when i put a
domain user account it doesn't login. and i've found out why. for some reason
the connection default to "computer authentication" and since the login i'm
using is a user and not a computer account, login fails. to be able to
connect, i have to create the wireless connection manually and disable
validate server certificate, since this is not a domain computer it doesn't
have any certificate, and i have to go into advanced options and select "user
or computer" or just simply "user" on the specify authentication mode option.
this way it works.

2 - now for domain computers, what happens is, since the "authentication
mode" option defaults to computer auth. , the computer can logon even before
the user logon which is fine but completely ignores the domain users policy
on IAS. if i had a specific group of users who i'd want to connect to the
wireless network, it would be ignored since the computer is a domain computer
and is already authenticated.

is this supposed to be like this?

thank you so much.



"Anthony [MVP]" wrote:

> Syn,
> When is authentication happening?
> At Startup the computer will authenticate. It makes no difference who logs
> on afterwards.
> At Logon the user will authenticate. it makes no difference what the
> computer is.
> Anthony,
> http://www.airdesk.com
>
>
>
> "SynEngium" <> wrote in message
> news82050D8-A871-4D81-8686-...
> > Hi.
> > I have setup an IAS server for wireless authentication with these
> > policies:
> >
> > 1) NAS-Port-Type matches "Wireless - Other OR Wireless - IEEE 802.11"
> > 2) Windows-Group matches "domain\Domain Users;domain\Domain Computers"
> >
> > using PEAP-MS-CHAP-V2
> >
> > but i have 2 problems:
> >
> > 1 - a computer who is part of the domain but logged on with a local
> > computer
> > account can still connect to the wireless network.
> > 2 - a computer who is not on the domain can't connect even when providing
> > the right domain credentials (which also gives me the problem of trying to
> > connect a windows mobile device since it's not part of the domain)
> >
> > can someone please tell me what am i doing wrong?
> >
> > thank you
> >

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Wireless authentication settings? anton Windows Vista Networking 6 10-11-2008 04:58 PM
Re: EAP-TLS certificates for wireless authentication Cris Hanna [SBS-MVP] Windows Small Business Server 0 12-08-2006 11:22 PM
Wireless Authentication Warren Server Networking 0 11-28-2006 01:33 PM
Wireless authentication: IAS Event 2 DPM Server Networking 0 04-10-2006 03:42 PM
Setting up wireless authentication through GP Marc_MCSE_MCSA Server Networking 0 04-23-2004 04:06 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59