Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

RADIUS users

Status
Not open for further replies.

disturbedone

Vendor
Sep 28, 2006
781
AU
I've never setup RADIUS before, on Windows or otherwise. We're implementing a new WiFi solution which will require it so we'll put in on W2K8R2 with NPS. The implementation of NPS looks pretty simple so I hope it is.

The question is regarding the users which will be authenticated against. Obviously being a Windows RADIUS server it will know about the AD users. But with the new WiFi the possibility of us holding seminars for external people to utilize (and pay for) is there. But we'd want them to authenticate before giving them access to an open SSID (not using WPA2). The WiFi solution would incorporate a device that would do the billing and time limiting for the accounts.

The question is then can a Windows RADIUS server have non-AD accounts as well as AD accounts for the WiFi users to authenticate to??
 
This is probably going to come down to your wifi controller device. The ones that I have seen will allow you to set up different types of users and authentication (some users defined on the device, others authenticated via LDAP or RADIUS). Ideally you would have a controller that advertises multiple SSIDs, with different users and authentication methods per-SSID.

For example, you could have an "internal" SSID for your employees that authenticates to the Windows RADIUS service. You could have a "seminar" SSID that authenticates to a locally defined (within the WLAN controller) list of users or a shared credential. Then you can have a "guest" SSID for unauthenticated users that only allows them access to your company's web site, or a simple page explaining how to arrange for proper access to the WLAN.


________________________________________
CompTIA A+, Network+, Server+, Security+
MCTS:Windows 7
MCSE:Security 2003
MCITP:Server Administrator
MCITP:Enterprise Administrator
MCITP:Virtualization Administrator 2008 R2
Certified Quest vWorkspace Administrator
 
Yeh, I had more of a think after I posted and thought this might be the case. The MS RADIUS is just for the AD users but if the WiFi doesn't find a match then it should look elsewhere. We'll be using a product called Nomadix along with Meru WiFi - Nomadix can do all that sort of stuff.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top