Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

wireless with Active Directory.

Status
Not open for further replies.

swabs

IS-IT--Management
Jul 28, 2003
155
US
I am not sure if this is the correct forum, but here goes.

Hello All,
I am looking for a wireless solution. I would like to ulitmately have a scenario where anyone who connects to our wireless network would be forced onto a logon page (similar to what many hotels do to charge access).
Then the user would logon using their domain credentials and thereby gain access based on their domain permissions. Is there an out of box product that ties wireless access credentials to Active Directory?

How are others handling the issue of wireless access to users, not including just WEP or SSID? I work at in the educational field. The problem is that up to 600 of our wireless devices are not going to be part of the domain. They will be student laptops or tablet pc's. So I am trying to find a wireless solution that not only gives web access, but Domain Acess to devices that are not part of the Active Directory Domain.

Any experience, pointers to documents, or products would be greatly appreciated.

Thanks,
 
trying to read your post, the first part of the post is the opposid of the second part. In the first part you're speaking about users login in to their domain, using their domain account credentials, and in the second part you tell that the devices will nto be a member of the domain. Does this mean that:

A: The users (students) have a domain account in your domain
B: The devices the use do NOT have a domain (copmuter) account?

For the last rule in your post, if a (network) device is NOT in the AD domain ,it is not a member of the domain, so there is nothing to do with domain rights.

Regards,
Robert
 
rwullems,
you are correct and thanks for the reply. My post was not clear.

1.Each student has an active directory account and they use desktops in the school for domain access to resources (file server, other apps, etc) and internet access.

2. The school will be implementing a policy where each student will now have a laptop. I would like to have a situation where those laptops are not part of the domain. But with their existing active directory accounts they could access domain resources.

So i am looking for a wireless solution that gives users on their personal laptops the ability to only have to log-into a centralized web-page 1 time with their domain account. That logon would tie into AD and let users access the resources that they have permissions for.

Thanks for your help.
Ben
 
okay, that makes it clear.

Still i think it will be difficult to realize. Normally the computer account is first initaited by the domain, and after that the user account is initiated.

I really don't know if it is possible what your are looking for, especially because you still want to use domain resources wile the computer is not a member of the domain, but the user is....
regards,
Robert
 
It is possible, but would be very difficult from a managment perspective.

I use my personal laptop quite often at work. It is not a memeber of the Domain, but I am. So I created shortcuts in My Network Places to the resources I use most, and connect. I am then prompted for a password and I save it so I can keep it as long as I am logged into that session. Anytime I reboot, I normally have to input it again.

For me this is no big deal, as I am the network admin. To implement this for users... I wouldn't want to try it, seems like it would be big headaches.

Best of Luck to you!

Thanks,

Matt Wray

GFH

 
mattwray,
thanks for your reply and input. I have been doing a bit of research and it looks like their are a couple of options. The newer access points have the ability to authenticate with a RADIUS server before they are granted network access, so that might be an option to tie Domain credentials in.
There are also products like Bluesocket and Caymas that have the ability to tie in authentication with Active Directory.

I need to do more research on both methods. I am not very familar with RADIUS servers other than knowing what the name means.

I will keep on reading.
thanks,
Ben
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top