Command of the Day

Reply
Guru Elite
Posts: 21,021
Registered: ‎03-29-2007

COTD: How to create a Wireless Group Policy on Windows 2008

[ Edited ]

Congratulations, you finally figured out how to create a wireless network on Windows 2008 server using the instructions here: http://airheads.arubanetworks.com/vBulletin/showthread.php?t=2759

Now, how do you get that wireless network configured on all your computers in the domain, so that they can connect? The answer, of course, is group policy. Below we will detail in words and pictures how to configure a WPA2-AES (we should all be using this) on domain computers. **THESE INSTRUCTIONS ASSUME THAT YOU HAVE ALREADY CONFIGURED WPA2-AES WITH PEAP AND YOUR CLIENTS HAVE ALREADY CONNECTED SUCCESSFULLY*** These are only instructions to distribute that connection to your clients in a domain.

First, you have to RDP into a Windows 2008 server that has the group policy snapin and is part of your domain with a domain admin account. After you do that, go to Start> Administrative Tools> Group Policy Management. When you open the snapin, drill down to your default domain policy. Right click on it, and left click on edit:


You should then see the screen below:
gp-1.jpeg

 


Under Computer Configuration, expand Policies, Expand Windows Settings, Expand Security Settings and you should see Wireless Network (IEEE 802.11) Policies:
gp-3.jpeg

Right-Click on Wireless Network (IEEE 802.11) policies and left click on Create New Windows XP Policy. Name your XP policy name RISD (this is a friendly name and has nothing to do with the network we are connecting to) and change the networks to access to "Access point (Infrastructure) networks only". Also make sure that "Use Windows WLAN AutoConfig service for clients" has a check in it:
gp-4.jpeg

Click on the Preferred Networks Tab. Click on Add Infrastructure. In the Network name (SSID) box, type RISD (pretending that RISD is the wireless network you want to connect to). Make sure "Connect even if network is not broadcasting" is enabled. Make sure the Authentication is WPA2 and the Encryption is AES:
gp-5.jpeg

After that, click on Apply, then Ok, Ok, Ok, OK to get out of all the dialogs.

NOTE: To make sure that a XP wireless client on the domain gets the policy, plug it in wired, then type "gpupdate" on the commandline and press enter. Check the wireless networks configured on the client to make sure they got the definition. All the other clients that are connected wired should get the wireless config in the group policy refresh period, which should be 4 hours are less, if they are plugged in wired. The "gpupdate" method is only if you want your clients to get it immediately.

NOTE: You have to create another separate, identical policy for Windows 7 computers.

Big shout out to the School District in Texas that inspired this post.



Colin Joseph
Aruba Customer Engineering

Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base

Search Airheads
Showing results for 
Search instead for 
Did you mean: