Wireless Access

last person joined: 23 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Block AD user to access wireless network

This thread has been viewed 1 times
  • 1.  Block AD user to access wireless network

    Posted Oct 25, 2017 02:30 AM

    Which method is the best practice to block the Active Directory (AD) user access the wireless network? Configure on it Microsoft NPS or Aruba controller policy?

     

    Now my customer authenticate through 802.1x by using NPS and AD. If configure at Aruba controller it is add block list under "Authenticated" profile?

     

    Please advise



  • 2.  RE: Block AD user to access wireless network

    EMPLOYEE
    Posted Oct 25, 2017 09:00 AM
    Do you want to block all users in AD from connecting to a specific wlan network?


  • 3.  RE: Block AD user to access wireless network

    Posted Oct 25, 2017 09:03 AM

    Just want to block specific user on wlan network.



  • 4.  RE: Block AD user to access wireless network

    EMPLOYEE
    Posted Oct 25, 2017 09:10 AM

    You should blacklist that user's device.  If you are using an AD group to provide access to the WLAN, you should remove that user from that AD group.



  • 5.  RE: Block AD user to access wireless network

    Posted Oct 25, 2017 09:19 AM

    They don't have AD group to provide wlan access.

    If my customer's end users has multiple device, then have to blacklist few times for each user. 

     

    Does it good practice create a group on Aruba controller to block end user?



  • 6.  RE: Block AD user to access wireless network
    Best Answer

    EMPLOYEE
    Posted Oct 25, 2017 09:22 AM

    You would block access via group on the NPS server in the remote access policy.  NPS is not very flexible, so blocking a single user is difficult, unless you are allowing access via a specific AD group and that user is not in the group.



  • 7.  RE: Block AD user to access wireless network

    Posted Oct 26, 2017 03:34 AM

    How to permenantly blacklist the end user device? Because i did try to blacklist the user devices but it only can blacklist 60 minutes. 



  • 8.  RE: Block AD user to access wireless network