Controllerless Networks

 View Only
last person joined: 15 hours ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

Aruba Wireless Controller - AD Logon Script

This thread has been viewed 21 times
  • 1.  Aruba Wireless Controller - AD Logon Script

    Posted 10 days ago

    Hi all,

    need help with settings / workaround as when we implement this ARUBA AP (previously using Cisco), we notice that our AD user profile logon script no longer/unable to run. This really inconvenient as we can't use script to push when user login to windows.

    below is the current setting 

     

    have notice few things when troubleshooting:

    -I tried to create new SSID with less secure the logon script able to push. 

    -when user log out = WIFI connection unlink need user credential to connect to WIFI again.



  • 2.  RE: Aruba Wireless Controller - AD Logon Script

    EMPLOYEE
    Posted 10 days ago

    Are you assigning a user-role post network login that allows access to the AD DCs?

    What EAP method?  Are you using computer and/or user authentication?



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: Aruba Wireless Controller - AD Logon Script

    Posted 7 days ago

    Are you assigning a user-role post network login that allows access to the AD DCs?

    -Not sure about this, can provide path to check?

    What EAP method?  Are you using computer and/or user authentication?

    -We using EAP-TLS and EAP (PEAP) both are accepted 

    - We using computer and user authentication.




  • 4.  RE: Aruba Wireless Controller - AD Logon Script

    EMPLOYEE
    Posted 7 days ago

    First, check what user role is being assigned to the session when a user isn't logged in, and then after the user has logged in.  That is available on the UI dashboard or through CLI show clients.

    Once you know what the user roles in play are, check the configuration of those user roles either under the Security configuration in the UI or through CLI.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 5.  RE: Aruba Wireless Controller - AD Logon Script

    Posted 7 days ago

    Hi Chulcher seems like it has something to do with ClearPass as we are using it for authentication. where to check next?

    as below

    settings




  • 6.  RE: Aruba Wireless Controller - AD Logon Script
    Best Answer

    Posted 6 days ago

    If I have understood correctly, you want the windows devices AD logon scripts to be executed.

    For this to work, windows devices must establish the WiFi connection before the user logs on. You cannot control this behavior in WiFi Controller and not in ClearPass. It depends on the windows devices and the authentication mode used.

    You write that WPA2-Enterprise is used. Furthermore, the WiFi connection is disconnected when the windows users log off. From this I conclude that the windows devices use user-authentication-mode. This means that the WiFi connection is only established after the user logs on to the windows device. This is the reason why the logon scripts are not running.

    Change the authentication mode to computer authentication. Then the windows device will use a computer certificate for authentication and establish the WiFi connection before the user logs on.



    ------------------------------
    Regards,

    Waldemar
    ACCX # 1377, ACEP, ACX - Network Security
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------