Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Machine group policy not applied with RADIUS authentication

This thread has been viewed 0 times
  • 1.  Machine group policy not applied with RADIUS authentication

    Posted Dec 13, 2012 02:01 AM

     

    Hi,

     

    A prospective client is testing a 620 controller with a 135 AP at the moment. On one of the SSIDs it is setup to use an external RADIUS server (running NPS on Windows) with authentication being via an internal domain issued certificate. This works okay but the problem is that machine group policies are not being applied.

     

    From correlating the client and RADIUS logs you can see that the client fails to find a DC to get the machine group policy from a few seconds prior to the successful authentication on the RADIUS server. As the machine GP is only applied at boot-up the client will never get it.

     

    What is responsilbe for the delay? Can I get better visibility on this somewhere in the controller?

     

    This work-around below works but the client is still concerned as the same setup with Meru does not have this issue. Also would rather not implement a client side fix and is worried that this could be an issue for other services at boot-up that need full network connectivity straight away.

     

    http://support.microsoft.com/default.aspx?scid=kb;EN-US;2421599

     

    Also, he has only been able to test that on Win7 as that is all that is available.

     

    Can anyone assist?

     

    Cheers,

     

    Dan



  • 2.  RE: Machine group policy not applied with RADIUS authentication

    EMPLOYEE
    Posted Dec 13, 2012 05:52 AM

    Do you have machine authentication setup on the wireless workstation AND the NPS server?

     



  • 3.  RE: Machine group policy not applied with RADIUS authentication

    Posted Dec 13, 2012 06:48 AM

    Yes, both sides. It does work, just too slowly.



  • 4.  RE: Machine group policy not applied with RADIUS authentication

    EMPLOYEE
    Posted Dec 13, 2012 07:04 AM

    Can you see if the laptop logs in as host/<hostname> when it is at the ctrl-alt-delete screen?