Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

RADIUS server, prevent users from signing in

This thread has been viewed 3 times
  • 1.  RADIUS server, prevent users from signing in

    Posted Jan 26, 2016 02:50 PM

    Hi guys, 

    I have setup a secure network using a RADIUS server for authentication.  My question is, is there a way to prevent people from clicking on the network and entering their credentials to connect to the network.  I would like to have group policy to be the only way people connect to the network, if a computer is not joined to the domain, I dont want them to be able to connect to wireless network, dont want them to be able to join their personal devices to wireless by putting their domain credentials in.



  • 2.  RE: RADIUS server, prevent users from signing in

    EMPLOYEE
    Posted Jan 26, 2016 02:52 PM
    Yes, you can leverage machine authentication.

    What RADIUS server are you using?


  • 3.  RE: RADIUS server, prevent users from signing in

    Posted Jan 26, 2016 04:07 PM

    using SBS2011 as my RADIUS server



  • 4.  RE: RADIUS server, prevent users from signing in



  • 5.  RE: RADIUS server, prevent users from signing in

    Posted Jan 27, 2016 09:24 AM

    thanks Tim, have already done all of that, didnt see anything in article about preventing someone from clicking on wireless network from personal device and putting in their domain credentials and joining network which is what I am trying to do



  • 6.  RE: RADIUS server, prevent users from signing in
    Best Answer

    Posted Jan 31, 2016 08:40 AM

    Tim is still pointing you to the machine authentication part of the solution to this. page 33.

     

    if you use machine authentication and enable the corresponding section on the controller dot1x profile (i believe) then you can exclude non domain joined machine (i.e. smartphones, tablets, ...) from authentication on your SSID.

     

    that is pretty much the only thing you can do with NPS. with ClearPass you get some extra options. but this remains a tricky thing to work out.



  • 7.  RE: RADIUS server, prevent users from signing in

    Posted Jan 26, 2016 02:53 PM

    Unfortunately you can't do that , you could try hidding the SSID but if the user knows the name or has already saved you can't prevent the user from attempting to authenticate.

     

    Why are you trying to do this ?

     

    Are you using ClearPass ?



  • 8.  RE: RADIUS server, prevent users from signing in

    Posted Jan 26, 2016 04:08 PM

    If I hide the SSID, then it does not seem to connect users to the network automatically any more, I just dont want users to be able to connect their personal phone, tablet etc.. to this network by having the option to put in their domain credentails