Tuesday, February 16, 2010

Authenticate Wi-fi clients against IAS/Radius

Note that "Domain Computers" is used to authenticate your computer for "machine authentication" which connects your wireless PC before the user even logs in. This is a very usefuland unique benefit of the Windows Wireless Client since it emulates the fullwired experience for wireless users.

If "machine authentication" isn't implemented, group policies and login scripts won't fire off. Furthermore, only cached users can login to the wireless computer, because users who have never signed on to that PC can't authenticate with the domain.

Source:
Ultimate wireless security guide: Microsoft IAS RADIUS for wireless authentication
www.techrepublic.com/article/ultimate-wireless-security-guide-microsoft-ias-radius-for-wireless-authentication/6148579

Self experience on first setup

If computer is joined to domain:
If you never logged on to domain using this computer before and no wired conn is available, you have no choice but to log on using local account first, set up wireless security and then re-log on using domain credential
If you had logged on to domain using this computer before, you should be able to log on now using cached credential then configure wireless app to use Windows user name and password for next reboot (no need to enter credential twice: one for windows logon, one for wireless security)

If computer is not joined to domain:
No problem then...just use the usual username and password then set up wireless security. One drawback with this case, double credential entry seems inevitable (one for wireless security, one for accessing domain shared resources); storing domain credential is not recommended since it can cause account lockout when password is expired

Related article(s)

How to fix iPad and iPhone Wi-Fi problems
http://searchnetworking.techtarget.com.au/articles/41498-How-to-fix-iPad-and-iPhone-Wi-Fi-problems

BlackBerry Curve Smartphone: WPA2-Enterprise
http://supportforums.blackberry.com/t5/BlackBerry-Curve-Smartphone/WPA2-Enterprise/m-p/41249

Ultimate wireless security guide: Self-signed certificates for your RADIUS server
www.techrepublic.com/article/ultimate-wireless-security-guide-self-signed-certificates-for-your-radius-server/6148560

No comments:

Post a Comment