Part 1: Radius Server for WiFi Authentication with Windows Server 2016

  Рет қаралды 227,191

TekNex Solutions

TekNex Solutions

Күн бұрын

Пікірлер: 285
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
Checkout next part of this series here kzbin.info/www/bejne/h4TRmmV_hZWEgK8 . Wi-Fi network settings deployment through GPO.
@CessnaLifelineVeterinaryClinic
@CessnaLifelineVeterinaryClinic 6 жыл бұрын
Thanks let me go through it.
@РоманПетрик-щ9р
@РоманПетрик-щ9р 5 жыл бұрын
ДЖЗ*33'333×2@= ПЕТРИЬІК**?°¿|©
@gynxineko8456
@gynxineko8456 4 жыл бұрын
Hi and thank you for this tutorial. May I ask if its possible to make a "Timed Connection" for each clients who are connected to the network? I would be nice if it limits them to connect like 1-2 hour(s) a day.
@robertoquinones785
@robertoquinones785 2 жыл бұрын
Thank you so much, brother, great content!! . Note: If someone is having issues make sure to also open the inbound firewall port UDP 1812 on your server, and if you have a network firewall also make sure it allows that same traffic from the wireless AP to the Radius Server.
@francoisaissan6519
@francoisaissan6519 2 жыл бұрын
Thank you for this precision, it helped me a lot.
@stormish8220
@stormish8220 3 жыл бұрын
BROTHER!! You are so awesome!! Your video is great! keep up the work! Perfectly edited, you made sure we dont waste time. I am a person who never comments on any video or likes or subscribes. But I have done all this because your work impressed me. The explanation is clear and precise.
@TekNexSolutions
@TekNexSolutions 3 жыл бұрын
Thanks for the amazing feedback and I am glad you enjoyed the video.
@arturpopielski7051
@arturpopielski7051 8 ай бұрын
Finally got this to work, I knew it was a server config error, but this explained it very well, bravo!
@mohammadz1296
@mohammadz1296 Жыл бұрын
man I really appreciate it, I spent hours trying to do it without on my own. I was missing the certificate part, I didn't know it was required. Even though that I have enabled all authentication methods. Thank you very much.
@jamesmctaggart
@jamesmctaggart 6 жыл бұрын
Excellent Video!!! Thank you so much for making this, I’ve been trying to do this for years and all the videos I follow something doesn’t work. Follows the instructions In this video and now my wifi is using a fully functional radius server. Thanks so much
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
Perspective Thanks. I am glad it helped.
@fromdil6470
@fromdil6470 Жыл бұрын
It would be beneficial to provide concise explanations for the addition of certain roles and features. This way, the audience can better understand the purpose of these steps. Additionally, some users may find it unclear how to establish connections or create another virtual machine linked to the server for testing its functionality. Anyways, thank you for creating this video.
@remiolawuyi6177
@remiolawuyi6177 6 жыл бұрын
Thank you for the video, I tested this with a ubiquiti Wifi and it worked
@hennessy6996
@hennessy6996 5 жыл бұрын
Did you have a mix of Win7 and Win10 clients? Did you have to install any certs on any of the end clients for this to work?
@itgreene3837
@itgreene3837 4 жыл бұрын
Thank you for the very super helpful and detailed guide, I used this today and it was most helpful.
@muhammadowaiskhan4132
@muhammadowaiskhan4132 21 күн бұрын
Thank you sir for the great video I have a query, If I follow this tutorial how could I achieve the requirement to setup Radius server for Wireless Users Authentication. I need to set up RADIUS for our Wireless Access Points (APs). The challenge I'm facing is RADIUS server is separate machine and I need guidance on how to properly link the AD with the RADIUS server which the requirement is to create on Separate machine. Could anyone help me understand the additional steps involved in configuring RADIUS server and how to integrate the AD and RADIUS? (Does the Radius Server could be the Domain User and then it integrate as well? What would be the configuration at AD and Radius for integration) I would appreciate a detailed breakdown of the additional configurations needed on both ends. If you have any documents, guidelines, or videos that could walk me through the process, that would be immensely helpful. I’ve been unable to find the right resources so far.
@nadirurbina3198
@nadirurbina3198 11 ай бұрын
Great video, a very nice explanation of the components to achieve the goal, thanks, you've helped a lot today!
@pcpmtiservicos9855
@pcpmtiservicos9855 3 жыл бұрын
Thank you for this great and direct guide towards RADIUS
@BartvandenDonk
@BartvandenDonk 2 жыл бұрын
Somethings are incorrect. Like the thumbprint mentioned is different than the one showed... But that is because it is stitched together I think.
@jessegarcia6711
@jessegarcia6711 Жыл бұрын
Very cool and informative. Do ADCS and NPS need to be on the same server as DC?
@raviutam
@raviutam 5 жыл бұрын
very well done bro. useful information with easy explanation and examples
@tahirkhan-tk8zl
@tahirkhan-tk8zl 5 жыл бұрын
Very detailed and excellent video. Dear we have some quires will you please help us out. We have Multiple VLAN's for Multiple SSID's all VLAN's are in different IP pools. So kindly guide us if we define multiple IP scope for multiple SSID's how user can authenticate to their particular specific SSID ? Waiting for your response.
@TekNexSolutions
@TekNexSolutions 5 жыл бұрын
Hi Tahir, This would be a sophisticated set up. Give me some time to think. Jay
@vetribull8318
@vetribull8318 3 жыл бұрын
Hi bro, beautiful video, are you using vmware workstation or bare metal?
@TekNexSolutions
@TekNexSolutions 3 жыл бұрын
Thank you. This is on Hyper-V.
@vetribull8318
@vetribull8318 3 жыл бұрын
@@TekNexSolutions Hi bro. Thank you very much for your reply. Did you have any radius server videos with wired.
@ninja2807
@ninja2807 5 жыл бұрын
As always...an excellent video. Thanks very much.
@TekNexSolutions
@TekNexSolutions 5 жыл бұрын
ninja2807 you are most welcome
@Bluraycollec
@Bluraycollec Жыл бұрын
Hello, I have configured the radius server and it works. On the session I have the button to connect but I also have the possibility of entering another login / mdp how to prevent this? THANKS
@techydanish
@techydanish Жыл бұрын
Thanks for the great content and it was really helpful as I was looking to learn more about servers
@RowBoCawp
@RowBoCawp Жыл бұрын
Excellent guide! However, I - for whatever reason - cannot get mine to work. It is stuck on "Checking Network Requirements". Event viewer reveals repeated 802.1x authentication restarts. Our DHCP is currently running on our Meraki firewall, with the DNS running on DCs. Any idea what might be the cause?
@noelvilladolid3959
@noelvilladolid3959 6 жыл бұрын
Thank you for the very detailed instructions, sir! Very helpful!
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
Your welcome, glad it helped
@temptemp012
@temptemp012 5 жыл бұрын
Excellent video. Thanks for posting.
@TekNexSolutions
@TekNexSolutions 5 жыл бұрын
Eldrinarr you’re welcome.
@BruX013
@BruX013 6 жыл бұрын
Well done demonstration, Jay Mann. Any plans on an upcoming video on SSO 802.1X GPO for WS2016/W10?
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
Thanks. Yes, it can be done but have not planned anything about it yet.
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
Here is the link kzbin.info/www/bejne/h4TRmmV_hZWEgK8
@rishabhmishra6401
@rishabhmishra6401 5 жыл бұрын
Nice video .. Just a quick question, how do you set up similarly for Guest Users? Please post me some steps, appreciate your help. Thanks
@sgpood
@sgpood 5 жыл бұрын
Excellent Video. Pls i need to know. If I have multiple Domain Controllers does requesting certificate on one DC replicate to the others?
@deutscheslotto8923
@deutscheslotto8923 2 жыл бұрын
Great video, I can get communication when I’m on the normal net but it doesn’t work on the enterprise net any tips? Also I had to put the router in bridge mode for communication to occur
@nawalsingh9159
@nawalsingh9159 3 жыл бұрын
Thank you so much this wonderful video..
@hennessy6996
@hennessy6996 5 жыл бұрын
Hi, Great video, did you register the NPS in Active Directory also?
@TekNexSolutions
@TekNexSolutions 5 жыл бұрын
Thank you. You have to do that if your NPS server is different than the DC. In this case, I did not have to register because of TEST-CERT01 is a DC itself and it has the permission to read the dial-in properties of user accounts during the authorization process.
@DolphinSkys
@DolphinSkys 5 жыл бұрын
Great video. Can you please offer advice on how to install a certificate from a trusted CA so that mobile clients are not asked to Trust the CA when connecting?
@TekNexSolutions
@TekNexSolutions 5 жыл бұрын
I am sorry, it seems like I missed this comment. Yes, there is a way. However, you can create Wi-Fi profile and can be managed with any MDM solution. This is a bit complex and a lot is involved in it.
@sandeepsharma-fd6xl
@sandeepsharma-fd6xl 3 жыл бұрын
How would guest connect their macOS when policy is computer based with certificate authentication? How would guest get/request certificate and where to place in macOS.
@yassmax91
@yassmax91 9 ай бұрын
I have a problem. We would like to allow only domain computers and when the NPS authenticates the computer it need toi asks for username and password, but when we add the group( Domain computers/Users in the same policy the NPS does not allow access. If we create 2 separate policies this one does not ask for password since the domain computer is already authenticated with cert. Any help
@ateeqsrehman9230
@ateeqsrehman9230 5 жыл бұрын
it was in detailed video, thanks for sharing. what if i just want the laptops that are in domain only be able to connect in that case i think we will set the local computers group instead of users. but if we dont add user groups how the username and password will work to connect???
@TekNexSolutions
@TekNexSolutions 5 жыл бұрын
You are welcome. Here is the video for computer based authentication kzbin.info/www/bejne/h4TRmmV_hZWEgK8
@wicket20
@wicket20 5 жыл бұрын
Thank you for the great tutorials! I am pretty green when it comes to certificates. So it looks like the GPO will automatically renew the certificate. But what about on the domain controller/CA? I assume when those certificates are close to expiring i'll have to manually go in and create/renew the certificate?
@BartvandenDonk
@BartvandenDonk 2 жыл бұрын
Normally you would create a Root CA on a laptop (OR cheap Raspberry PI) and Create a life Intermediate CA instead. The laptop (Raspberry Pi) should be shutdown put into a safe and only be used when renewing that intermediate CA.
@francoisaissan6519
@francoisaissan6519 2 жыл бұрын
Thanks for this content, it is very helpful.
@TekNexSolutions
@TekNexSolutions 2 жыл бұрын
Glad it was helpful!
@basitsahab
@basitsahab Жыл бұрын
Hi, Please could you help me with using Microsoft NPS and setting up a test OU for machine-based wired and wireless authentication? created an SSID on our cisco interface which points the wireless to the correct authentication server and perhaps the same on our switches.
@ghostmomo8814
@ghostmomo8814 3 жыл бұрын
What if my AD CS role wasn’t install in the domain controller but other server? Do I need to request the certificate in the DC but not my server, which got AD CS role? Thank you.
@hamidchendawoli7497
@hamidchendawoli7497 5 жыл бұрын
Hi Jay, did you use your Wireless Router as Default-Gateway ?
@TekNexSolutions
@TekNexSolutions 5 жыл бұрын
Hamid Chendawoli Yes, for wireless clients.
@brianb1381
@brianb1381 6 жыл бұрын
Hello Jay, Thank you for your video. I'm having issues connecting to the wifi network. Everytime i fill in my credentials it loads and sends me back to where i need to put in the credentials, without giving me an error message. When i test this with the built in authentication tester in my AP it does work... I'm using a Ruckus zoneflex r510.
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
Brian Boere Hi Brian, Have you triend another client, may be a phone could be a good test? Does the same problem occur on other devices as well? Tester checks the radius server only, which means there is no issue with the radius authentication. Once you hit connect from a client, server should offer a certificate. Let me know if the issue is same accross different devices.
@brianb1381
@brianb1381 6 жыл бұрын
Jay Mann, I've also tried this on my phone. The same problem occurs.
@kewlheadkewlhead4038
@kewlheadkewlhead4038 2 жыл бұрын
Thanks for this! Quick querry, i have my mx84 act as dhcp server, i am able to authenticate from nps but not getting an IP, appreciate if you can give light on this, thanks!
@CJayWorld
@CJayWorld 2 жыл бұрын
How can we specify which SSID The users from the Network group will be connecting? If I have multiple SSIDs but I do not want users from the Security group1(SSID1) to SSID2
@kviiyak2488
@kviiyak2488 5 жыл бұрын
Hello! I have a problem here. I have windows server 2012 and AD DNS DHCP install than I turn off dhcp on my wireless router, my pc get IP address from my dhcp server but my device can’t get IP address from WiFi! So any help pls thx.
@rhielx
@rhielx 2 жыл бұрын
Hi Jay, I have some question about the certificate. For user authentication like this, does the certificate have to be installed on the client side or only on the server side?
@TekNexSolutions
@TekNexSolutions 2 жыл бұрын
Server will offer the client a cert upon successful authentication. Only server side will be sufficient.
@mrintune
@mrintune 2 жыл бұрын
Amazing Video with Smooth Process. Why td-w8980.test.local device level setup is missing in this video ? this device is windows server or a windows client machine ?
@keinechancee5361
@keinechancee5361 2 жыл бұрын
Its an accesspoint :)
@mrintune
@mrintune 2 жыл бұрын
@@keinechancee5361 Device: rs-w8980.test.local is a windows 10 or windows server device ?
@mrintune
@mrintune 2 жыл бұрын
@jay
@keinechancee5361
@keinechancee5361 2 жыл бұрын
On which minute did you found that? The accesspoint is named “TD-W8980”. The Windows Server is named “TEST-CERT1” and the windows 10 client is named “Win10”. test.local is the local domain, so for example “TD-W8980.test.local” is the accesspoint inside the domain and “Win10.test.local” is the Windows 10 Client inside the domain. Have a nice weekend and greetings KeineChancee
@mdsayedalam4511
@mdsayedalam4511 4 жыл бұрын
Thank you for the great tutorials!
@TekNexSolutions
@TekNexSolutions 4 жыл бұрын
Glad you like them!
@vasujain7224
@vasujain7224 3 жыл бұрын
Hi.. If possible I need to get some help... Setup made successfully but not able to connect Wi-Fi...
@rizkiyudi
@rizkiyudi 8 ай бұрын
How to check existing configuration 802.11x ? Cause i have problem 1 group cannot connect to wifi
@hennessy6996
@hennessy6996 5 жыл бұрын
Hi, this is a really great video. I was thinking of applying this a similar concept using username and password only for a College for Students to access resources with their personal machines, and not the domain computers. What would I have to change to make this happen. I'd prefer to not have to use certificates for the students' laptops.
@TekNexSolutions
@TekNexSolutions 5 жыл бұрын
Big Ric Than you. For Radius authentication you supposed to have a CA in action. It will be user auth for students BYODs and computer auth for domain joined devices.
@hennessy6996
@hennessy6996 5 жыл бұрын
@@TekNexSolutions Thanks for replying, but let me ask this, is there some issue(s) with Windows 10 clients requiring a certificate and causes problems to connect to these types of public Wi-Fi with RADIUS auth? I can see Android devices not having this issue, I'm asking as I have a college Wi-Fi network to deploy in the fairly distant future and smooth student connectivity is an area of contention for me.
@TekNexSolutions
@TekNexSolutions 5 жыл бұрын
@@hennessy6996 Android, IOS, macOS and Win 10 Client uses the Windows Radius Authentication in a similar fashion. As demonstrated in the video, when you connect the client and it prompts to trust the Certificate from your CA. Once you do that and connection works as it supposed to be. This method is widely deployed in different production environments that I know of personally, we are talking anywhere between 1500 to 60,000 end users. Have you faced any issues?
@hennessy6996
@hennessy6996 5 жыл бұрын
@@TekNexSolutions About 9 months ago I tried this and had problems with the Win10 clients requesting credentials repeatedly without ever connecting, I'm picking this up again as I'll have to deploy soon. I'm even thinking of dynamic VLANS with some Aruba Networks switces for wired clients as the existing IT team is very inexperienced. I'll be labbing it out over the next 2 weeks.
@TekNexSolutions
@TekNexSolutions 5 жыл бұрын
@@hennessy6996 I don't see any issues moving forward with this. However, try it in your lab and it should work.
@chris9384
@chris9384 Жыл бұрын
Excellent tutorial!!! Thanks!
@MonitoringAlerts
@MonitoringAlerts Жыл бұрын
Hi, this is a great video. I appreciate your content. Question though, is there any way to avoid the prompting of the certificate notice during the authentication process?
@TekNexSolutions
@TekNexSolutions Жыл бұрын
Yes, there is. If you install the root cert on the machines. However, on BYO devices you won't be able to install the root cert since you don't manage those devices.
@TheAmazeer
@TheAmazeer 5 жыл бұрын
Thanks dude.. Can Android clients Access their home folder via a file explorer ?
@TekNexSolutions
@TekNexSolutions 5 жыл бұрын
TheAmazeer Yes they can. I haven’t tried with the in-built file explorer. You might have to use a third party app which will allow you to enter the share name, credentials and other settings required to access share.
@brianboere93
@brianboere93 6 жыл бұрын
Hey Jay, I'm getting the following message when connecting to the Wi-Fi: If you expect to find [wireless SSID name] in this location, go ahead and connect. Otherwise, it may be a different network with the same name. Do you know how I can remove this warning for my clients? Thank You.
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
brian b Hi Brian, Disregard my earlier message if you received. I checked this and even in production we get the same message, unless you use group policy to deploy the Wi-Fi profile for users/computers. However, I will look into this further and update you once I found if there is anything we can do without GPO. Of course GPO will only work with domain joined devices only. Jay
@sschreffler1
@sschreffler1 5 жыл бұрын
@@TekNexSolutions I'd really like an answer to this question if you have one. Thanks.
@DarthCircuit
@DarthCircuit 6 жыл бұрын
I see mostly tutorials on how to do authentication with a domain user. Is there a tutorial or an easy way to do this with a certificate by itself? I was reading about TLS authentication, which i think would work. We've got several thousand chromebooks, and a new wifi network we're deploying. I don't really want to have to explain to everyone how to log in. I just want it to be seamless.
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
darthcircuit I can see where you coming from. In your case, you have to build a Wi-Fi profile and enroll each device to it.
@DarthCircuit
@DarthCircuit 6 жыл бұрын
That sounds awful. I guess we'll just stick with PSK for now lol. Thanks :)
@chrisramos6671
@chrisramos6671 3 жыл бұрын
do you have a guide on how to apply captive portal using this?
@dasnabajyoti
@dasnabajyoti 3 жыл бұрын
Nicely explained 👌
@CessnaLifelineVeterinaryClinic
@CessnaLifelineVeterinaryClinic 6 жыл бұрын
hi it was a nice video. but i would like to know. if user is already part of domain then how to skip putting user/pass while connecting to wifi. it should be automated. any suggestion on it.
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
Thank you. Yes it can be done with the help of GPO. Nothing planned yet, may be I record another video for this.
@CessnaLifelineVeterinaryClinic
@CessnaLifelineVeterinaryClinic 6 жыл бұрын
@@TekNexSolutions oh great, if you could create quick video on this GPO will be helpful
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
Care For You Hi there, just letting you know you can check this video deploying Wi-Fi profile through GPO. You can only deploy this profile to Windows devices. Here is the link kzbin.info/www/bejne/h4TRmmV_hZWEgK8
@MuhammadArshadThaheem
@MuhammadArshadThaheem 6 ай бұрын
you are awesome bro ... i am getting an error "Unable to join wifi-sid". Can you help what should I have to checked. I am using server 2022
@rogauze
@rogauze 7 ай бұрын
Great detailed guide!!
@lcjl312
@lcjl312 6 жыл бұрын
Hi. Good video, I have a problem specifying the type of installation of the CA, the CA enterprise mode appears disabled and I would like to know why ?. Thanks for the video best explained
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
Jose Luis Llampa Colque Strange issue. I never had that problem. Are you installing CA on a DC(like I did) or it is a different server?
@lcjl312
@lcjl312 6 жыл бұрын
@@TekNexSolutions Hello, at minute 17:56 you are shown two options: Enterprise CA and Standalone CA, both active, but in my case only Standalone CA shows active and Enterprise CA is disabled, that shows me when configuring in Windows Server 2012 R2 and in Windows Server 2016 and I do not know what the problem is, maybe the problem is that the operating system is virtualized ???, use VMWare 14.
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
I just figured out what is your issue here. Type of virtualization is not a problem. When I created fresh Windows Server 2016 > added role Active Directory Certificate Services > Tried to configure Certificate Authority as an Enterprise CA. It is greyed out same as yours. Reason: My server is not domain joined or it is not a Domain Controller itself. Solution 1: You need a domain in your network > domain join your server > Enterprise CA option will be available Solution 2: Follow exactly same steps in the above video (Create a DC and test the setup), you will not have any issues at all
@HamzaRasheed
@HamzaRasheed 3 жыл бұрын
Can you please make a video on Wired authentication?
@jojojorisjhjosef
@jojojorisjhjosef 6 жыл бұрын
So is the 'windows server 2016' (the thing on the right in your connection diagram in the beginning of the video) a physical machine connected via Ethernet or can you have this as a virtual one in a virtual box? fyi im a total noob
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
The way it is implemented it acts as a physical machine. However, it is a virtual machine in Hyper-V connected to a physical switch through External Network Adapter. Wi-Fi modem is connected to the same physical switch.
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
Same thing can be achieved through Virtual Box as well with understanding of how the virtual network adapters work.
@jojojorisjhjosef
@jojojorisjhjosef 6 жыл бұрын
Thanks, first clarification on that on the internet.
@heribertonietoo1424
@heribertonietoo1424 2 жыл бұрын
The Radius server use user and password to sincronize with LDAP?
@vigneshthalamuthu5949
@vigneshthalamuthu5949 2 жыл бұрын
Have you configured NAT rule in your physical machine to enable connection for Hyper-V?
@TekNexSolutions
@TekNexSolutions 2 жыл бұрын
Using external virtual switch in Hyper-V which is connected to a physical switch.
@ArkaSatpathifindme
@ArkaSatpathifindme 3 жыл бұрын
Hey, Thanks for tutorial. Can I authenticate W-Fi(with certificate integrated) on a win 10 client present in Workgroup? Or is it a pre-requisite for the client to join a Domain?
@TekNexSolutions
@TekNexSolutions 3 жыл бұрын
Configuration requires either a user or machine authentication. User auth does not require the computer to be domain joined, but machine authentication needs the device to be domain joined.
@parasbc2288
@parasbc2288 2 жыл бұрын
what should i do if i already have DHCP from my firewall
@devidasalhat4573
@devidasalhat4573 Жыл бұрын
thank you for sharing this video, how can we create the policy when mobile device user authenticates with ID and password, after admin approval they can get the access. Because when i was created SSID with AD authentication our all employee uses same on mobile devices also and it is not good our security perspective. pls help in this
@TekNexSolutions
@TekNexSolutions Жыл бұрын
Create a security group and give that group access to Wi-Fi. End users can log a service request and admins can add them to the security group on the requests basis to give Wi-Fi access.
@roshanmenaka2996
@roshanmenaka2996 6 жыл бұрын
Hi Jay, Just another question if i plan AD in one server and NPS on another server what is the best practice to install CA? is it on AD server or NPS server ?
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
It is recommended to use a dedicated server for CA. Not recommended it to be a DC.
@roshanmenaka2996
@roshanmenaka2996 6 жыл бұрын
@@TekNexSolutions Hi Jay, in my scenario if i have a resources limitation what would be the best server to install CA . i only have server s for AD and NAS.
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
I would install CA on NPS Server.
@botak12312
@botak12312 3 жыл бұрын
How about for wired connection authentication with Windows Server?
@Reels9
@Reels9 3 жыл бұрын
If I change WPA password into radius password now I not able to connecting what I should do
@lubaorton6086
@lubaorton6086 5 жыл бұрын
Hello! I have configured it as in your video, but it fails to connect to Enterprise WiFi. I entered the credentials and press connect and then it switches back to enter the credentials again? I tried to connect on my PC/laptop/Android device, but it fails on every device. How to fix this issue? Thanks.
@TekNexSolutions
@TekNexSolutions 5 жыл бұрын
Hi Luba, I would suggest you to go over the video again and check if everything is done according to the video. It seems like you might have missed one or two things. Double check the things like network policy, permissions for AD groups etc.
@hennessy6996
@hennessy6996 6 жыл бұрын
Any one had problems getting this to work under Server 2K8 R2 with Windows 7 and/or Windows 10 clients? I believe I've followed all the steps clearly. Android mobile clients are authenticated, however my Windows clients keep asking for credentials over and over again. Any suggestions? As an FYI, none of the clients have ever joined the domain, but this is the same for the android devices. So I'm assuming I should not have any problems but I am unfortunately. Your video is very much detailed, thanks for the efforts and energies invested to create and publish.
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
You need to install Certificate manually in Win 7. As you can see in the video, Win 10 received the certificate as soon as I authenticated with the credentials.
@hennessy6996
@hennessy6996 6 жыл бұрын
@@TekNexSolutions Hi, is this approach confirmed? Is their not a way to have the certificate presented to the user automatically? I'm working on a solution to authenticate students via the Wi-Fi, with the accounts managed in AD.
@hennessy6996
@hennessy6996 6 жыл бұрын
@@TekNexSolutions Much thanks for the response thus far.
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
So far to my knowledge this is confirmed. However, I can double check with someone who works with Server 2K8. In production (Server 2016), we have the same issue where we have to install certificate manually on Win 7 machines. Fortunately, we have few(1 in 500) machines which fall under this category. If Android devices connect to the Wi-Fi through Radius then there is nothing wrong with the set up you have.
@omerozgun3403
@omerozgun3403 4 жыл бұрын
Can we authenticate users with radius coming as visitor and connect our wifi ?
@fareedahmedshah
@fareedahmedshah 21 сағат бұрын
Setting for android phone ? Kindly
@abdoucs3923
@abdoucs3923 6 жыл бұрын
Thank you for the tutorial. It's working fine with Dlink Ap and windiws srv 2012 standard. But the issue is not working for non domain pc.... Any help with that please?
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
Bagga caticoti abdou It should work for the non-domain pc’s. Check the following: 1. Have you tried the same user which you used for the domain joined pc? User has to be in the right group. 2. Try connecting any phone, your phone should connect to the wireless and it will get certificate from your CA. 3. If phone connects fine then re-install Wi-Fi driver on the non-domain join pc. Let me know how did you go.
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
Bagga caticoti abdou Also, use fully qualified domain name on the non-domain joined devices. For instance, if your domain is “test.com” and user is “user” then FQDN will be user@domain.com.
@abdoucs3923
@abdoucs3923 6 жыл бұрын
Hi Jay Maan Yes it is working fine with the smartphones but not for the laptops, I jave tried with two different laptops with win 10 installed but it did not work. I will try reinstalling the driver and check again. Thank you
@abdoucs3923
@abdoucs3923 6 жыл бұрын
Hello Finally it is working, 1- we have to Register NPS server on Active Directory 2-I did not use the wizard to create the policy, I have create it manually and specify the condition as "NAS port Type" and select "IEEE802.11 + Wireless Other" You don't have to use FQDN just type the username and the password Thank you again Jay
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
Bagga caticoti abdou sounds good. I am happy that it is working now.
@TheFredom1989
@TheFredom1989 5 жыл бұрын
Thanks for this demonstration. A research a possibility to have mutiple SSID depending of groups in AD. I think i need multiple radius server on my server (if it's possible) but i'v not yet find a way. If anyone have a idea... thank for it
@jerrysanchez8361
@jerrysanchez8361 Жыл бұрын
What if your DHCP server is elsewhere ?
@NoajmIsMyName
@NoajmIsMyName 10 ай бұрын
You are amazing!! Do you know why Android device connecting the WiFi ask weird question beside the username and password. Question about certificate
@TekNexSolutions
@TekNexSolutions 10 ай бұрын
Thanks. It is the OS, and it doesn’t pick the security requirements from the Wi-Fi.
@bansdeepsingh
@bansdeepsingh 6 жыл бұрын
Amazing stuff!!
@drakkeno
@drakkeno 5 жыл бұрын
il nostro prof. ci costringe a vedere sto video
@TekNexSolutions
@TekNexSolutions 5 жыл бұрын
Is it a good thing?
@TheJzee007
@TheJzee007 3 жыл бұрын
Thank you budy it helped a lot
@GelsonMwale
@GelsonMwale Жыл бұрын
Brilliant!
@scottfitzhugh9393
@scottfitzhugh9393 2 жыл бұрын
If my radius server is not a domain controller, how do I need to create the certificate? Do I create it on the domain controller, export it, and import it on the radius server? Or do I create a certificate locally on the radius server (the only cert option is 'Computer)'?
@TekNexSolutions
@TekNexSolutions 2 жыл бұрын
Here is a workaround they put in place techcommunity.microsoft.com/t5/windows-11/accessing-trials-and-kits-for-windows-eval-center-workaround/m-p/3361125.
@Wisdomisgood448
@Wisdomisgood448 3 жыл бұрын
I cannot get this to work with my Fortigate device at all.
@Hammouda-IT
@Hammouda-IT 4 жыл бұрын
very nice ... Thanks
@roshanmenaka2996
@roshanmenaka2996 6 жыл бұрын
Hi Jay, if we have number of APs (around 10-15) working in a single cluster. do we have to add each as a client in NPS clients ? or only master AP would enough ?
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
It depends on the capability of APs, if they can afford to do that. Otherwise, you might have to add one by one.
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
Do you already have those APs on hand or are you planning to do something like that?
@roshanmenaka2996
@roshanmenaka2996 6 жыл бұрын
Yes. I do already have Ruckus APs.
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
Oh nice. What model in particular?
@roshanmenaka2996
@roshanmenaka2996 6 жыл бұрын
R500.
@saqibshaikh6655
@saqibshaikh6655 10 ай бұрын
Hi, We have configured the Radius Server (NPS) for Wi-Fi authentication. However, we are currently experiencing an issue: when an Active Directory user's password expires, the Wi-Fi connection is disconnected. Upon attempting to re-authenticate, the system indicates incorrect credentials. We have enabled the setting to reset the AD user password in the Radius Server Policy, but our attempts to reset the password have been unsuccessful. Could you please assist us in resolving this issue?
@Newtttton
@Newtttton 10 ай бұрын
Are you using a cloud hosted VM as you radius server? like with Azure Domain Name Services?
@jasminescobar-tq2kr
@jasminescobar-tq2kr 2 жыл бұрын
i was able to get it to ask for user and password, but it will not authenitcate to get wifi access :(
@faizbhagett2241
@faizbhagett2241 Жыл бұрын
i follow step by step but does'nt work. i user radius server as server but not dc. In my enviornment, i have dc and member server radius server and unify network.
@TekNexSolutions
@TekNexSolutions Жыл бұрын
Must have missed something. I have added Unifi with same setup and works fine.
@dylandahie9765
@dylandahie9765 3 жыл бұрын
Thank you from France
@TekNexSolutions
@TekNexSolutions 3 жыл бұрын
You are welcome!
@sanzview3741
@sanzview3741 5 жыл бұрын
how to bind mac address for the users in AD
@BPITRohini
@BPITRohini 3 ай бұрын
I have configured the radius and NPS services by following the same steps but when try to connect Wi-Fi a error showing "unable to connected" kindly guide how to resolve this problem
@TekNexSolutions
@TekNexSolutions 3 ай бұрын
Check the steps again, must have missed something simple. The guide hasn’t changed for years.
@BPITRohini
@BPITRohini 3 ай бұрын
@@TekNexSolutions I checked all the steps from the video and reconfigure radius and NPS but the problem not resolve showing same error message when try to login
@nawalsingh2985
@nawalsingh2985 3 жыл бұрын
Hello I am not able to connect when i enter user name and password. Please help me.. I followed all the steps.
@ComSigma
@ComSigma 6 жыл бұрын
Great Video!!!
@zeddls6147
@zeddls6147 6 жыл бұрын
Hi, I have an issue with the certificate. The user connected just fine and have internet connection. But, the certificate is not showing up.
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
Hi Zedd, Sorry somehow I missed your question. Have you resolved this issue in question?
@zeddls6147
@zeddls6147 6 жыл бұрын
TekNex Solutions yes I do. I thought the certificate is not showing up. It did on windows 10 . I tested it on older windows beforehand. Anyway, thank you for doing this video. I easily learnt new things here
@TheAmazeer
@TheAmazeer 5 жыл бұрын
Hello thanks for your clear video.. I have a pb. I have installed every thing clean, but I want users to log via WiFi before they open a session on Windows... Clients are not logged with wire, they need to connect to WiFi first to have network, and then authenticate with Windows prompt login screen, which is 2 authentications... So bad idea.. Do you know how to connect to the Windows session through WiFi authentication? Thanks a lot if you have an answer dude 👍👍👍
@TekNexSolutions
@TekNexSolutions 5 жыл бұрын
You have to create a gpo. Allow user login only when DC is available. DC will only be available when device is connected to the network.
@IMRAN-AHMED-TECH-TALKS
@IMRAN-AHMED-TECH-TALKS 6 жыл бұрын
What will be the Network setting in Vmware 12 if we want to deploy it physical network thorough Vmware
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
IMRAN AHMED how many physical network cards you have?
@IMRAN-AHMED-TECH-TALKS
@IMRAN-AHMED-TECH-TALKS 6 жыл бұрын
Only one which is set as (bridged, replicate physical connection state) on Vmware
@mdnashrulikhwan5531
@mdnashrulikhwan5531 4 жыл бұрын
how can your router get dhcp from the server
@mnawaz7021
@mnawaz7021 2 жыл бұрын
Guys what computer should i use?
@kamranaslam5882
@kamranaslam5882 5 жыл бұрын
how can i use the same setup but without the users having to enter username and password? Basically only have provided them the certificate to authenticate.
@TekNexSolutions
@TekNexSolutions 5 жыл бұрын
What type of end users and devices we are looking at?
@ArshadSiddiquie
@ArshadSiddiquie 6 жыл бұрын
very nicely presented!
@TekNexSolutions
@TekNexSolutions 6 жыл бұрын
Thank you.
Configure Windows Server 2019 for Ubiquiti UniFi RADIUS Authentication
20:39
Alexander C. Hubbard
Рет қаралды 115 М.
Smart Sigma Kid #funny #sigma
00:33
CRAZY GREAPA
Рет қаралды 6 МЛН
Why no RONALDO?! 🤔⚽️
00:28
Celine Dept
Рет қаралды 83 МЛН
Миллионер | 3 - серия
36:09
Million Show
Рет қаралды 2,1 МЛН
Players push long pins through a cardboard box attempting to pop the balloon!
00:31
UniFi Network RADIUS Server
22:04
MrTimTech
Рет қаралды 8 М.
Wireless Radius Authentication with Windows Server 2016
18:08
Tech Pub
Рет қаралды 135 М.
28. Configuring RADIUS Authentication for VPN with NPS
20:52
MSFT WebCast
Рет қаралды 81 М.
Learn Windows Server DNS in Just 20min
20:49
Andy Malone MVP
Рет қаралды 94 М.
Securing RADIUS with EAP-TLS [Windows Server 2019]
39:18
OsbornePro TV
Рет қаралды 72 М.
802.1X | Authenticating Hosts | DrayTek, Cisco and Ruckus
21:01
SammytheSalmon
Рет қаралды 6 М.
Windows Server 2025 Is Here - But Should You Upgrade?
15:55
This Week in IT
Рет қаралды 6 М.
How to Secure Wi-Fi Network from Neighbors?
7:05
MalwareFox
Рет қаралды 54 М.
Smart Sigma Kid #funny #sigma
00:33
CRAZY GREAPA
Рет қаралды 6 МЛН