Wireless Authentication via AD?

G

Guest

Guest
Archived from groups: microsoft.public.windows.networking.wireless (More info?)

I'm new to the wireless security world other than the basic stuff
(hide SSID, WEP). I want to add a WAP to my network for a few laptop
users. I have a Windows 2003 Active Directory domain and would like
wireless users to authenticate via Active Directory to gain access to
the network. Is that possible? How would I do that (overview is
fine)? Thanks guys. -Mike.
 

Niklas

Distinguished
May 25, 2004
23
0
18,510
Archived from groups: microsoft.public.windows.networking.wireless (More info?)

By using a radius server (ms IAS) you can use peap-ms-chap v2 to
authenticate aginst the AD.

Look at "Deployment Resources" in the link below. There is a step-by-step
guide to set up the environment.
http://www.microsoft.com/windowsserver2003/technologies/networking/wifi/default.mspx

"LiquidNoize" <mike.made@att.net> wrote in message
news:d0d6d39d.0408091856.54414d23@posting.google.com...
> I'm new to the wireless security world other than the basic stuff
> (hide SSID, WEP). I want to add a WAP to my network for a few laptop
> users. I have a Windows 2003 Active Directory domain and would like
> wireless users to authenticate via Active Directory to gain access to
> the network. Is that possible? How would I do that (overview is
> fine)? Thanks guys. -Mike.
 
G

Guest

Guest
Archived from groups: microsoft.public.windows.networking.wireless (More info?)

Thanks Niklas. I'll look over that. Can I use any WAP? I was
thinking about trying the Linksys WAP first because of the price.

"Niklas" <niklaso@nospamhotmail.com> wrote in message news:<unV4rTqfEHA.1656@TK2MSFTNGP09.phx.gbl>...
> By using a radius server (ms IAS) you can use peap-ms-chap v2 to
> authenticate aginst the AD.
>
> Look at "Deployment Resources" in the link below. There is a step-by-step
> guide to set up the environment.
> http://www.microsoft.com/windowsserver2003/technologies/networking/wifi/default.mspx
>
> "LiquidNoize" <mike.made@att.net> wrote in message
> news:d0d6d39d.0408091856.54414d23@posting.google.com...
> > I'm new to the wireless security world other than the basic stuff
> > (hide SSID, WEP). I want to add a WAP to my network for a few laptop
> > users. I have a Windows 2003 Active Directory domain and would like
> > wireless users to authenticate via Active Directory to gain access to
> > the network. Is that possible? How would I do that (overview is
> > fine)? Thanks guys. -Mike.
 
G

Guest

Guest
Archived from groups: microsoft.public.windows.networking.wireless (More info?)

Also, can I use IAS as a standalone server? In other words, do I need
a AD domain to be able to authenticate wireless users via IAS? or can
I just use local accounts?

"Niklas" <niklaso@nospamhotmail.com> wrote in message news:<unV4rTqfEHA.1656@TK2MSFTNGP09.phx.gbl>...
> By using a radius server (ms IAS) you can use peap-ms-chap v2 to
> authenticate aginst the AD.
>
> Look at "Deployment Resources" in the link below. There is a step-by-step
> guide to set up the environment.
> http://www.microsoft.com/windowsserver2003/technologies/networking/wifi/default.mspx
>
> "LiquidNoize" <mike.made@att.net> wrote in message
> news:d0d6d39d.0408091856.54414d23@posting.google.com...
> > I'm new to the wireless security world other than the basic stuff
> > (hide SSID, WEP). I want to add a WAP to my network for a few laptop
> > users. I have a Windows 2003 Active Directory domain and would like
> > wireless users to authenticate via Active Directory to gain access to
> > the network. Is that possible? How would I do that (overview is
> > fine)? Thanks guys. -Mike.
 

Niklas

Distinguished
May 25, 2004
23
0
18,510
Archived from groups: microsoft.public.windows.networking.wireless (More info?)

WAP=wireless access point? :)
In theory they should all support the same standard, but I have noticed my
cisco adapter will make my access point (belkin 7130) to stop function and I
had to restart it, but I havn't had any problem with my linksys WAP54g
(though I have only tried with a few different adapters) but if possible
stick with the same manufacturer with both WAP and adapters (ofcourse this
is just my opinion).

/Niklas

"LiquidNoize" <mike.made@att.net> wrote in message
news:d0d6d39d.0408100622.52c692c8@posting.google.com...
> Thanks Niklas. I'll look over that. Can I use any WAP? I was
> thinking about trying the Linksys WAP first because of the price.
>
> "Niklas" <niklaso@nospamhotmail.com> wrote in message
news:<unV4rTqfEHA.1656@TK2MSFTNGP09.phx.gbl>...
> > By using a radius server (ms IAS) you can use peap-ms-chap v2 to
> > authenticate aginst the AD.
> >
> > Look at "Deployment Resources" in the link below. There is a
step-by-step
> > guide to set up the environment.
> >
http://www.microsoft.com/windowsserver2003/technologies/networking/wifi/default.mspx
> >
> > "LiquidNoize" <mike.made@att.net> wrote in message
> > news:d0d6d39d.0408091856.54414d23@posting.google.com...
> > > I'm new to the wireless security world other than the basic stuff
> > > (hide SSID, WEP). I want to add a WAP to my network for a few laptop
> > > users. I have a Windows 2003 Active Directory domain and would like
> > > wireless users to authenticate via Active Directory to gain access to
> > > the network. Is that possible? How would I do that (overview is
> > > fine)? Thanks guys. -Mike.
 

Niklas

Distinguished
May 25, 2004
23
0
18,510
Archived from groups: microsoft.public.windows.networking.wireless (More info?)

There is a newsgroup called microsoft.public.internet.radius where I think
you will find the best answers.
I'm not sure with the local users, there are a two options to authenticate
with the IAS either using peap-ms-chap which uses "domain\user" and password
to authenticate, the other is EAP-TLS which uses certificates and with that
I don't think you would need a AD. But if you can't find the answer, ask in
the mentioned newsgroup.

/Niklas

"LiquidNoize" <mike.made@att.net> wrote in message
news:d0d6d39d.0408101357.28d16626@posting.google.com...
> Also, can I use IAS as a standalone server? In other words, do I need
> a AD domain to be able to authenticate wireless users via IAS? or can
> I just use local accounts?
>
> "Niklas" <niklaso@nospamhotmail.com> wrote in message
news:<unV4rTqfEHA.1656@TK2MSFTNGP09.phx.gbl>...
> > By using a radius server (ms IAS) you can use peap-ms-chap v2 to
> > authenticate aginst the AD.
> >
> > Look at "Deployment Resources" in the link below. There is a
step-by-step
> > guide to set up the environment.
> >
http://www.microsoft.com/windowsserver2003/technologies/networking/wifi/default.mspx
> >
> > "LiquidNoize" <mike.made@att.net> wrote in message
> > news:d0d6d39d.0408091856.54414d23@posting.google.com...
> > > I'm new to the wireless security world other than the basic stuff
> > > (hide SSID, WEP). I want to add a WAP to my network for a few laptop
> > > users. I have a Windows 2003 Active Directory domain and would like
> > > wireless users to authenticate via Active Directory to gain access to
> > > the network. Is that possible? How would I do that (overview is
> > > fine)? Thanks guys. -Mike.
 
G

Guest

Guest
Archived from groups: microsoft.public.windows.networking.wireless (More info?)

Thanks man.

"Niklas" <niklaso@nospamhotmail.com> wrote in message news:<u1F9rR3fEHA.3676@TK2MSFTNGP12.phx.gbl>...
> There is a newsgroup called microsoft.public.internet.radius where I think
> you will find the best answers.
> I'm not sure with the local users, there are a two options to authenticate
> with the IAS either using peap-ms-chap which uses "domain\user" and password
> to authenticate, the other is EAP-TLS which uses certificates and with that
> I don't think you would need a AD. But if you can't find the answer, ask in
> the mentioned newsgroup.
>
> /Niklas
>
> "LiquidNoize" <mike.made@att.net> wrote in message
> news:d0d6d39d.0408101357.28d16626@posting.google.com...
> > Also, can I use IAS as a standalone server? In other words, do I need
> > a AD domain to be able to authenticate wireless users via IAS? or can
> > I just use local accounts?
> >
> > "Niklas" <niklaso@nospamhotmail.com> wrote in message
> news:<unV4rTqfEHA.1656@TK2MSFTNGP09.phx.gbl>...
> > > By using a radius server (ms IAS) you can use peap-ms-chap v2 to
> > > authenticate aginst the AD.
> > >
> > > Look at "Deployment Resources" in the link below. There is a
> step-by-step
> > > guide to set up the environment.
> > >
> http://www.microsoft.com/windowsserver2003/technologies/networking/wifi/default.mspx
> > >
> > > "LiquidNoize" <mike.made@att.net> wrote in message
> > > news:d0d6d39d.0408091856.54414d23@posting.google.com...
> > > > I'm new to the wireless security world other than the basic stuff
> > > > (hide SSID, WEP). I want to add a WAP to my network for a few laptop
> > > > users. I have a Windows 2003 Active Directory domain and would like
> > > > wireless users to authenticate via Active Directory to gain access to
> > > > the network. Is that possible? How would I do that (overview is
> > > > fine)? Thanks guys. -Mike.