cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
729
Views
1
Helpful
3
Replies

Cisco 9800 SSID with NPS for Domain Joined Computers

mumbles202
Level 5
Level 5

Working on a 9800 configuration and have it setup w/ a radius server for 1 of the SSIDs.  That radius server is a Windows server w/ NPS and it's currently configured to only allow domain joined computers.  Created a GPO and assigned it to the correct OU and have validated that all is working. 

As the SSID is set to broadcast, a non-domain computer or smartphone can attempt to join, which fails.  If they keep trying to connect, they get a login prompt asking for username and password.  If they use valid credentials they're unable to login, which is expected; the question has been asked if it's possible to simply not display this prompt at all.  So if they keep trying nothing happens, they just fail to connect.

3 Replies 3

marce1000
VIP
VIP

 

 - Perhaps it could be possible to add a policy on the NPS server to deny non-domain devices  ,

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Rich R
VIP
VIP

I suspect this is a client behaviour rather than NPS.  You might be able so solve it with an exclusion policy on the WLAN.
https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9800-series-wireless-controllers/guide-c07-743627.html#Clientexclusion

JPavonM
VIP
VIP

As @Rich R says, this is Windows bvehaviour and cannot be modified, as Windows tries to use the login credential first and then ask for a new credential. Are you using PEAP only for authentication? If so try using EAP-TLS as NPS should be able to reject all connections without the proper certificate before asking for credentials.

Review Cisco Networking for a $25 gift card