Wireless Controller and Microsoft Windows 2008 NPS

Hello Community,
Got a Nightmare project to convert our Wireless over to Windows 2008 NPS for AP, Controller and User Athenication.  Anyone have a link to a good Deployment Guide/How To on what is needed for the NPS Server (esp the attributes for AP, Contoller and Users)?
Thank You
Michael

So you are looking to use RADIUS to authenticat the managment users and the actual wireless clients?
RADIUS Managment
http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a0080782507.shtml
This goes over what attribute you need to return from the RADIUS server.
For the users:
http://www.cisco.com/en/US/products/ps10315/products_configuration_example09186a0080bfb19a.shtml
HTH,
Steve
Please remember to rate useful posts, and mark questions as answered

Similar Messages

  • 802.1x PEAP Windows 2008 NPS Certificate

    I've setup a centrally switched SSID on a 5508 WLC utilising 802.1x PEAP authentication to a pair of Windows 2008 NPS which authenticate the PEAP username and password to our Active Directory domain.
    Currently the Windows 2008 NPS servers are utilsing a server certificate issued from our internal Certificate Authority with the certificate being presented to the device upon connection depending upon which server the WLC sends the authentication too. The servers names on the internally issued certificate are in the form of:
    Server01.domain.local
    Server02.domain.local
    Due to these certificates being internally issued certificates when some devices specifically Apple iPad and iPhones connect to the SSID initally they are prompted to accept the certificate but it is listed as not verified as its issued by an internal domain CA and not an external root certificate authority.
    I am going to be obtaining an external root CA issued certificate for both servers to replace the internally issued certifcates however I notice using the internal certificate if I connect a device to the SSID and accept the certificate of server with certificate name server01.domain.local and then if disable the ability for clients to connect to server01 the WLC will automatically forward the authentication connection to the next server on the list however as this server is presenting a different certificate "server02.domain.local" devices which are conducting certificate validation will fail to connect as the certificate does not match the previously accept certificate.
    Does anyone know a way around this?
    Will adding say server02.domain.local as an additional name to the certificate for server01.domain.local resolve this issue?

    Hi,
    Please confirm the Win7 clients has renew the certificate and deleted the old certificate. And confirm you are not using the default server certificate template.
    More information:
    Renew a Certificate
    http://technet.microsoft.com/en-us/library/cc730605.aspx
    NPS Server Certificate: Configure the Template and Autoenrollment
    http://msdn.microsoft.com/en-us/library/cc754198.aspx
    Hope this helps.
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Language change on my microsoft windows 2008

    i want to change the language of my microsoft windows 2008 on my macbook from Norwegian to English? what sould i do, i really need your help.

    I've never heard of anything called "Windows 2008".  There's 98, NT, 2000, XP, Vista, 7, and 8.  Could you give more detail about what exactly you are talking about?
    http://en.wikipedia.org/wiki/Microsoft_Windows
    I think you would have to ask on a Windows forum, as it has nothing to do with the Mac.  I know some Windows versions only come in one language at a time, so you have to get a separate version to change it.  But it may be easier with the newer ones.

  • Monitoring Microsoft Windows 2008 Active Directory by a remoted Agent

    Oracle documentation (E14542-01) said that for remote Agent monitoring with default settings, Grid Control can monitor only the Active Directory associated with the primary domain controller.
    But for Microsoft Windows 2008 Active Directory primary domain doesn't exist anymore, can we use a remote Agent to monitor Microsoft Windows 2008 Active Directory ?
    Thanks
    Dominik

    Dominik wrote:
    Oracle documentation (E14542-01) said that for remote Agent monitoring with default settings, Grid Control can monitor only the Active Directory associated with the primary domain controller.
    But for Microsoft Windows 2008 Active Directory primary domain doesn't exist anymore, can we use a remote Agent to monitor Microsoft Windows 2008 Active Directory ?I think , you can monitor it . Please check :
    Oracle Enterprise Manager Grid Control Certification Checker [ID 412431.1]
    How to Install the Microsoft Active Directory Plugin for Grid Control R2 [ID 359621.1]
    Regards
    Rajesh

  • Lost program icons Microsoft word 2008 and Microsoft excel 2008

    Hi I accidently turned Microsoft excel 2008 and microsoft word 2008 into wads of trash that disappeared when I accidnetly clicked the icons and moved them from the dock into the internet box.  I talked to one person already but can't seem to get back to them and he suggested that I use MIcrosoft Office 2008 but hte problem is is that I don't have it anymore because I deleted the program from my computer a few days ago (yesterday or the day before)  I had originally bought hte program from Best Buy and downloaded it from a disc but  I can't find the disc anymore.  Do you know what  I can do to recover the programs I checked the applications, office (of course, and word and excel 2008 aren't there and they aren't in the trash I checked there too.  I thought that it might be on my back-up time machine?  And I also couldn't go to undo to change what happened.  Thank you.

    Things just don't disappear. If you didn't put them in the trash, they must be there somewhere. Click the magnifying glass at the top right side of your screen and search for Microsoft Office and see if you can locate the folder. Also, I'm wondering if you actually installed office or if you were just running it from the downloaded .dmg file? When doing the search, keep an eye open for a Microsoft Office 2008 DMG file.

  • Non iCloud contact sync not working with iPhone 4S and Microsoft Windows/Outlook

    Trying to sync contacts without success! Have iPhone 4S and Microsoft Windows, not using iCloud.  I've gone through the Info route and told it to sync but the data doesn't transfer.  Any idea why?

    what version of Outlook are you using. I know right now its not compatible with Outlook 2013.

  • Difference between Microsoft Windows NT Workstation 6.1 (Tablet Edition) and Microsoft Windows NT Workstation 6.1

    I am trying to pull a report for all Windows 7 machines. But, i could find 2 attributes in view V_r_system that are operating_system_name_and0 and operatingsystem0 where I can get the OS information. Few machines are showing as "Microsoft Windows NT
    Workstation 6.1" on operating_system_name_and0 and few are "Microsoft Windows NT Workstation 6.1 (Tablet Edition)".
    I am so curious to know about "Microsoft Windows NT Workstation 6.1 (Tablet Edition)", so I just compared those machines with V_GS_Computer_system view to know whether these machines are a normal Laptop or Tablet based laptop. But, those are ALL
    NORMAL LAPTOPS ONLY. however, those machines OSes are showing as "Microsoft Windows NT Workstation 6.1 (Tablet Edition)".
    But, the build numbers and OS versions are same as "Microsoft Windows NT Workstation 6.1" machines. So,
    I could not find any difference between "Microsoft Windows NT Workstation 6.1" machines and "Microsoft Windows NT Workstation 6.1 (Tablet Edition)" machines in terms of models number , OS build number.
    Could someone of you please why the operating_system_name_and0 attribute shows as "Microsoft Windows NT Workstation 6.1 (Tablet Edition)" for part of the machines.

    Thanks for your reply.
    How do we check without RDP on those machines? Because, I have around 11,000 machines which are showing as "Microsoft
    Windows NT Workstation 6.1 (Tablet Edition)" out of 40,000 machines. 
    Is there a way to find that touch screen info in SCCM DB or somewhere?

  • Microsoft Windows 2008 Server and RDC

    hi:)
    We have a fairly serious problem. Many of our customers have a Microsoft Windows Server 2003 running our ASP web solution on that machine. In this web solution we use RDC (crystal) to show reports on the net, which works perfectly. But now a couple of our new customers have installed Microsoft Windows Server 2008 32 bit and 64 bit version. But when we are showing these reports on a Windows Server 2008, the result is not correct. It show a completely wrong result in the reports. This meaning showing 4 timers the records it should do.
    Do u support Windows Server 2008 32 bit and 64 bit with RDC (crystal) ?
    Have anyone experienced the same problem?
    Sincerly Jan Tovgaard, Egdatainform, DK

    Hi Jan
    CR XI, CR XIR2 and CR 2008 have not been tested with Microsoft Windows Server 2008 and MS Windows Server 2008 would be added to the supported platforms Guide when it is done.
    Please refer to the Supported Platforms Guide for CR XI, CR XIR 2, CR 2008 for more information. 
    Hope this helps!!!
    Regards
    Sourashree

  • Cisco wireless controller and AP-binding domain how do you integrate wireless domain authentication?

    With Cisco equipment wlc 2500 and AP 1600 combines windows 2008 r2 domain controller to achieve the following purposes, 
    1, all cell phones and laptops can access the wireless network with a domain user authentication. 
    2, the guest network should how to do it? 
    My idea is: 
    Made a total of two ssid below 
    Mobile users cnnewcity_mobile: Use webportal certification, so the center certification, local forwarding 
    Computer users cnnewcity_wifi: transparent certification, local forwarding, local authentication 
    The basic steps are as follows: 
    1, set the Radius server clients (AP or controller) 
    2, locking authorization group --- this should be based on the domain user group authorization radius server 
    3, the mobile roaming - different locations on the DHCP server choose to do this you have to consider the next 43 
    4, the establishment of a two vlan to a mobile user to the computer user, create a DCHP scope on the DHCP
    I do not know if you have wood there are better ways?

    Integrating the AD to the WLC Requires:
    1. AD to be registered:
     AT: Security->AAA
        AT: LDAP     
        CLICK: New
        Server IP:    <AD IP>
        Port Number:    389     
        Simple Bind:    Authenticated
        Bind User:    CN=Administrator,CN=Users,DC=testing,DC=local,DC=com
        Bind Pass:    <LDAP Admin pass>
        Confirm Pass: <LDAP Admin pass>
        User Base DN:    OU=WebAuth_Users,DC=testing,DC=local,DC=com
        User Attrib:    sAMAccountName      
        User Obj. Type:    person        
    Enable at WLAN Profile
    1. AT: WLAN->WLANs
        CLICK: <Desired WLAN> -typically web authentication
    2. AT: Security Tab
        AT: AAA Servers
    3. AT: LDAP Servers
        **Select Created LDAP
    4. Apply to Save
    Source: Tried it in implementations :))

  • Wireless mouse and keyboard Windows 7

    I successfully installed Windows 7 (32 bit) on Apple boot camp (3.2) of my iMac 24.
    Everything is working perfectly, except my wireless Magic mouse and wireless keyboard.
    I found 2 Bluetooth adapters (Generic Bluetooth adapter and Microsoft Bluetooth-enumerator).
    The mouse and keyboard are found but won't install!
    What am I doing wrong?

    Try to use this guide to install your keyboard and mouse (mouse is the same as keyboard)
    http://www.tenniswood.co.uk/technology/how-to-pair-an-apple-wireless-keyboard-wi th-windows-7/?utmsource=feedburner&utm_medium=feed&utmcampaign=Feed:tenniswood(TenniswoodBlog)&utm_content=GoogleReader

  • Unable to Install KB 3001652, 2961149. and 2796590 (Windows 2008 R2 Systems Not Connected to the Internet)

    To Anyone That Can Help,
    I'm on a set of WSUS enabled Windows 2008 R2  servers with no network access to the Internet and I am unable to  install the following:
    Update for Microsoft Visual Studio 2010 Tools for Office Runtime
    KB's 300162, KB 2961149. and KB 2796590
    Equally as painful, I am unable to find anything that helps.
    Any ideas...???
    Roderick Lyons

    The above from Don Pick pointed me to the answer!!!!
    1) obtained the actual update files (KB2796590,KB2961149,and KB3001652) from my Infrastructure Team WSUS Administrators (download is also available from Internet)
    2)
    Ran the update, which of course blew an error
    3) Clicked the error log file which gave me the following:
           Summary:Failed with error 0x800B010A (A certificate chain could not be built to a trusted root authority)
           file signature could not be verified
    4)https://support.microsoft.com/en-us/kb/2746268
    5)https://gallery.technet.microsoft.com/Configuring-Trusted-Roots-281be43a#content
    For all supported x64-based versions of Windows Server 2008 R2
    (The file was actually already installed)
    6) Executed the repair from step 4
    7) All updates (KB2796590,KB2961149,and KB3001652) installed without incident!!!
    Thanks All!!!
    Roderick Lyons

  • Network home folders, collaboration sharepoint and Microsoft Word 2008

    I'm hoping someone who knows how Microsoft Word 2008 works on network volumes can shed some light on our situation.
    We run a small managed network with about 15 leopard clients and a leopard server. We've got two sharepoints, a "homes" share for network home folders, and an "Office" share with our shared office document folders.
    Several times a week, users will encounter a situation where Microsoft Word 2008 will claim that a file is open by another user, or that the file can be opened in "read only" mode, even though the file is not in use. Naturally, the problem cannot be replicated when I am present.
    ### My Hypothesis ###
    My users are in the habit of quickly borrowing machines from other users to pull up documents in the "office" share by using the "connect as" button. So, for example, userA is logged in to her machine (and is thus connected to the network home folder on the server). userB comes along and borrows her machine -- without logging out, will connect to the shared office folder, pull up and edit/print a document, etc. We're not currently auto mounting the office share.
    I know that Microsoft Word creates lock folders located in the .TemporaryItems folder at the root level of the "office" share. The folders are named "folder.xxxx", where xxxx is the userid of the account that created the lock folder. Everyone uses a network account, so everyone has a unique userID. If I list the .TemporaryItems folder using the CLI, i can see lock folders that are several days or a week old. So Word doesn't seem to be cleaning up after itself immediately, at least not always.
    So my question: when userB connects to the office share on a borrowed machine (logged in to the client machine using the network home folder of userA), is it possible that word will now create lock folders for userB, and will be unable to clean up lock folders created by userA?
    Anyone have other ideas for investigating the "file in use" problem?

    Switched user back to the network home folder and adjusted the MS Word preferences so that the autorecovery files would be stored on the local client machine. There doesn't seem to be a comparable setting in the Excel preferences.
    My initial testing suggests that this has reduced how often this problem occurs, but has not eliminated it. I tested by repeatedly opening and closing a couple of different word files in rapid succession -- i was able to replicate the "file opens as read only" problem occasionally.
    I've talked to Apple server support about this issue. While they were helpful, they didn't have an explanation or solution for this problem. There are a number of postings in the microsoft mactopia discussion boards site where people report similar problems.

  • Problems between a Wireless Controller and a Switch.

    I have a Wireless Controller 4402 connected to one sw2960G.
    I configured the controller with LAG and the switch (sw2960G) with etherchanel.
    I connected the controller 2 distribution ports to the 2 ports of the switch (configured with etherchanel).
    It worked like it should work.
    But the problem is like this: if I take one cable that is connected to the switch and unplugged that cable from the switch (if that cable is the one connected to controllers port one) I have connectivity between both machines.
    If I plug in the switch the cable connected to controller port one and take the other cable and unplugged that cable from the switch I stop the connectivity between the two machines.
    I think that was not supposed to happen… because the LAG in the controller should put every AP in the second controller's port, and the connectivity between the machines should not end.
    Can any one help me?
    Can any one tell me what I am doing wrong?
    Thanks in advance,
    Rui

    With LAG enabled in the controller I think I can have only one ap-manager interface.
    The LAG will (it is supposed to) do the load balance automatically.
    I mean, if one of the interfaces is “down” the other will have to coupe with all the AP's.
    I should have always connection between the controller and the switch.
    The STP of the controller is configured by default (STP Mode = OFF).
    In the case of etherchannel load balance… I saw the Cisco documentation and I did not saw any thing about that. I think that The LAG as to do that for the controller… I'm right about that?
    I will see the link that you advised…
    Can you help me?
    Thanks,
    Rui

  • Crystal x and iis7 windows 2008

    I am upgrading to a new box that haas windows server 2008 and iis7.  My sql 08 backend server is on another box running windows 2008.
    I currently have my live environment working which is using iis 6 with the same backend sql server and all is working fine.
    When I run the crystal report x from the crystal designer on the new 08 box I am able to generate the report no problem.
    However, when I run my application with a crystal report viewer I am getting the logon prompt (no matter what credetials i use I can't continue).  The rest of my app works fine and i am able to retrieve data from my sql server.
    Is there something I have to change about iis 7 like with sql reporting services in order to get crystal to work with iis 7.

    Only CR 10.5 and CR 12.x is supported on Win 2008. See [this|https://wiki.sdn.sap.com/wiki/display/BOBJ/CrystalReportsassemblyversionsandVisualStudio+.NET] wiki for more details.
    Ludek

  • Question about Wireless Controller and LAG.

    I have a Wireless Controller 4400.
    When I configure the controller with LAG, I have to connect the controller to a L3 switch?
    If I connect the controller to a L2 switch the LAG works?
    Some one can tell me something about this?
    Thanks in advance,
    Rui

    Copper? so you are using rj-45 Gb SFPs on the controller. If that is the case, what is the speed of the switchports on the 2960?
    I use the rj-45 Gb SFPs on our 4402s and they work fine connected to Gb rj-45 ports on the switches.
    Also, check out the following:
    http://www.cisco.com/en/US/docs/wireless/controller/4.2/configuration/guide/c42mint.html#wp1116136
    "Using the CLI to Verify Link Aggregation Settings
    To verify your LAG settings, enter this command:
    show lag summary
    Information similar to the following appears:
    LAG Enabled
    Configuring Neighbor Devices to Support LAG
    The controller's neighbor devices must also be properly configured to support LAG.
    •Each neighbor port to which the controller is connected should be configured as follows:
    interface GigabitEthernet
    switchport
    channel-group mode on
    no shutdown
    •The port channel on the neighbor switch should be configured as follows:
    interface port-channel
    switchport
    switchport trunk encapsulation dot1q
    switchport trunk native vlan
    switchport trunk allowed vlan
    switchport mode trunk
    no shutdown

Maybe you are looking for

  • IPhoto Locks Up

    Here is what happens (iPhoto 6.02 and OS 10.4.6): 1) iPhoto starts and organizes itself, then after a few seconds it send up the "Alert...the movie x or photo y could not be opened, because the original item cannot be found." 2) I find the photo. It

  • Jar file download

    I have an applet served from orion application server. There are several Jar files that need to be downloaded to the client in order for the application to work. I noticed in JRE 1.3.1 when a Jar file was downloading a pop up with status Bar appeared

  • Template Error Msg

    Hey there folks, I've run into an odd problem with the a layout template I created off the index file I made for the portfolio website I wish to make, and have 'dummy' index files for all of the relevant folders ready for the template to be applied t

  • L540 ExpressCard Slot

    I am very disappointed in my L540 design quality.  It comes with the ExpressCard slot, but no dummy or door on the slot.  Therefore, I have a huge gaping hole in the side of my laptop.  I thought this was a manufacturing defect, so I took my laptop t

  • Web Services Management tools

    Given the capabilities of the WebLogic Enterprise Platform™ to build, deploy, manage, and integrate enterprise-class Web Services, is there still a need for Web Services Management tools like Talking Blocks, Interkeel, West Global, Infravio, etc., or