Go Back   Velocity Reviews > Newsgroups > Wireless Networking
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Wireless Networking - EAP-TLS and GPOs

 
Thread Tools Search this Thread
Old 11-09-2006, 04:39 PM   #1
Default EAP-TLS and GPOs


We have about 500 Cisco Wireless APs managed by a few controllers with
EAP-TLS authentication. Each workstation has a certificate installed to it
via GPO and each user must also install a certificate inorder to access the
wireless infrastructure. The issues which we are having are

1) Software deployed by GPO is not installing because the computer does not
have an IP at the time the software is installing -- pre-userlogin.
2) User's mapped drives are not getting mapped because the workstation is
not technicaly connected at the time of login.
3) Workstation login scripts are not running.

We rely very heavily on all three of these tasks in our environment. We have
experimented with KB Article http://support.microsoft.com/?id=840669 and the
value in HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon --
GpNetworkStartTimeoutPolicyValue. However, I am getting mixed results with
it. None of which apply or re-apply GPOs, software or scripts. It appears
that if it does not see a network, it does not wait for the network. We have
also set the GPO to Always Wait for Network before logging in but have not
seen this fix the issue etiher. Finally, we have set the cachedlogonscount
to 0 but cannot log in with a domain account at all.

Any suggestings for applying our GPOs over this type of wireless network?

Thanks.

Bart Perrier




Bart Perrier
  Reply With Quote
Old 11-09-2006, 06:09 PM   #2
OscarSotoCL
 
Posts: n/a
Default Re: EAP-TLS and GPOs
Bart

I think you need to use a third party Supplicant like Juniper (formerly
Oddysey) or Aegis.
Oddysey make a replacement in GINA to allow pre-user Authentication, in
order to the machines are authenticated before the user logins.

Hope this helps.

Oscar Soto Casali
MVP Directory Services


"Bart Perrier" <> escribió en el mensaje de
noticias:%23W% ...
> We have about 500 Cisco Wireless APs managed by a few controllers with
> EAP-TLS authentication. Each workstation has a certificate installed to it
> via GPO and each user must also install a certificate inorder to access
> the wireless infrastructure. The issues which we are having are
>
> 1) Software deployed by GPO is not installing because the computer does
> not have an IP at the time the software is installing -- pre-userlogin.
> 2) User's mapped drives are not getting mapped because the workstation is
> not technicaly connected at the time of login.
> 3) Workstation login scripts are not running.
>
> We rely very heavily on all three of these tasks in our environment. We
> have experimented with KB Article http://support.microsoft.com/?id=840669
> and the value in HKLM\SOFTWARE\Microsoft\Windows
> NT\CurrentVersion\Winlogon -- GpNetworkStartTimeoutPolicyValue. However,
> I am getting mixed results with it. None of which apply or re-apply GPOs,
> software or scripts. It appears that if it does not see a network, it does
> not wait for the network. We have also set the GPO to Always Wait for
> Network before logging in but have not seen this fix the issue etiher.
> Finally, we have set the cachedlogonscount to 0 but cannot log in with a
> domain account at all.
>
> Any suggestings for applying our GPOs over this type of wireless network?
>
> Thanks.
>
> Bart Perrier
>
>




OscarSotoCL
  Reply With Quote
Old 11-09-2006, 09:59 PM   #3
Bart Perrier
 
Posts: n/a
Default Re: EAP-TLS and GPOs
Our authentication is working correctly but my policies are not applying,
unless they are tatooed in the registry, and any new configuration we need
to deploy post-implementation, via script, GPO, or software deployment, is
not occuring.



"OscarSotoCL" <> wrote in message
news:...
> Bart
>
> I think you need to use a third party Supplicant like Juniper (formerly
> Oddysey) or Aegis.
> Oddysey make a replacement in GINA to allow pre-user Authentication, in
> order to the machines are authenticated before the user logins.
>
> Hope this helps.
>
> Oscar Soto Casali
> MVP Directory Services
>
>
> "Bart Perrier" <> escribió en el mensaje de
> noticias:%23W% ...
>> We have about 500 Cisco Wireless APs managed by a few controllers with
>> EAP-TLS authentication. Each workstation has a certificate installed to
>> it via GPO and each user must also install a certificate inorder to
>> access the wireless infrastructure. The issues which we are having are
>>
>> 1) Software deployed by GPO is not installing because the computer does
>> not have an IP at the time the software is installing -- pre-userlogin.
>> 2) User's mapped drives are not getting mapped because the workstation is
>> not technicaly connected at the time of login.
>> 3) Workstation login scripts are not running.
>>
>> We rely very heavily on all three of these tasks in our environment. We
>> have experimented with KB Article http://support.microsoft.com/?id=840669
>> and the value in HKLM\SOFTWARE\Microsoft\Windows
>> NT\CurrentVersion\Winlogon -- GpNetworkStartTimeoutPolicyValue. However,
>> I am getting mixed results with it. None of which apply or re-apply GPOs,
>> software or scripts. It appears that if it does not see a network, it
>> does not wait for the network. We have also set the GPO to Always Wait
>> for Network before logging in but have not seen this fix the issue
>> etiher. Finally, we have set the cachedlogonscount to 0 but cannot log in
>> with a domain account at all.
>>
>> Any suggestings for applying our GPOs over this type of wireless network?
>>
>> Thanks.
>>
>> Bart Perrier
>>
>>

>





Bart Perrier
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46