Tuesday, June 25, 2019

Want to test cert auth instead of domain credentials via GPO/NPS?

Hi everyone,

Quick question! I recently set up our company's NPS server and created a few new SSIDs on our WLCs. They are mimics of our old setup on another domain and currently we have one corporate SSID using mac filtering (I know... it sucks) and all use domain username and password for auth.

After doing some research I would love to use cert based, automatic joining for laptops to this/these SSIDs. I've read a couple articles on how to accomplish this but I would preferably like to test this out before mucking with production. Am I correct in assuming the following that I can test this out and not affect the production wireless SSIDs by doing the following:

  • create a new Network and Connection Request Policy for cert based auth
  • create a new TEST SSID on the WLC to... test with ;)
  • create a new Security Group in AD with some domain computers (laptops)
  • create a GPO(s) to add the cert and configure the computers to auth automatically using the cert

I'm mostly concerned with the first two bullets. I want to make sure I can create new, separate policies within the NPS server to test the cert based auth without affecting the current SSIDs everyone is using which utilize domain credential auth. Thanks everyone!



No comments:

Post a Comment