Quantcast
Channel: Network Access Protection forum
Viewing all 1875 articles
Browse latest View live

Allow access to shared folders on server 2012 from workgroup users.

$
0
0

Thank you in advance.

I have setup a 2012 standard server, setup and am able to connect remotely with vpn. How ever users not connected to the domain are unable to open shared folders but users which are on the domain can. What do I need to do to give the non domain users access to their folders as when they connect directly onto the LAN they can open the shared folders but not through the VPN connection.

I am guessing it is a policy issue but am not sure, any help will be appreciated.


Network Policies Processing Order

$
0
0

Setup:

Unifi AP's connected to NPS running on Server 2012 R2.

Goal:

1. Laptop users to be able to connect to the production wireless network simply by having their computer accounts in an authorized group egCompany/Laptops

2. If your device is not in the said group (not an AD object in essence), promote for credentials from eg.Company/Authorized Users.

What so far:

I created a Network Policy with one of its conditions being that you have to be a member ofCompany/Laptops to be granted access to the wireless network. This works fine as laptop connect directly if authorized.

A second policy was created where the condition was you have to be a member ofCompany/Authorized Users.

Problem:

1. After implementing the second policy, which is 2nd in the processing order, even authorized laptop are prompted for credentials.

2. Devices not in the Company/Laptops group are not granted access at all.

802.1X NAP Setup

$
0
0

Defeated does not begin to describe my current situation, to a point wordings will not assist my cause. So here are screen shots (apologies in advance):

Radius Client:

Connection Request Policy (Processing No. 1)

Network Policy Settings:

NB:The user certificate as been successful autoenrolled to intended users.

Result:

NB: I am assuming if we have been prompted for credentials, the communication process is so far ok.

However:

I hope the pictorial illustration can successful substitute my word, for I have completely no idea what is wrong here.


Limited Access when connect to Wifi on Window Server 2012 R2

$
0
0

Hi everyone, i have a problem with wifi conection and i think it so strange.
I install window server 2012 r2 on my laptop and then active wireless LAN service follow this guide https://www.niallbrady.com/2012/09/01/how-can-i-manually-enable-wireless-networking-in-windows-server-2012/

it work ok but when i try connect to wifi, it always noticet that connection limited and wifi is broadcasted bymodem. The strangeness here is when i connect to wifi is broadcasted byMacbook is actualy ok, who can help me solve this prolem ?.
Sorry for my bad english, Thanks so much.

NAP Remediation

$
0
0

Hi All,

I'm setting up a NAP IPsec enforcement.

I can see that it's already working, the auto-remediation is working.

But my problem here is that when I try to apply the Anti Virus on SHV, it detects my test unit which doesn't have an Anti Virus, but it still connect on the Network.

Correct me if I'm wrong, but my understanding to this is that if the computer is non-compliant, it will have restricted access like it can't access the network, the internet, etc. Is that right? And if yes, what do you think I'm missing on my setup to restrict those non compliant computers?

I'm very new to this, please help me.

Thank you!

Radius Server SHA 256

$
0
0

I have a problem in my RADIUS server.

Here is the chronology in my client:

  1. We use RADIUS Server using SHA1 Certificate Algorithm to connect to WiFi. It works fine as long asthe user have SHA 1 in trusted Root, anduser account is in a certain group.
  2. We upgrade the certificate to SHA256.
  3. When we change the settings to SHA 256 in EAP Properties, somehowuser can connect to WiFi without using certificate.

Is there something miss in my configuration? Where should I start?

Thank You

Win7 not prompting to accept cert from NPS

$
0
0
We have Cisco WLC, MS NPS RADIUS server, and some clients doing WPA2-Enterprise authentication.
For some reason, all the endpoints work, except Win7 clients.

With either self, or public signed certs, Win7 would prompt for username/password, but after clicking OK, authentication would fail.

Win7 does NOT prompt for uer to accept cert, while NPS has a log saying cert is not trusted.
Why would Win7 not prompt for user to accept cert, and how do we enable that prompt?

NPS - RADIUS authentication works locally, but access-request identified as "malformed" when proxied over the WAN

$
0
0

Hi all,

We are using a pair of Microsoft 2012 NPS servers as RADIUS proxy servers, behind which are another pair of NPS servers as RADIUS authentication servers. Users on our local wireless network can authenticate via this infrastructure, using Active Directory accounts, without problems. Authentication is PEAP/EAP-MSCHAP v2.

However, the NPS infrastructure is also used when our users are at other organisations that offer the academiceduroam service, with their authentication requests being proxied back to our authentication servers. These roaming users are failing to authenticate nearly all the time, though occasionally a successful authentication is observed in the event viewer on the authentication servers. The failed authentication attempts typically generate an event viewer message:

Network Policy Server discarded the request for a user.

The reason in this event viewer message is given as:

The RADIUS Request message that Network Policy Server received from the network access server was malformed.

Because the authentication server discards the request and so does not respond to the proxy server, the proxy server also discards the request.

The problem is evident on RADIUS authentication servers running on both Windows 2008r2 and Windows 2012.

I'd be grateful for any advice on how to discover what it is that makes the authentication servers consider the access-requests as "malformed", or indeed what might be causing this for so many users when authenticating remotely over the WAN, even though local authentication is fine.

One possible problem is described in

https://technet.microsoft.com/en-us/library/cc755205(v=ws.10).aspx

We have applied the relevant configuration described in

https://technet.microsoft.com/en-us/library/cc771164(v=ws.10).aspx

but the problem remains.

There are also postings that suggest malformed requests can be related to server certificate issues, but I understand that if there were such an issue it would affect local authentication as well.

Thanks in advance for any help anyone can offer.

Stuart


Event 6273 Reason Code 8

$
0
0

Setup:

  1. Server 2012 r2 as a Active Directory DC, Certificate Authority and Network Policy Server.
  2. Auto enrollment of User, Computer and Workstation Authentication Certificates have been enabled and installed on all machines in the domain including the DC
    (PS: Not too sure which to use between Computer and Workstation Authentication certificate, so I selected both)
  3. Unifi AP's as RADIUS clients broadcasting wireless network configured with WPA2-Enterprise.
  4. A Grant Access Wireless Policy withConditions: Wireless Groups - Domain Users,NAS Port Type - Wireless IEEE 802.11 or Other, and Authentication Type -EAP, Constraints: Authentication Methods - Microsoft PEAP(CHAP and CHAPv2 unselected)

Problem:

  1. I connect to the wireless network, and it prompts for credentials.
  2. I use an account of authorized domain user and receive Can't connect to this network
  3. Event viewer as two events with the same 6273 number: one with Account Name ofhost/computer.domain and the other with Account Name domain\user,both with Reason: The specified user account does not exist. 

Help.

Server 2012 firewall to block all incoming traffic based on available computing resources

$
0
0
I am setting up a network commander, which main role is to run heavy calculation tasks, with windows server 2012 R2 firewall turned on. There is no other computer on the network. The computer is only set up as a network commander to use windows HPC job batch manager (requirement).
This computer only needs to communicate with the rest of the world when it has finished its heavy calculation tasks.
I'd like to set up my server 2012 firewall to block all traffic when the computer is running heavy calculation.

Scenario 1-I use Windows System Resource Manager to give priority to the computing tasks
During a calculation task, what will happen when the firewall doesn't have sufficient computing resources allocated to it:
-Does it simply block all traffic until compute resources are available again?
-Does this lack of resources create a security risk? or is security actually enhanced?

scenario 2-I automaticaly STOP the windows firewall service  when using the computer for heavy calculation task. I understand this is an unsupported state.
http://www.dell.com/support/article/au/en/aubsd1/SLN156677 says that the computer "will appear to other machines as though the server has been disconnected from the network", which is exactly the behavior I am seeking. I understand it doesn't get safer than this.
but https://technet.microsoft.com/en-us/library/cc766337(v=ws.10).aspx in CAUTION at the bottom of the page says that TURNING OFF the firewall service exposes my network to  "attacks that employ network fingerprinting". Is this also the case if I STOP the service?

Should I just try the above scenarios and run intrusion testing for both scenarios and see what happens?


NAP Remediation - IPsec OU Inquiry

$
0
0

Hi All,

Followed the Step-by-step NAP IPsec.

I build the OU for Secure and Boundary and put my NPS1 to Boundary OU and 2 Windows 7 client on Secure OU. 1 is non-compliant and 1 is compliant, what happens here is that when I try to ping Windows7(Non-Compliant) on my NPS Server the result is RTO when I ping Windows7(Compliant) on my NPS Server I can ping it, however when I'm on Windows7(Non-Compliant) unit and I ping every server on my network, I can ping them and remote them. What do I need to add on my configuration? I think it should be like Windows7(Non-Compliant) cannot ping and access every Compliant workstation and Servers but the result is different.

Another question is, do I really need to set my workstations firewall ON? because as per my boss requirement, the default policy is to turn off the Firewall.

Thank you!

How does NPS make NTLMv2 authentication for MSCHAPv2 packets

$
0
0

Hi,

I am wondering how MSCHAPv2 packets can be transformed to NTLMv2 authentication?

I know it can be done using the following:

https://support.microsoft.com/en-us/kb/2811487

Basically, I would like to do the same in NPS extension, is it possible?

Best regards,

Roman

Disable Smb v3

$
0
0
how to disable v3 on server 2012?

NAP Enforcements Inquiry

$
0
0

Hi All,

I have a question regarding all NAP Enforcement Method.

Do they all need to have the Firewall ON? Because as per step-by-step NAP IPsec, the IPsec policy for Boundary and Secure OU requires that Firewall is ON so the connectivity rule will be applied.

Thanks

NAP DHCP Enforcement Inquiry

$
0
0

Hi All,

First of all Sorry for so many questioned ask by me, I'm very new to this and given a minimum time to deploy this NAP thing.

I have AD server that also have DNS and DHCP role, and I have this RADIUS server which where I will setup as NAP Server also. And planning to deploy a NAP DHCP Enforcement. Is it possible that may NAP is different server from my DHCP? Because my Boss doesn't want me to use AD Server as my NAP Server.

Thank you.


UNC not supported and network access password??

$
0
0
I'm trying to network two computers in my office, making my computer the server for a software program we use for our business. The first problem is after I map the desired drive path, and download the software to computer #2, I am unable to use the program due to the drive path being invalid and that UNC is not supported.  I'm confused, I can access the files from my computer from C#2, but not the other way around. When I attempt to access c#2 through the network from my computer I'm prompted to enter a password to have access, which I don't have. HELP PLEASE!!

Add a change on my secondary NPS server.

$
0
0

Hello everyone,

Currently I work on backup radius and I want to duplicate/synchronize configuration on multiple server, but I don't want to reset the configuration on my secondary server each time (import/export etc), so is it possible to update the configuration on the slave server without erase and replace ?

Regards

IPSec Policy

$
0
0

Hi All,

I'm currently working for NAP IPsec Enforcement and recently saw this IP Security Policy in GPO, thinking this is the IPsec Policy mentioned in this thread :

https://social.technet.microsoft.com/Forums/en-US/ef4cecde-a43d-4d28-b476-b1fa6a460409/ipsec-nap-limited-network-access-is-not-very-limited?forum=winserverNAP

 and out of curiosity I assign one of the IP Security Policy created by default on that part and applied the second one

After I assign this and run gpupdate /force command on my NPS/NAP Server, I now cannot remote my NPS/NAP Server. Is there a way I can recover this? Or I can use it again?

Because on my WIN7 unit, I assign the 3rd policy, and same problem occurs, cannot remote it and it's like blocked on my domain, what I did is that I unjoin and rejoin my WIN7 unit then it is okay now, but I can't do it on my NPS/NAP Server since it have ADCS.

What would you recommend me to do for this? Or any workaround or solution for my NPS/NAP Server to be normalize again?

Thank you.


NPS Event 6723 Code 8

$
0
0

I receive this event twice in the NPAS event viewer:

Note:

  1. User MararoD is in a security group granted access as a Condition in the Network Policy.
  2. Certificate has successfully been auto-enrolled to the above user and valid.
  3. PEAP is the Authentication Method.

I've posted this question 3 times and still no help.

So, please, anyone, HELP!!

Windows server 2012 is not accessible and not visible on the network

$
0
0

Hi,

I have a small problem and i don't know how to resolve it, please help me.

I want to set up an file/printing server. I installed Windows Server 2012 Standard on a HP micro server, and here is my problem. I can't see the server on the network. The rest of the clients (laptops and desktops with windows 7/10) can see each other, can ping them self, can access, only the servers is the one that can't be accessed. Also from the server i can't see the rest of the clients. The network on the server is working, I can make internet browsing from it, also the client and the server are in the same VLAN. Only the router can see the server, from it I can ping the server and from the server I can ping the router.

Thank you

Best Regards

Viewing all 1875 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>