Networking Forums

Networking Forums > Computer Networking > Windows Networking > How to have access to recources without adding laptops to domain?

Reply
Thread Tools Display Modes

How to have access to recources without adding laptops to domain?

 
 
Joris van der Struijk
Guest
Posts: n/a

 
      02-04-2006, 12:05 PM
We are having trouble creating following scenario.

A lot of students at our campus are using there laptops when not in class
and even during lessons.
All students have an account in our Windows 2003 Active Directory.

We want to provide the student with access to our network recources WITHOUT
adding all those laptop computer accounts to our AD. This would be a lot of
work, and student won't be happy having to add the home laptop to our domain.

What we want:
No laptop computer accounts.
As secure as possible (ea. PEAP with MS-CHAP v2).
Authentication should be based on the user account of the students, already
present in AD.
We would like some kind of system where we provide the student with
instructions of some sort. When setup correctly and the client is connecting
he is provided a login screen where he/she has to enter the students AD user
and password.

Our infrastructure contains several Cisco 1100 AP's, IAS radius server, 2003
Servers.

Hope to find some concrete info here.

Grx,
Joris
 
Reply With Quote
 
 
 
 
BerkHolz, Steven
Guest
Posts: n/a

 
      02-04-2006, 05:50 PM
(Wired) If they go to Start, Run, and type in \\Servername\sharename, Enter, They will be prompted for their name and password.
They need to enter their username as Domain\Username, and they will connect.

As for the PEAP issue, whey will have to have driver that support it.
And because their computer are not on the Domain, they will not have he required certificate.
You will have to publish the certificate on a non secured network, or floppy\CD, etc. so they can install it on their Laptops.

--
--
Steven

May you have the peace and freedom that come from abandoning all hope of having a better past.
--- - --- - - - - - - - -- - - - --- - ------ - - --- - - -- - - - -- - - -
"Joris van der Struijk" <(E-Mail Removed)> wrote in message
news:559EA849-DAE3-4A9C-9968-(E-Mail Removed)...
> We are having trouble creating following scenario.
>
> A lot of students at our campus are using there laptops when not in class
> and even during lessons.
> All students have an account in our Windows 2003 Active Directory.
>
> We want to provide the student with access to our network recources WITHOUT
> adding all those laptop computer accounts to our AD. This would be a lot of
> work, and student won't be happy having to add the home laptop to our domain.
>
> What we want:
> No laptop computer accounts.
> As secure as possible (ea. PEAP with MS-CHAP v2).
> Authentication should be based on the user account of the students, already
> present in AD.
> We would like some kind of system where we provide the student with
> instructions of some sort. When setup correctly and the client is connecting
> he is provided a login screen where he/she has to enter the students AD user
> and password.
>
> Our infrastructure contains several Cisco 1100 AP's, IAS radius server, 2003
> Servers.
>
> Hope to find some concrete info here.
>
> Grx,
> Joris



 
Reply With Quote
 
Joris van der Struijk
Guest
Posts: n/a

 
      02-05-2006, 08:15 AM
As the clients are unable and not allowed to use the wired network, that's no
option.

All our clients are using Windows XP, and by my knowledge this has buildin
support for PEAP.
We tried a setup like this, but it's not working well.

1) We exported the Root CA certificate and installed it on the client.
2) We have setup the client to use PEAP with MS-CHAP v2 and ask for username
and password.
3) Try to connect.

Then the strange thing start.
Sometimes it askes for a username and password, but most often is doesn't.
Most of the time it doesn't get connected.

When looking at the IAS eventlog's it shows me that it is using a username
that i can't remember giving in at any point. It looks like it's a username
that's been cached sometime before.

When i install the Intel ProSet i'm also provided the option to givein a
"Roaming identity.
When i fillin my username there, it connects but doesn't ask me for a
Password When lookin at te eventlogs again, it telling me it connected
correctly using the account-name provided in the Roaming identity field.
Again: It never askes me for a Password.

WHY?



"BerkHolz, Steven" schreef:

> (Wired) If they go to Start, Run, and type in \\Servername\sharename, Enter, They will be prompted for their name and password.
> They need to enter their username as Domain\Username, and they will connect.
>
> As for the PEAP issue, whey will have to have driver that support it.
> And because their computer are not on the Domain, they will not have he required certificate.
> You will have to publish the certificate on a non secured network, or floppy\CD, etc. so they can install it on their Laptops.
>
> --
> --
> Steven
>
> May you have the peace and freedom that come from abandoning all hope of having a better past.
> --- - --- - - - - - - - -- - - - --- - ------ - - --- - - -- - - - -- - - -
> "Joris van der Struijk" <(E-Mail Removed)> wrote in message
> news:559EA849-DAE3-4A9C-9968-(E-Mail Removed)...
> > We are having trouble creating following scenario.
> >
> > A lot of students at our campus are using there laptops when not in class
> > and even during lessons.
> > All students have an account in our Windows 2003 Active Directory.
> >
> > We want to provide the student with access to our network recources WITHOUT
> > adding all those laptop computer accounts to our AD. This would be a lot of
> > work, and student won't be happy having to add the home laptop to our domain.
> >
> > What we want:
> > No laptop computer accounts.
> > As secure as possible (ea. PEAP with MS-CHAP v2).
> > Authentication should be based on the user account of the students, already
> > present in AD.
> > We would like some kind of system where we provide the student with
> > instructions of some sort. When setup correctly and the client is connecting
> > he is provided a login screen where he/she has to enter the students AD user
> > and password.
> >
> > Our infrastructure contains several Cisco 1100 AP's, IAS radius server, 2003
> > Servers.
> >
> > Hope to find some concrete info here.
> >
> > Grx,
> > Joris

>
>
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Limiting Access for non-domain Laptops PLAdmin Windows Networking 1 05-25-2011 01:09 PM
Laptops and Tablets Cannot Logon to Domain k3v1nr055 Wireless Networks 27 08-31-2010 12:49 AM
adding wirelss laptops into a workgroup John Owens Wireless Networks 3 11-26-2006 04:56 PM
Adding new laptops to existing network? MARS Wireless Networks 1 03-17-2005 10:06 PM
Accessing recources on two domains Windows Networking 1 11-27-2003 01:48 PM



1 2 3 4 5 6 7 8 9 10 11