Petri IT Knowledgebase Forums
 

Petri.co.il forums Home Forums Start Page Forums Frequently Asked Questions FAQ Member List Members List
Go Back   Petri IT Knowledgebase Forums > Server Operating Systems > Windows Server 2008 / 2008 R2
Petri.co.il is happy to award auglan the title of Most Valuable Member !!!
Register Calendar Calendar Search Petri IT Knowledgebase Forums Search Todays Posts Today's Posts Mark Forums Read

Notices

Network Access protection in Windows 2008 SP2 not working as expected

Network Access protection in Windows 2008 SP2 not working as expected

this thread has 0 replies and has been viewed 634 times

Closed Thread
 
Thread Tools Search this Thread Display Modes
  #1  
Old 23rd July 2012, 20:38
ajayhunt ajayhunt is offline
Casual
Casual
 
 Join Date: May 2012
  6 month star 12 month star
 Posts: 4
 Reputation: ajayhunt is on a distinguished road (10)
Default Network Access protection in Windows 2008 SP2 not working as expected

Dear Experts,
We are using Network policy server for assigning IP address to different VLAN using Windows 2008 DHCP server based on user groups. We have our Wi-Fi controller setup for 802.1x authentication and NPS as RADIUS. Now we need to enable Network Access Protection in same setup. The NPS have enterprise CA and DHCP on same box. So we configured NAP with wirelless enforcement as follows:
  • EAP Qurantine NAP enforcement clients enabled
  • NAP Agent service set to automatic
  • Wired Autoconfig service set to automatic
  • Security Center user interface enabled
  • Wifi policy for Windows XP and VISTA configured in GPO with PEAP access and to trust NPS server
After these settings are configured in the GPO and linked to NPS OU. We have created a global security group and added the computer name to same on which we want to enable NAP. Then NAP was configured using wizard on NPS for wireless network as follows:
1. Wi-Fi controller added as RADIUS client
2. 2 VLAN configured for COMPLIANT and NON_COMPLIANT client
3. Non NAP capable system denied access to networks
4. New test user created to validate NAP
5. Same user added in productiuon group so that it can take production VLAN IP through DHCP if compliant
We are facing below issues:
1. On windows 7 32-bit, system is behaving properly but didnt display any NAP messeage in action center, e.g. if compliant it takes prodction IP but if we disable antivirus then goes out of production network and takes non compliant VLAN
2. On Windows XP, even after disabling firewall, antivirus, it still remians in prodcution VLAN. Even command "netsh nap client show grouppolicy" and netsh nap client show state" shows correct output but nothing happens for NAP, no message, no error
3. On windows 7 64-bit, even group policy setting are not getting deployed. Can anyone see what can be wrong?
Please help!!! also recommend if the way we are doing isw correct.
thanks in advance......
Closed Thread


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows 2008 R2 Cannot Access Network Shares By Namespace TokyoBrit Windows Server 2008 / 2008 R2 11 25th March 2011 10:19
GlobalNames Zone not working as expected gtomsho Windows Server 2008 / 2008 R2 0 4th March 2010 20:10
Network connectivity on windows server 2008 is working only one way (From server to L pankaj.prmar@gmail.com Windows Server 2008 / 2008 R2 2 4th September 2009 16:57
IIS virtual directory not working as expected ASS-Ware SBS 2000 / 2003 2 8th July 2008 18:33
Introduction to Network Access Protection yuval14 Windows Server 2008 / 2008 R2 1 11th April 2006 20:36


All times are GMT +3. The time now is 18:39.

Steel Blue 3.5.4 vBulletin Style ©2006 vBEnhanced
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
 

Valid XHTML 1.0!   Valid CSS!

Copyright 2005 Daniel Petri