NAP DHCP Enforcement - Group Membership condition?


hello,

i've got following setup on network:

- wireless access points 802.1x (wpa enterprise) authentication uses nap server radius server authenticates ad.
- nap ipsec using hra enterprise ca appropiate ipsec rules applied via group policy (domain isolation requirement of health certificate authenticate computer in ipsec negotiations)
- nap dhcp enforcement 

(nap, dc , hra servers running windows server 2008)

however, network has number of wireless non-nap capable clients (e.g smartphones, tablets, etc.) want allow trusted users ignore dhcp enforcement when connecting non-nap capable clients. 

how go setting policy allow domain users belong specific group not subject dhcp enforcement?

thanks :)


hi,

nap dhcp enforcement supports computer groups, not user groups. in other words, there no user authentication done in access request. cannot configure group of users have special rules dhcp enforcement. requires eap based method such 802.1x or vpn.

-greg



Windows Server  >  Network Access Protection



Comments

Popular posts from this blog

DCOM received error "2147746132" from...

DFSR RPC replication errors 5014 1726 with large files over VPN

ADFS 3.0 Event ID 4625 | An Error occurred During Logon | Status: 0xC000035B