NAP DHCP Enforcement - Group Membership condition?
hello,
i've got following setup on network:
- wireless access points 802.1x (wpa enterprise) authentication uses nap server radius server authenticates ad.
- nap ipsec using hra enterprise ca appropiate ipsec rules applied via group policy (domain isolation requirement of health certificate authenticate computer in ipsec negotiations)
- nap dhcp enforcement
(nap, dc , hra servers running windows server 2008)
however, network has number of wireless non-nap capable clients (e.g smartphones, tablets, etc.) want allow trusted users ignore dhcp enforcement when connecting non-nap capable clients.
how go setting policy allow domain users belong specific group not subject dhcp enforcement?
thanks :)
hi,
nap dhcp enforcement supports computer groups, not user groups. in other words, there no user authentication done in access request. cannot configure group of users have special rules dhcp enforcement. requires eap based method such 802.1x or vpn.
-greg
Windows Server > Network Access Protection
Comments
Post a Comment