I have begun to tackle the confusing effort of trying to implement a byod wireless network in the place of my employment.
The problem is no one really knows the requirements or wants to decide what is exactly needed so I can only assume which just makes it more confusing.
My opinion of what is needed is to provide easy and secure access to the internet for all users. We have 3 different domains staff, students and an admin domain. Devices that will be used will include, iphones, androids, macs and pc’s.
We will eventually be using iboss to filter users according to domain credentials.
I have already set up an NPS server with the standard settings according to the meraki guide to implementing NPS.
I only created one policy, which is user based authentication – it would allow all three domains students, staff and admin access to gain internet access via the slash page as long as they have a valid user account.
When I test the connectivity in the Radius settings for slash page, using the servers external ip it states that the server can communicate with meraki cloud
We have school own devices on a different lan and each school owned devices automatically gets a cert once it is joined to the domain but I seem to be getting different results using the slash page and authenticating user groups vs machine auth.
My question is, I’ve seen so many ways to do this I’m not sure of the easiest but I think I have all the pieces just don’t know how to fit them together properly, can anyone help me find the correct but secure settings to use. I am using Microsoft a 2019 NPS Server and MR42 Meraki aps, I would like to authenticate three different domain user groups on an array of devices all from a splash screen and put them on a natted meraki network (not on our internal lan)
Any help would be greatly appreciated.