Setup Guide: Windows Server Radius Certificate Based Authentication for Wifi Computer Clients

NetSage
New here

Setup Guide: Windows Server Radius Certificate Based Authentication for Wifi Computer Clients

Hello Group,

 

I am in search of a setup guide for windows server radius certificate based authentication for wireless access using both user based and machine based certificates.  I found this article,  https://documentation.meraki.com/MR/Encryption_and_Authentication/Configuring_RADIUS_Authentication_... but I feel I am missing something or something just is not clicking.

 

In a previous role, we had wireless authentication setup with a windows NPS, Cisco wireless controller using both user and computer certificates.  I remember having to reach out to multiple support experts to get our desire result and I wished I would have taken better notes.  Here is what we have setup, on-prem AD, internal Cert (root/intermediate) server, and Meraki Wireless APs currently using PSK for access to the corporate network.

 

Any help on providing step by step instructions for building this certificate based wireless auth system for both users certs and device certs would be greatly appreciated.

 

Thanks.  

1 Reply 1
alemabrahao
Kind of a big deal

There are some requirements that must be followed for it to work, please review each one carefully.

 

https://documentation.meraki.com/MR/Encryption_and_Authentication/Configuring_RADIUS_Authentication_...

 

https://documentation.meraki.com/MR/Encryption_and_Authentication/RADIUS%3A_WPA2-Enterprise_With_EAP...

 

https://www.youtube.com/watch?v=Iput9nLnldA&pp=ygUII25wc2F1dGg%3D

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco ID. If you don't yet have a Cisco ID, you can sign up.
Labels