Splash created with radius server is not working with actual AD credentials

Rohit_Rana
Getting noticed

Splash created with radius server is not working with actual AD credentials

Hello Everyone,

 

I have created Radius server for splash page authentication to access the internet. Splash page is reflecting on user devices but AD credentials are not working properly. If user is typing anything in username and password it is allowing the access to internet which means t is not checking for AD actual credentials and anything which we are typing randomly it is taking that garbage also as a credentials and allowing to the internet access.

 

I have done below mentioned settings.

 

Rohit_Rana_0-1689769549519.pngRohit_Rana_1-1689769786740.png

 

  .

8 Replies 8
alemabrahao
Kind of a big deal
Kind of a big deal

Can you share your SSID configuration?

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Rohit_Rana
Getting noticed

HI @alemabrahao 

Please have a look at SSID configuration.

 

Rohit_Rana_0-1689915228110.png

 

alemabrahao
Kind of a big deal
Kind of a big deal

To use splash page your server must be reachable through the Internet.

 

alemabrahao_0-1689935944370.png

 

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
cmr
Kind of a big deal
Kind of a big deal

You have created an outbound rule, is traffic allowed to the radius server from the Meraki APs/cloud etc.?  You need an inbound rule to it.  In terms of the behaviour it is expected as the RADIUS server is unreachable and you have said to allow access if that happens, hence they can type anything.

If my answer solves your problem please click Accept as Solution so others can benefit from it.
Rohit_Rana
Getting noticed

I tried with Inbound rule as well, but still it is behaving in the similar way.

CameronS
Getting noticed

Have you tried using the Active Directory authentication rather than RADIUS?

Rohit_Rana
Getting noticed

Hi @CameronS 

 

Yes , I tried. In AD case , while user was typing username and password , it was showing error "Access Denied" on splash page every time and users were not able to get connected with internet. So i used Radius which is at least allowing to get connected with internet.

CameronS
Getting noticed

You could try using the AD auth but on the client device, set the network adapter settings for the VPN as below:

 

CameronS_0-1690359180408.png

 

Get notified when there are additional replies to this discussion.