cancel
Showing results for 
Search instead for 
Did you mean: 

802.1X authentication fails after restricting AD user logon to specific computers

802.1X authentication fails after restricting AD user logon to specific computers

williamszen666
New Contributor

Hi everyone,

I would like to ask if anyone has experienced a similar issue while working with ExtremeControl.

Our customer has the following environment:

  • 2 × ExtremeControl Engines
  • 1 × ExtremeCloud IQ Site Engine
  • 2 × Wireless LAN Controllers (WLCs)
  • Active Directory used as the authentication source
  • 802.1X authentication (PEAP/MSCHAPv2)
  • Dynamic VLAN assignment after successful authentication

The authentication workflow is the following:

Client

│ Connects to SSID (802.1X)

Wireless AP


WLC


ExtremeControl (ACE)

│ RADIUS Authentication

Active Directory

│ User authenticated

ExtremeControl returns VLAN


Endpoint receives VLAN and network access

The issue

At the customer's request, they modified the user's Active Directory account.

In:

Active Directory Users and Computers
→ User Properties
Account
Log On To...

Instead of allowing the user to log on to all computers, they restricted the account to only one specific computer.

After applying this change, the user is no longer able to authenticate through the 802.1X wireless SSID.

williamszen666_0-1784564309178.png

My questions

  • Has anyone encountered this behavior before?
  • Does ExtremeControl (or Windows NPS/LDAP authentication) validate the Log On To restriction during 802.1X authentication?
  • Is this expected behavior from Active Directory?
  • Is there any recommended approach if the customer wants to restrict interactive Windows logons without affecting wireless 802.1X authentication?

Any insights or best practices would be greatly appreciated.

 

 

 

2 REPLIES 2

Ryan_Yacobucci
Extreme Employee

Hello,

When ExtremeControl is configured to directly integrate with Active Directory. (LDAP Authentication) it uses an NTLM authentication that is sourced from the Control appliance. 

It obtains the users credentials viae 802.1x and authenticates to the domain controller with those credentials.

From the domain Controller's perspective, the user is logging onto the Control appliance, not onto the computer that is authenticating to Control. You'll find that there are logs in the domain controller that indicate the users are all logging onto the Control appliance.

At a minimum, all users MUST have permission to logon to all ExtremeControl appliances. If you remove the ability to logon to the Control appliance, the authentication will be rejected.

Since Control is masking the source computer, I don't think restrictions for logon based on machine is going to work.

If you change Control from an LDAP authentication to a proxy RADIUS configuration and set up NPS on the Domain Controller it should operate the way you want.  I can't think of a way to restrict each user to their specific machine using the features within Control that is efficient.

Thanks
-Ryan

jerica63figaro
New Contributor

I appreciate the detailed troubleshooting steps. Problems involving AD policies and 802.1X can be difficult to diagnose, so it's great to have a clear explanation of what was happening. Paylocity

GTM-P2G8KFN