Re: Create a wireless domain?



=?Utf-8?B?V2VidGVjaGll?= <Webtechie@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
news:9236C497-2494-48A8-820D-D1F96C101D55@xxxxxxxxxxxxx:

> I searched the posts and didn't see this question, so I apologize if
> it has been asked already.
>
> I have an office building with three rooms spread out and not next to
> each other. I want to create network for the pcs. I will load
> windows server and create a domain controller. There will be no
> internet connectivity. Can I wirelessly add pcs? Set a router on
> domain controller and then add pcs with wireless usb devices and a
> couple access points?
>
> Do I need to string wire throughout the place (which would be a pain).
>
> Thanks,
>
> Tony
>

As Robert said, you can do this. You only need to run cable between the
access points and the server.

As Robert also mentioned, security is a concern -- so you should use PEAP-
MS-CHAP v2 as the authentication method for clients.

For details on this authentication method, see "The Advantages of Protected
Extensible Authentication Protocol (PEAP): A Standard Approach to User
Authentication for IEEE 802.11 Wireless Network Access"
http://www.microsoft.com/windowsserver2003/techinfo/overview/peap.mspx

In general/overview, you need to do the following to use this
authentication method (which uses a server certificate but allows users to
log on securely with user names and passwords):

Purchase access points that are compatible with 802.1X and RADIUS.

Install Active Directory and DNS on the server. Raise the domain functional
level to Windows 2000 native or Windows Server 2003 (preferred, but only do
this if all of your domain controllers/global catalogue servers are WS03).
Create user accounts for each user and set the remote access permission
setting on the user accounts to "Control access through remote access
policy."

Also install Internet Authentication Service (which is Microsoft RADIUS).
Add each wireless access point as a RADIUS client in IAS. Create a secure
wireless remote access policy using the instructions in the IAS Help. For
details see "Enterprise Deployment of Secure 802.11 Networks Using
Microsoft Windows" at
http://www.microsoft.com/windowsserver2003/technologies/ias/default.mspx

Obtain a server certificate from Verisign or another public trusted root CA
that the clients already trust. See "Obtaining and Installing a VeriSign
WLAN Server Certificate for PEAP-MS-CHAP v2 Wireless Authentication" at
http://www.microsoft.com/downloads/details.aspx?FamilyID=1971d43c-d2d9-
408d-bd97-139afc60996b&DisplayLang=en


--
James McIllece, Microsoft

Please do not send email directly to this alias. This is my online account
name for newsgroup participation only.

This posting is provided "AS IS" with no warranties, and confers no rights.
.



Relevant Pages

  • HELP! Error /w Wireless Client Connecting to Win2003 Server /w IAS, CA
    ... The wireless client system goes to authenticate with windows ... 2003 server and it looks like the authentication is making it to the server ... "The client could not be authenticated because the Extensible Authentication ...
    (microsoft.public.windows.server.general)
  • HELP! Error /w Wireless Client Connecting to Win2003 Server /w IAS, CA
    ... The wireless client system goes to authenticate with windows ... 2003 server and it looks like the authentication is making it to the server ... "The client could not be authenticated because the Extensible Authentication ...
    (microsoft.public.windows.server.setup)
  • HELP! Error /w Wireless Client to Win2003 Server /w IAS, CA
    ... The wireless client system goes to authenticate with windows ... 2003 server and it looks like the authentication is making it to the server ... "The client could not be authenticated because the Extensible Authentication ...
    (microsoft.public.internet.radius)
  • Netlogon 5783
    ... For about there mounts I<m having small network problem, with clients, that ... The session setup to the Windows NT or Windows 2000 Domain Controller ... On DC1r there is Exchange 2000 server, witch is Exchange system manager is ... The failure code from authentication protocol Kerberos ...
    (microsoft.public.win2000.networking)
  • Re: I have a Windows 2003 server that is unable to communicate with the domain controller
    ... not work so i removed the server from the domain and added it again. ... The Security System detected an authentication error for the server ... see Help and Support Center at ... domain controller for domain PREP, ...
    (microsoft.public.win2000.active_directory)