Enterprise AV Home WiFi Mobile Wifi Support Shop Deals

This article describes how to use the WC7600 wireless controller as a RADIUS server with the Microsoft Windows Server 2012 Network Policy Server.  The article also describes how to use Active Directory Certificate Services and how to push wireless profiles to domain-joined computers that use a group policy.

The following services must already be installed on the Windows Server 2012R2:

  • Active Directory Domain Services (AD DS)
  • DNS
  • DHCP

During the installation of additional services on Microsoft Windows Server 2012R2, be aware of the following requirements:

  • Install Active Directory Certificate Services (AD CS) and Network Policy Server (NPS).
  • For AD CS, choose Certification Authority & Certification Authority Web Enrollment from the available options. For the configuration for this article, all options are left as default.
  • For NPS configuration, click the Tools - Network Policy Server button. When the NPS console opens, click the Action - Register server button in Active Directory.

Configure the Network Policy Server (NPS) and the RADIUS Server

To configure the Network Policy server and the RADIUS server:

 1.  On the Windows 2012R2 server, open the NPS console.

 2.  On the left hand pane, click NPS (Local).

 3.  In the menu circled in red, select RADIUS server for 802.1x wired or wireless connections and then click the Configure 802.1x button.

 4.  In the next screen, select the Secure Wireless Connections radio button. 

 5.  In the next screen, specify a RADIUS client.

In this example, the client is the IP address of the WC7600. Ensure that the shared secret entered here is the same shared secret that is entered into the WC7600 (as described later).

 6.  In the next screen, as the type, select Microsoft: Protected EAP (PEAP) and to review the settings, click the Configure button.

 7.  Click the OK button, then click the Next button, and finally click the Finish button.

Configure the WC7600

To configure the WC7600:

 1.  On the WC7600 admin interface, go to Configuration > Security > Authentication Server.

 2.  Select External RADIUS Server.

 3.  Enter the IP address of the Windows 2012R2 server and the same shared secret entered in the NPS set-up above.

 4.  Click the Apply button.

 5.  Go to Configuration > Profile.

 6.  Add a profile with the desired SSID.

Make note of this SSID as it will be needed in the group policy settings later.

 7.  Set the Network Authentication to WPA & WPA2 with RADIUS and set Authentication Server to External / basic-Auth.

 8.  Configure other settings as needed and click the Apply button.

Configure the Group Policy for Wireless Profiles

To configure the group policy for wireless profiles:

 1.  On the 2012R2 server, open Group Policy Management.

 2.  Expand the tree on the left hand pane until you find Default Domain Policy. Right-click on Default Domain Policy and click the Edit button.

 3.  In the Default Domain Policy, go to Computer Configuration > Windows Settings > Security Settings > Wireless Network (IEEE 802.11) Policies.

 4.  Right-click on Wireless Network (IEEE 802.11) Policies) and select Create a new Wireless Network Policy for Windows Vista and Later Releases.

 5.  Give the policy a name and a description and then click the Add button.

 6.   For the network type, select Infrastructure.

 6.  In the Profile Name and Network Name(s) SSID) fields, enter the SSID that was configured in the WC7600 server above.

In this example, the SSID is DemoRadius.

 7.  When finished, click the Add button.

 7.  Click the Security tab.

 8.  Next to Microsoft: Protected EAP (PEAP) field, click the Properties button.

 9.  In the Protected EAP Properties screens, select Verify the server's identity by validating the certificate.

10.  Select the certificates from the list that have the same name as the Windows server.

11.  To close this dialog box, click the OK button.  Click the OK button again and then click the Apply button.

The group policy for the wireless profile is now configured.

To receive the group policy from the domain, the client conputer first needs to connect to a wired connection because the client computer must be joined to the domain. After logging the computer into the domain, search for the SSID that was configured above and click the Connect button. The client can then connect to the wireless network.

Last Updated:07/07/2025 | Article ID: 26052

This article applies to:

Recently Viewed Articles

    Our team is here to help!

    Phone
    Chat
    Email