I
I
Ivan Eliseev2018-02-28 14:58:44
Active Directory
Ivan Eliseev, 2018-02-28 14:58:44

How to make a network BEFORE AD in Mikrotik?

Hello!
Actually, the question is in the title :))
Make two levels of the network:
1. Welcom network, without Internet access, from where you can only log in to AD
2. After authorization in AD, the computer is already in another vlan, where all the necessary routing settings are already, etc. .
To be honest, I can only imagine how it's done. But I'm sure there are already examples of implementation. Thank you!

Answer the question

In order to leave comments, you need to log in

1 answer(s)
\
\0x20 \x64, 2018-02-28
@e4ovjgepyzts

I'm not an expert, but I've used similar technology.
As far as I know, the network device needs to support the 802.1x protocol.
A simple scheme looks like this:
- the client connects an ethernet cable to his laptop and tries to log in using 802.1x
- the radius server processes the request on its own, or by contacting AD
- the radius server gives a response to the network device about the success (failure) of authorization
- the network device redirects the client to one or another vlan

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question