Cisco WLC security: best solution for authentication

We have about 20 cisco wireless lan controllers in our environment, placed on different locations.
Today we broadcast two SSIDs, one with web-auth and one with WPA + WPA2+802.1X.
This is a ok solution, but we are now looking for a way to improve the security.
The perfect solution would be that we could install a certificate when we install the user computers, and that this was used to authenticate the user to the wireless network. We should also be able to distribute the certificate with a gpo setting or something like that as well, for old computers that wont be reinstalled for a while.
We also have to log all traffic with the users username, but I hope that it is enough that the user is in the domain and dont have to authenticate with credentials again when connecting to the wireless network (we use ISA server for logging).

Does anyone have a idea on how we can solve this?

Thanks in advance :)
evuhleyeAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

naykamCommented:
What server/AD environment you running?
0
evuhleyeAuthor Commented:
We use active directory on windows 2008 server.
0
naykamCommented:
Hi, I just saw no response on that, how did you go
0
evuhleyeAuthor Commented:
I have solved this using win 2008 enterprise with network policy server.
As long as you have a CA-server, this is easy to solve using dot1x :)
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Wireless Networking

From novice to tech pro — start learning today.