Link to home
Start Free TrialLog in
Avatar of Shain Allen
Shain AllenFlag for United States of America

asked on

Can i set expiration duration of a network password?

In our building (very large) we have a public wireless access in the front of the building since that's were our firewall (DMZ) lives. We have an encrypted wireless throughout the rest of the building for our staff.

Occasionally we have outside speakers who need internet access but are in a room outside the reach of teh public access point.

Can i give them temporary access to the non-public wireless network that would expire like in a day. And a password that's not the same as the staff access

Hope this made sense.
Avatar of Shain Allen
Shain Allen
Flag of United States of America image

ASKER

Just to clarify. . .
I have set up the default wireless access for the encrypted wireless network so the staff automatically have access to network resources (i.e. access file servers).

What I'm asking is if i can give an outside speaker only access to the internet and not the network resourses
I know how to set a user account so it expires on a specific date in AD.
Avatar of kevinhsieh
You could make the account a member of domain guests (not domain users) and also a member of a group that has access to the wireless (assuming you don't want to give Domain Guests access to the Wi-Fi. This is assuming you use NPS as the RADIUS server to authorize wireless connections.
ASKER CERTIFIED SOLUTION
Avatar of chakko
chakko
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Thank you for the clear and concise solution. Perfect
chakko, i don't know if you are still monitoring this question but if you are i have one more questiosn if you don't mind.
So since there is only 1 password to the encrypted wireless network i still give them this password and then just control their access in AD, right

thank you,
Ron
That should probably work.  Their AD account can be used to deny access to Servers.

if your equipment supports the features, one option is to made another SSID on the Wireless and set that on a separate VLAN, then restrict that VLAN to only internet access.
okay thanks again