?
Solved

Can i set expiration duration of a network password?

Posted on 2011-09-25
8
Medium Priority
?
296 Views
Last Modified: 2012-05-12
In our building (very large) we have a public wireless access in the front of the building since that's were our firewall (DMZ) lives. We have an encrypted wireless throughout the rest of the building for our staff.

Occasionally we have outside speakers who need internet access but are in a room outside the reach of teh public access point.

Can i give them temporary access to the non-public wireless network that would expire like in a day. And a password that's not the same as the staff access

Hope this made sense.
0
Comment
Question by:ronfast
  • 5
  • 2
8 Comments
 

Author Comment

by:ronfast
ID: 36595732
Just to clarify. . .
I have set up the default wireless access for the encrypted wireless network so the staff automatically have access to network resources (i.e. access file servers).

What I'm asking is if i can give an outside speaker only access to the internet and not the network resourses
0
 

Author Comment

by:ronfast
ID: 36595740
I know how to set a user account so it expires on a specific date in AD.
0
 
LVL 43

Expert Comment

by:kevinhsieh
ID: 36597351
You could make the account a member of domain guests (not domain users) and also a member of a group that has access to the wireless (assuming you don't want to give Domain Guests access to the Wi-Fi. This is assuming you use NPS as the RADIUS server to authorize wireless connections.
0
Easily Design & Build Your Next Website

Squarespace’s all-in-one platform gives you everything you need to express yourself creatively online, whether it is with a domain, website, or online store. Get started with your free trial today, and when ready, take 10% off your first purchase with offer code 'EXPERTS'.

 
LVL 22

Accepted Solution

by:
chakko earned 2000 total points
ID: 36597601
What I have done at one company is that I setup a group called NoAccess and then configured explicit DENY Access for that group to all resources which I thought were important.

So, when I encounter something like your situation I create a guest account and add it to the NoAccess group.  Similarly, I can 'lockout' a user from the LAN side if needed.  (I had this requirement before where management allowed an outgoing staff person to logon to their PC and access Outlook mail, but wanted all server resources blocked).
0
 

Author Closing Comment

by:ronfast
ID: 36600318
Thank you for the clear and concise solution. Perfect
0
 

Author Comment

by:ronfast
ID: 36943393
chakko, i don't know if you are still monitoring this question but if you are i have one more questiosn if you don't mind.
So since there is only 1 password to the encrypted wireless network i still give them this password and then just control their access in AD, right

thank you,
Ron
0
 
LVL 22

Expert Comment

by:chakko
ID: 36943683
That should probably work.  Their AD account can be used to deny access to Servers.

if your equipment supports the features, one option is to made another SSID on the Wireless and set that on a separate VLAN, then restrict that VLAN to only internet access.
0
 

Author Comment

by:ronfast
ID: 36943882
okay thanks again
0

Featured Post

What Kind of Coding Program is Right for You?

There are many ways to learn to code these days. From coding bootcamps like Flatiron School to online courses to totally free beginner resources. The best way to learn to code depends on many factors, but the most important one is you. See what course is best for you.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

It’s time for spooky stories and consuming way too much sugar, including the many treats we’ve whipped for you in the world of tech. Check it out!
One thing I've always found frustrating is no matter how many times one asks the end users to not save things on their local machines, they do it anyway.  Forget that we don't back up the desktops - only the servers.  Well, let's sneak their data on…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

569 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question