Solved

Can i set expiration duration of a network password?

Posted on 2011-09-25
8
261 Views
Last Modified: 2012-05-12
In our building (very large) we have a public wireless access in the front of the building since that's were our firewall (DMZ) lives. We have an encrypted wireless throughout the rest of the building for our staff.

Occasionally we have outside speakers who need internet access but are in a room outside the reach of teh public access point.

Can i give them temporary access to the non-public wireless network that would expire like in a day. And a password that's not the same as the staff access

Hope this made sense.
0
Comment
Question by:ronfast
  • 5
  • 2
8 Comments
 

Author Comment

by:ronfast
ID: 36595732
Just to clarify. . .
I have set up the default wireless access for the encrypted wireless network so the staff automatically have access to network resources (i.e. access file servers).

What I'm asking is if i can give an outside speaker only access to the internet and not the network resourses
0
 

Author Comment

by:ronfast
ID: 36595740
I know how to set a user account so it expires on a specific date in AD.
0
 
LVL 42

Expert Comment

by:kevinhsieh
ID: 36597351
You could make the account a member of domain guests (not domain users) and also a member of a group that has access to the wireless (assuming you don't want to give Domain Guests access to the Wi-Fi. This is assuming you use NPS as the RADIUS server to authorize wireless connections.
0
 
LVL 22

Accepted Solution

by:
chakko earned 500 total points
ID: 36597601
What I have done at one company is that I setup a group called NoAccess and then configured explicit DENY Access for that group to all resources which I thought were important.

So, when I encounter something like your situation I create a guest account and add it to the NoAccess group.  Similarly, I can 'lockout' a user from the LAN side if needed.  (I had this requirement before where management allowed an outgoing staff person to logon to their PC and access Outlook mail, but wanted all server resources blocked).
0
 

Author Closing Comment

by:ronfast
ID: 36600318
Thank you for the clear and concise solution. Perfect
0
 

Author Comment

by:ronfast
ID: 36943393
chakko, i don't know if you are still monitoring this question but if you are i have one more questiosn if you don't mind.
So since there is only 1 password to the encrypted wireless network i still give them this password and then just control their access in AD, right

thank you,
Ron
0
 
LVL 22

Expert Comment

by:chakko
ID: 36943683
That should probably work.  Their AD account can be used to deny access to Servers.

if your equipment supports the features, one option is to made another SSID on the Wireless and set that on a separate VLAN, then restrict that VLAN to only internet access.
0
 

Author Comment

by:ronfast
ID: 36943882
okay thanks again
0

Join & Write a Comment

You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now