I'm having trouble getting my NPS which is on the same computer as my DC for the domain, to validate a system health check on a client PC that i'm intentionally switching off the firewall for. It's my first time doing this type of setup but as you can see i'm using a wired 802.1X trigger which i'm assuming is correct because the virtual machine is technically using a "wired" connection, along with PEAP and MS-CHAPv2 encapsulated in PEAP and my trusted certificated from my DC. Along with the network policy using only "system health check" with no other options and the health policy connecting to the health validator that says the firewall must be enabled. All the services are enabled on server and client and the user is set to login using the NPS on their account. I honestly dont know what the problem is here. Any help would be appreciated, cheers.
Also, this is confusing again now haha! Because i was under the impression that when a user logs onto a domain its Kerberos that handles the process (not including winlogon and the lsa etc...) and authenticates the client. But now with implementing an NPS server, does this mean that when a user logs into the domain the NPS along with PEAP and MsCHAPv2 instead of kerberos? It's just a bit confusing (onto of this not working to haha)