ExamNotes.net  -  IT certification portal

ForumsCertResearchTop sitesNewslettersFree email
HomeRegister
Exams Notes
Practice exams
Exam games
Questions by email
Online training
Training videos
College degrees
Boot camps
Book store
Links directory
Tell a friend
For webmasters

CompTIA Exam Vouchers
Save money on CompTIA exams
Question of the day
Sign up to receive
interactive practice questions
for MCSE, CompTIA
Cisco and other exams
TestKing
Get MCSE, MCSD, CCNA, CCNP,A+, N+ and many more

* ExamSheets *
Guide for Success!
Actual Questions & Answers
MCSE, MCSD, A+ ,CCNA, CCNP
Oracle 8i, Oracle 9i

Online practice tests

Certification sites

Online university

Online college

Online education

Distance learning

Software forum

Server administration forum

Programming resources






This is interesting: Free IT Magazines | Databases help forum



Other IT certifications > CWNP > (Kevin/Devin or someone with experience) Help with setting up 802.1x/PEAP

Show a Printable Version
Email This Page to Someone!
Receive updates to this thread




Order the official CWNA Study Guide endorsed by the Wireless LAN Association (WLANA)



Author (Kevin/Devin or someone with experience) Help with setting up 802.1x/PEAP
Evilphil
Member
M




Registered: Mar 2003
Location:
Country: United States
State:
Certifications: A+, NT 4 MCSE, 2000 MCSE, CWNA
Working on: CWSP

Total Posts: 51
(Kevin/Devin or someone with experience) Help with setting up 802.1x/PEAP

I've been working on securing my wireless LAN, and was having issues getting Win2k Advanced Server's Radius to work properly with PEAP-MSCHAPv2. I've installed a CA on my network, and it is trusted by the clients. The Certificates are installed, and the machines are passing credentials to the Radius server... The problem is that the IAS server is dropping ALL of the Radius authorization requests because of unknown packets. I've looked in the IAS log, and system events, and there is no helpful information in either. I've searched all over the net for the issue that I'm having, but to no avail. It seems like the Authentication Server is not expecting the client machine's digital cert prior to user credential authentication.

I've gotten TLS to work just fine utilizing machine, and client certs... It's just PEAP that's acting really funky... Any help at all would be appreciated. Anybody care to share other issues they've had with labs, or production wireless LANs?

Last edited by Evilphil on 01-16-04 at 02:35 PM

Report this post to a moderator

Old Post 01-16-04 02:20 PM
Evilphil is offline Click Here to See the Profile for Evilphil Click here to Send Evilphil a Private Message Add Evilphil to your buddy list Find more posts by Evilphil Reply w/Quote Edit/Delete Message IP: Logged
Devinator
Senior Member
M




Registered: Apr 2003
Location:
Country: United States
State:
Certifications: MCSE, MCT, CCNA, CCDA, CCDP, CCNP, CCSP, ISSP, CNE6, MCNE4, CNE5, CWNA, CWSP, Other
Working on: CWAP

Total Posts: 176
good question indeed!

The problem here is:

1. Cisco, Microsoft, and RSA codeveloped PEAP. After getting it all rolling, Cisco and Microsoft had differing opinions on how PEAP should be implemented.

2. As of VERY recently, both Cisco and Microsoft support both PEAP-EAP-TLS (certificates on the server and client) and PEAP-EAP-MSCHAPv2 (certificate on the server and passwords for the clients). HOWEVER, Cisco and Microsoft's implementations of PEAP (both kinds) are incompatible with each other.

3. Your solution options: 1) Switch to Funk, Cisco, or Meetinghouse RADIUS, or 2), Make sure to use Microsoft's XP-sp1 PEAP supplicant.

If you're already using the Microsoft PEAP supplicant, then that's a whole other list of details to cover.

Report this post to a moderator

Old Post 01-25-04 02:44 AM
Devinator is offline Click Here to See the Profile for Devinator Click here to Send Devinator a Private Message Add Devinator to your buddy list Find more posts by Devinator Reply w/Quote Edit/Delete Message IP: Logged
Evilphil
Member
M




Registered: Mar 2003
Location:
Country: United States
State:
Certifications: A+, NT 4 MCSE, 2000 MCSE, CWNA
Working on: CWSP

Total Posts: 51
Re: good question indeed!

Well, I've got SP1 installed, and even attempted it with the 802.1x supplicant for Win2k (on Win2k machines)... No dice... I'm ready to start stabbin monitors...

Report this post to a moderator

Old Post 01-29-04 01:46 AM
Evilphil is offline Click Here to See the Profile for Evilphil Click here to Send Evilphil a Private Message Add Evilphil to your buddy list Find more posts by Evilphil Reply w/Quote Edit/Delete Message IP: Logged
Devinator
Senior Member
M




Registered: Apr 2003
Location:
Country: United States
State:
Certifications: MCSE, MCT, CCNA, CCDA, CCDP, CCNP, CCSP, ISSP, CNE6, MCNE4, CNE5, CWNA, CWSP, Other
Working on: CWAP

Total Posts: 176

http://www.microsoft.com/downloads/...&displaylang=en

see if this helps.

Report this post to a moderator

Old Post 01-29-04 02:42 PM
Devinator is offline Click Here to See the Profile for Devinator Click here to Send Devinator a Private Message Add Devinator to your buddy list Find more posts by Devinator Reply w/Quote Edit/Delete Message IP: Logged
Evilphil
Member
M




Registered: Mar 2003
Location:
Country: United States
State:
Certifications: A+, NT 4 MCSE, 2000 MCSE, CWNA
Working on: CWSP

Total Posts: 51

That was one of the MANY references that I used, but it doesn't help... Maybe it's a corrupt install of Win2k... I should be getting Server03 soon, so I'll see if that clears it up.

Everything is technically setup correctly from what I can see... From the IAS log, it looks as though the Radius server isn't ready for a PEAP connection... DAMN MICROSOFT!

Report this post to a moderator

Old Post 01-29-04 06:08 PM
Evilphil is offline Click Here to See the Profile for Evilphil Click here to Send Evilphil a Private Message Add Evilphil to your buddy list Find more posts by Evilphil Reply w/Quote Edit/Delete Message IP: Logged
All times are GMT.
Post new thread   Post reply

CWNP exam notes

CWNA exam details



Forum Jump:
Rate This Thread:
Forum Rules:
Who Can Read The Forum? Any registered user or guest.
Who Can Post New Topics? Any registered user.
Who Can Post Replies? Any registered user.
Changes: Messages can be edited by their author.
Posts: HTML code is OFF. Smilies are ON. vB code is ON. [IMG] code is OFF.
 

ExamNotes forum archive


Powered by: vBulletin 2.2.8
Copyright ©2000, Jelsoft Enterprises Limited.

  Free Braindumps | mcse braindumps