Re: SP1 und Netzwerkauthentifizierung 802.1x



Hallo,

was sich bei SP1 geaendert haben koennte kann ich leider nicht sagen.
Es gab mal ein Problem wenn das Client Certificat
Sonderzeichen (International Characters) enthielt.

Vielleicht sind aehnliche Aenderungen wie bei XP SP3 erfolgt:
949984 Changes to the 802.1X-based wired network connection settings in
Windows XP Service Pack 3
http://support.microsoft.com/default.aspx?scid=kb;EN-US;949984

953650 You cannot connect to an 802.1X wired network after you upgrade to Windows XP Service Pack 3
http://support.microsoft.com/default.aspx?scid=kb;EN-US;953650

Moeglicherweise findest Du einen Ansatz dabei.
--------------
Weitere Referenzen:

947219 A Windows Vista-based computer may be unable to connect to the
network after you configure the computer to use machine authentication and
to validate the RADIUS server certificate
http://support.microsoft.com/kb/947219/en-us


838502 802.1x client authentication fails when you connect to a Windows Server
2003-based computer that is running IAS
<http://support.microsoft.com/default.aspx?scid=kb;EN-US;838502>

931856 A Windows XP-based wired client computer will not obtain a valid IP address
from a guest VLAN or from an "Authentication failed-VLAN"
<http://support.microsoft.com/default.aspx?scid=kb;EN-US;931856>

929847 How to enable computer-only authentication for a 802.1X-based network in
Windows Vista
<http://support.microsoft.com/default.aspx?scid=kb;EN-US;929847>

- - - - - - -

IAS Best Practices:
<http://technet2.microsoft.com/windowsserver/en/library/7f26a61e-8dfa-455f-b596-53aa
6349f0511033.mspx?mfr=true>

IAS How To -
<http://technet2.microsoft.com/windowsserver/en/library/06c438a8-fe36-41e6-b084-81c1
9c450c1a1033.mspx?mfr=true>

Troubleshooting IAS as a RADIUS server
<http://technet2.microsoft.com/WindowsServer/en/library/d2a1ffaf-cc01-4e00-a92e-3369
23302a501033.mspx?mfr=true>

837911 TechNet Support WebCast: IEEE 802.1x authentication client in Microsoft
Windows for wireless and wired networks
<http://support.microsoft.com/default.aspx?scid=kb;EN-US;837911>

Gruss,
Helmar


"Walter Auernig" <wauernig@xxxxxxxxxxx> wrote in message news:22BDA7CB-FFEC-442F-9A55-1503CCBE07BA@xxxxxxxxxxxxxxxx
Hallo NG,
habe in meiner Netzwerkumgebung ein Enterprise Netzwerk, das ich mit Cisco
APs bestückt habe. Die Authentifizierung erfolgt mit 802.1x auf einem Radius
Server.
Das funktioniert mit XP und Vista einwandfrei. Seit dem SP1 sind (neue)
Clients nicht mehr in der Lage, Zugang zum Netz zu erhalten. Der Radius
Server (ein W2003 Server mit IAS) Reject die Anforderung. Ich habe den
Eindruck, als verlange er ein Zertifikat, obwohl die Einrichtung bislang ohne
TLS funktionierte.
Was hat sich da seit dem SP1 geändert und wie kann ich das Problem lösen?

Danke
Walter Auernig

.



Relevant Pages

  • RE: How to start/stop windows service on a remote machine?
    ... impersonate the client user(authenticated via integrated windows ... authentication in IIS) and access some remote protected resource(windows ... the problem you meet is a typical windows ... want to continue access other remote machine, ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Please help! I am just about to go berserk and pull a terror attack on my Radius Server. WIFI us
    ... 802.1x client authentication fails when you connect to a Windows Server 2003-based computer that is running IAS ... Client: Windows XP Pro SP2 ...
    (microsoft.public.windows.server.networking)
  • Re: Aironet 1200/Radius Help Needed
    ... I just fired up a W2003 Advanced Server so that I can take ... >> IAS servers (do I need a separate certificate for the secondary IAS ... >> of authentication since it involves just installing the certificate on ... >between the AP and the client. ...
    (microsoft.public.internet.radius)
  • Re: 802.1X/EAP authentication issue with XP client
    ... I also tried adjusting the IAS remote access policy framed MTU param ... client, same scenario, is not getting a successful authentication. ... or system event logs. ...
    (microsoft.public.internet.radius)
  • Re: IAS to authenticate CISCO VPN traffic
    ... I ran the netsh ras set tracing iassam enabled, ... in the ias log file i still see the normal log details as follows.. ... I created a client within IAS called ... >> Within this profile Under authentication and encryption I have tried ...
    (microsoft.public.internet.radius)