Re: Computer authentication doesn't work with PEAP ?

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Sam Salhi [MSFT] (samers_at_online.microsoft.com)
Date: 02/19/04


Date: Thu, 19 Feb 2004 14:15:05 -0800

It looks like your computer is authenticating EAP-TLS instead of PEAP; and
you have not enabled that on the IAS server
You have 2 options: Change to PEAP or Add EAP-TLS to the list of
authentication protocols your IAS server supports

-- 
===========================================================
This posting is provided "AS IS" with no warranties and confers no rights
===========================================================
<Claude.Gauthard@mcdonalds.fr> wrote in message
news:OxydP6u9DHA.2472@TK2MSFTNGP10.phx.gbl...
> We have the following configuration :
>
> - Wireless AP : Cisco AP1231 configured with WPA, 802.1x authentication is
> MSCHAP-V2
> - clients : Windows XP SP1 with patch for WPA
> - Wireless adaptor : cisco Aironet 5GHz or D-link Airpro DWL-AB650 with
> latest drivers and firmware supporting WPA
> - Radius server : Windows 2003 server with IAS and proper certificate
> installed
> - Active Directory : Windows 2000 in mixed mode
>
> User authentication works fine as shown below :
>
>  User (myself) was granted access.
>  Fully-Qualified-User-Name = ourdomain/Guyancourt/Dept
> Informatique/Users/myself
>  NAS-IP-Address = 192.168.56.72
>  NAS-Identifier = ap
>  Client-Friendly-Name = Switch_AP1200_3sud_02
>  Client-IP-Address = 192.168.56.72
>  Calling-Station-Identifier = 000a.f4f3.4ba0
>  NAS-Port-Type = Wireless - IEEE 802.11
>  NAS-Port = 641
>  Proxy-Policy-Name = Use Windows authentication for all users
>  Authentication-Provider = Windows
>  Authentication-Server = <undetermined>
>  Policy-Name = test wireless bogdan
>  Authentication-Type = PEAP
>  EAP-Type = Secured password (EAP-MSCHAP v2)
>
> However computer authentication is always rejected :
>
> User host/PCxxxx.ourdomain was denied access.
>  Fully-Qualified-User-Name = ourdomain/Guyancourt/Dept
> Informatique/Computers/PCxxxx
>  NAS-IP-Address = 192.168.56.72
>  NAS-Identifier = ap
>  Called-Station-Identifier = 000e.384a.246f
>  Calling-Station-Identifier = 000a.f4f3.4ba0
>  Client-Friendly-Name = Switch_AP1200_3sud_02
>  Client-IP-Address = 192.168.56.72
>  NAS-Port-Type = Wireless - IEEE 802.11
>  NAS-Port = 545
>  Proxy-Policy-Name = Use Windows authentication for all users
>  Authentication-Provider = Windows
>  Authentication-Server = <undetermined>
>  Policy-Name = Connections to other access servers
>  Authentication-Type = EAP
>  EAP-Type = <undetermined>
>  Reason-Code = 66
>  Reason = The user attempted to use an authentication method that is not
> enabled on the matching remote access policy.
>
> When the computer boots computer authentication is attempted several
> times, fails, and a couple of minutes later user authentication is
> attempted which succeeds.
> If this can be of any help, I had a look at the request packet with Netmon
> and the EAP identifier which is passed to IAS has a value of 2 for
> computer authentication.
>
> Any idea ?
>


Relevant Pages

  • Re: How secure is the WPA-PSK wireless encryption
    ... Authentication Protocol), ... PEAP and EAP-TTLS, both establish a TLS connection with the RADIUS ... server and then do an EAP authentiation to authenticate the user. ...
    (sci.crypt)
  • Re: PEAP-TLS vs EAP-TLS
    ... and PEAP is that PEAP is a two-step process where 1) the RADIUS server is ... authenticated to the client via the RADIUS server's certificate, ... encrypted TLS channel is set up for 2) client authentication (either using ... But I wonder how much more secure PEAP-TLS is than EAP-TLS, ...
    (microsoft.public.windows.server.security)
  • Re: Configuration of an Aironet 1130AG
    ... Cisco 1130AG Documentation: ... An incorrect username and password on the RADIUS server. ... An incorrect PEAP configuration. ... MS PEAP machine authentication does not work with the ADU supplicant. ...
    (comp.dcom.sys.cisco)
  • Re: W2K3, IAS, Cisco 1200 AP, PEAP, and MAC authentication
    ... > I am having a heck of a time getting PEAP working with MAC ... > scanners to access my 802.11b network and configuring them for static ... > created an AD user with the MAC address as the user name and password. ... > I configured the access point to do MAC authentication against the ...
    (microsoft.public.internet.radius)
  • RE: PEAP based 802.1x LAN authentication
    ... Authentication, EAP Methods. ... Do you have PEAP added here? ... edit and make sure the certificate that you want to use is selected. ... the server certificate is now stored in "Personal " ...
    (Focus-Microsoft)