Authenticate Computer account using PEAP MS-CHAPv2 on IAS 2k

Tech-Archive recommends: Fix windows errors by optimizing your registry



Hi All

I am trying to implement a 802.1x WLAN with WinXP clients on a Cisco AP1200.

So far, I have managed to get a user authenticated and working, but only if
they have cached credentials on the machine. The problem seems that even
though I have selected the "Authenticate as Computer when available", the IAS
is unable to authenticate the computer.

The extra complication in my case is that the user and computer accounts are
still on an NT4 domain!

I thought I had discovered the problem, when I saw that the
Fully-Qualified-User-Name was presented in the "host/computer.domain" format:
no GC available, authentication fails.
So, using the Replace Realms function (and a lot of trial and error), I now
present the computer name in the old-style "domain\computer$" format.
Unfortunately, IAS now doesn't seem to respond in any way!

When the user (w/cached p/w) logs on, everything goes through fine.

Help!?!? Even if there is no fix, can anyone explain?

Thanks in advance.

R
.



Relevant Pages

  • Re: Authenticate Computer account using PEAP MS-CHAPv2 on IAS 2k
    ... > I am trying to implement a 802.1x WLAN with WinXP clients on a Cisco ... the IAS is unable to authenticate the computer. ... IAS now doesn't seem to respond in any way! ... What kinds of IAS messages are being recorded in the event log? ...
    (microsoft.public.internet.radius)
  • Re: 802.1x authentication for wireless issues w/ ISA 2004
    ... The do support WPA-EAP and the radius ... authenticate the computer and this is trying to authenticate the user and not ... If you can post perhaps 10 lines from the IAS log, ... represent my IAS server or the client laptops. ...
    (microsoft.public.windows.server.sbs)
  • RE: radius server implimentation
    ... I read from the other posts that IAS can be used to ... Is there a way to tell one AD controller to authenticate its users using ... > I'm looking into implementing a radius server that will do ... > for a Cisco VPN 3000 concentrator. ...
    (Security-Basics)
  • Re: VPN 3005 to IAS authentication failure...
    ... Call it something like "VPN Users" or similar. ... install IAS using the Add/Remove Programs icon in Control Panel. ... we can now configure the PIX firewall as a RADIUS client. ... Any user that should be allowed to authenticate on a VPN connection will ...
    (comp.dcom.sys.cisco)
  • Re: IAS server and access points
    ... I use PEAP and passwords to authenticate wireless clients. ... I get an occassional message on my IAS server that says "A RADIUS ...
    (microsoft.public.internet.radius)