Re: PEAP Authentication Issues



"=?Utf-8?B?U2Vhbg==?=" <user@xxxxxxxx> wrote in
news:8079682D-097C-4D12-B166-DC704DB466A7@xxxxxxxxxxxxx:

>
> I have setup a wireless security environment using PEAP, w2k3 server
> (RADIUS/IAS and MS Cert Service) with WPA on Cisco 1200 APs.
>
> Everything works great.... IF the wireless device has already had a
> user authenticate via ethernet (basically established cached
> credentials on the workstaion).
> ex.)
> If a user attempts to login to a device that they have never logged
> into before, wireless-ly they will see the error msg "Domain not
> available". If they hook up to the ethernet, login, establish their
> profile/cached credentials, log out, unplug ethernet; they can then
> log in fine and connect up to wireless -- and will be fine from that
> point on.
>
> Is there an easy way to correct this? Is turning on the guest account
> a good idea?
>
> Thx for any feedback!!
>
> -Sean
>
>
>
>
>

The main issue is that you deployed a server certificate for the IAS server
that clients do not trust. A client that has not been plugged into the LAN
does not have the CA certificate in the Trusted Root Certification
Authorities store, and therefore does not trust the CA or the IAS server,
so server cert validation by the client fails.

When you are plugging the clients into the Ethernet network, the clients
are receiving certs -- the CA cert is automatically enrolled in the Trusted
Root Certification Authorities store on client computers. Once that occurs,
the clients trust the CA -- but until it does, they do not. Because you
deployed your own PKI (as opposed to buying an IAS server cert from a
trusted public CA like Verisign), you have to configure the clients so that
they trust your CA. The easiest way to do this is the way you are doing it.
(You can also do this using a floppy or USB flash drive).

Turning on the guest account is not a good idea, as it creates a large and
easily exploited security hole - which defeats the whole purpose of
deploying PEAP. The only exception to this is if you create a guest VLAN,
but that is fairly complex, and you would need a specific purpose for doing
so (such as providing visitors with Internet access but no access to the
rest of the organization LAN).

--
James McIllece, Microsoft

Please do not send email directly to this alias. This is my online account
name for newsgroup participation only.

This posting is provided "AS IS" with no warranties, and confers no rights.
.



Relevant Pages

  • Re: Multiple Wireless Access Points
    ... >>The devices are Belkin High Speed Mode Wireless G Routers. ... > the internal web server was disabled in their bridge mode. ... That means the clients are not connecting to the DHCP server. ...
    (alt.internet.wireless)
  • RE: ISA bug blocking IAS authentication?
    ... IAS and VPN are on the same SBS2003 server. ... wireless radius authentication works but the VPN connection fails. ... Implement WPA with shared keys on your clients. ...
    (microsoft.public.isa)
  • Re-Authentication Woes
    ... PEAP authentication for wireless access. ... The WAPS are pointed to the IAS and Cert server and seem to be working ...
    (microsoft.public.internet.radius)
  • Re: Using DHCP to separate activity?
    ... DHCP has address reservations matched to the MAC addresses on the visitors' laptops and assigns these to a specific range of IPs. ... The address range used by the reservation is set up as a Computer Set in ISA Server. ... I have another client that allows limited wireless access to visitors, but the wireless access point is between the firewall appliance and external interface of the SBS box. ... wireless clients must use VPN access if they want into the internal network. ...
    (microsoft.public.windows.server.sbs)
  • Re: Wireless Clients losing connections
    ... convinced that the server is the problem. ... that the problem is wireless and not network related. ... First thing to try is changing the channel on the wireless access ... server that is serving the wired clients with no problem. ...
    (microsoft.public.windows.server.sbs)