Enhancing IAS with extension DLLs



Dear,

Would it be possible, with an extension DLL for IAS (or something else?), to
make sure that the VLAN that IAS will send for a 802.1x user authentication
will always match the VLAN that IAS sent for the 802.1x machine
authentication so we do not break the secure channel?

Context: IEEE 802.1x authentication
Goal: Link 802.1x machine authentication with 802.1x user authentication
Current Situation: IAS does not link 802.1x machine authentication with
802.1x user authentication
Problem: This is the problematic scenario:
- If a machine authenticates using 802.1x & radius configures the switchport
in VLAN_X
- If then a user authenticates using 802.1x & radius configures the
switchport in VLAN_Y, then the secure channel is broken & all sorts of
problems occurs (no roaming profile, no GPOs, ...)
Challenge: IAS would have to know a common element to link 802.1x machine
authentication & 802.1x user authentication... we could use the
workstation's MAC-address for this (IAS would have to learn it dynamically)
which is present in the radius messages for both 802.1x machine
authentication & 802.1x user authentication.

What do you think?

Regards,

/Thomas


.



Relevant Pages

  • Re: Enhancing IAS with extension DLLs
    ... >>Would it be possible, with an extension DLL for IAS, ... >>authentication so we do not break the secure channel? ... Link 802.1x machine authentication with 802.1x user authentication ...
    (microsoft.public.internet.radius)
  • Re: Enhancing IAS with extension DLLs
    ... >Would it be possible, with an extension DLL for IAS, to ... >make sure that the VLAN that IAS will send for a 802.1x user authentication ... Link 802.1x machine authentication with 802.1x user authentication ...
    (microsoft.public.internet.radius)
  • Re: Enhancing IAS with extension DLLs
    ... >>Would it be possible, with an extension DLL for IAS, ... >>authentication so we do not break the secure channel? ... Link 802.1x machine authentication with 802.1x user authentication ... > unless the connection is broken. ...
    (microsoft.public.internet.radius)
  • Re: RADIUS (IAS) and Cisco Concentrator? (PDF Attachment)
    ... The order the radius statements in IOS will determine the order the ... IAS servers are checked. ... RADIUS client what policy to use? ... I'm not sure what this is, but if it refers to a secure authentication ...
    (microsoft.public.windows.server.active_directory)
  • RE: check group membership in Connection Request Policy
    ... The access request does not contain a valid user password, ... Authentication is done at the VPN3000, ... So what data does the VPN3000 send to the IAS? ... a custom IAS extension would be really a solution. ...
    (microsoft.public.internet.radius)

Quantcast