Re: 802.1x Authentication Question



hi andy,

in the end its all upon your choice. EAP-TLS is more secure cause of
client certificates, but PEAP is a bit easier to set up.

but you have to think first if it will be possible for all users to get
a machine certificate on their clients. so its usually easier to manage
all these passwords for PEAP.
One problem of PEAP is also, that you have to change the 802.1x
settings on your NIC. its default on authentication via EAP-TLS...

maybe you can give some more information about your company ? what kind
of users, many guests, what about printers etc.

hope that helps a bit :)

Greetz Eric


Andy schrieb:

Hi All,

I am setting 802.1x for wired and wireless network using IAS 2000 as RADIUS
server. My goal is to prevent users from bringing their laptops, APs or
Switches in and use their logins to grant access to the company network. I am
not sure which authentication method is a approriated choice for me either
PEAP-MSCHAP-V2 or EAP-TLS

Please advice

Thanks,
--
Andy

.



Relevant Pages

  • Re: Group Policies over WLAN
    ... PEAP may resolve this issue? ... > either EAP-TLS or PEAP. ... >> We have recently acquired a wireless lab of all laptops. ... >> that any group policy applied as a startup script does not come down ...
    (microsoft.public.win2000.networking)
  • Wireless EAP Problem
    ... I am using on my wireless network EAP-TLS which requires user certificates ... for authentication. ... I want to go back to PEAP which will eliminate this requirement. ...
    (microsoft.public.windows.server.networking)
  • Re: IAS, PEAP-MSCHAPv2, Windows XP Wireless cant authenticate !
    ... > You could also try to do EAP-TLS instead of PEAP? ... that's really not the purpose... ... Prev by Date: ...
    (microsoft.public.internet.radius)
  • WI-FI auth/encr protocols supported in WM5
    ... supported in WM5? ... (ie. EAP-TLS, PEAP, LEAP and so on...) ...
    (microsoft.public.pocketpc.wireless)
  • 802.1X and Guest
    ... I tested via peap and eap-tls. ... However I would like to know how to make to authenticate computers which do ... because one cannot change the login. ...
    (microsoft.public.windows.server.networking)

Loading