Re: IAS RADIUS Test build for integration with Foundry 4802CF switch



=?Utf-8?B?TWFyayAoQ1RSTWludCk=?= <MarkCTRMint@xxxxxxxxxxxxxxxxxxxxxxxxx>
wrote in news:C9B7BF7E-D02B-4799-9DF2-DA9A29CBEBE1@xxxxxxxxxxxxx:

I'm attempting to complete a test lab build of 802.1x using an 4802CF
switch and IAS.
Unfortunately I just don't seem able to get the certificate based
authentication to work. I've managed to get the MD5 working OK. But
I'm after getting the computer based certifcates working.
However, it seems that when I get a Remote Access Policy which matches
the incoming RADIUS request I don't get anything logged. But if a
connection misses a policy match then it seems to match as such. So I
can only assume that the RADIUS process is at least working. Is there
any where I can check what is happening with the certificates.

Ensure that the certs conform to the minimum cert requirements in the
Help topic "Network access authentication and certificates" in Windows
Server 2003 IAS or VPN Help, or on the web at
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/Serv
erHelp/9d8b61c9-a870-4627-a8f2-148625fd7fba.mspx

Also check your configuration against the instructions in "Deployment of
IEEE 802.1X for Wired Networks Using Microsoft Windows" at
http://www.microsoft.com/downloads/details.aspx?FamilyID=05951071-6b20-
4cef-9939-47c397ffd3dd&DisplayLang=en

--
James McIllece, Microsoft

Please do not send email directly to this alias. This is my online account
name for newsgroup participation only.

This posting is provided "AS IS" with no warranties, and confers no rights.
.



Relevant Pages

  • Re: PEAP-TLS vs EAP-TLS
    ... MSCHAPV2 will not be used and then maybe that would be PEAP-TLS. ... select authentication method there are two choices - secured password ... certificates for both server authentication and client authentication; ... I think this means that there's a PEAP-TLS that's separate from EAP-TLS ...
    (microsoft.public.windows.server.security)
  • Re: public key vs passwd authentication?
    ... note that in the generic description of 3-factor authentication, ... certification authorities, and/or certificates ... considered a totally orthogonal business issue. ... possible to deploy a digital signature based two-factor authentication ...
    (comp.security.ssh)
  • RE: IAS server blues (Cant get 802.1x to work)
    ... clients. ... and it appears that the certificates are deploying correctly. ... Proxy-Policy-Name = Use Windows authentication for all users ... IAS Log Sample ...
    (microsoft.public.windows.server.general)
  • Re: Allow only Domain PCs to access Network
    ... NAC, where TCP/UDP traffic may be used to connect to a policy server (rather ... certificates stored in TPMs or SmartCards are even ... authentication, and require client certificates (as in - Computer ... that users haven't got admin access to computer certificate stores (this ...
    (microsoft.public.security)
  • client certificates for authentication but not encryption
    ... resolved the crash, but at the cost of using a secure ... client certificates for authentication but not encryption ... > server using the WebDAV protocol. ...
    (microsoft.public.inetserver.iis.security)

Loading