Re: Wireless EAP Problem



In this case, I would double check the group policy settings.

FYI, We have Cisco AP 1200 and 1300 APs. We setup Enterprise WPA2 with IAS as authentication. Any domain users just logon their domain user IDs without configuring computer certificate.

--
Bob Lin, MS-MVP, MCSE & CNE
Networking, Internet, Routing, VPN Troubleshooting on
http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on
http://www.HowToNetworking.com
"Redleg6" <redleg6@xxxxxxxxxxxxxxxx> wrote in message news:eioebhd9IHA.2332@xxxxxxxxxxxxxxxxxxxxxxx
OK, sorry 'bout that.

I have a Win2003 domain. An enterprise CA running on a Win2003 Enterprise OS. I use group policy. This is a test domain that I use for working out problems before I place anything on the production domain which is used to service a hospital.

The workstations are all WinXP SP2.

The problem I am working on is how to best setup some COWS(computers on wheels) for the nurses in the patient areas. We have wireless with Cisco AP's thruout the hospital to service the COWs. These AP's connect into our primary VLAN that connects to our production system. Since sensitive patient info is sent over the wireless network it is essential that the communications be highly secure.

At first I set up a test using EAP-TLS. I also used autoenrollment in GP. Each COW has a computer certificate and a user certificate for each user. This setup is very secure but having 20-30 user certificates to manage on each COW is a huge managment problem. BTW the certs use a custom wireless template and all the users must be in a special wireless global group. The connections with the COWS use IAS that has a certificate from the CA.

Now I want to try using PEAP. This will still encrypt the wireless common but will not require all the user certificates on the COWS. I can easily change to PEAP in the remote access policy for IAS. But when I try to change to PEAP in the wireless connection on the COW the change is not allowed. Everytime I change the properties for the wireless network to use PEAP instead of a certificate the change is not accepted.

I need some help on how to change to PEAP on the COWS.


"Robert L. (MS-MVP)" <findemail@xxxxxxxxxxxxxxx> wrote in message news:%23cb9%23Kb9IHA.3544@xxxxxxxxxxxxxxxxxxxxxxx
We need more details to help you. Where do you make the change? Do you have group policy?

--
Bob Lin, MS-MVP, MCSE & CNE
Networking, Internet, Routing, VPN Troubleshooting on
http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on
http://www.HowToNetworking.com
"Myrt Webb" <myrtwebb@xxxxxxxxxxxxxx> wrote in message news:O6gnGPY9IHA.5928@xxxxxxxxxxxxxxxxxxxxxxx
I am using on my wireless network EAP-TLS which requires user certificates for authentication.

I want to go back to PEAP which will eliminate this requirement. Problem is the wireless network configuration on my Win XP SP2 will not allow me to change. Everytime I make the change I get a message that will not allow the change. The card is a Linksys.

How can I change from user certs to PEAP and make it stick?





.



Relevant Pages

  • Re: WM5 PEAP with Certificates
    ... to connect to our wireless with my Axim x51v. ... in the trusted root certificate area. ... using TKIP encryption and then PEAP, if I hit the properties button for PEAP ... EAP/TLS and you do need a user and root cert on the device. ...
    (microsoft.public.pocketpc.wireless)
  • Re: Need help with 802.1x peap authentication
    ... I do see the certificate in my personal folder in the mmc console but when I ... Guess I don't need that if I'm using PEAP right? ... If you open an mmc console on the server and add ... > wireless Remote Access Policy, select Edit Profile, click the Authentication ...
    (microsoft.public.windows.server.general)
  • Re: How to use PEAP-MSCHAP in WM5
    ... when you setup your wiress profile the last page of the setup asks about 802.1x. ... Here you can choose PEAP or Certificate based authentication. ... Once you select PEAP and tap finish a few moments later you will be presented with a screen asking for you credentials. ...
    (microsoft.public.pocketpc.wireless)
  • Re: Can Windows dialer (XP/2000) use PEAP?
    ... PEAP is only available for Wireless and Wired authentication ... > I also find that I can choose 'Smart card or other Certificate' and PEAP> within the NIC authentication tab on XP (Wireless and Wired). ...
    (microsoft.public.internet.radius)
  • Re: 3 PC SOHO Network setup problem
    ... As I say below, my setup should ... >>so security on the wireless side is not a major concern. ... no PC has an internet connection other than through the router. ... > only by the Guest account, which means this computer will be open to anyone. ...
    (microsoft.public.windowsxp.network_web)