Re: RADIUS server setup



With my Linksys wireless router, I have the following options but I'm not
sure which one to pick for authentication. My tabletPC - Toshiba 3500
doesn't support WPA. I also tried setting up a group policy for Zero
Wireless Configuration and there's a setting for WEP but it doesn't allow me
to enter a WEP key. Any help is much appreciated,

Simon

Here's what I can pick for "Wireless Security" for the Linksys wireless
router:

WPA Pre-Shared Key: There are two encryption options for WPA Pre-Shared Key,
TKIP and AES. TKIP stands for Temporal Key Integrity Protocol. TKIP utilizes
a stronger encrytption method and incorporates Message Integrity Code (MIC)
to provide protection against hackers. AES stands for Advanced Encryption
System, which utilizes a symmetric 128-Bit block data encryption.

To use WPA Pre-Shared Key, enter a password in the WPA Shared Key field
between 8 and 63 characters long. You may also enter a Group Key Renewal
Interval time between 0 and 99,999 seconds.

WPA RADIUS: WPA RADIUS uses an external RADIUS server to perform user
authentication. To use WPA RADIUS, enter the IP address of the RADIUS
server, the RADIUS Port (default is 1812) and the shared secret from the
RADIUS server.

RADIUS: RADIUS utilizes either a RADIUS server for authentication or WEP for
data encryption. To utilize RADIUS, enter the IP address of the RADIUS
server and its shared secret. Select the desired encryption bit (64 or 128)
for WEP and enter either a passphrase or a manual WEP key.

WEP: There are two levels of WEP encryption, 64-bit and 128-bit. The higher
the encryption bit, the more secure your network, however, speed is
sacrificed at higher bit levels. To utilize WEP, select the desired
encryption bit, and enter a passphrase or a WEP key in hexadecimal format.






"Newbie" <newbie@xxxxxxxxxxx> wrote in message
news:uPXfq5Z5FHA.2484@xxxxxxxxxxxxxxxxxxxxxxx
> Owen,
>
> That's correct. I just got the certificate service installed and I'll see
> if I can get it to work. I'm just updating SBS2003 to SP1 and I'll
> upgrade ISA from 2000 to 2004. Hope it'll go smoothly.
>
> Thanks,
>
> Simon
>
>
> "Owen Williams" <Owen@xxxxxxxxxxxxxxxxxx> wrote in message
> news:MPG.1ddbd140fafb4c0f9896be@xxxxxxxxxxxxxxxxxxxxx
>> Simon:
>>
>> You're welcome!
>>
>> I assume when you say "I have RADIUS working authenticating against
>> domain usernames" that you were successful specifying EAP-MSCHAPv2
>> (i.e., username/password) in the remote access policy rather than EAP-
>> TLS (certificates)? If you meant something else, please advise.
>>
>> I see Andrew provided a suggestion for the certificate issue. Let us
>> know whether that worked.
>>
>> -- Owen
>>
>> In article <u7Jq3HB5FHA.3292@xxxxxxxxxxxxxxxxxxxx>, newbie@xxxxxxxxxxx
>> says...
>>> I have a Dell Axim 50 and it requires a certificate to authenticate. So
>>> far
>>> I have RADIUS working authenticating against domain usernames. Don't
>>> know
>>> how to get a certificate set up!
>>>
>>> I have a Dell managed gigabit switch, I'm going to play with the RADIUS
>>> authentication. Hopefully I don't lock myself out :)
>>>
>>> I also would like to thank Owen for sending me the documentation. I
>>> couldn't have done it without the documentation, much appreciated.
>>>
>>> Simon
>
>


.



Relevant Pages

  • Re: wireless network disconnects when using IEEE 802.1x authentica
    ... Before I discuss wireless encryption differences, ... Change that authentication key say every six months. ... RADIUS server to do that, and it works best if you've got an Active ...
    (microsoft.public.windowsxp.security_admin)
  • Re: 802.1X wireless connection without WEP
    ... Wirless to an AP with configuration 802.1X but without static WEP ... and without dinamic WEP (without encryptation only with authentication ... WEP is an encryption standard. ... Dynamic WEP allows the access point to deliver a temporary WEP key to ...
    (alt.internet.wireless)
  • Re: 802.1X wireless connection without WEP
    ... Wirless to an AP with configuration 802.1X but without static WEP ... and without dinamic WEP (without encryptation only with authentication ... WEP is an encryption standard. ... Dynamic WEP allows the access point to deliver a temporary WEP key to ...
    (alt.internet.wireless)
  • Help
    ... WEP and AD for authentication and encryption ... purposes. ...
    (microsoft.public.internet.radius)
  • Cisco Security Advisory: RADIUS Authentication Bypass
    ... Cisco Security Advisory: RADIUS Authentication Bypass ... Cisco has made free software available to address this vulnerability. ...
    (Bugtraq)