jfinnigan Posted May 24, 2013 Posted May 24, 2013 I am trying to get radius authentication setup on some new AP's that I'm going to deploy that will host both Staff and Open Guest Wireless. I have 8 of the EnGenius EAP350s They are Setup to do WPA2-Enterprise Radius Server Points to the IAS/Primary Domain Controller Which is a windows 2000 Server Shared Secret Matches the one Set for the Client in IAS IAS Remote Access Policy Setup as follows Conditions: Windows Group Matches - Domain\WirelessUsers AND NAS-Port Type Matches "Wireless - IEEE 802.11 or Wireless-Other" Grant Remote Access Permission Profile: Dial In Restricted to Media Wireless- IEEE 802.11 and Wireless-Other Encryption: Strongest Authentication: PEAP - Certificate is Set to the Domain Controllers Certificate (number of Retries =2 And allow client to change password after expired is checked) I did delete the Frame-Protocol PPP under Advanced. User Account I am testing with is in the WirelessUsers Group and the user is allowed to Dial in to the server. I can connect if I manually make a wifi profile on windows 7 and change the to User Authentication and also disable Validate the Server Certificate. Both of those settings are required for it to work. I am pushing the Domain controllers certificate out from group policy under Computer Configuration->Windows Settings->Security Settings->Public Key Pollicies->Trusted Root Certification Authority I also see this certificate under the wifi profile where it says Trusted Root Certification Authority on windows 7. I would like it to automatically do user authentication and have the certificate either trusted or just have the pop-up (on non domain computer) that say connect or terminate because it could not be validated. However if I try the connection Automatically it says; Failed because of user user account (or something like that) Here are the logs from my AP if I do an automatic connection (this is windows doing Multiple attempts I assume) May 24 15:07:01 EAP350 daemon.warn hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.1X: authentication failed - EAP type: 25 (PEAP) May 24 15:07:01 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: disassociated May 24 15:07:01 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: associated May 24 15:06:57 EAP350 daemon.warn hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.1X: authentication failed - EAP type: 25 (PEAP) May 24 15:06:57 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: disassociated May 24 15:06:57 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: associated May 24 15:06:53 EAP350 daemon.warn hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.1X: authentication failed - EAP type: 25 (PEAP) May 24 15:06:53 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: disassociated May 24 15:06:53 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: associated May 24 15:06:49 EAP350 daemon.warn hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.1X: authentication failed - EAP type: 25 (PEAP) May 24 15:06:49 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: disassociated May 24 15:06:49 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: disassociated May 24 15:06:49 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: associated May 24 15:06:48 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: disassociated May 24 15:06:48 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: associated May 24 15:06:35 EAP350 daemon.warn hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.1X: could not extract EAP-Message from RADIUS message May 24 15:06:35 EAP350 daemon.warn hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.1X: authentication failed - EAP type: 0 (Unknown) May 24 15:06:35 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.1X: Supplicant used different EAP type: 1 (Identity) May 24 15:06:35 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: associated This is what a Successful Manual connection looks like:May 24 15:41:19 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 WPA: pairwise key handshake completed (RSN) May 24 15:41:19 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.1X: authenticated - EAP type: 25 (PEAP) May 24 15:41:19 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: associated Any Ideas would be appreciated. I would like it to work automatically with single-signon obviously pushing wifi setting through GP is not an option on windows 2000 server. But I would also like a prompt to come up for username and password when non-domain machine connect so I can enter Domain\user and password. I tried this with a DDWRT based router (in AP only mode) to make sure it was not just the APs and I get the same results. I had this working at a previous Job in a with previous job and windows 2003/2008 domain environment with Aruba APs. Thanks, Jason
jfinnigan Posted May 28, 2013 Author Posted May 28, 2013 Windows 2000 does not support everything needed for it to work. Solution here: 802.1x Authentication With IAS Thread Can Be Closed
jfinnigan Posted May 28, 2013 Author Posted May 28, 2013 Public Library Budget, Enough said I'm hoping to upgrade all 4 this fiscal year though.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now