Jump to content

Recommended Posts

Posted

I am trying to get radius authentication setup on some new AP's that I'm going to deploy that will host both Staff and Open Guest Wireless.

 

I have 8 of the EnGenius EAP350s

They are Setup to do WPA2-Enterprise

Radius Server Points to the IAS/Primary Domain Controller Which is a windows 2000 Server

Shared Secret Matches the one Set for the Client in IAS

 

IAS Remote Access Policy Setup as follows

 

Conditions:

Windows Group Matches - Domain\WirelessUsers AND

NAS-Port Type Matches "Wireless - IEEE 802.11 or Wireless-Other"

Grant Remote Access Permission

 

Profile:

Dial In Restricted to Media Wireless- IEEE 802.11 and Wireless-Other

Encryption: Strongest

Authentication: PEAP - Certificate is Set to the Domain Controllers Certificate (number of Retries =2 And allow client to change password after expired is checked)

 

I did delete the Frame-Protocol PPP under Advanced.

 

 

User Account I am testing with is in the WirelessUsers Group and the user is allowed to Dial in to the server.

 

 

I can connect if I manually make a wifi profile on windows 7 and change the to User Authentication and also disable Validate the Server Certificate. Both of those settings are required for it to work.

I am pushing the Domain controllers certificate out from group policy under Computer Configuration->Windows Settings->Security Settings->Public Key Pollicies->Trusted Root Certification Authority

I also see this certificate under the wifi profile where it says Trusted Root Certification Authority on windows 7.

 

I would like it to automatically do user authentication and have the certificate either trusted or just have the pop-up (on non domain computer) that say connect or terminate because it could not be validated.

 

However if I try the connection Automatically it says; Failed because of user user account (or something like that)

 

 

Here are the logs from my AP if I do an automatic connection (this is windows doing Multiple attempts I assume)

May 24 15:07:01 EAP350 daemon.warn hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.1X: authentication failed - EAP type: 25 (PEAP)

May 24 15:07:01 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: disassociated

May 24 15:07:01 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: associated

May 24 15:06:57 EAP350 daemon.warn hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.1X: authentication failed - EAP type: 25 (PEAP)

May 24 15:06:57 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: disassociated

May 24 15:06:57 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: associated

May 24 15:06:53 EAP350 daemon.warn hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.1X: authentication failed - EAP type: 25 (PEAP)

May 24 15:06:53 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: disassociated

May 24 15:06:53 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: associated

May 24 15:06:49 EAP350 daemon.warn hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.1X: authentication failed - EAP type: 25 (PEAP)

May 24 15:06:49 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: disassociated

May 24 15:06:49 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: disassociated

May 24 15:06:49 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: associated

May 24 15:06:48 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: disassociated

May 24 15:06:48 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: associated

May 24 15:06:35 EAP350 daemon.warn hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.1X: could not extract EAP-Message from RADIUS message

May 24 15:06:35 EAP350 daemon.warn hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.1X: authentication failed - EAP type: 0 (Unknown)

May 24 15:06:35 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.1X: Supplicant used different EAP type: 1 (Identity)

May 24 15:06:35 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: associated

 

 

This is what a Successful Manual connection looks like:

May 24 15:41:19 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 WPA: pairwise key handshake completed (RSN)

May 24 15:41:19 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.1X: authenticated - EAP type: 25 (PEAP)

May 24 15:41:19 EAP350 daemon.info hostapd: ath0: STA 8c:70:5a:6f:1e:74 IEEE 802.11: associated

 

 

Any Ideas would be appreciated. I would like it to work automatically with single-signon obviously pushing wifi setting through GP is not an option on windows 2000 server. But I would also like a prompt to come up for username and password when non-domain machine connect so I can enter Domain\user and password. I tried this with a DDWRT based router (in AP only mode) to make sure it was not just the APs and I get the same results. I had this working at a previous Job in a with previous job and windows 2003/2008 domain environment with Aruba APs.

 

Thanks,

Jason

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...