Jump to content

Recommended Posts

Posted (edited)

This is beginning to drive me nuts so hoping someone can help shed some light on the matter :p

 

I'm trying to set up wireless laptops via RADIUS so we can have effectively the same look and feel as a desktop machine i.e. automatic logon to the domain, applying GPOs, profiles etc. Have been trying to get my head around the numerous ways of defining PEAP etc and seem to see two methods...

 

EAP-TLS... machine certificate used for authentication cert is auto-enrolled via Group Policy

PEAP-MSCHAPv2... uses the user credentials to connect (although there seems to be a Computer Account option as well)

 

There also seems to be PEAP-EAP-TLS, which as far as I understand is a slightly more secure version of EAP-TLS?

 

Have been trying the EAP-TLS method but not having much joy :(

 

- created Enterprise CA

- set up auto enrolment for clients and the NPS server as per NPS Server Certificate: Configure the Template and Autoenrollment and Deploy Client Computer Certificates

- create a GPO for the wireless settings, used "Microsoft: Smart Card or other Certificate" as the authentication method (I believe this is EAP-TLS?)

- set up the NPS server using the wizard, matched the Network Policy to use the same "Microsoft: Smart Card or other Certificate" authentication method

- set up Ruckus AAA server as "RADIUS" and configured NPS with the ZoneDirector IP address and shared secret

 

Logged in as Local Admin on one laptop and tried to connect to the wireless, logic being it should connect as it's authenticating as the machine doing the auth... just sits there saying "Attempting to Authenticate". On the XP SP3 laptop packets go back and forth but on the Win7 it's 0 sent \ 0 received.

 

Checking certificates store on both laptops shows machine certificate in Machine\Personal store and CA cert in Machine\Trusted Root Certification Authorities

 

Annoyingly I'm seeing very little in log files on the NPS server or on the client, seems like you have to dig quite deep to get anything of use... time for Wireshark? Also noticed this when using machine authentication, do I really need to make these changes just to get EAP-TLS to connect? http://support.microsoft.com/kb/929847

 

Any ideas for where I'm going wrong as I can't see it at the moment?

Edited by gshaw
Posted

It looks as though you've done everything right. On the NPS server you need to look in Custom Logs, not the Windows Logs (you won't see anything from NPS in there). You should see plenty of logs if you're trying to get a client to associate using Computer Authentication.

 

Can you have a look in the log and post any errors you get here?

Posted (edited)

Cracked it :D

 

A couple of changes sorted the problem...

 

a) making sure 802.1X EAP was entered on authentication method on the WLAN in Ruckus (someone else set this up for me initially and left it off)

b) re-creating the shared secret, RADIUS client etc from scratch... start with a really simple secret to make sure it works then go for a complex one later

c) XP SP3 clients won't auto enrol their certs if you use the 2008 template when following the MS guide to duplicating templates

 

Think I might leave my cert template as 2008 due to XP being removed in summer anyway...

 

Thanks for the reply, knowing that the method was correct helped go back and find the simple things... I'm a happy RADIUS user now :)

Edited by gshaw
  • Thanks 1
Posted (edited)

Nice way to end the week with a bit of success :)

 

Just need to decide whether to stick with EAP-TLS or go PEAP-MSCHAP or PEAP-EAP-TLS... seeing as I have the certificates working OK I guess it's just a matter of deciding how I want the security set up (as far as I understand it)...

 

- EAP-TLS... just authenticate the WLAN via machine certificate (set up and working at the moment)

- PEAP-EAP-TLS... authenticate user and computer via certificates

- PEAP-MSCHAPv2... basic authentication via Computer account then username \ password

 

Just reading another thread on here I'm leaning towards EAP-TLS to avoid the possible Computer Account expiration issue some experienced when machines aren't used for a while. Also wondering if EAP-TLS might work better for any non-MS devices we might use in future (iPads, Android devices etc?)

Edited by gshaw
Posted (edited)

@gshaw

 

Can you recommend any (step by step) guides in relation to getting the Windows 2008 R2 RADIUS up and running?

 

Not been successful as yet (but keep trying, much easier as using Hyper-V instance) but once setup would be easier to authenticate our new laptops (with Ruckus) than coding the wireless keys in etc.

 

Thanks,

 

 

Update

Managed to get it working following these 2 articles:

http://community.spiceworks.com/how_to/show/1455

http://forums.ruckuswireless.com/forums/8/topics/1278

Edited by MYK-IT
  • 1 month later...
Posted

a) making sure 802.1X EAP was entered on authentication method on the WLAN in Ruckus (someone else set this up for me initially and left it off)

Thanks! This post made me check this and solved the same problem for me!

I decided to use PEAP-MSCHAPv2 and a check on whether the machine is a domain computer. Therefore all domain machines can join with no extra info supplied but non domain machines are rejected.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...