Home > Ask the Networking Experts > Wireless networking with Lisa Phifer Questions & Answers > NAC solution authentication fix for your wireless network
Ask The Networking Expert: Questions & Answers
EMAIL THIS

NAC solution authentication fix for your wireless network

Lisa Phifer EXPERT RESPONSE FROM: Lisa Phifer

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 20 January 2008

We are testing NAC solutions with our Aruba 802.11a/g wireless APs, using Windows 802.1X supplicants. When the user logs on, the Windows roaming profile download fails when the connection is re-established during transition from Machine authentication to User authentication. Do you know of any workaround for this problem?


>
EXPERT RESPONSE

A Windows roaming profile contains environmental information (like desktop items) associated with an individual who uses multiple computers. Whenever that user logs onto a Windows PC, his or her roaming profile is automatically copied from the domain controller to the local computer to provide a consistent environment.

Microsoft's website describes a roaming profile problem that might be what you're experiencing. Specifically, Windows XP users who authenticate with 802.1X and EAP-TLS or PEAP may intermittently fail to download their roaming profiles. According to knowledge base article 938117:

"This problem occurs because EAP-TLS and PEAP-TLS use a client certificate to validate the network connection. The roaming profiles that contain the certificate are stored on a domain controller. When you try to download the roaming profiles after you restart the computer, Windows XP also tries to re-authenticate the user. User re-authentication times out before you can download the roaming profiles."

Microsoft recommends two workarounds for this problem. Either stick to machine (computer) authentication only, or reduce the size of the roaming profile so that the download completes faster. You can configure either EAP-TLS or PEAP to "authenticate as the computer when computer information is available" by using the Authentication tab on the Wireless Connection's Properties panel.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Wireless networking with Lisa Phifer
How can I implement VLANs across WLAN links?
Extending Wi-Fi range indoors or outside with 802.11n and WDS
How does WiMAX compare to other wireless broadband services?
How many more users will 802.11n wireless access points support?
Accessing printers on a LAN while connected to a WLAN.
How to maintain corporate VPN connection while printing to a private network.
How to connect wireless networks for printing capabilities
What is the Free Public WiFi network I keep seeing in public places?
Will different wireless card link speeds cause network latency?
Open source authenticator implementation for LANs: How is open1x an 802.1X supplicant?

Network Access Control (NAC)
Shifting defenses and dynamic perimeters challenge network security
Compliance in a virtualized world: Server virtualization and NAC security
Securing the new network architecture: Security for distributed, dynamic networks
What is data loss prevention? -- An introduction to DLP
How to set passwords on folders in Windows 2003 servers
Is my firewall setting preventing wireless network guest access?
NAC vendor Bradford Networks offers simplified product for guest and contractor access
What commands allow network traffic to pass through PIX firewalls?
Intelligent network switches on the rise as more is expected of the network
Where is a cheap wireless access solution requiring no administration/support?

Wireless Network Security
What are recent security developments for MIPv6?
Wireless LANs -- 'CCNA Official Exam Certification Library, Third Edition,' Chapter 11
Book of Wireless author on wireless advantages and issues
Buying your own WAPs vs. Internet service provider's wireless routers
Aruba Networks unveils wireless intrusion prevention enhancements, other security upgrades, at Interop
Is my firewall setting preventing wireless network guest access?
Wireless hot spot security -- podcast
Wireless troubleshooting: AP not reestablishing association after loss of connectivity
Wireless security protocols -- How WPA and WPA2 work
Wireless security -- How WEP encryption works

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
network access control  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Expert networking advice and tips for IT professionals
Visit KnowledgeStorm's comprehensive and easy to use business white paper directory.
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersNetworking Product Trials
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts