Home > Ask the Networking Experts > Wireless networking Questions & Answers > Advice on configuring 802.1X authentication
Ask The Networking Expert: Questions & Answers
EMAIL THIS

Advice on configuring 802.1X authentication

EXPERT RESPONSE FROM: Retired expert - Graham Robinson

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 11 August 2003
Our organization has a basic WLAN (3 aironet 350's.) Some users have 350 nics, but the majority have integrated third party nics embedded into their laptops. We also have a Cisco ACS server to which I want all the clients to authenticate to. The Cisco nics do this with no problem however; I cannot get the third-party nics to authenticate with the server. The clients all use the windows xp wireless support feature.

I have created the users on the ACS server using their MAC address as the user name and password and also set the AP up according to Cisco's documentation.

The XP wireless support software is set up to authenticate using peap. Please help!


>
The configuration of 802.1X authentication is not as simple as some people would like to think and there are many different implementations.

For the purposes of this answer I'm going to assume you have Windows XP on EVERY client and you are using PEAP on each laptop.

A good thing to know about PEAP is that there are two different implementations of PEAP:

  1. PEAP w/ CHAP – Used by Cisco and requires the Cisco ACU and CiscoSecure ACS
  2. PEAP w/ MS-CHAP v2 – Used by Microsoft and Incompatible with Cisco's ACU.

Also good things to know:

  • For ALL 802.1X implementations (PEAP, LEAP, EAP-TLS, etc) you need a card that supports 128bit WEP.
  • Not all 128bit WEP implementations are compatible with each other (please see my earlier postings explaining WEP), thus you may find that some cards simply will NOT work with some access points when you try and use 128bit WEP OR any type of 802.1X user authentication.

    Now, given that you're using cards of all different types you need to check that each card is compatible with the Cisco Access Points – try using a 128bit WEP key for testing here.

    After you've done that and they all work, you need to make sure that you have CiscoSecure ACS version 3.2. Only the recent release (3.2) supports the Microsoft version of PEAP. Any PEAP support prior to ACS 3.2 will be for Cisco PEAP only and will require Cisco cards with the Cisco ACU (version 6.0 or above) installed onto the laptops.

    Hopefully this has sent you in the right direction.
    Cheers.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Enterprise Wireless
    How do I find the IP address of my wireless router?
    What is the difference between Digital Microwave technology vs. 802.11b?
    Using IP-based cameras from different geographical locations
    Configuring a wireless network
    Can I use wireless AP's for point to multipoint connectivity?
    Thesis guide involving wireless and networking
    Diagnose connectivity problems on Cisco products
    Help adding WAP to an existing network
    Guide to creating a hotspot zone
    Diagnosing connection drops

    Wireless networking
    Why is my network adapter not working after a Vista Business upgrade?
    How many wireless base stations can connect to 802.11g access points?
    APs drop connection in WLAN configured as a wireless mesh network
    How does Wi-Fi ad-hoc mode react when 802.11n and legacy peers are present?
    Can wireless adapters operate as client access points to make SoftAPs?
    Will using a VPN protect me against fake wireless hotspots?
    WLAN QoS and SLA monitoring with 7/24 Wireless Quality Assurance costs
    How can I hide my WLAN's SSID in an Aruba AP-61?
    How radio frequency (RF) of microwaves alter wireless signal strength
    Stolen laptop recovery using remote access and wireless network SSIDs

    Wireless LAN Implementation
    University tackles large-scale 802.11n wireless network management
    Why is my network adapter not working after a Vista Business upgrade?
    How many wireless base stations can connect to 802.11g access points?
    802.11n wireless APs bring IP video to sprawling Illinois high school
    No data cable? Wireless mesh networking the answer for Wi-Fi backhaul
    Integrated wireless and wired LAN: Brocade-Motorola deal ups the ante
    802.11n WLAN architecture strategies: The 2.4 vs. 5 GHz band debate
    802.11n upgrade: College ditches legacy network for new vendor
    802.11n ratification will drive down wireless LAN prices
    How does Wi-Fi ad-hoc mode react when 802.11n and legacy peers are present?

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    802.11a  (SearchNetworking.com)
    Asynchronous Pulsed Radiated Incident Light  (SearchNetworking.com)
    beamforming  (SearchNetworking.com)
    cognitive radio  (SearchNetworking.com)
    direct sequence spread spectrum  (SearchNetworking.com)
    frequency-hopping spread spectrum  (SearchNetworking.com)
    patch antenna  (SearchNetworking.com)
    phase-locked loop  (SearchNetworking.com)
    radio frequency  (SearchNetworking.com)
    wireless mesh network  (SearchNetworking.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Expert networking advice and tips for IT professionals
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts