<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PEAP - Kerberos - Active Directory - Wifi Authentication in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/peap-kerberos-active-directory-wifi-authentication/m-p/1028314#M20127</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, we have setup Guest access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Send me the link (or I will look for it now with your usename) so I can hopefully help you out as you have so kindly helped me :))))&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will find and get back to u&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ken&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 28 Mar 2008 08:15:57 GMT</pubDate>
    <dc:creator>kfarrington</dc:creator>
    <dc:date>2008-03-28T08:15:57Z</dc:date>
    <item>
      <title>PEAP - Kerberos - Active Directory - Wifi Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-kerberos-active-directory-wifi-authentication/m-p/1028307#M20120</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am very confused as to the authentication method used for a wifi client logging into a windows domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;802.1x supports EAP type eap-peap-mschap-v2, but active directory supports Kerberos and not MSCHAPv2 (I believe).  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do I have to do to get a wifi-client working to connect to active-directory using Kerberos whilst EAP only supports MSCHAPv2?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help,  I am a tad confused &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thx indeed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Ken&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 22:35:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-kerberos-active-directory-wifi-authentication/m-p/1028307#M20120</guid>
      <dc:creator>kfarrington</dc:creator>
      <dc:date>2021-07-03T22:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP - Kerberos - Active Directory - Wifi Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-kerberos-active-directory-wifi-authentication/m-p/1028308#M20121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe you need some sort of RADIUS server to perform the authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In our enviorment - we use a Cisco ACS (RADIUS) server to authenticate our wireless clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our clients all use PEAP auth, and the APs all point to the RADIUS server. The RADIUS server has agents that get installed on AD member servers - then those agents act as the go-between for ACS(RADIUS) and Active Directory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I beleive M$ has a radius server (IAS) which should tie nicely into AD - I just have never used M$ RADIUS solution so I cant tell you how to make it work - although I can tell you how to make a Cisco ACS work&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Mar 2008 16:27:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-kerberos-active-directory-wifi-authentication/m-p/1028308#M20121</guid>
      <dc:creator>dewmancco</dc:creator>
      <dc:date>2008-03-26T16:27:38Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP - Kerberos - Active Directory - Wifi Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-kerberos-active-directory-wifi-authentication/m-p/1028309#M20122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thx indeed for your reply.  You are very kind.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So can I just have my WLCs pointing directly to the M$ IAS ?  and does that run Kerberos?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, still a little confused?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thx&lt;/P&gt;&lt;P&gt;Ken&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Mar 2008 18:00:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-kerberos-active-directory-wifi-authentication/m-p/1028309#M20122</guid>
      <dc:creator>kfarrington</dc:creator>
      <dc:date>2008-03-26T18:00:02Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP - Kerberos - Active Directory - Wifi Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-kerberos-active-directory-wifi-authentication/m-p/1028310#M20123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just set this up and I'm still confused. Here is an overview of what you will need to do:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Install a Windows 2003 certificate server CA, and IAS/RADIUS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Authorize your IAS server in active directory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3)  Create a wireless policy in IAS for PEAP Secure password (EAP-MSCHAP v2).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) Configure your AP as a RADIUS client in IAS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5) Deploy the certificate from your CA to all your wireless laptops either automatically through AD, through web-enrollment with IIS or manually.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6) I think all laptops must be members of the AD domain but I'm not positive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the best links that I could find that will guide you step by step.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Microsoft word document:  Step-by-Step Guide for Setting Up Secure Wireless Access in a Test Lab:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=0f7fa9a2-e113-415b-b2a9-b6a3d64c48f5&amp;amp;DisplayLang=en" target="_blank"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=0f7fa9a2-e113-415b-b2a9-b6a3d64c48f5&amp;amp;DisplayLang=en&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ultimate wireless security guide Automatic PEAP deployment with Microsoft Active Directory GPO:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://articles.techrepublic.com.com/5100-1035-6148576.html" target="_blank"&gt;http://articles.techrepublic.com.com/5100-1035-6148576.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Checklist: Configuring the IAS server and wireless access points for wireless access&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://technet2.microsoft.com/windowsserver/en/library/60fa5de5-58a0-4673-be1e-dd24fb1014a41033.mspx?mfr=true" target="_blank"&gt;http://technet2.microsoft.com/windowsserver/en/library/60fa5de5-58a0-4673-be1e-dd24fb1014a41033.mspx?mfr=true&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Mar 2008 21:16:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-kerberos-active-directory-wifi-authentication/m-p/1028310#M20123</guid>
      <dc:creator>rileymartin</dc:creator>
      <dc:date>2008-03-26T21:16:51Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP - Kerberos - Active Directory - Wifi Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-kerberos-active-directory-wifi-authentication/m-p/1028311#M20124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have configured all of the above from 1-6. &lt;/P&gt;&lt;P&gt;Access points which are wired are no problem to configure.&lt;/P&gt;&lt;P&gt;But I have two 1300 series bridges (1310),&lt;/P&gt;&lt;P&gt;one configured as a Root Bridge with wireless clients the other as a NonRoot Bridge with wireless clients. &lt;/P&gt;&lt;P&gt;The non-root cannot associate to the root and is giving the following error:&lt;/P&gt;&lt;P&gt;Interface Dot11Radio0, cannot associate: EAP authenticating.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I configure the nonroot?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thx in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Mar 2008 07:06:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-kerberos-active-directory-wifi-authentication/m-p/1028311#M20124</guid>
      <dc:creator>DUSANVAUPOTIC</dc:creator>
      <dc:date>2008-03-27T07:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP - Kerberos - Active Directory - Wifi Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-kerberos-active-directory-wifi-authentication/m-p/1028312#M20125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is absolutley fantastic.  Many thx indeed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One question if I may :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4.  Configure your AP as a RADIUS Client in IAS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I am using 1242 zero touch APs,  and using 440x controlers (WLCs), I assume I just configure the WLCs as the RADIUS clients?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you or anyone else confirm that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then I beleive you have given me exactly what I need :)))))))))))))))&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thx indeed,&lt;/P&gt;&lt;P&gt;Ken&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Mar 2008 08:48:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-kerberos-active-directory-wifi-authentication/m-p/1028312#M20125</guid>
      <dc:creator>kfarrington</dc:creator>
      <dc:date>2008-03-27T08:48:51Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP - Kerberos - Active Directory - Wifi Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-kerberos-active-directory-wifi-authentication/m-p/1028313#M20126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm sorry but I'm new to Cisco as well as wireless so I'm really lost.  I was lucky to get some good help to setup the PEAP.  I wish I could help you further but I really don't know what I'm doing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm still trying to get help with setting up some sort of 'Guest' access.  I've posted a question but no one replied.  I don't suppose you have any experience with that?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Mar 2008 01:54:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-kerberos-active-directory-wifi-authentication/m-p/1028313#M20126</guid>
      <dc:creator>rileymartin</dc:creator>
      <dc:date>2008-03-28T01:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP - Kerberos - Active Directory - Wifi Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-kerberos-active-directory-wifi-authentication/m-p/1028314#M20127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, we have setup Guest access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Send me the link (or I will look for it now with your usename) so I can hopefully help you out as you have so kindly helped me :))))&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will find and get back to u&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ken&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Mar 2008 08:15:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-kerberos-active-directory-wifi-authentication/m-p/1028314#M20127</guid>
      <dc:creator>kfarrington</dc:creator>
      <dc:date>2008-03-28T08:15:57Z</dc:date>
    </item>
  </channel>
</rss>

