<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PEAP authentication problems in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/peap-authentication-problems/m-p/250551#M20786</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know this doesn't help, but I have exactly the same problem and symptoms as your are experiencing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would be happy to hear about your resolution. I suspect that we will have better luck using the MS supplicant rather that the Cisco supplicant, but I have not been able to try this yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will inform you if this approach works.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 Apr 2004 14:07:00 GMT</pubDate>
    <dc:creator />
    <dc:date>2004-04-01T14:07:00Z</dc:date>
    <item>
      <title>PEAP authentication problems</title>
      <link>https://community.cisco.com/t5/wireless/peap-authentication-problems/m-p/250547#M20782</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured a Cisco AP 1200 IOS with PEAP.&lt;/P&gt;&lt;P&gt;Hereby the AP Config:&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius rad_eap&lt;/P&gt;&lt;P&gt; server 192.168.4.58 auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius rad_mac&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius rad_acct&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius rad_admin&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ tac_admin&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius rad_pmip&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius dummy&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login eap_methods group rad_eap&lt;/P&gt;&lt;P&gt;aaa authorization exec default local &lt;/P&gt;&lt;P&gt;aaa authorization ipmobile default group rad_pmip &lt;/P&gt;&lt;P&gt;aaa accounting network acct_methods start-stop group rad_acct&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;dot11 arp-cache optional&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;bridge irb&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dot11Radio0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; encryption vlan 184 key 1 size 128bit 7 xxxx transmit-key&lt;/P&gt;&lt;P&gt; encryption vlan 184 mode wep mandatory mic key-hash &lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; encryption key 1 size 128bit 7 xxxxx transmit-key&lt;/P&gt;&lt;P&gt; encryption mode wep mandatory &lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; broadcast-key vlan 184 change 3600&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; ssid test&lt;/P&gt;&lt;P&gt;    vlan 184&lt;/P&gt;&lt;P&gt;    authentication open eap eap_methods&lt;/P&gt;&lt;P&gt;    authentication network-eap eap_methods &lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; world-mode&lt;/P&gt;&lt;P&gt; speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0&lt;/P&gt;&lt;P&gt; rts threshold 2312&lt;/P&gt;&lt;P&gt; station-role root&lt;/P&gt;&lt;P&gt; dot1x reauth-period 1800&lt;/P&gt;&lt;P&gt; dot1x client-timeout 1800&lt;/P&gt;&lt;P&gt; bridge-group 1&lt;/P&gt;&lt;P&gt; bridge-group 1 subscriber-loop-control&lt;/P&gt;&lt;P&gt; bridge-group 1 block-unknown-source&lt;/P&gt;&lt;P&gt; no bridge-group 1 source-learning&lt;/P&gt;&lt;P&gt; no bridge-group 1 unicast-flooding&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dot11Radio0.184&lt;/P&gt;&lt;P&gt; encapsulation dot1Q 184&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; bridge-group 184&lt;/P&gt;&lt;P&gt; bridge-group 184 subscriber-loop-control&lt;/P&gt;&lt;P&gt; bridge-group 184 block-unknown-source&lt;/P&gt;&lt;P&gt; no bridge-group 184 source-learning&lt;/P&gt;&lt;P&gt; no bridge-group 184 unicast-flooding&lt;/P&gt;&lt;P&gt; bridge-group 184 spanning-disabled&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; ip accounting output-packets&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; full-duplex&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0.3&lt;/P&gt;&lt;P&gt; encapsulation dot1Q 3 native&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; bridge-group 1&lt;/P&gt;&lt;P&gt; no bridge-group 1 source-learning&lt;/P&gt;&lt;P&gt; bridge-group 1 spanning-disabled&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0.184&lt;/P&gt;&lt;P&gt; encapsulation dot1Q 184&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; bridge-group 184&lt;/P&gt;&lt;P&gt; no bridge-group 184 source-learning&lt;/P&gt;&lt;P&gt; bridge-group 184 spanning-disabled&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface BVI1&lt;/P&gt;&lt;P&gt; ip address 192.168.4.98 255.255.254.0&lt;/P&gt;&lt;P&gt; ip accounting output-packets&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip default-gateway 192.168.4.3&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;ip http help-path &lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag/ivory/1100" target="_blank"&gt;http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag/ivory/1100&lt;/A&gt;&lt;/P&gt;&lt;P&gt;ip radius source-interface BVI1 &lt;/P&gt;&lt;P&gt;radius-server local&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;radius-server host 192.168.4.58 auth-port 1645 acct-port xxxx key xxx&lt;/P&gt;&lt;P&gt;radius-server timeout 120&lt;/P&gt;&lt;P&gt;radius-server deadtime 1200&lt;/P&gt;&lt;P&gt;radius-server domain-stripping &lt;/P&gt;&lt;P&gt;radius-server attribute 32 include-in-access-req format %h&lt;/P&gt;&lt;P&gt;radius-server authorization permit missing Service-Type&lt;/P&gt;&lt;P&gt;radius-server vsa send accounting&lt;/P&gt;&lt;P&gt;bridge 1 protocol ieee&lt;/P&gt;&lt;P&gt;bridge 1 route ip&lt;/P&gt;&lt;P&gt;bridge 184 protocol ieee&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;W're using a Cisco Wireless client adaptor with the latest ACU version fully installed and configured my client for PEAP. I also configured the Windows XP network settings appropriately.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The RADIUS we are using is a Cisco ACS 3.2.1. We used a Microsoft certificate for the server that we issued ourselves.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Without configuring security, the client can associate with the AP, but when we enable PEAP and I open the ACU status screan, the client associates with the AP, but canot authenticate successfully. Status hangs on 'autenticating'. I don't see any traffic to the RADIUS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Who can help us?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 16:26:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authentication-problems/m-p/250547#M20782</guid>
      <dc:creator>stefaanbolle</dc:creator>
      <dc:date>2021-07-04T16:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP authentication problems</title>
      <link>https://community.cisco.com/t5/wireless/peap-authentication-problems/m-p/250548#M20783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try installing the latest image for the AP 1200, if you have not already done this&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Mar 2004 23:06:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authentication-problems/m-p/250548#M20783</guid>
      <dc:creator />
      <dc:date>2004-03-15T23:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP authentication problems</title>
      <link>https://community.cisco.com/t5/wireless/peap-authentication-problems/m-p/250549#M20784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply!&lt;/P&gt;&lt;P&gt;We're already runing the latest image version of the AP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Mar 2004 07:27:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authentication-problems/m-p/250549#M20784</guid>
      <dc:creator>stefaanbolle</dc:creator>
      <dc:date>2004-03-16T07:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP authentication problems</title>
      <link>https://community.cisco.com/t5/wireless/peap-authentication-problems/m-p/250550#M20785</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. You do not want to use windows to configure the adaptor if you are using ACU.&lt;/P&gt;&lt;P&gt;2. Make sure you install the certificate on the client machine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have had better luck using the XP client for peap than ACU.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Mar 2004 20:23:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authentication-problems/m-p/250550#M20785</guid>
      <dc:creator>steve.deal</dc:creator>
      <dc:date>2004-03-17T20:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP authentication problems</title>
      <link>https://community.cisco.com/t5/wireless/peap-authentication-problems/m-p/250551#M20786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know this doesn't help, but I have exactly the same problem and symptoms as your are experiencing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would be happy to hear about your resolution. I suspect that we will have better luck using the MS supplicant rather that the Cisco supplicant, but I have not been able to try this yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will inform you if this approach works.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Apr 2004 14:07:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authentication-problems/m-p/250551#M20786</guid>
      <dc:creator />
      <dc:date>2004-04-01T14:07:00Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP authentication problems</title>
      <link>https://community.cisco.com/t5/wireless/peap-authentication-problems/m-p/250552#M20787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many things could be wrong unfortunately, so I'll list a few that I've had to trudge through in the hopes they help:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)  You're using ports 1646/1645 for RADIUS.  Those are the older ports.  Newer servers use 1812 (I think 1813 for accounting, I'd have to verify).  Ensure your server is listening on 1645 as you have defined or you wont get any authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Turn on dot11 debugging. The nice thing about new IOS APs is they give you the ability to see if you're even hearing your client.  I'm still learning to use this tool but I use "debug dot11 aaa dot1x all" to see who's talking and when.  The output is of course cryptic, but it's nice to see the output.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3)  Lastly, once you're talking to the RADIUS server, use it's logs to determine the output error. I've found that with PEAP, depending on the client I use (I use a FUNK radius server, and FUNK Odysee Clients - thank you Cisco for ignore CF form factor wireless cards for 4 years ;p), the inner authentication protocal version 1 or 2 is the complaint from the RADIUS server. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Apr 2004 17:57:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authentication-problems/m-p/250552#M20787</guid>
      <dc:creator>jczaplewski</dc:creator>
      <dc:date>2004-04-01T17:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP authentication problems</title>
      <link>https://community.cisco.com/t5/wireless/peap-authentication-problems/m-p/250553#M20788</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just opened a TAC case on this one whereby I have already installed the latest client, made sure PEAP is installed, had the latest WAP image, network security setup on the ACU as per the documentation to select the "host base EAP(802.1x) and select dynamic wep, then turned on debug options on the WAP to see the communication between the client and the WAP:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug radius authentication&lt;/P&gt;&lt;P&gt;debug dot11 aaa dot1x process&lt;/P&gt;&lt;P&gt;debug dot11 aaa dot1x state-machine&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Guess what... there is no communication between the client and the wap for authentication.  You can see association and even get an ip address from dhcp but...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The advise as per the TAC engineer is to put in a Static WEP key for now and you should get the communication going.  They have already noticed this on some calls and have not seen a bug case # assigned to it.  They will be working a fix on the next release.  Once you do that you should see the Raduis and 802.1x communication going on.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After doing this I can then concentrate on why I am not getting PEAP authenticated on our Funk Radius EE Server v4.7.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other thing...remove the "authentication network-eap eap_methods"  when you are doing PEAP.  You enable that for LEAP so you have to create a different vlan for that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use 1812/1813 for the radius server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Ed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Apr 2004 01:52:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authentication-problems/m-p/250553#M20788</guid>
      <dc:creator>emcpherson</dc:creator>
      <dc:date>2004-04-02T01:52:55Z</dc:date>
    </item>
  </channel>
</rss>

