<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: problems on peap.... in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/problems-on-peap/m-p/530727#M25895</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, ScottMac! That clears away some of the cobwebs and i hope the sun will come out tomorrow for me.:) crsytal clear partic with certificates and WDS, but i am still confused with PEAP as to why it is not working considering I did exactly what I read on cisco documents and some microsoft articles. I probably missed some minor but very important configuration detail. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will try to look for the "Configure Cisco IAS" (no qoutes, of course)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, ScottMac!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct with my LEAP configuration, I did just used the Local (AP) Radius Server. But I have tried it as well via the ACSv3.3 and no problem with LEAP on that as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another question,ScottMac, with LEAP, after powering ON my notebook (configured with LEAP, of course), before cached and non-cached users logon to the domain or even just the local computer, LEAP is doing all the association, authentication, and is able to get an IP address (considering a DHCP network it is). I have learned that PEAP doesn't do this (well, at least with my conifuration), but is there a way for PEAP to do all the AAA before a user can login. For users already cached in the local notebook, there is no problem, but for non-cached users, there seem to have problems with my PEAP configuration. I hope you can help me pinpoint my mistakes...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 26 Feb 2006 05:09:58 GMT</pubDate>
    <dc:creator>n.manlangit</dc:creator>
    <dc:date>2006-02-26T05:09:58Z</dc:date>
    <item>
      <title>problems on peap....</title>
      <link>https://community.cisco.com/t5/wireless/problems-on-peap/m-p/530725#M25893</link>
      <description>&lt;P&gt;hello, experts!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my setup&lt;/P&gt;&lt;P&gt;AP - 1231 G&lt;/P&gt;&lt;P&gt;AUTHENTICATION SERVER - IAS (POINTED THE AP TO THE IAS)&lt;/P&gt;&lt;P&gt;AUTHENTICATION METHOD - Open Authentication with EAP&lt;/P&gt;&lt;P&gt;CLIENT - AIRONET a/b/g&lt;/P&gt;&lt;P&gt;3Com OfficeConnect 11g&lt;/P&gt;&lt;P&gt;WINXP SP2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my peap (mschapv2) is not working via the winxp utility and neither on ADU. with winxp, it really is not working. the username and password prompt keeps appearing but when i tried to enter the correct credentials it just goes back to a blank username and password login dialog. with the ADU, it works. but it keeps on disassociating. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does winxp peap (mschapv2), NOT THE ADU, works? &lt;/P&gt;&lt;P&gt;is there additional configuration i have to do, patches i have to install? &lt;/P&gt;&lt;P&gt;i didn't use certificates, do i have to when using mschapv2? &lt;/P&gt;&lt;P&gt;are certificates easier to install and more secure than just mschapv2?&lt;/P&gt;&lt;P&gt;Is Open Authentication meant for multi-vendor clients (EAP) and Network EAP is meant for cisco only, particulary LEAP?&lt;/P&gt;&lt;P&gt;Will WDS make it easier to configure and implement security for clients?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the same setup works perfectly with LEAP, and i had not one problem with it, it works the way it says on the cisco documents. but i have multi-vendor clients and with this, it went from easy to extremely complicated... Please help, any input is greatly appreciated. thanks&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 18:42:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-on-peap/m-p/530725#M25893</guid>
      <dc:creator>n.manlangit</dc:creator>
      <dc:date>2021-07-04T18:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: problems on peap....</title>
      <link>https://community.cisco.com/t5/wireless/problems-on-peap/m-p/530726#M25894</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm guessing, but I believe you'd have to be using the AP's local RADIUS server for LEAP to work - MS IAS doesn't support LEAP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You don't need certificates on the client for PEAP, only on the server providing the IAS service. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tried PEAP with Zero Wireless Config (the MS software), and it worked OK (Win2003 server running IAS). I've also used the same setup with EAP-TLS, but that would require certs on all of the clients. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Certificates are "more secure," in that only legitimate clients should have valid certs. They are also more administration intensive ... you can push the cert out with a Group Policy ... which make things marginally easier (depending on how well you know MS administration). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WDS won't make administration or implementation any easier - WDS primarliy is used to make roaming quicker and "seamless" - so the clients can roam (especially 802.11 phones) without the re-authentication delays (which would cause the phones to drop the call). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured my PEAP and EAP-TLS according to instructions in a Windows 2003 Administrator's Handbook ...if I can find the book I'll re-post with the ISBN. I'm pretty sure Cisco has a configuration Guide online, Micrisoft also has one (search for "Configure Cisco IAS" (no quotes) on the MS site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good Luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Feb 2006 15:53:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-on-peap/m-p/530726#M25894</guid>
      <dc:creator>scottmac</dc:creator>
      <dc:date>2006-02-25T15:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: problems on peap....</title>
      <link>https://community.cisco.com/t5/wireless/problems-on-peap/m-p/530727#M25895</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, ScottMac! That clears away some of the cobwebs and i hope the sun will come out tomorrow for me.:) crsytal clear partic with certificates and WDS, but i am still confused with PEAP as to why it is not working considering I did exactly what I read on cisco documents and some microsoft articles. I probably missed some minor but very important configuration detail. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will try to look for the "Configure Cisco IAS" (no qoutes, of course)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, ScottMac!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct with my LEAP configuration, I did just used the Local (AP) Radius Server. But I have tried it as well via the ACSv3.3 and no problem with LEAP on that as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another question,ScottMac, with LEAP, after powering ON my notebook (configured with LEAP, of course), before cached and non-cached users logon to the domain or even just the local computer, LEAP is doing all the association, authentication, and is able to get an IP address (considering a DHCP network it is). I have learned that PEAP doesn't do this (well, at least with my conifuration), but is there a way for PEAP to do all the AAA before a user can login. For users already cached in the local notebook, there is no problem, but for non-cached users, there seem to have problems with my PEAP configuration. I hope you can help me pinpoint my mistakes...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Feb 2006 05:09:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-on-peap/m-p/530727#M25895</guid>
      <dc:creator>n.manlangit</dc:creator>
      <dc:date>2006-02-26T05:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: problems on peap....</title>
      <link>https://community.cisco.com/t5/wireless/problems-on-peap/m-p/530728#M25896</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the Cisco ADU configuration screens for PEAP (and probably some others) there should be a box for "machine authentication" .... so it verifies your pc/laptop initially instead of the username. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check it out / try it and see if it woeks for you. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good Luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Feb 2006 08:29:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-on-peap/m-p/530728#M25896</guid>
      <dc:creator>scottmac</dc:creator>
      <dc:date>2006-02-26T08:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: problems on peap....</title>
      <link>https://community.cisco.com/t5/wireless/problems-on-peap/m-p/530729#M25897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello,ScottMac. Finally I got it working. PEAP is now working with non-cahced users. i can get AAA even before logging in. So cool after all I've been through. whew! that is....:) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help. Forum rules!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Mar 2006 04:45:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-on-peap/m-p/530729#M25897</guid>
      <dc:creator>n.manlangit</dc:creator>
      <dc:date>2006-03-04T04:45:33Z</dc:date>
    </item>
    <item>
      <title>Re: problems on peap....</title>
      <link>https://community.cisco.com/t5/wireless/problems-on-peap/m-p/530730#M25898</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;dont forget the adjust the registry settings on win xp!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best regards&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Mar 2006 21:11:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-on-peap/m-p/530730#M25898</guid>
      <dc:creator>o-ziltener</dc:creator>
      <dc:date>2006-03-06T21:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: problems on peap....</title>
      <link>https://community.cisco.com/t5/wireless/problems-on-peap/m-p/530731#M25899</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oliver what registry settings are you refering to? &lt;/P&gt;&lt;P&gt;Also when you say AAA authenication before login. What does that mean? Does that mean machine authenication and if so does the ACS have a database locally or is the ACS referencing  Active Directory by computer name? Thanks for clearing that up for me.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Mar 2006 01:48:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-on-peap/m-p/530731#M25899</guid>
      <dc:creator>jhoude660</dc:creator>
      <dc:date>2006-03-08T01:48:20Z</dc:date>
    </item>
    <item>
      <title>Re: problems on peap....</title>
      <link>https://community.cisco.com/t5/wireless/problems-on-peap/m-p/530732#M25900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;/P&gt;&lt;P&gt;Check this settings:&lt;/P&gt;&lt;P&gt;Software\Microsoft\EAPOL\Parameters\General\Global\SupplicantMode -- REG_DWORD&lt;/P&gt;&lt;P&gt;0: Disable IEEE 802.1X operation.&lt;/P&gt;&lt;P&gt;1: Inhibit transmission of EAPOL-Start and EAPOL-Logoff packets under all scenarios.&lt;/P&gt;&lt;P&gt;2: Include learning to determine when to initiate the transmission of EAPOL packets.&lt;/P&gt;&lt;P&gt;3: Compliant with IEEE 802.1X Specification.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Software\Microsoft\EAPOL\Parameters\General\Global\AuthMode -- REG_DWORD&lt;/P&gt;&lt;P&gt;0: Machine authentication mode in Windows XP Client RTM. When a user logs in, if the&lt;/P&gt;&lt;P&gt;connection has already been authenticated with Machine credentials, the user&amp;#146;s&lt;/P&gt;&lt;P&gt;credentials are not used for authentication.&lt;/P&gt;&lt;P&gt;1: Machine authentication with re-authentication functionality. Whenever a user logs in,&lt;/P&gt;&lt;P&gt;802.1X authentication is performed using the user&amp;#146;s-credentials.&lt;/P&gt;&lt;P&gt;2: Machine authentication only &amp;#150; Whenever a user logs in, it has no effect on the&lt;/P&gt;&lt;P&gt;connection. 802.1X authentication is performed using machine credentials only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maschine Authentication needs AD, it is possible to do it with the local database! Maschine Authentication (you will see entries like host\computer-name.domain.com) is based on kerberos and is dynamically exchanged between DomainPC and AD at the first connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Mar 2006 09:43:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-on-peap/m-p/530732#M25900</guid>
      <dc:creator>o-ziltener</dc:creator>
      <dc:date>2006-03-08T09:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: problems on peap....</title>
      <link>https://community.cisco.com/t5/wireless/problems-on-peap/m-p/530733#M25901</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This resolved my issues&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://support.microsoft.com/?kbid=885453" target="_blank"&gt;http://support.microsoft.com/?kbid=885453&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Mar 2006 16:58:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-on-peap/m-p/530733#M25901</guid>
      <dc:creator>jhoude660</dc:creator>
      <dc:date>2006-03-17T16:58:05Z</dc:date>
    </item>
  </channel>
</rss>

