<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problems using PEAP with IAS in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/problems-using-peap-with-ias/m-p/139963#M26179</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the same problem. When I use MS PEAP, it works fine. After I install ACU and use Cisco PEAP. The user name change to PEAP-XXXXXXXXX. Anyone know what's wrong?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Dec 2003 07:10:12 GMT</pubDate>
    <dc:creator>dengqi</dc:creator>
    <dc:date>2003-12-10T07:10:12Z</dc:date>
    <item>
      <title>Problems using PEAP with IAS</title>
      <link>https://community.cisco.com/t5/wireless/problems-using-peap-with-ias/m-p/139956#M26172</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to authenticate PEAP clients (W2K) for Cisco &lt;/P&gt;&lt;P&gt;1200 access points using IAS on Windows 2003.  When the &lt;/P&gt;&lt;P&gt;initial RADIUS request packet is sent to the IAS it &lt;/P&gt;&lt;P&gt;includes the following information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RADIUS: ----- RADIUS HEADER -----&lt;/P&gt;&lt;P&gt;      RADIUS: &lt;/P&gt;&lt;P&gt;      RADIUS: Code          = 1 (Access-Request)&lt;/P&gt;&lt;P&gt;      RADIUS: Identifier    = 0&lt;/P&gt;&lt;P&gt;      RADIUS: Length        = 173&lt;/P&gt;&lt;P&gt;      RADIUS: Authenticator = &lt;/P&gt;&lt;P&gt;30F51BA0C55ABDC0E7028131C927E056&lt;/P&gt;&lt;P&gt;      RADIUS: &lt;/P&gt;&lt;P&gt;      RADIUS: Attributes follow&lt;/P&gt;&lt;P&gt;      RADIUS: Attribute Type    = 1 &lt;/P&gt;&lt;P&gt;      RADIUS: Attribute Length  = 19&lt;/P&gt;&lt;P&gt;      RADIUS: User-Name         = "PEAP-0009B7F1111F"&lt;/P&gt;&lt;P&gt;      RADIUS: &lt;/P&gt;&lt;P&gt;      RADIUS: Attribute Type    = 26 (Vendor Specific)&lt;/P&gt;&lt;P&gt;      RADIUS: Attribute Length  = 25&lt;/P&gt;&lt;P&gt;      RADIUS: Vendor ID         = 9 (Cisco)&lt;/P&gt;&lt;P&gt;      RADIUS: Attribute          = 1 (minimum links)&lt;/P&gt;&lt;P&gt;      RADIUS: Vendor Length     = 19&lt;/P&gt;&lt;P&gt;      RADIUS: Vendor Data       = &lt;/P&gt;&lt;P&gt;737369643D496E7465726E65744F4E4C5904&lt;/P&gt;&lt;P&gt;      RADIUS: &lt;/P&gt;&lt;P&gt;      RADIUS: Attribute Type    = 6 &lt;/P&gt;&lt;P&gt;      RADIUS: Attribute Length  = 139&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The RADIUS response that is sent back from the IAS looks &lt;/P&gt;&lt;P&gt;like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RADIUS: ----- RADIUS HEADER -----&lt;/P&gt;&lt;P&gt;      RADIUS: &lt;/P&gt;&lt;P&gt;      RADIUS: Code          = 3 (Access-Reject)&lt;/P&gt;&lt;P&gt;      RADIUS: Identifier    = 0&lt;/P&gt;&lt;P&gt;      RADIUS: Length        = 20&lt;/P&gt;&lt;P&gt;      RADIUS: Authenticator = &lt;/P&gt;&lt;P&gt;FAE99D0AFF61F66129DF6153B1AEED13&lt;/P&gt;&lt;P&gt;      RADIUS: &lt;/P&gt;&lt;P&gt;      RADIUS: No attributes&lt;/P&gt;&lt;P&gt;      RADIUS: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The event written to the event log by the IAS for the &lt;/P&gt;&lt;P&gt;above request is as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User PEAP-0009B7F1111F was denied access.&lt;/P&gt;&lt;P&gt;Fully-Qualified-User-Name = BOUNCER\PEAP-0009B7F1111F&lt;/P&gt;&lt;P&gt;NAS-IP-Address = 139.127.8.251&lt;/P&gt;&lt;P&gt;NAS-Identifier = HOMEAP2&lt;/P&gt;&lt;P&gt;Called-Station-Identifer = 0009b7d1fe47&lt;/P&gt;&lt;P&gt;Calling-Station-Identifier = 0009b7f1111f&lt;/P&gt;&lt;P&gt;Client-friendly-Name = HOMEAP2&lt;/P&gt;&lt;P&gt;Client-IP-Address = 139.127.8.251&lt;/P&gt;&lt;P&gt;NAS-Port-Type = Wireless - IEEE 802.11&lt;/P&gt;&lt;P&gt;NAS-Port = 38&lt;/P&gt;&lt;P&gt;Proxy-Policy-Name = Use Windows authentication for all &lt;/P&gt;&lt;P&gt;users.&lt;/P&gt;&lt;P&gt;Authentication-Provider = Windows&lt;/P&gt;&lt;P&gt;Authentication-Server = &amp;lt;undetermined&amp;gt;&lt;/P&gt;&lt;P&gt;Policy-Name = &amp;lt;undetermined&amp;gt;&lt;/P&gt;&lt;P&gt;Authentication-Type = EAP&lt;/P&gt;&lt;P&gt;EAP-Type = &amp;lt;undetermined&amp;gt;&lt;/P&gt;&lt;P&gt;Reason-Code = 8&lt;/P&gt;&lt;P&gt;Reason = The specified user does not exist.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the above event message, it appears that the IAS &lt;/P&gt;&lt;P&gt;is looking for user BOUNCER\PEAP-0009B7F1111F in the local &lt;/P&gt;&lt;P&gt;user database.  This doesn't seem to make sense since in &lt;/P&gt;&lt;P&gt;the first phase of PEAP, the IAS should return an identity &lt;/P&gt;&lt;P&gt;request message to the access point and then establish a &lt;/P&gt;&lt;P&gt;TLS tunnel directly to the authenticating wireless &lt;/P&gt;&lt;P&gt;client.  Once the tunnel has been established, then the &lt;/P&gt;&lt;P&gt;client should deliver the actual username/password &lt;/P&gt;&lt;P&gt;combination to the IAS for authentication.  Does anyone &lt;/P&gt;&lt;P&gt;know how to fix this problem?&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 16:00:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-using-peap-with-ias/m-p/139956#M26172</guid>
      <dc:creator>mzeman</dc:creator>
      <dc:date>2021-07-04T16:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: Problems using PEAP with IAS</title>
      <link>https://community.cisco.com/t5/wireless/problems-using-peap-with-ias/m-p/139957#M26173</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I thought Cisco does not support PEAP with IAS servers. was I wrong in my thinking so ??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Sep 2003 13:37:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-using-peap-with-ias/m-p/139957#M26173</guid>
      <dc:creator>mchin345</dc:creator>
      <dc:date>2003-09-19T13:37:46Z</dc:date>
    </item>
    <item>
      <title>Re: Problems using PEAP with IAS</title>
      <link>https://community.cisco.com/t5/wireless/problems-using-peap-with-ias/m-p/139958#M26174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you provide us with a copy of your AP config? Here is a good link to setup Client, AP, and IAS for PEAP, just so you can verify all settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.missl.cs.umd.edu/Projects/wireless/8021x/" target="_blank"&gt;http://www.missl.cs.umd.edu/Projects/wireless/8021x/&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Oct 2003 15:03:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-using-peap-with-ias/m-p/139958#M26174</guid>
      <dc:creator>baileja</dc:creator>
      <dc:date>2003-10-05T15:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: Problems using PEAP with IAS</title>
      <link>https://community.cisco.com/t5/wireless/problems-using-peap-with-ias/m-p/139959#M26175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It does indeed work.  I have setup 2 shops using IAS and 340's,350's, 1100's and 1200's.  I used the ms-chap option.  You create a server cert, configure the IAS server with the client (AP) and secret and configure the AP to point to the IAS server.  On the client side I had to authenticate the workstation in order to get login scripts and policies to work.  One problem we ran into was Native versus mixed modes in AD.  You do not need to switch to native but in order for the machine to authenticate prior (meaning the machine is in the VPN group) you need to have the domain in Native mode as you can't grant dial in permission to the workstation.  Once this is complete the machine logs in first allowing it to obtain an IP and giving the user time to authenticate.  Keep in mind if the user does not succesfully authenticate the connection is terminated whether the computer authenticates or not.  If you have any questions send me an email at &lt;A href="mailto:jcusick@qmail.homelinux.com"&gt;jcusick@qmail.homelinux.com&lt;/A&gt; and I will be happy to help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Oct 2003 15:31:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-using-peap-with-ias/m-p/139959#M26175</guid>
      <dc:creator>j.cusick</dc:creator>
      <dc:date>2003-10-06T15:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: Problems using PEAP with IAS</title>
      <link>https://community.cisco.com/t5/wireless/problems-using-peap-with-ias/m-p/139960#M26176</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;just another link for how-to configure client/AP/IAS&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;familyid=0f7fa9a2-e113-415b-b2a9-b6a3d64c48f5" target="_blank"&gt;http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;familyid=0f7fa9a2-e113-415b-b2a9-b6a3d64c48f5&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2003 12:39:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-using-peap-with-ias/m-p/139960#M26176</guid>
      <dc:creator>mschuh</dc:creator>
      <dc:date>2003-10-07T12:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: Problems using PEAP with IAS</title>
      <link>https://community.cisco.com/t5/wireless/problems-using-peap-with-ias/m-p/139961#M26177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure if you ever got your question answered, but in MS Active Directory you need to go t the Dial-in tab and set to allow access.  If you need to do HOST based authentication, you need to call MS for a patch that allows you to see a Dial-in tab for computer accounts in AD, then change to allow access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Nov 2003 20:25:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-using-peap-with-ias/m-p/139961#M26177</guid>
      <dc:creator>mhs</dc:creator>
      <dc:date>2003-11-13T20:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: Problems using PEAP with IAS</title>
      <link>https://community.cisco.com/t5/wireless/problems-using-peap-with-ias/m-p/139962#M26178</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It may be your NAS-Port-Type the setting for this on the latest IOS based 1200 AP is set to 16 I believe.  In addition to this for Win 2003 IAS policy set up it puts that Nas-Port-type in automatically.  You should remove this, that is comming right from Microsoft, it is known to cause problems.  I hav ethe exact setup you are using except I am using XP clients.  Also don't for get to set the EAP Client Timeout to something like 40 or so, this made all the difference in the world for me.  It is under advanced security EAP authntication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck (I am still having problems)&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Nov 2003 04:04:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-using-peap-with-ias/m-p/139962#M26178</guid>
      <dc:creator>mhs</dc:creator>
      <dc:date>2003-11-15T04:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: Problems using PEAP with IAS</title>
      <link>https://community.cisco.com/t5/wireless/problems-using-peap-with-ias/m-p/139963#M26179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the same problem. When I use MS PEAP, it works fine. After I install ACU and use Cisco PEAP. The user name change to PEAP-XXXXXXXXX. Anyone know what's wrong?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Dec 2003 07:10:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-using-peap-with-ias/m-p/139963#M26179</guid>
      <dc:creator>dengqi</dc:creator>
      <dc:date>2003-12-10T07:10:12Z</dc:date>
    </item>
  </channel>
</rss>

