cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2674
Views
9
Helpful
22
Replies

PEAP with computer authentication

remco.gussen
Level 1
Level 1

Hi

I was wondering if it is posible to use computer authentication as well as user authentication with PEAP ? I need to make a design with a WLC and ACS. The ACS checks the correct Active Directory global group for user authentication. I also want to check the membership of a client computer in the Active Directort. Computer not member of domain, no access to WLAN. Is this posible ?

Another question, is it posible to do a trace (after three weeks) to find out witch user was connected to the wireless network, based on the ip address ?

GR.

Remco

22 Replies 22

I know that as the TLS channel is established the server sends the certificate to the client so that the client can confirm the identity of the server. My assumption would be that the TLS channel still gets established, but the client is just unable to confirm the identity of the server.

So without validating the certificate chain it's basically the equivilent to using self-signed HTTPS (a secure channel to a suspect target).

Some more information about PEAP with MSCHAP v2 here:

http://technet.microsoft.com/en-us/library/bb878077.aspx

Erik

EDIT: And keying for AES/TKIP doesnt happen at the RADIUS server at all (that is between the AP and client), so this setting would have no bearing.

I can see the option "machine access restriction". But where can i configure the machines that are allowed ? Can I link it to a Windows Group ?

The allowed machines are built dynamically based on machine authentications.

But than I can still bring my home laptop and log in. Isn't it ?

I've configured machine authentication, but everytime I try, I get Authen Failed:

Authen failed host/PAL3556.eu.ten Default Group 0040.96b0.f3c7 External DB user invalid or bad password .. .. 356 10.61.160.101 taxxx056 .. .. .. .. .. .. xxx0101 .. .. .. No 25 MS-PEAP (Default) .. .. .. .. .. .. .. .. .. .. .. .. .. ..

Guys, PEAP does not require certificate validation on the Clients. that is why your authentication was successfull.

But the certificate must be installed on the client machine to build a secure tunnel for password exchange. Isn't it ?

Accordin to Microsoft specs, the certificate is only check if you use PEAP-EAP-TLS, PEAP by default is using PEAP-MSCHAPV2.

I am trying to figure out how to configure PEAP-EAP-TLS on an ACS.

Review Cisco Networking for a $25 gift card