11-02-2004 01:48 PM - edited 07-04-2021 10:07 AM
This forum does say getting started, so don't bash me too much on my ignorance.
I am looking to find out exactly what I need to setup a LEAP infrastructure. (this will be just a lab test environment).
I have a 1200 AP and both Windows 2000 and Windows 2003 servers running AD. It is confusing to me as to whether I need some other pieces like ACS or a 3rd party RADIUS server.
This will be a simple setup to test client CCX compatibility and profile mgmt with domain authentication.
Thanks.
11-02-2004 04:37 PM
You need a radius server to authenticate users. Windows 2000 and Windows 2003 server with AD only provide user database. IAS, the radius server comes with Windows 2003 server does not support LEAP. Cisco has asked Microsoft to support LEAP many times, but Microsoft decides not to support LEAP.
The easiest way to set up a LEAP lab is to use local radius server coming with Cisco AP. Please go to the following URL for detailed information:
Just in case that you do not have access to the above URL, I attach the document.
11-03-2004 09:05 AM
Thank you very much.
How does using the AP as a local RADIUS server interract with Windows domain authentication?
What I am looking to do is test the client's single sign on features setting LEAP authentication to use Windows logon credentials.
Thanks again for you help.
Rgds,
Doug
11-03-2004 01:10 PM
There is no interaction between the local RADIUS server and the Active Directory. If you want to use the user database in Active Directory, you need a Cisco ACS radius server or an external radius server from other vendor.
11-04-2004 07:05 AM
We use Cisco's ACS and set it up to use Windows AD for single sign on. After setting up the ACS server you configure the Acess Points to send authentication requests to ACS and then it will forward the request to AD. You may want to look at EAP-Fast from Cisco instead of LEAP however. I have not looked at it much yet, but it is supposed to provide greater security from dictionary attacks.
11-04-2004 09:17 AM
Thanks for the info. I have downloaded the trial version of ACS 3.3. The documentation does talk about using MS AD, but it is a little confusing when going thru the setup.
The learning curve is somewhat high for me...all that I am really trying to accomplish is to get LEAP working with AD in a lab environment so that I can investigate a problem one of our customers is reporting.
It is a profile / domain logon problem...since I really don't know that much about Wlan security & authentication I am not sure if I can use another authentication mechanism (say PEAP) in which Microsoft supports.
The reported problem is that when they create a new user / Wlan profile using Intel Proset configured with WEP 128bit + LEAP and then try to logon to Windows XP, it will fail with the can't find a domain controller error.
At any rate, I will keep digging into ACS and see if I can get it setup correctly.
Thanks again!
11-04-2004 04:43 PM
How about PEAP MS-CHAP v2. Please go to the following URL for details:
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: