Cisco :: PEAP MSCHAPv2 With Multiple ACS4.2 Authentication Servers Clients Get Dropped?

Feb 10, 2011

I have a WPA2/AES network with PEAP MsChapv2 authentication. I have 2 ACS servers for authentication. The problem I have is dropped clients. Both ACS servers are setup identical. The database replcation has been preformed.A series of 10 clients connects wirelessly and they are all  successful.  ACS server 1 is the primary and ACS server 2 is the backup.   We verified that the 10 users authenticated to the primary ACS. My time out to reauth is 30 minutes on the WiSM. 10 minutes into the test we took down the Primary server.  This should have had no impact on the clients. 5 minutes later the clients lost thier authentication and were dropped from the network. They were able to reconnect by shutting down thier wireless client and reconnecting. The authentications were seen on the Backup ACS server.on a test of falling back to the primary  the same thing happened again to the clients.

View 2 Replies


ADVERTISEMENT

Cisco AAA/Identity/Nac :: ACS4.2 Windows Authentication To Other Trusted Domain?

Jun 6, 2011

I'm installing ACS4.2 in our lab domain and want to leverage the corporate domain for authentication.  The one way trust is in place, but there is a facet that I'm not clear on in regards to the installation requirement.
 
I'd like to install ACS on a lab domain member server, but I'm not sure that will work.  The installation docs seem to imply that a member server must be in the same domain as the authentication server, but its not very clear. if I want to use the one way trust to the Corporate Domain, am I required to install ACS on the domain controller of the Lab Domain?

View 3 Replies View Related

Cisco :: 1140 - Win XP Clients Not Authenticating Using PEAP

Apr 2, 2013

A customer has RADIUS running on a Win Server 2008 R2 machine, has Autonomous 1140 APs and a mix of Windows 7 and XP Pro clients.  Using PEAP as the authentication method the Win 7 clients can access the WLAN, but the Win XP clients cannot.  The Win XP clients are at least SP2.  I am doing some research before going to site on Friday and wanted to poll the community.  I found an older post speaking to a MS Hotfix under KB#885453, but it referes to "third-party RADIUS servers," not MS servers URL.

View 14 Replies View Related

Cisco :: PEAP Machine Authentication With ACS 4.2

Jan 23, 2012

I have 802.1x/peap authentication in my wireless network with ACS 4.2 as the authentication server. I enabled PEAP machine authentication under the Unknown user policy --->database configuration sub-menu. I discovered that I was still able to access the wireless network on my android phone with my domain logon. I later discovered that there is an option in Group policy to force Windows XP clients to perform computer authentication. Now the problem is that windows 7 clients do not have the EAPOL option in the registry, hence the group policy object may not work. How to enforce machine authentication and stop unwanted devices without having to purchase a NAC server.

View 10 Replies View Related

Cisco :: ACS 5.1 EAP-PEAP Machine Authentication

Jun 29, 2011

ACS 5.1 EAP-PEAP Machine Authentication,
 
I have configured ACS 5.1 to check AD domain computer accounts then permit access, the next rule authenticates AD domain users and checks machine accounts with WAS MACHINE AUTHENTICATED "TRUE" permit.
 
My dilemma - Windows XP supplicant work fine and I can see the host/machine (Wireless device) authenticating followed by user credentials, but when I use the Intel Pro/set supplicant version 12.1 the same device fails authentication due to ACS not being able to verify a good previous machine authentication?
 
Is this problem ACS related or down to the Intel supplicant.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 PEAP With Machine Authentication

Sep 11, 2011

Any good guide for configuring PEAP with Machine Authentication to allow for domain login?This is a clean install on a new 5.2 install.We are moving from 4.X to 5.2 and i want to make sure i dont miss anything.

View 3 Replies View Related

AAA/Identity/Nac :: SSL Certificate Installation On Acs Appliance 1120 For PEAP Clients

Apr 18, 2011

I need this SSL certficate installation on my acs appliance 1120 for PEAP clients.I have exported SSL server certficate from my old acs 3.3 server which is under acscertstore folder issued by CA vendor . I need to reuse this same SSL certificate on my acs appliance .ACS appliance certficate setup requires following two certificate to be installed for PEAP clients authentication

1) Server Certificate

2) CA certificate
 
Server Certificate : For server certifcate , I have my old certificate which is exported from my old acs 3.3 server , when i tried to download my server certficate via ftp server on my acs appliance , its looking for private key & private key file .Private key & file is generated intially on CSR request when this server certificate is requested to CA vendor for my old acs 3.3 . I dont know the private key password . If i need private key & file , then i need to generate new CSR from my acs appliance and i need to submit this CSR output to my CA vendor to generate new SSL server certificate .which is something like new server certificate request .CA certficate : For CA certficate , when i open my existing SSL certificate under detials tab in CRL distribution point , i could see below URL . whn i open this URL it giving certificate revocation list . [1]CRL Distribution Point.

View 10 Replies View Related

Cisco Routers :: PEAP Authentication Failure With RV120W

Jul 31, 2012

I have a Cisco Small bussiness RV120w and I setup the radius server , WPA2 Enterprise with a windows 2008 NPS radius server . The big problem is that the authentication fails .This is the error that I see in event viewer / server roles / Network policy and access services: reason-code 49 "The connection attempt did not match any connection request policy".The radius key is matching between the server and the client . The radius server is reachable and I don't find any routing issues .Does anybody tested this router with this type of wireless security?

View 3 Replies View Related

Cisco :: Acs 4.2 PEAP Machine Authentication Wireless 4404

Sep 26, 2012

we have acs 4.2 as our radius server, and 2 wlc 4404 with a wism2 for our wireless network. we have 2 SSID network, lets call them SSID A and B. A have a more restricted access to server than B.PEAP machine authentification is authorize on both network, to let our users laptop connect before the user login, this enable us to have our computer gpo deploy before the user logon, or have network access to authenticate a user to our directory if he had not logon previously on the laptop.
 
Users from group A can't logon to SSID B, they can only logon to SSID A, but we have some clever users from group A who have change they wireless setting to only send machine authentification (this can be done in the advance setting of a wireless network in windows 7) to connect to SSID B
 
We can't force the wireless config by GPO because we don't have an ad 2008 domain, we are still in 2003 soo we can't change the gpo for windows 7 wireless setting . I can't force user to require machine authentification and user authentification because we have a lot of ipad and iphone, and other mobile device that connect using only their user credentials.Is there a way I could configure this without having to disable machine authentification for SSID B?

View 7 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 / PEAP (EAP-GTC) Machine Authentication With LDAP?

Aug 19, 2012

Cisco 5508 wireless controllerCisco ACS 5.1LDAP connection I have setup the wireless controller to do RADUIS authentication with the ACS 5.1 using LDAP. The setup is currently working, Brief info below on setup.
 
I setup the PC client to use WPA2-Enterprise AES and authentication method CISCO PEAP. When I connect to the SSID this will prompt for a username and password. I will enter in my AD details and the ACS with the LDAP connection will authenicate and on the network I go.
 
Now I want to add machine authentication with CERTIFICATES, each laptop and pc in our network has CA certificates installed.
 
way that I can add these certificates into the ACS 5.1 so I pretty much want to import them into the ACS. Once they are imported inside I want the ACS to check that the certificates are on the PC and then prompt for the AD username and password, and only once it meets these two conditions it allows the workstation onto the network.So it will be a two form authentication one with certificates and the other ldap.

View 18 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2(0) Build 124 / Failed To Initialize PEAP Or EAP-TLS Authentication Protocol

Oct 31, 2010

I replaced an ACS certificate that had been installed as follows:

1. Generate CSR file and private key file, then send CSR to GeoTrust (Key length: 2048 and Digest to sign with SHA1)

2. GeoTrust send me a certificate. Issued by "GeoTrust SSL CA".

3. Install the certificate on the ACS. Restart ACS service.

4. ACS Certification authority setup. Issued by "VeriSign Class 2 Public Primary Certification Authority - G3"

5. Edit certificate trust list and select "VeriSign Class 2 Public Primary Certification Authority - G3" as trusted.

6. Enable EAP-TLS, then restarted the ACS service. The problem is when i try to enable EAP i get the error msg:Failed to initialize PEAP or EAP-TLS authentication protocol because CA certificate is not installed. Install the CA certificate using "ACS Certification Authority Setup" page.I searched on cisco and it said to disable the CSA, but in fact there is no CSA installed on this server.
 
OS: Win 2003 sp2Cisco ACS: Release 4.2(0) Build 124

View 4 Replies View Related

Cisco Wireless :: WLC 5508 / SW 6.0.199.4 / 1142 AP / Clients Getting Dropped?

Apr 14, 2013

We have deployed a WLC 5508 w/ SW version 6.0.199.4, 1142 AP's & open authentication w/ MAC filtering. Clients are randomly getting dropped with "Limited Access" shown in Win 7. In this state, the client machine is unable to ping the gateway and sometimes lose their DHCP assigned IP as well. A manual disconnect/re-connect to the SSID is required everytime.I ran a debug on one the clients stuck in the "Limited Access" state (debug client xx:xx:xx:xx):
 
*Apr 15 16:59:23.205: e0:91:53:60:1f:e4 Adding mobile on LWAPP AP 3c:ce:73:c5:1e:b0(0)
*Apr 15 16:59:23.205: e0:91:53:60:1f:e4 Scheduling deletion of Mobile Station:  (callerId: 23) in 5 seconds
*Apr 15 16:59:23.205: e0:91:53:60:1f:e4 apfProcessProbeReq (apf_80211.c:4722) Changing state for mobile e0:91:53:60:1f:e4 on AP 3c:ce:73:c5:1e:b0 from Idle to Probe

[code]....

View 7 Replies View Related

Cisco Wireless :: AIR-CT2504-K9 - Clients Are Dropped Or Can’t Connect

Jun 2, 2013

I am using two AIR-CT2504-K9 controllers
Product Version.................................. 7.4.100.0
Bootloader Version............................... 1.0.16
Field Recovery Image Version..................... 1.0.0
Firmware Version................................. PIC 16.0
 
and 20 access points AIR-CAP2602I-E-K9 Cisco IOS Software, C2600 Software Version 15.2(2)JA, RELEASE SOFTWARE (fc1) LWAPP image version 7.4.100.0
 
I created 3 SSID:
1.    [WPA2][Auth(PSK)]
2.    Web-Passthrough
3.    [WPA2][Auth(PSK)]
 
Configuration on controllers is identical. High Availability is configured on all APs. First controller controls only those APs witch have SSIDs with [WPA2][Auth(PSK)], second controller is basically for APs with Web-Passthrough SSID. From the start I have problem, some clients who try to connect to SSID with PSK are dropped or can’t connect entirely, but when they go to the next AP they connect successfully. For example I have Android smartphone and Lenovo laptop, smartphone connects successfully but laptop fails connection to the same AP, but when I take it to other AP it connects successfully. Sometimes smartphones can’t connect too. When devise can’t connect to one SSID it can’t connect to other SSID either. Sometimes there are up to 20 clients tying to connect to the same AP.
 
When I look into logs, I get these two messages:
 
Jun  3 08:58:58 192.168.224.1 WLC1: *dot1xMsgTask: Jun 03 08:58:51.176: #DOT1X-4-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:456 Max EAPOL-key M1 retransmissions exceeded for client 7c:e9:d3:f4:74:4d

[Code].....

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 - Multiple Identity Store For PEAP

Sep 25, 2011

I am trying to setup PEAP authentication for wireless users but I got stuck at place where I have single ssid and users are store in different identity stores like some will be using their active directory and some are locally created users on ACS. I created separate service for wireless authentication and under that I am unable to create rule to differentiate them with identity stores. any idea how to achieve this.
 
I tried creating identity selection based on role but it does not work as for protocol like radius.peap,ms-chap ACS does not look for another identity store once user not find in an identity stores.

View 1 Replies View Related

Connecting Clients To Servers?

Apr 19, 2012

i don't know any thing about connecting clients to servers & it's methods & requirements

View 7 Replies View Related

Cisco VPN :: Asa 5510 Allow AnyConnect Clients Access To Only Few Servers

Jun 26, 2012

We have 30 remote workers which we have recently acquired which are being set up with the AnyConnect client to connect to our head end ASA 5510. For security purposes, we have to allow them access to only 3 of our local internal servers, all on our 10.10.X.X/16 subnet. The remotes are being issued a 10.10.50.X/24 address via DHCP on the ASA when connecting. I thought this would be as simple as creating an access list but have not had any luck doing so. In addition, we need to allow them full access to servers in a datacenter connected to our same head end ASA via a site-to-site VPN while they are connected to us using AnyConnect.

View 1 Replies View Related

Cisco VPN :: ASA 5510 - Allow AnyConnect Clients Access To Only Few Servers

Mar 19, 2012

We have 30 remote workers which we have recently acquired which are being set up with the AnyConnect client to connect to our head end ASA 5510. For security purposes, we have to allow them access to only 3 of our local internal servers, all on our 10.10.X.X/16 subnet. The remotes are being issued a 10.10.50.X/24 address via DHCP on the ASA when connecting. I thought this would be as simple as creating an access list but have not had any luck doing so. In addition, we need to allow them full access to servers in a datacenter connected to our same head end ASA via a site-to-site VPN while they are connected to us using AnyConnect.

View 4 Replies View Related

Servers :: DHCP Clients And Internet Connections

Jan 11, 2013

I have successfully configured my DHCP server because I can ping it from the clients PC and my clients PC automatically grabs IP from my DHCP. How my clients can have access to internet. Here is my hardware setup: 1. I connect clients PC and one DHCP server in one unmanaged switch2. I have my Bell DSL Modem but not connected yet to one of these machines. I do not know how I can configure it yet to work with my machines.The IP I assigned started at 10.10.200.10 to 10.10.200.90How do I connect the DSL and configure so that it may give everyone access to internet?

View 1 Replies View Related

Servers :: Map Drives From Windows Clients To SUN / UNIX

Aug 16, 2011

Working on Windows desktops and cannot map drives to unix servers without undoing a particular windows update. network policy pushes this update out again. Cannot change that policy....Active Directory Bridge solution needed to map drive letters from windows users to Unix (SUN) systems?

View 1 Replies View Related

Cisco :: 4402 / Certificate Authentication For Clients?

Oct 16, 2011

I am using wireless system with certificate athentication ( CA Server ) and RADIUS server.
 
I want to know if certificate is not installed and configured in wireless client laptop.
 
Do client get athenticate in wireless system and get access of wireless network ?
 
Also want to know any configuration required in WLC CISCO 4402 for authentication with  CA server of client laptop.

View 2 Replies View Related

Cisco :: MSCHAPv2 / Windows Client Cannot Connect To Wireless AP

Oct 1, 2011

I have a wireless system with Wireless controller and AP. I deploy wireless with WPA2-Enterprise and use Active directory domain account for authentication. But I have to modify some settings on client (windows XP, windows 7) to have it connect.

- If my clients joined in domain, they can connect to wireless sucessfully.

- If my clients are not joined in domain (they use local username and password), I have to go to wireless properties on client, and uncheck the option "Automatically use my Windows logon name and password" on EAP MSCHAPv2 properties. If not, windows automatically use the local account of the client to connect.

View 2 Replies View Related

Cisco WAN :: Multiple PPPoE Clients On 881

Mar 2, 2011

Is it possible to set up a pppoe client on a VLAN interface, or a switch interface associated to an VLAN?. For example, in a 881 ethernet router, could I configure a pppoe client on any of the lan interfaces in addition to the pppoe client configured on the WAN interface?.

View 4 Replies View Related

Cisco Firewall :: ASA 5505 - Get Clients To Talk To Active Directory Servers?

Nov 9, 2011

I'm trying to get a couple clients to talk to my Active Directory servers. I've created sub-interfaces on my ASA. So, my clients are on Gi0/1.139 and my two Active Directory servers are on Gi0/1.132. I've enabled traffic on TCP 53-5000 port range according to Microsoft. My clients still can't join the domain. What ports I need to open up? My AD servers are Windows 2003.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2 - Delete Multiple Clients?

Jun 28, 2011

I've inherited some ACS appliances from another part of my organization.  I need to keep most of the settings but want to remove all the AAA clients; and preferably not one-by-one.  I don't see a way in the documentation and web searches have proven fruitless.

View 1 Replies View Related

Wireless Network For Multiple Clients

Feb 8, 2012

On every floor there are 10 rooms which can have multiple clients (laptops, ipads, smart phones) so let's say 50 clients.how to set up whole thing so the users in every room have decent speed for surfing and watching videos online
[code]...

View 5 Replies View Related

Multiple Clients On Single Server?

Mar 30, 2012

I just want to keep one PC as a server and one switch connect to it (For LAN). I want to connect multiple client/screen to that server, so I can use single servers for multiple screen/client.(Client machine will not have any CPU, they will utilize servers memory.)

View 1 Replies View Related

Cisco Switching/Routing :: 2960 - Web Authentication On Switches For 802.1x Incompatible Clients

Apr 2, 2013

I am trying to get to work Web-based authentication on Catalyst 2960 and 3560 for clients that don't support dot1x. I followed this guide. Here's the problem: Client (win7) joins the network, opens the web browser and tries to navigate to any http site. The switch forces him the "login" page in which he has to enter credentials. After the client enters credentials, the switch sends http 500 internal server error page and nothing happens. Doesn't matter if the credentials were correct or not. Also i checked radius logs for requests, the switch doesn't even ask radius.
 
The configuration:
 
sh ip admission configuration
Authentication Proxy Banner not configured
Consent Banner is not configured

[Code].....

View 6 Replies View Related

Cisco Wireless :: WLC 4402 Multiple Clients Can Connect To AP But Only One Gets An IP

Nov 4, 2012

I have a 4402 which is connected to a 4506 Switch int Gig 3/1 via a trunk port. The Managment and AP-manger interfaces are on vlan 6 [code] I have a 1142N AP also connected to the switch and it pulls a DHCP IP Address and configs etc and registers to the WLC. It too is on Vlan 6 and it is connected to the 4506 on int gig 4/33 which is an access port. [code] I am doing local authentication, so i have added users to the WLC.. My problem is that the first client that connected was able to get an IP address and connect to anything internal and external.I then connected another client on another laptop and that client could connect but not get an IP address, it  just self assigned.When i look at the clients i can see the MAC address of both Clients on the WLC, but doing a show mac address-table dynamic i only see the MAC of the client that works properly. The client that doesnt get an IP has no entry in the 4506 switch.I am stumped, from what I understand, is that the 2nd clients traffic is being trunked to the WLC , hence it has the MAC address. But I dont know why its not getting a DHCP assigned IP address.

View 37 Replies View Related

Cisco Switches :: SG300 Port Authentication 802.1x No Logon Servers Available

Oct 11, 2012

I have configured a Microsoft Server 2008 R2 with Radius Server and connect it with a Cisco SG300 Switch.
 
If a new device connect to the switch it goes automatically to the guestnet. If a device with the correct certificate and a valid useraccount connect to the switch, the deivce goes in to the local company network.
 
Now my problem: If I connect a device which is in the domain and which have installed the correct certificate and want to login with a new domain user (which is not cached in windows) I can not login.
 
The following message appears: "There are Currently no Logon Servers Available"
 
I think the problem is that the authentication process only starts after a user have succsess logged in in windows.
 
Now I search for a solution which allows me to conntact the Logon Server for Domain Login before the User has logged in.

View 1 Replies View Related

Cisco VPN :: ASA5515X - Remote Access VPN Clients / Multiple DNS Suffixes?

Dec 13, 2012

I am setting up a new remote access VPN using the traditional IPSec client via ASA 5515-X runnning OS 8.6.1(5). We require to provide each client multiple DNS suffixes, but are only to provide a single DNS suffix in the group policy.I have tested using an external DHCP server, but using our Windows Server 2008 infrastructure and Option 119 the list is not provided to clients, and I have read that Windows 7 clients may ignore this option anyway.

View 0 Replies View Related

Cisco Routers :: ISA570W / DHCP Reservation For Multiple Clients At Once?

Jun 4, 2013

All the SOHO routers I have used had a table which shows IP, MAC, Name, etc. In this table, I could easily put a check mark to a check box in a row  that I would like to bind/reserve and IP would be reserved for that specific MAC.
 
In ISA570W, when I need to reserve/bind an IP to a MAC it asks me to fill out a table in which I have to manually type in the name, IP, and MAC.
 
Is there an easier way?Is there a way to do the reservation for multiple clients at once?If this is the only way, do I need to copy the mac address of each client somewhere and then reserve IPs for each one manually? This method looks very far from user friendly and efficient, unless there is a very logical reason that I cannot think of. 

View 2 Replies View Related

Cisco :: 871 - Configuring Static Nat For Multiple Web Servers

Mar 13, 2012

I am trying to configure a Cisco 871 router.There are 3 servers on my network that need static public IPs but also still need to communicate on the local network.I have given my WAN interface the first IP in the block and set up PAT for the rest of the computers on the network with that IP which is working fine. Next I set up static NAT rules for the servers translating 3 of the remaining public IPs to the internal addresses of the servers.I can access those servers internally using the public IPs but not from outside the network. A traceroute from outside the network gets dropped when it gets to my ISP.I've never configured more than one static ip for a network before and i know i've just missed a step here. Do I also need to use static routes? Will that update the next hop's routing table? Do I need to make an ACL to permit any host to the servers? If so, do I use the internal or external address? [code]

View 2 Replies View Related

Broadband :: Can 1 Server Feed Multiple Clients At Different Places

May 30, 2011

I want to open a branch office but need to access the same server as in the main office.How do I do this without losing speed?

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved