Cisco :: Wireless AP1140 Radius Authentication With Microsoft IAS

Sep 3, 2011

I have a Cisco C1140 Ap. I have cnfigured the device. Initially for testing i used WPA and authenticated locally. I have now setup a radius server and added my AP in as a client etc. I have changed my SSID's to authenticate with the radius server and i am having issues authenticating.I can connect via a PC and an iphone. They say that i am connected but i get no ip address and the debugs.

View 1 Replies


ADVERTISEMENT

Cisco :: WCS 7.0.220.0 Authentication With RADIUS Microsoft NPS?

Nov 14, 2011

I'm running WCS 7.0.220.0.I would like to authenticate users that are able to logon the WCS, through MS Network Policy Service (RADIUS).I would like all my domain users to be member of the local group on the WCS "Lobby Ambassador", so all domain users has access to generate guest access accounts, for the web auth... I can see under the WCS Administration under AAA that it should be able to use RADIUS - but i'm not sure how to setup the NPS policy?

View 1 Replies View Related

Cisco Wireless :: Configuring Microsoft Radius Server For 5508?

Apr 28, 2013

I would like to know if microsoft 2008 server RADIUS server could be use for authentication on Cosco 5508 instead of Cisco ACS.

View 4 Replies View Related

Cisco VPN :: AnyConnect And MSChap-V2 On Microsoft Radius With ASA5510?

May 13, 2013

We have a Cisco ASA5510 configured to work with Microsoft Radius Server.  VPN authorization and authentication is working well with L2TP over IPSec, and users are authenticating with MSChapV2 like we want them to.
 
Now we are trying to setup Anyconnnect to do the same.  How do we tell AnyConnect to use MSChap-V2 versus PAP? using ADSM?  I think I know how to do the Microsoft Part of it, but I don't know where to go in ADSM to configure this.

View 2 Replies View Related

Cisco :: Setting Up Aironet 1140 AP With Microsoft IAS Radius / PEAP And WPA2?

Jan 25, 2012

I bought 2 Cisco 1140 series Access Points a couple of months ago. We would like to use PEAP to autheticate with Microsoft IAS Radius Server & Active directory. I cannot find a document which describes how to setup this type of configuration. The only document which is close is how to setup LEAP & with ACS: [URL] I initially followed the 'TechReplublic's Ultimate Guide to Enterprise  Wireless LAN Security' which has all the steps to setup Radius server,  client side configuration, Certificates and finally a handy excel script  to generate a config for the AP. This did not work. [URL] I am now trying to configure the AP using the Web GUI. I can see the network on the client machine but when I try to connect it timesout.

View 1 Replies View Related

Cisco VPN :: ASA5540 VPN Smartcard (CAC) Authentication Microsoft IAS?

Apr 5, 2011

Are there any configuration documents that shows how to configure a Cisco ASA5540 for client VPN access using smartcards and Microsoft IAS.  Microsoft IAS will stand between the ASA5540 and Active Directory.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Authentication Against Microsoft AD / TACACS Authorization

Feb 2, 2013

I am trying to configure ACS 5.2 to do all authentication against Microsoft AD, but use local identity groups to determine TACACS+ authorization. 

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 For Wireless Authentication Using Radius?

Jul 4, 2012

how to setup ACS 5.3 to authenticate wireless users over radius? I currently have the SSID pointing to a Microsoft IAS server and would like to move the authentication to be done via ACS.

View 1 Replies View Related

Cisco Wireless :: Radius Authentication With Aironet 1140?

Mar 28, 2012

I try to setup a 1141 aironet AP to authenticate my user through our Ms Radius Server ( Win 2008 R2).Everything is fine with small Bussiness AP WAP4410N with the following configuration:But I can't setup successfully the aironet 1141 with the same settings and getting it works.Here is my configuration for the Aironet 1141 Vlan 1 is the ssid I want to get it work with Radius.  

View 1 Replies View Related

Cisco Wireless :: WLC 5508 No Further RADIUS Authentication Requests?

Mar 18, 2013

I'm working on a project where a wi-fi client is tracked and located using RADIUS authentication requests. The problem I'm running into is that the WLC (5508) sends an RADIUS authentication request to my freeradiusd, which is ok so far, but if the client roams to another accesspoint (3602AG, 1131AG, 1252AG), the WLC does not send a further RADIUS auth. request - and the client is allowed to connect to the next ap.Is there an option like RADIUS-cache which I can disable, so that the WLC sends everytime an authentication request when a client tries to connect to an ap or roams from one ap to another one?

View 4 Replies View Related

Cisco Wireless :: 2504 - 802.1x Radius Dual Authentication

Jun 20, 2012

I configured the 2504 with 2 SSIDs for staffs and guests.I also configured the Lobby admin with web auth. But if a guest wants to connect our wireless he/she has to enter the PSK key and then only they are able to connect with the user id and password given by Lobby admin. Can we avoid this key and let the guests connect straightaway with the web auth?I’m planning to configure 802.1x & Radius dual authentication for staffs SSID..

View 5 Replies View Related

Cisco Wireless :: 5508 Controller With Radius Authentication

Feb 16, 2012

I am setting up a WIFI network with a Cisco 5508 controller. I want  to configure a first WIFI network (WIFI1) that will authenticate my  business laptop based on the AD computer accounts and will access my  corporate network.I want to setup a second WIFI network (WIFI2) that will authenticate  my phones and tablets devices with AD user accounts and will be on a  separate vlan with only access to the Internet.I created 2 policies on the Radius server : one that authenticate  computers coming from wireless and a second one authenticating users  coming from wireless.
 
if a user manually creates the WIFI1 network on his phone  and enter his AD username, he is going to have access to the corporate  network.  I would like to be able to say that when a request is coming  from WIFI1, only the policy for authenticating  wireless devices with computer accounts will apply and the second  policy authenticating user wouldn't apply.

View 1 Replies View Related

Cisco Wireless :: Radius Server Authentication AIR-AP1231G-A-K9

Apr 30, 2012

Below is he output from debug radius authentication from my AP.
 
I can see request is forwarding from AP to radius but Radius is not sending any response.Not sure why its not responding.
 
I also did not under stand few out outputs also
no sg in radius-timers and
RADIUS/DECODE: parse response no app start; FAIL
what does it mean.
 
I  restarted radius server , changed secret key but no luck.
 
019639: May  1 16:15:08.727: RADIUS:  User-Name           [1]   32  "host/3KYGRH1.idcap.intdata.com"
019640: May  1 16:15:08.727: RADIUS:  Framed-MTU          [12]  6   1400
019641: May  1 16:15:08.727: RADIUS:  Called-Station-Id   [30]  16  "0012.01d6.f691"
[Code]...

View 4 Replies View Related

Cisco Wireless :: C1200 Client Authentication Is Against RADIUS Server

Jan 9, 2013

i am trying to connect clients to my AP1231 which is running C1200 Software (C1200-K9W7-M), Version 12.3(8)JED. Client authentication is against RADIUS server. [code]

View 3 Replies View Related

Cisco AAA/Identity/Nac :: AP 3500 - 802.1x Wireless Authentication Against RADIUS Authenticator?

Nov 1, 2012

Would like to check out some client side setting on Wireless 802.1x authenticaiton.
 
Network setup is using

- Cisco WLC 7.2 and AP3500,
- ACS 5.3
- Microsoft Windows server 2008 hosting AD and CA services (same machine)
- Client OS is Microsoft Window 7.
 
Authentication mehtod would use PEAP-MSChap V2 Combo.
  
My question :
 
01. In AD environment, should ACS 5.3 be part of the domain computer?
 
02. To have secure connectivity, IF the security policy force client to check "Validate server certificate", which certificate it is look for? Is it ACS's identity certifate, that require CA server to sign on the CSR?
 
03. Back to client side, should the client also need to import this certificate in trusted root certification authorities?
 
Or the client will trust ACS identity certificate against the root CA certificate store at client's trusted root certification authorities, where they have the identical issuer?
 
04. Extra question: If no CA environment, would it be sufficient simply export ACS self-signed certificate and import to client computer, and it's trusted?

View 3 Replies View Related

Cisco Wireless :: WAP321 - Radius Authentication For Captive Portal

Aug 1, 2012

I'm fighting for a few days now to setup the captive portal of 2 wireless access point WAP321. I was able to make it work with local user authentication but now, I want to manage my guest users on active directory. So I setup the captive portal to authentication user with NPS on Windows 2011 SBS.

The problem is that my guest SSID in not encrypted, so the NPS server do not let me login. I try to setup the NPS server like that :

Uncrypted authentification (PAP, SPAP)
Service-Type : Login

View 2 Replies View Related

Cisco Wireless :: Enable SSH On 3500 / 3600 APs Along With Use Radius For Login Authentication

Sep 11, 2012

Can we enable ssh on 3500 /3600 APs along with use radius  for login authentication? idea here is to that  ssh will provide another method to access the AP for troubleshooting purposes.I know with autonomous mode APs this should not be an issue but not sure with  lightweight APs.

View 2 Replies View Related

Cisco Wireless :: AP1140 Not Working Correctly?

Dec 9, 2012

I recently aquired a 2nd AP1140, however when i configure it for WPA 2 it works inconsistent, a ping for example will work only for 33% of the time.The same client has no issues with my 1st AP using WPA2, with the 2nd AP WEP works without a glitch.

View 2 Replies View Related

Cisco Wireless :: IOS 12.4 On AP1140 How To Rmdir Recursive And Non Empty Directory

Sep 5, 2011

How do I have to tell the IOS on an Aironet AP1142N to delete (rmdir) a whole directory with its contents and maybe subfolders?I've tried "rmdir /recursive flash:/directory" but I get asked if I'd like to remove "/recursive"!I don't have the time to dig myself into every and each sub folder deleting single files.

View 8 Replies View Related

Cisco VPN :: SSL VPN Authentication Using Radius ASA 8.4

Apr 25, 2011

I am running ASA version 8.4(1), and anyconnect version 3.0.1047. My SSL VPN works fine, but i run into an issue with one user . his account did not work , and everytime users logged in it got this message "VPN Server could not parse request".
 
I found the problem after getting a user information meaning his username and password. His password had "&" as one of the special characters. when we change it to something that does not have that , it works just fine.
 
We are using microsoft NPS server as radius. but when i run a test within CLI it works just fine, only when anyconnect asks to authenticate it fails.

View 5 Replies View Related

Cisco :: Radius Authentication Time

Aug 6, 2012

Any software to measure Authentication time between client and Radius serverr.

View 8 Replies View Related

AAA/Identity/Nac :: IPS / IDS Authentication With Cisco Radius ACS 5.2

Nov 22, 2011

I have been trying to get our IPS (ASA-SSM-10 and 4260) to authenticate with Cisco Radius ACS 5.2 and they are not working. However, I was able to get them working with Microsoft Radius. Below is the logs from the IPS:
  
evStatus: eventId=1321566464942057375 vendor=Cisco  originator:    hostId: NACAIRVIDLAB1    appName: authentication    appInstanceId: 350  time: 2011/11/23 17:50:38 2011/11/23 09:50:38 GMT-08:00  controlTransaction:

[Code].....

View 0 Replies View Related

Cisco AAA/Identity/Nac :: Radius Authentication In ACS 5.2 With AD

Mar 10, 2011

I have a questión about radius authenticaction with AD, when I log in into the network with user in AD and I make a mistake in password my radius authenticaction event in ACS 5.2 dont show me this logg. only show the authentication succeeded but dont show me the authentication failed. Maybe i must to enable same service to show the authentiaction failed. The Voice authetication works fine..
 
This is the confg in the port of the switch:
 
interface FastEthernet0/12 switchport mode access switchport access vlan 2 switchport voice vlan 10 authentication port-control auto authentication host-mode multi-domain authentication violation protect authentication event fail action authorize vlan 11 authentication event fail retry 2 action authorize vlan 11 authentication event no-response action authorize vlan 11 authentication periodic authentication timer reauthenticate 60 mab dot1x pae authenticator dot1x timeout tx-period 10 dot1x max-reauth-req 3 spanning-tree portfast end
 
Vlan 2: DATA
Vlan 10: VOICE
Vlan 11: GUEST

View 1 Replies View Related

Cisco :: Can't Do Radius Authentication Via WLC 4400

Jan 3, 2013

I am configuring an old WLC4400 with V4.2.130.0. I added a new sub-interface for VLAN 50 with proper IP for the subnet and then add the Radius server(Windows server 2008 with NPS) onto WLC4400. I then created new WLAN with WPA+WPA2 Encryption and 802.1x key management and selected the Radius server under AAA for authentication.
 
Configured the test XP with WPA-Enterprise and PEAP as EAP method. I purposely configured computer to prompt for username and password.
 
When I try to connect, I did get prompt for username and password. However after that nothing happens. It seems like laptop just keep trying to authenticate.
 
I checked windows event log and do not see anything under NPS. I know this windows server NPS setup works as it is also the authentication server for our remotevpn.
 
is there any special option I need to turn on for WLC in order for Radius authentication work? Or is there any known bug with V4.2.130.

View 13 Replies View Related

Cisco VPN :: ASA 5520 VPN With Radius Authentication?

Aug 11, 2011

I'm in the process of moving some of our remote access vpn to an asa5520 and anyconnect.
 
The problem I've come across is that when using radius as authentication, I choose any one of my connection profiles in anyconnect and log in with any username regardless of the group on radius.
 
How do I map the connection profile to a group on radius so that i can separate the users?

View 1 Replies View Related

Cisco Firewall :: Getting ASA 5510 Radius Authentication

May 17, 2011

I have a 5510 authenticating successfully with a RADIUS server.  I'm using it for VPN authentication and it works great.  I would also like to do this for administrator access to the ASA.  When I turn it on though, any authentication for VPN access is also granted administrative access to the ASA.  Obviously, I need to limit that to a select few users. 

View 1 Replies View Related

Cisco WAN :: Best RADIUS Server For 802.1x Wired Authentication?

Sep 2, 2012

which is the best RADIUS server for 802.1x wired authentication?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Authentication Radius Juniper NSM?

May 24, 2011

I am trying to authenticate on Juniper NSM express using cisco ACS 5.2.  The request is arriving at the cisco ACS but i am getting the following error.RADIUS requests can only be processed by Access Services that are of type Network Access.

View 4 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.0.2 Radius Authentication Setup

Jan 9, 2012

I am having ACS 4.0.2 in my network, which I want to use for 802.1x Radius Authentication for Clients on PEAP-MSCHAPv2 methodology.As per the documentation " EAP Authentication with RADIUS Server",  Doc ID: 44844.I have configured Network Configuration and populated AAA client IP range and Secret Key.
 
Question1: Under Authenticate Using option, there are various RADIUS flavors available for selection. For a Non Cisco AAA client, should I select RADIUS IETF?

Question 2: In the above snap shot, It has an option called Global Authentication Setup, where we can setup EAP configuration. Under PEAP subsection there is an option to "Allow EAP-MSCHAPv2" check box.After checking that, is a restart required to the ACS Server? Would it cause any disruptions to the existing services on the ACS?

View 3 Replies View Related

Cisco Routers :: Using Radius Authentication For VPN On RV042?

Nov 6, 2011

I am trying to setup a RV042 for a Client VPN using AD / Radius authentication. When it was purchased I saw radiuslisted as a feature on it, but I'm not seeing a way to set this up.
 
[URL]
 
I have upgraded to the latest firrmware, I have a VPN working with accounts on the router that I manually create, but am not seeing anyplace to configure radius.

View 5 Replies View Related

Cisco :: 5508 / Radius Authentication Not Working?

Apr 8, 2013

I have a 5508 controller running 7.4.100 and have a WLAN where I have radius configured. On my controller the client machine I'm using appears but the radius authentication doesn't appear to be working. Is there anything on the controller I can do to verify that the request is even being sent to my Microsoft IAS server? The log on the server doesn't show any requests from the controller so my early days guess is the controller isn't actually sending it.

View 3 Replies View Related

Cisco :: WLC 2504 With RADIUS Server Authentication And EAP-TLS

Mar 6, 2013

Can the 2504 WLC be configured to work with one RADIUS Server for Authentication of Management Users and with a second server for 802.1x EAP-TLS certificate authentication for the end users.
 
Management Users will authenticate on RADIUS Server 1.Wireless End users will request 802.1x EAP-TLS authentication certificate from AAA server 2.

View 5 Replies View Related

Cisco WAN :: Radius Authentication On Catalyst 2960?

Feb 25, 2013

I have a problem with radius authentication on catalyst 2960 with freeradius as radius-server. The Catalyst is behind a HP5412zl layer3-switch. The rest of the network are hp-layer2 switches, which do radius authentication to the same radius server. The ios on the catalyst is c2960-lanbasek9-mz.150-1.SE3. Apparently there are no requests made to the radius-server, since I dont see any requests coming in. Port 0/7 is voice port with laptop behind , /port 0/8 access-port with laptop directly connected.
 
config :
 
aaa new-model
aaa authentication dot1x default group radius
 dot1x system-auth-control
!
!
!
interface FastEthernet0/1

[code]....

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved