Advertisement

09.23.2008 at 08:37PM PDT, ID: 23757344 | Points: 500
[x]
Attachment Details

PEAP authentication issues with MS client

Asked by nodisco in Windows Network Security, Wireless Application Protocol (WAP), Microsoft Windows Operating Systems, Wireless Local Area Network, Networking

Tags: , , ,

hey all

I have been testing a PEAP deployment for the past couple of weeks and have an unusual error that is stopping me in my tracks.  I have 4 test machines  - all Dell laptops beside the test AP.  The test AP runs 2 different SSIDS on different vlans - one is for external and works fine using WPA auth - and one is for internal using PEAP back to our Cisco ACS 4.2 server.  The problem is that 2 of them machines work fine with the Windows client to PEAP and get internal addresses without issue on authentication with ACS.  Both of these machines are XP SP3.
The other 2 are XP SP2 but will not connect using the Windows client.  On associating with the WAP, the ACS failed attempts log shows the following error:
 EAP-TLS or PEAP authentication failed during SSL handshake

Apparently MS have released a hotfix for PEAP issues which i applied.  The 2 laptops still give the same error on trying to connect.  I upgraded them to SP3 and they still give the same problem.
The bizarre thing is that regardless of SP or hotfix, if I use the Intel Proset wireless manager instead of the Windows wireless manager, both machines connect to PEAP every time.
Both are configured exactly the same as the 2 working Windows machines and as this is going to be rolled out live in a global policy - I am not confident of it working considering i have 2 machines that don't like it.

Has anyone encountered any strange issues with PEAP and Windows wireless like this or have any suggestions on how I can try to resolve this?  I am pretty confident the problem is individually with these laptops and not with the Cisco AP or Cisco ACS as I don't have any issues with the AP or ACS on different clients.

Would be v grateful for help on this one!

cheersStart Free Trial
[+][-]10.15.2008 at 07:44AM PDT, ID: 22721667

Experts Exchange has a courteous staff of administrators who help members get the most out of the website by means of administrative comments like this one.

Start your 7-day free trial to view this Administrative Comment or ask the Experts your question.

 
[+][-]10.17.2008 at 04:18AM PDT, ID: 22739327

Experts Exchange has a courteous staff of administrators who help members get the most out of the website by means of administrative comments like this one.

Start your 7-day free trial to view this Administrative Comment or ask the Experts your question.

 
[+][-]10.17.2008 at 06:10AM PDT, ID: 22740260

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10.17.2008 at 01:54PM PDT, ID: 22745185

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_EXPERT_20070906