Solved

ldap ACS PEAP EAP-MSCHAPv2

Posted on 2014-03-18
3
1,085 Views
Last Modified: 2014-03-28
Hi there !

I would like to know if there is a problem with a radius authentification with a Cisco ACS and PEAP (EAP-MSCHAPv2) using a Digicert wild card certificate ?

We are using cisco 5508 wifi controlers and a Cisco ACS 5.2.0.26, an Active directory 2012 and a Digicert wild card 2048bit.

And we are using the ldap fonction in the ACS.

In the ACS, Access Policies >       Access Services >       service-wifi-acs >       Edit: "service-wifi-acs", Allowed Protocols,        Allow PEAP. When I activate "EAP-MS-CHAPv2" ipads and androides are not working. And when I activate "EAP-MS-CHAPv2", I can't make Microsoft boxes work. I did try to activate all protocols with no success.

We are using a wpa2 enterprise, aes on the Cisco 5508 wifi controlers.

Any clues how to make work the radius/ldap with Microsoft boxes + ipads + androides ?


Thank you !
Chris
0
Comment
Question by:nu_bee
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 46

Accepted Solution

by:
Craig Beck earned 500 total points
ID: 39939172
I would highly recommend using AD-integration with ACS for PEAP-MSChapV2.  The fact that you're using multiple client OS makes this hard to use LDAP.

If you're using PEAP it's not recommended to use LDAP, especially when using MSChapV2, due to the way the user password is handled.  Basically, PEAP-MSChapV2 and LDAP are not compatible.

If you absolutely have to use LDAP (even though you have AD) you can use EAP-GTC as the inner EAP method.  This will work with LDAP but it means you may have to install a third-party supplicant on the majority of client machines and handhelds.
0
 

Author Comment

by:nu_bee
ID: 39950262
Hi craigbeck !

Thank you for the tip.

Well, now it has nothing to do with the certificate from what I understand.

I did upgrade the Cisco ACs from 5.2 to 5.5 and put it in "ad mode".

I was able to activate the mschapv2 without causing trouble to ipads/androides.

The Windows 7 are able to authenticate but I have to manually configure the conexion to force the usage of prompted user input so it wont use the local account of the open session on the windows box.


So now I'm searching to configure the ACS so I don't have to configure anything on Windows boxes. Some are saying it's not possible.   :_(


Thank you again !
Chris
0
 
LVL 46

Expert Comment

by:Craig Beck
ID: 39950290
That's true.  Windows will send the currently logged-in user credentials to authenticate by default.  You have to turn that off manually if you want to prompt for alternative credentials.

If you deploy the WLAN profile via GPO you can turn this off on each Windows machine automatically.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Monitor bandwidth 3 147
Cisco MAC address finding 5 110
catalyst 6500 - recover from corrupted IOS 4 69
Non Distrubtive Core Switch Repacement 8 37
I wrote this article to help simplify the process of combining multiple subnets. This can be used for route summarization also but there are other better ways to summarize routes, This article is a result of questions I participate in here at Ex…
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

697 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question