Any Windows WPA2 Enterprise Wireless Experts?

Hemigod

n00b
Joined
Jan 2, 2009
Messages
34
So I just setup wireless using a Cisco 1240AG, with Windows 2003 IAS as Radius server, and GPO to deploy the wireless settings and certificates to my windows clients.

This is all working great...but you can bypass needing the certificate by unchecking the "Validate Server Certificate" on the windows client. Then you just need to enter a valid domain user in the wireless access security group.

I have Validate Server Certificate Checked and specified one server that has a valid cert on my wireless setup in GPO.

What am I missing? I thought you needed to have a certificate installed on a client computer to be able to access a setup like this.

I loaded a new XP SP3 computer from CD and never connected it to the domain and i can get on the wireless with just a domain user account.

Or is this normal?

Thanks you guys for any ideas!!
 
I'm guessing you are using PEAP for the EAP type? You must have a certificate (cert) for PEAP to be supported on the Radius server (service won't start without it) but there are no requirements on the client. PEAP has an optional client cert piece but I've never heard of it being done. TLS requires a certificate on both ends but you have to set up a full blown PKI for client certs. It's doable with AD but may or may not fit your needs.

You might try to enforce machine authentication on your wireless side. This should create an environment where only your devices can get on the wireless. I use Aruba Wireless so I don't know the exact capabilities of the Cisco (I used Airespace before Cisco bought them but it's been at least 3+ years since I've seen it).

Also, remember the radius is doing an LDAP type query on the back end. AD is only seeing a username/password combination. The client device itself is not being considered with the normal WPA2 authentication process.
 
Last edited:
Yes, I set it up to use PEAP. Maybe its just a limitation of trying to use Microsoft with Cisco.

Thanks for your time and input Linux_Box
 
Back
Top