Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Clayton Dukes
I can see from searching the mailing list that this has been asked many times, but what I can't seem to locate are config examples or a good howto on setting everything up. I have the radius server set up -- and it appears to work on, but I am not sure what I am lacking/doing wrong on the AP. I

Re: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Bob McCormick
Here's a config template I use for Cisco 1120 AP's.Try this and see if it works for you. !# ! Basic config template for Cisco IOS Access Points ! 4/20/2004 - BDM - I've tested it with 1120's but should work with 1200's

RE: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Clayton Dukes
Corp. http://www.esnet.com 813.301.2620 (o) 813.545.7373 (c) -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Bob McCormick Sent: Friday, April 23, 2004 2:26 PM To: [EMAIL PROTECTED] Subject: Re: Cisco 1100 AP and XP Client using tls (PEAP) Here's a config

Re: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Alan DeKok
Clayton Dukes [EMAIL PROTECTED] wrote: I'm connecting now but getting an Auth failure. You are setting Auth-Type := LDAP somewhere. Don't do that. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Bob McCormick
. http://www.esnet.com 813.301.2620 (o) 813.545.7373 (c) -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Bob McCormick Sent: Friday, April 23, 2004 2:26 PM To: [EMAIL PROTECTED] Subject: Re: Cisco 1100 AP and XP Client using tls (PEAP) Here's a config

RE: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Clayton Dukes
Well, I want that -- can I not use LDAP to authenticate the users? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Alan DeKok Sent: Friday, April 23, 2004 3:18 PM To: [EMAIL PROTECTED] Subject: Re: Cisco 1100 AP and XP Client using tls (PEAP) Clayton

RE: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Clayton Dukes
- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Bob McCormick Sent: Friday, April 23, 2004 3:13 PM To: [EMAIL PROTECTED] Subject: Re: Cisco 1100 AP and XP Client using tls (PEAP) I don't know much about the the LDAP module, but it sure looks like it's not returning a password

Re: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Bob McCormick
Solutions Corp. http://www.esnet.com 813.301.2620 (o) 813.545.7373 (c) -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Bob McCormick Sent: Friday, April 23, 2004 2:26 PM To: [EMAIL PROTECTED] Subject: Re: Cisco 1100 AP and XP Client using tls (PEAP

RE: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Clayton Dukes
] [mailto:[EMAIL PROTECTED] On Behalf Of Alan DeKok Sent: Friday, April 23, 2004 3:28 PM To: [EMAIL PROTECTED] Subject: Re: Cisco 1100 AP and XP Client using tls (PEAP) Clayton Dukes [EMAIL PROTECTED] wrote: Well, I want that -- can I not use LDAP to authenticate the users? No. The packet

RE: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Albers Darren
: Friday, April 23, 2004 4:25 PM To: [EMAIL PROTECTED] Subject: Re: Cisco 1100 AP and XP Client using tls (PEAP) WinXP doesn't pop up a dialog box asking for your username and password? On Apr 23, 2004, at 2:22 PM, Clayton Dukes wrote: As far as I can tell, the username is getting

Re: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Alan DeKok
Clayton Dukes [EMAIL PROTECTED] wrote: Hmmm, I believe that is what I have done. shrug Nothing in the default configuration of the server sets Auth-Type to LDAP. So you must have edited something to set it in your local system. a) find out what you edited b) look at the debug trace to

Re: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Bob McCormick
: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Bob McCormick Sent: Friday, April 23, 2004 3:25 PM To: [EMAIL PROTECTED] Subject: Re: Cisco 1100 AP and XP Client using tls (PEAP) WinXP doesn't pop up a dialog box asking for your username and password? On Apr 23, 2004, at 2:22 PM, Clayton

RE: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Dennis Skinner
On Fri, 2004-04-23 at 16:17, Clayton Dukes wrote: Well, I want that -- can I not use LDAP to authenticate the users? Read up on the difference between Authorize and Authenticate. You want to use LDAP for the former, not the latter. Once you understand that, Alan's emails will start making

RE: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Clayton Dukes
} -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Alan DeKok Sent: Friday, April 23, 2004 3:42 PM To: [EMAIL PROTECTED] Subject: Re: Cisco 1100 AP and XP Client using tls (PEAP) Clayton Dukes [EMAIL PROTECTED] wrote: Hmmm, I believe that is what I have

Re: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Alan DeKok
Clayton Dukes [EMAIL PROTECTED] wrote: Sorry, I must have misunderstood. Forgive me...If I turn off LDAP in the authenticate section, Did I say to do that? No. Go back and read what I said. If you're retrieving passwords from the LDAP directory, then setting Auth-Type := LDAP is not only

RE: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Clayton Dukes
Finished request 4 Going to the next request Waking up in 6 seconds... -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Alan DeKok Sent: Friday, April 23, 2004 4:31 PM To: [EMAIL PROTECTED] Subject: Re: Cisco 1100 AP and XP Client using tls (PEAP

Re: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Bob McCormick
Finished request 4 Going to the next request Waking up in 6 seconds... -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Alan DeKok Sent: Friday, April 23, 2004 4:31 PM To: [EMAIL PROTECTED] Subject: Re: Cisco 1100 AP and XP Client using tls (PEAP) Clayton

RE: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Clayton Dukes
Well poop... -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Bob McCormick Sent: Friday, April 23, 2004 5:10 PM To: [EMAIL PROTECTED] Subject: Re: Cisco 1100 AP and XP Client using tls (PEAP) If your not getting an IP it's still not working

Re: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Alan DeKok
Clayton Dukes [EMAIL PROTECTED] wrote: Well, I have it working, at least it appears to be, but I am still not getting an ip on the laptop -- do I need to pass the dhcp server somewhere? No. The client should send a broadcast DHCP request, and the dhcp server should pick that up. Alan

Re: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Bob McCormick
... -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Bob McCormick Sent: Friday, April 23, 2004 5:10 PM To: [EMAIL PROTECTED] Subject: Re: Cisco 1100 AP and XP Client using tls (PEAP) If your not getting an IP it's still not working... The only times I've had

Re: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Bob McCormick
PROTECTED] Subject: Re: Cisco 1100 AP and XP Client using tls (PEAP) Clayton Dukes [EMAIL PROTECTED] wrote: Well, I have it working, at least it appears to be, but I am still not getting an ip on the laptop -- do I need to pass the dhcp server somewhere? No. The client should send a broadcast DHCP

RE: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Clayton Dukes
: Friday, April 23, 2004 5:21 PM To: [EMAIL PROTECTED] Subject: Re: Cisco 1100 AP and XP Client using tls (PEAP) Clayton Dukes [EMAIL PROTECTED] wrote: Well, I have it working, at least it appears to be, but I am still not getting an ip on the laptop -- do I need to pass the dhcp server somewhere

RE: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Clayton Dukes
- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Alan DeKok Sent: Friday, April 23, 2004 5:21 PM To: [EMAIL PROTECTED] Subject: Re: Cisco 1100 AP and XP Client using tls (PEAP) Clayton Dukes [EMAIL PROTECTED] wrote: Well, I have it working, at least it appears to be, but I am

RE: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Clayton Dukes
:[EMAIL PROTECTED] On Behalf Of Clayton Dukes Sent: Friday, April 23, 2004 6:11 PM To: [EMAIL PROTECTED] Subject: RE: Cisco 1100 AP and XP Client using tls (PEAP) Here's my latest error... TLS_accept:error in SSLv3 read client certificate A Did I screw up the certificates? -Original Message

RE: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Michael Griego
: Cisco 1100 AP and XP Client using tls (PEAP) If it's working you should get something like this at the end of the debugs: modcall: group authenticate returns ok for request 8 Sending Access-Accept of id 47 to 10.140.24.12:21666 Session-Timeout := 300 MS-MPPE-Recv-Key

Re: Cisco 1100 AP and XP Client using tls (PEAP)

2004-04-23 Thread Bob McCormick
) 813.545.7373 (c) -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Clayton Dukes Sent: Friday, April 23, 2004 6:11 PM To: [EMAIL PROTECTED] Subject: RE: Cisco 1100 AP and XP Client using tls (PEAP) Here's my latest error... TLS_accept:error in SSLv3 read