Re: Seeking advice on Aironet 1232 config for visitor and staff access



Thanks for your advice. I worked on this yesterday and used IAS to
authenticate visitors based on their MAC address. Switches were not
configured for VLANS and there wasn't enough time to configure them, so
I used the filters you mentioned and they worked. When a visitor comes
in, the admin writes down the mac address of the device and creates an
account named after the mac address in AD and adds the account to a
group called Wireless guest whose members IAS will allow to
authenticate. The IAS logs say the authentication type is PAP which
isn't secure but I I need something that will work with almost any
device that a visitor might want to connect to our AP so I will use PAP
until I figure out what to replace it with. The device (laptop) is
configured for WEP with open auth, and pointed to the correct SSID.
I'm sure there are better ways to do this, but this is a start. I will
continue to work on making it better. As for the WLSM mentioned by
Nick, I ever knew they even existed. I googled "WLSM" and found
something for the Cisco 6500. We only have a couple of Dell switches
and 40 users.
Thanks for your replies!!

.



Relevant Pages

  • Re: 802.1x authentication for wireless issues w/ ISA 2004
    ... The do support WPA-EAP and the radius ... authenticate the computer and this is trying to authenticate the user and not ... If you can post perhaps 10 lines from the IAS log, ... represent my IAS server or the client laptops. ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN 3005 to IAS authentication failure...
    ... Call it something like "VPN Users" or similar. ... install IAS using the Add/Remove Programs icon in Control Panel. ... we can now configure the PIX firewall as a RADIUS client. ... Any user that should be allowed to authenticate on a VPN connection will ...
    (comp.dcom.sys.cisco)
  • Re: IAS server and access points
    ... I use PEAP and passwords to authenticate wireless clients. ... I get an occassional message on my IAS server that says "A RADIUS ...
    (microsoft.public.internet.radius)
  • Re: PEAP (MSCHAPV2) - Confusion over User vs. Computer Authentication
    ... > authenticate WLAN clients via Cisco 1200 APs. ... > somewhere that you could configure IAS to ENFORCE the rule ... If you deploy EAP-TLS without smart cards you can prevent non-domain member ... that the user cert that your CA issues goes only to machines that are ...
    (microsoft.public.internet.radius)
  • RE: How do I install & set up RADIUS?
    ... IAS is a server enable you to ... you configure a user can log in via VPN and the authenticate ... The initila use of RADIUS has just been clarified for me. ... How do I install & set up RADIUS? ...
    (microsoft.public.windows.server.general)