PEAP - user authentication and mac authentication

Answered Question
Jun 4th, 2008
User Badges:

Hi,


Can I use PEAP with Mac and user (login and password windows) authentication ?

Do I need CISCO ACS?



PEAP with user authentication and MAC filtering, Is this possible?


Thanks

Correct Answer by Scott Fella about 9 years 1 month ago

You will have to do MAC Authentication on each ap. This would require you to enter all the allowed mac address on each ap. You will not be able to do PEAP without a radius server. You can always install MS IAS server if you are a MS shop. :)

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Scott Fella Wed, 06/04/2008 - 02:44
User Badges:
  • Super Silver, 17500 points or more
  • Hall of Fame,

    The Hall of Fame designation is a lifetime achievement award based on significant overall achievements in the community. 

  • Cisco Designated VIP,

    2017 Wireless

You can do PEAP with MAC Authentication on the WLC. It will be under local EAP. MAC Authentication is really not required, since it is so easy to spoof a MAC. Also with PEAP, they will have to authicate to the WLC DB or LDAP.


http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a008093f1b9.shtml

lamanso Wed, 06/04/2008 - 03:44
User Badges:

Thanks Fella,


We have today an autonomous systems with 19 air-ap1131ag and 1 WLSEExpress.


We want do PEAP with user authentication and mac authentication.


Can I do this with this devices?


Can I do PEAP and mac filtering (centralized or configured each one?

Thanks


Thanks




Correct Answer
Scott Fella Wed, 06/04/2008 - 05:21
User Badges:
  • Super Silver, 17500 points or more
  • Hall of Fame,

    The Hall of Fame designation is a lifetime achievement award based on significant overall achievements in the community. 

  • Cisco Designated VIP,

    2017 Wireless

You will have to do MAC Authentication on each ap. This would require you to enter all the allowed mac address on each ap. You will not be able to do PEAP without a radius server. You can always install MS IAS server if you are a MS shop. :)

lamanso Wed, 06/04/2008 - 06:05
User Badges:

Thanks fella5


We are going to install a MS IAS server like Radius server for PEAP.




Scott Fella Wed, 06/04/2008 - 06:28
User Badges:
  • Super Silver, 17500 points or more
  • Hall of Fame,

    The Hall of Fame designation is a lifetime achievement award based on significant overall achievements in the community. 

  • Cisco Designated VIP,

    2017 Wireless

You will need to install a certificate also into your radius server. So you can bring up an MS certificate CA and generate one and you will be good to go.

drgebhardt Tue, 06/17/2008 - 12:09
User Badges:

Does anyone have PEAP/IAS config example for an autonomous AP (1242) ?

drgebhardt Wed, 06/18/2008 - 06:45
User Badges:

Thanks for the input. Any possibility that a the text based config from an autonomous AP is available? Or possibly the 1242 GUI screen shots?

Actions

This Discussion

 

 

Trending Topics: Other Wireless Mobility

client could not be authenticated
Network Analysis Module (NAM) Products
Cisco 6500 nam
reason 440 driver failure
Cisco password cracker
Cisco Wireless mode