cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2207
Views
0
Helpful
34
Replies

3945 ABG PEAP & CHAP

linhthasack
Level 1
Level 1

Help, I cant get the 3945 ABG card to work with our cisco AP using peap & chap. Has anyone have this problem. If so could you please help. Thanks

34 Replies 34

Mike, wait for your report. Thx.

I too install Cisco's AIR-CB21AG-A-K9 card in the PCMCIA slot. The client authenticate but was not able to sustain the connection. It would drop every 5 to 10 minutes and ask for authentication. This is also with MS Hotfix for 802.1x. With this result, it also leads me to beleive that their may be a need for the software fix for the new 945 chipset in the new motherboard that comes with all this laptop. But if you can get better result with other cards please let me know. Thanks for the reply ....Now I know that im not the only one out there..

I have peap working with mschap-v2 using lenovo t60 laptops using the intel 3945 abg chipset. You have to use ibm access connections v4.11a. The ibm access connections changed the peap single sign-on in v4.12. I am using cisco 1242ag access points using 12.3.8-ja2 ios on the ap's. In version 4.12 of ibm access connections they are sending domain/login id which causes authentication problems on the radius server. We are using the free radius server on linux to authenticate our clients. We are trying to strip the domain from the login id so then we are able to authenticate the client with just the login id and password. The only way of i have gotten the client the to authenticate in v4.12 of access connections is fill in the userid and password with no domain.

Do you have a copy of 4.11a? I cannot find it on the IBM/Lenovo site, and they say they do not have it available now.

I would like to test with 4.11a and validate in my environment.

I would love to have a copy of the 4.11a supplement to test. I too cannot find that copy. There is no way that we can change our structure to not include domain. please send supplecant to slinhthasack@pacific.edu

The file size is a 11 megabytes and I only send a maximum size of 10 megabyte through our email server. Unless somebody has a ftp site i can upload it to.

Mr. Futros,

I have created an ftp site for access. Send me an email address, and I can send you login info for upload.

Thank you for your help.

Mike

Intel just came out with a new release 10.5.1.57 version. I just finish testing it with Gateway's laptop. User authenthicate ok with Microsoft wireless connection but will not sustain connection. It will drop and reauthenthicate every 10-15 seconds. With Intel's supplecant the add profile was grayed out now we cant even add a user. I think intel's getting closer to solving the problem. If you guys have any new finding please post. I will test the new driver with an IBM T60 next and will post the result.

any update on your testing linhtasack? any update on your testing mwebb@odec.com? We are still trying to strip the domain from domain/username login id. No luck yet.

We finally got the domain stripped from domain/username login id. We can now authenticate using peap and mschap v2 with the windows username and password using v4.12 ibm access connections. This works with the ibm t60 with the intel 3945abg chipset.

Danny,

I am still where I was at last week. Running AC 4.11a did not good.

Recap from last week...

I have discovered that I cannot connect with this card on the first attempt. However, if I have the laptop plugged into our network via an ethernet cable, and then attempt to make a wireless connection (yes, while the ethernet cable is plugged in), it will connect. I can then shut down the laptop and from that point on, I can make successful wireless connections with no problems

Have you tried adding your RADIUS server certificate as trusted manually before trying to connect to the wireless. It sounds to me that your domain Group Policy is taking care of that for you when you log with the wired connection.

I have been able to create a new user from wireless logon without validating the server certificate. When i try creating a new user with server certifacte validation i am not able to log on to the network. My radius server sees it as a bad certificate. With an existing user i am able to logon to the network with validating the server certifacte.

FIX FIX FIX

I know what is causing the client to not authenticate the users. It is due to roaming issue. The client drops in and out when trying to authenticate because the client tries to roam to other APs, You will see the connect and a drop. If you have multiple APs BROADCASTING the same SSID then the client will roam even though physical location is the same. I FIXED the ISSUE by TURNING OFF broacast on SSID that uses PEAP to prevent the client from roaming. I know this is a temperary fix but it will surfice until Intel gets a new driver out. Good luck to everybody.....and thank you so much to all of you that replies and listen.....

I've just posted in another thread about this, but I'm seeing a very similar issue (not exactly the same though).

The APs in this case are 1200 series IOS upgraded running 802.11b interfaces only. There are multiple SSIDs NONE of which are broadcasting.

We've got a few different client types. The Cisco CB21ABG cards are fine, as are the Intel 2200 and 7920 phones. It's only the 3945 that has a problem and it's running Intel's 10.5.1.68 driver which is the latest. I'm considering downgrading it to an older driver.

Basically, the adapter is just unreliable with its connection. It will connect, but over time it drops packets and lattency increases. If you reboot it, it works ok for a bit again. The 3945 is being configured through XP Zero, and doesn't have a problem when running WPA-PSK, only when WPA/TKIP/PEAP is used. Also, if you stick a CB21ABG (still under XP) in the same machine and disable the 3945, it's perfect.

Review Cisco Networking products for a $25 gift card