Networking Forums

Networking Forums > Computer Networking > Windows Networking > 802.1X and Guest

Reply
Thread Tools Display Modes

802.1X and Guest

 
 
Cyril
Guest
Posts: n/a

 
      07-12-2005, 03:08 PM
I currently carry out tests on 802.1x. I tested via peap and eap-tls.
However I would like to know how to make to authenticate computers which do
not belong to the field. For the moment the only solution that I found, it
is to give a login/password to the person while passing by peap and decochant
the box "to use login Windows...". But this solution annoys me because
because one cannot change the login. After I followed this article, but I do
not find it complete or I did not include/understand, especially with
dimensions radius
http://www.microsoft.com/technet/pro...4fb1014a4.mspx

 
Reply With Quote
 
 
 
 
Mark Gamache
Guest
Posts: n/a

 
      07-14-2005, 03:49 PM
Your solution depends on your exact need. I've had good luck with issuing
machine and user certs to machines that aren't members of the domain. As
long as the proper credentials are presented, the user or computer is
granted access.

is it always the same user logging in on the workgroup computers? Is the
real problem maybe that you have multiple users logging in via the same user
profile?

--
Mark Gamache
Certified Security Solutions
http://www.css-security.com



"Cyril" <(E-Mail Removed)> wrote in message
news:5862A2C1-CA66-44F5-AC2A-(E-Mail Removed)...
>I currently carry out tests on 802.1x. I tested via peap and eap-tls.
> However I would like to know how to make to authenticate computers which
> do
> not belong to the field. For the moment the only solution that I found,
> it
> is to give a login/password to the person while passing by peap and
> decochant
> the box "to use login Windows...". But this solution annoys me because
> because one cannot change the login. After I followed this article, but I
> do
> not find it complete or I did not include/understand, especially with
> dimensions radius.
> http://www.microsoft.com/technet/pro...4fb1014a4.mspx
>



 
Reply With Quote
 
Cyril
Guest
Posts: n/a

 
      07-18-2005, 08:21 AM
Thank you for your answer.
However I do not understand the finality of your question. I can give very
well a different account for each counted invited, but I would have a great
number of account. However according to the article, the computer will not
send any identifier and thus the server radius to take the invited account
(?).
If not I found another solution, I work on a switch HP, and thus via the
VLAN and the mode Open VLAN, I can isolate not authenticated on a VLAN.
Thank you

"Mark Gamache" wrote:

> Your solution depends on your exact need. I've had good luck with issuing
> machine and user certs to machines that aren't members of the domain. As
> long as the proper credentials are presented, the user or computer is
> granted access.
>
> is it always the same user logging in on the workgroup computers? Is the
> real problem maybe that you have multiple users logging in via the same user
> profile?
>
> --
> Mark Gamache
> Certified Security Solutions
> http://www.css-security.com
>
>
>
> "Cyril" <(E-Mail Removed)> wrote in message
> news:5862A2C1-CA66-44F5-AC2A-(E-Mail Removed)...
> >I currently carry out tests on 802.1x. I tested via peap and eap-tls.
> > However I would like to know how to make to authenticate computers which
> > do
> > not belong to the field. For the moment the only solution that I found,
> > it
> > is to give a login/password to the person while passing by peap and
> > decochant
> > the box "to use login Windows...". But this solution annoys me because
> > because one cannot change the login. After I followed this article, but I
> > do
> > not find it complete or I did not include/understand, especially with
> > dimensions radius.
> > http://www.microsoft.com/technet/pro...4fb1014a4.mspx
> >

>
>
>

 
Reply With Quote
 
Mark Gamache
Guest
Posts: n/a

 
      07-18-2005, 06:02 PM
I think you are asking about computer only authentication.
http://www.microsoft.com/technet/pro...4ed8e7492.mspx

You can alter the registry so that only the computer is authenticated and
the user stays on the network in the computers security context. You will
still need to get one computer certificate on each PC. You will have to get
the computer certificate in the context of a valid domain computer account.
I believe the easiest way is likely to be via the CA web interface.

I hope that helps.

--
Mark Gamache
Certified Security Solutions
http://www.css-security.com



"Cyril" <(E-Mail Removed)> wrote in message
news:7062BCD9-9AB6-4031-A886-(E-Mail Removed)...
> Thank you for your answer.
> However I do not understand the finality of your question. I can give
> very
> well a different account for each counted invited, but I would have a
> great
> number of account. However according to the article, the computer will
> not
> send any identifier and thus the server radius to take the invited account
> (?).
> If not I found another solution, I work on a switch HP, and thus via the
> VLAN and the mode Open VLAN, I can isolate not authenticated on a VLAN.
> Thank you
>
> "Mark Gamache" wrote:
>
>> Your solution depends on your exact need. I've had good luck with
>> issuing
>> machine and user certs to machines that aren't members of the domain. As
>> long as the proper credentials are presented, the user or computer is
>> granted access.
>>
>> is it always the same user logging in on the workgroup computers? Is the
>> real problem maybe that you have multiple users logging in via the same
>> user
>> profile?
>>
>> --
>> Mark Gamache
>> Certified Security Solutions
>> http://www.css-security.com
>>
>>
>>
>> "Cyril" <(E-Mail Removed)> wrote in message
>> news:5862A2C1-CA66-44F5-AC2A-(E-Mail Removed)...
>> >I currently carry out tests on 802.1x. I tested via peap and eap-tls.
>> > However I would like to know how to make to authenticate computers
>> > which
>> > do
>> > not belong to the field. For the moment the only solution that I
>> > found,
>> > it
>> > is to give a login/password to the person while passing by peap and
>> > decochant
>> > the box "to use login Windows...". But this solution annoys me because
>> > because one cannot change the login. After I followed this article,
>> > but I
>> > do
>> > not find it complete or I did not include/understand, especially with
>> > dimensions radius.
>> > http://www.microsoft.com/technet/pro...4fb1014a4.mspx
>> >

>>
>>
>>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
How to access Guest OS with NAT tech_geek Linux Networking 3 01-11-2009 07:25 AM
guest vs anonymous user Agostino Sclauzero Windows Networking 1 04-24-2008 01:42 AM
guest vs anonymous user Agostino Sclauzero Windows Networking 0 04-23-2008 11:06 PM
Guest VLAN can connect but can't get an IP Mike Webb Wireless Networks 6 10-10-2007 05:39 PM
98 conect to the internet and xp as guest robson Windows Networking 1 07-11-2003 08:53 AM



1 2 3 4 5 6 7 8 9 10 11