Networking Forums

Networking Forums > Wireless Networking > Wireless Internet > 802.1x wireless security question

Reply
Thread Tools Display Modes

802.1x wireless security question

 
 
david_klusas@hotmail.com
Guest
Posts: n/a

 
      02-23-2007, 01:24 PM
Hello, I need some help with wireless security...

I am trying to design a strong security model for my company.

Proposed Wireless Network:
WPA2 - AES encryption
PEAP using MS-CHAP-V2 (no certs, except on IAS server)
802.1x authentication via a Windows Server 2003 IAS (against the AD)
Using Cisco 4402 wireless switches

Within IAS, I have created a policy that authenticates users and
computers based on this phrase:

NAS-Port-Type matches "Wireless - Other OR Wireless - IEEE 802.11" AND
Windows-Groups matches "domain\Domain Users;domain\Domain Computers"

Looking at the IAS log, the policy correctly rejects or denies
Machines and Users whether they are a part of these groups or not.
I'm hoping to authenticate the machine at boot up (which is working
fine) but also authenticate the username AND machine name when the
user logs in.

With these current settings, if a user logs in to any PC (even one
from home) they fail the machine authentication but if they use their
correct domain username and password, they are allowed on the wireless
network. Ideally, I would like to see the IAS server check the
username and machine at the same time during user authentication
preventing this issue.

Can this be done???

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Security Question (Wireless) fishcca Wireless Internet 34 02-16-2006 01:26 PM
question on wireless security WPA hawklord Wireless Internet 4 06-13-2005 04:45 PM
wireless security question ss Wireless Internet 3 02-14-2005 09:43 PM
Wireless Security question Jefferis NoSpamme Wireless Networks 5 12-11-2004 09:54 PM
security question about wireless g BigJIm Wireless Internet 6 12-28-2003 02:33 PM



1 2 3 4 5 6 7 8 9 10 11