Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.internet.wireless
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 02-23-2007, 01:24 PM
david_klusas@hotmail.com
Guest
 
Posts: n/a
Default 802.1x wireless security question

Hello, I need some help with wireless security...

I am trying to design a strong security model for my company.

Proposed Wireless Network:
WPA2 - AES encryption
PEAP using MS-CHAP-V2 (no certs, except on IAS server)
802.1x authentication via a Windows Server 2003 IAS (against the AD)
Using Cisco 4402 wireless switches

Within IAS, I have created a policy that authenticates users and
computers based on this phrase:

NAS-Port-Type matches "Wireless - Other OR Wireless - IEEE 802.11" AND
Windows-Groups matches "domain\Domain Users;domain\Domain Computers"

Looking at the IAS log, the policy correctly rejects or denies
Machines and Users whether they are a part of these groups or not.
I'm hoping to authenticate the machine at boot up (which is working
fine) but also authenticate the username AND machine name when the
user logs in.

With these current settings, if a user logs in to any PC (even one
from home) they fail the machine authentication but if they use their
correct domain username and password, they are allowed on the wireless
network. Ideally, I would like to see the IAS server check the
username and machine at the same time during user authentication
preventing this issue.

Can this be done???


Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Security '07 Call For Papers Lionel Garth Jones comp.security.misc 0 01-25-2007 04:32 PM
Router Security Question... spooker Network Troubleshooting 3 10-11-2006 12:29 PM
Call for Papers for the 16th USENIX Security Symposium Lionel Garth Jones comp.security.misc 0 10-02-2006 09:01 PM
The Repeater, Access Point, Laptop Triangle of Death (Please Help) TheKingsCrown Network Troubleshooting 9 04-25-2006 04:01 AM
Technical Question on wireless security David alt.computer.security 0 07-17-2005 07:05 AM


All times are GMT. The time now is 11:24 AM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45