RE: 802.1x Authentication

From: Wozny, Scott (US - New York) (swozny_at_deloitte.com)
Date: 10/28/04

  • Next message: Michael Silk: "RE: GPO that forces users to use a proxy server."
    Date: Thu, 28 Oct 2004 17:30:58 -0400
    To: "Jef Feltman" <feltman@pacbell.net>, "Billy Dodson" <billy@pmm-i.com>, <focus-ms@securityfocus.com>
    
    

    It's within the standard to set up a default role that users who choose
    not to authenticate will be put into (i.e. HTTP, HTTPS and VPNs only for
    visitors). It's also possible to do multiple authentication on the same
    port if the switch allows it. I would suggest experimenting with the
    wireless setting you've found and apply them to wired interfaces. I
    think you'll be surprised how much of it works.

    Scott

    -----Original Message-----
    From: Jef Feltman [mailto:feltman@pacbell.net]
    Sent: Wednesday, October 27, 2004 10:30 PM
    To: 'Billy Dodson'; focus-ms@securityfocus.com
    Subject: RE: 802.1x Authentication

    If the switch is not setup for 802.1x then it will not ask for
    authentication for access.

    If the switch is setup for 802.1x then every computer and/or user will
    need
    to authenticate. You can place this requirement on each port you wish
    to
    have authenticate.

    PLUG
    Integrity www.zonelabs.com supports 802.1x on switches and wireless
    AP's, if
    the device supports it.
    PLUG

    jef

    -----Original Message-----
    From: Billy Dodson [mailto:billy@pmm-i.com]
    Sent: Wednesday, October 27, 2004 9:21 AM
    To: focus-ms@securityfocus.com
    Subject: 802.1x Authentication

    Is is possible through active directory group policy, or any other
    means, to
    change the configuration of the ethernet authentication tab? I am
    trying to
    enable PEAP authentication and validate certificates. PEAP is not the
    default setting.
     
    I found in group policy where this can be changed for wireless clients,
    but
    I need to make this changes for a wired connection. Any ideas?
     
    Thanks,
     
    Billy

    ------------------------------------------------------------------------

    ---
    ------------------------------------------------------------------------
    ---
    This message (including any attachments) contains confidential information intended for a specific individual and purpose, and is protected by law.  If you are not the intended recipient, you should delete this message.  Any disclosure, copying, or distribution of this message, or the taking of any action based on it, is strictly prohibited.
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Michael Silk: "RE: GPO that forces users to use a proxy server."

    Relevant Pages

    • Re: http authentication against radius
      ... Authentication is working fine, authorization is failing. ... At the command line login to the switch it works perfectly. ... ip http authentication aaa ...
      (comp.dcom.sys.cisco)
    • Re: 802.1x authentication issue
      ... There was nothing wrong with the switch port, ... Yes, we are using IAS for PEAP authentication, I analyzed IAS logs but didn't ... I ended up switching the machine to a NON .1x port, disjoining the Domain, ... If the machine has an APIPA address it means it can't contact the DHCP ...
      (microsoft.public.windows.server.networking)
    • Re: 802.1x howto ias computer only authentication
      ... I have a Cisco 2960 switch and MS IAS Radius configured and the ... the authentication happen there - now the switch isn't changing the vlan it ... Windows XP because no dhcp can be found. ... access permission by your remote access policy. ...
      (microsoft.public.internet.radius)
    • RE: [fw-wiz] "802.1x"?
      ... wired and wireless end-point authentication solution. ... the access device (WAP or switch) has a default set of filters ...
      (Firewall-Wizards)
    • RE: IEEE 802.1x & dynamic vlan assignment
      ... As when the workstation send the EAPOL logoff message the switch puts the ... user authentication behavior of Windows XP and Windows Server 2003. ... - Computer authentication mode. ...
      (Focus-Microsoft)