Re: 802.1x machine authentication without directory



Hi Michael,

If I understand what you are trying to do correctly, you're running into the problem that a lot of radius servers and IAS don't work on an NT4 domain.

A tip I found earlier: Funk Software's Odyssee Server is great and simple for WLAN only use (RADIUS). Can authenticate against an NT4 domain specifically.

An other option (but I have not tried it myself, nor looked into it in-depth) seems to be that you could plug samba 2.x in your domain with a win2k client machine to provide the translation of NT4 domain authentication to LDAP (which can then be used for the RADIUS). At the very least this sounds rather tricky to set up but might be an option if nothing else works.

HTH

MC


michael.owen wrote:
Hi all,

I've been looking into a small-scale 802.1x rollout, and have encountered something of a problem. The systems on the network I'd be NAC-ing are XP boxes which are members of an NT4 domain, with all users authenticated at the domain level. (No local accounts are typically used.) I was hoping to use machine authentication, but it seems as though most RADIUS servers only support machine auth when they have a directory (typically AD) to confirm the membership of the supplicants.
.



Relevant Pages

  • Re: [fw-wiz] IPv6 comes in the game
    ... "Victor Williams" wrote: ... >> assigned address in the firewall, while still having static MAC ... then you're able to log the authentication at the RADIUS ... > I'd probably look at RADIUS servers to see if there's any group addressing ...
    (Firewall-Wizards)
  • Re: [fw-wiz] IPv6 comes in the game
    ... > static neighbor cache). ... some "hand out an address by authentication group" sort of thing. ... and equate network activity to a port. ... I'd probably look at RADIUS servers to see if there's any group addressing ...
    (Firewall-Wizards)
  • Re: RADIUS CERTIFICATES WPA PEAP
    ... IAS can run fine in an NT4 domain. ... You will need to setup a CA, or obtain a public certificate for your server. ... > Can the RADIUS server run W2K3 STD with IAS as a member server in an NT4> domain and carry out either machine authentication, user authentication or> both against this NT4 domain? ...
    (microsoft.public.internet.radius)
  • Re: SQL 2000 on NT4 under Active Directory
    ... We just went through this and experienced no issues with the SQL/NT ... We're using Mixed mode authentication and make ... > Our NT4 domain structure is going to be migrated to ... > that the sql server instances will continue to run on NT4 ...
    (microsoft.public.sqlserver.security)
  • Re: Forms authentication using domain account
    ... Use LogonUser API to validate against NT/2000 Server. ... Use ADSI to manage ... > Is there a way to use forms authentication to verify a UN/PW to a windows ... > NT4 domain? ...
    (microsoft.public.dotnet.framework.aspnet.security)