"RogerC" <> wrote in
news::
> Hi James,
> Thanks for your response.
> Yes, I am using PEAP-MS-CHAP v2 and I have "Enable Fast Reconnect."
> enabled on both servers and laptops.
> But.. I don't have "Validate server certificate." enabled on the
> laptops - where does this come into the roaming issue if my users
> authenticate correctly without it being enabled?
>
> I have 2 windows 2003 servers that are DC's with IAS configured. The
> 4 Access points are setup to use both of them
> as their primary and secondary RADIUS servers. The access points are
> set with the same SSID but all different channels.
> Is this the correct setup?
>
> RogerC
>
>snip<
PEAP-MS-CHAP v2 provides mutual authentication which cannot correctly occur
if clients are not configured to validate the server certificate; in
addition, and more importantly, clients are exposed to some security
vulnerabilities if they do not validate the server certificate, such as
unknowing connection to a rogue network deployed by an attacker attempting
to capture user name and password during the authentication attempt.
It sounds like you have the APs configured correctly. Here are a couple of
whitepapers you can take a look at to verify and/or troubleshoot your
configuration:
Troubleshooting Windows XP IEEE 802.11 Wireless Access
http://www.microsoft.com/technet/pro...n/wifitrbl.msp
x
"Enterprise Deployment of Secure 802.11 Networks Using Microsoft Windows"
at
http://www.microsoft.com/windowsserv...s/default.mspx
--
James McIllece, Microsoft
Please do not send email directly to this alias. This is my online account
name for newsgroup participation only.
This posting is provided "AS IS" with no warranties, and confers no rights.