Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Wireless Networking > New user authentication over wireless

Reply
Thread Tools

New user authentication over wireless

 
 
msteinhoff
Guest
Posts: n/a
 
      02-18-2009
I am having an issue when a new user attempts to logon to a laptop for the
first time using the wireless network. Here are some specifics:

Laptop OS: Windows XP SP2
Server: Server 2000 SP 4 IAS/RADIUS for authentication
Windows Wireless Settings:
Network Auth: WPA
Data Encry: AES
EAP Type: PEAP
Properties:
Check next to Validate server certificate
no other checks
Select auth method:
Secured Password (EAP-MSCHAP v2)
Configure:
check next to Automatically use my
Windows
logon name and password
no check next to Auth as computer when comp info is available
no check nex to auth as guest when user or computer info is unavailable


Problem details:

Running a sniff on the traffic to the auth server showed that Windows is
sending the computer\login information for the person who previously logged
into that device and successfully authenticated to the domain. The following
is an example:

local admin logs onto laptop changes wireless settings to match above and
logs off
new user attempts to connect ot the wireless
sniff shows the laptop sending the local admins infromation to the RADIUS,
not the user trying to login. login attempt fails

If I connect the laptop to the wired network and have the new user login to
that device, then they attempt to connect to the wireless everthing works as
it should.

These are training laptops and can potentially have a different user loggin
into AD everyday, how do I resolve this?

 
Reply With Quote
 
 
 
 
Phillip Windell
Guest
Posts: n/a
 
      02-18-2009
You cannot use the "utility" that came with the wireless Nic to manage its
activity. You need to have the Wireless Zewro Configuration Utility manage
the Nic.

The reason for this is that the thrid party Tool will not active and have
the Nic connect properly until the currently logged on user is at their
Desktop,...which requires a "cached account",...which doesn't exist because
the user has never logged into that machine before.

However the WZC Utility runs as a Service and will activate the Nic before
the user attempts to log in,...therefore the machine is already actively "on
the network" before the user actually logs in (just like a wired
nic),...therefore the Domain controller is avaialable to authenticate the
user and allow the cached account to be created.

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------


"msteinhoff" <> wrote in message
news:8D5AA542-C6C2-4D24-B475-...
>I am having an issue when a new user attempts to logon to a laptop for the
> first time using the wireless network. Here are some specifics:
>
> Laptop OS: Windows XP SP2
> Server: Server 2000 SP 4 IAS/RADIUS for authentication
> Windows Wireless Settings:
> Network Auth: WPA
> Data Encry: AES
> EAP Type: PEAP
> Properties:
> Check next to Validate server certificate
> no other checks
> Select auth method:
> Secured Password (EAP-MSCHAP v2)
> Configure:
> check next to Automatically use
> my
> Windows
> logon name and password
> no check next to Auth as computer when comp info is available
> no check nex to auth as guest when user or computer info is unavailable
>
>
> Problem details:
>
> Running a sniff on the traffic to the auth server showed that Windows is
> sending the computer\login information for the person who previously
> logged
> into that device and successfully authenticated to the domain. The
> following
> is an example:
>
> local admin logs onto laptop changes wireless settings to match above and
> logs off
> new user attempts to connect ot the wireless
> sniff shows the laptop sending the local admins infromation to the RADIUS,
> not the user trying to login. login attempt fails
>
> If I connect the laptop to the wired network and have the new user login
> to
> that device, then they attempt to connect to the wireless everthing works
> as
> it should.
>
> These are training laptops and can potentially have a different user
> loggin
> into AD everyday, how do I resolve this?
>



 
Reply With Quote
 
 
 
 
Phillip Windell
Guest
Posts: n/a
 
      02-18-2009
"msteinhoff" <> wrote in message
news:8D5AA542-C6C2-4D24-B475-...
> Windows Wireless Settings:
> Network Auth: WPA
> Data Encry: AES
> EAP Type: PEAP
> Properties:
> Check next to Validate server certificate
> no other checks
> Select auth method:
> Secured Password (EAP-MSCHAP v2)
> Configure:
> check next to Automatically use
> my
> Windows logon name and password
> no check next to Auth as computer when comp info is available
> no check nex to auth as guest when user or computer info is unavailable




Mine looks like this if I use only WPA with AES
(normally I use WPA-PSK)
Network Auth: WPA
Data Encry: AES
EAP Type: SmartCard or other Certificate
Properties:
Use Certificate on this computer
Use simple certificate selection
(*nothing else* selected)
*Enabled* check next to Auth as computer when comp info is available
*Disabled* check nex to auth as guest when user or computer info is
unavailable



--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------


 
Reply With Quote
 
Phillip Windell
Guest
Posts: n/a
 
      02-18-2009
"msteinhoff" <> wrote in message
news:8D5AA542-C6C2-4D24-B475-...
>I am having an issue when a new user attempts to logon to a laptop for the
> first time using the wireless network. Here are some specifics:
>
> Laptop OS: Windows XP SP2
> Server: Server 2000 SP 4 IAS/RADIUS for authentication


You don't need a RADIUS Server for what I described. That is needless extra
work, complexity, and overhead.

These are *training laptops* as you said,...keep it simple.

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------


 
Reply With Quote
 
Robert L. \(MS-MVP\)
Guest
Posts: n/a
 
      02-18-2009
I don't see any issues with your configuration except "Network Auth: WPA".
If you use IAS/RADIUS, it should be WPA-ENT. As I posted previously,
"Whenever I have a problem with our WPA-Ent TKIP, I would check the IAS
event log first".

--
Bob Lin, MS-MVP, MCSE & CNE
Networking, Internet, Routing, VPN Troubleshooting on
http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on
http://www.HowToNetworking.com
"msteinhoff" <> wrote in message
news:8D5AA542-C6C2-4D24-B475-...
>I am having an issue when a new user attempts to logon to a laptop for the
> first time using the wireless network. Here are some specifics:
>
> Laptop OS: Windows XP SP2
> Server: Server 2000 SP 4 IAS/RADIUS for authentication
> Windows Wireless Settings:
> Network Auth: WPA
> Data Encry: AES
> EAP Type: PEAP
> Properties:
> Check next to Validate server certificate
> no other checks
> Select auth method:
> Secured Password (EAP-MSCHAP v2)
> Configure:
> check next to Automatically use
> my
> Windows
> logon name and password
> no check next to Auth as computer when comp info is available
> no check nex to auth as guest when user or computer info is unavailable
>
>
> Problem details:
>
> Running a sniff on the traffic to the auth server showed that Windows is
> sending the computer\login information for the person who previously
> logged
> into that device and successfully authenticated to the domain. The
> following
> is an example:
>
> local admin logs onto laptop changes wireless settings to match above and
> logs off
> new user attempts to connect ot the wireless
> sniff shows the laptop sending the local admins infromation to the RADIUS,
> not the user trying to login. login attempt fails
>
> If I connect the laptop to the wired network and have the new user login
> to
> that device, then they attempt to connect to the wireless everthing works
> as
> it should.
>
> These are training laptops and can potentially have a different user
> loggin
> into AD everyday, how do I resolve this?
>


 
Reply With Quote
 
msteinhoff
Guest
Posts: n/a
 
      02-19-2009
We are using WZC, not third party software to manage the wireless NIC.

"Phillip Windell" wrote:

> You cannot use the "utility" that came with the wireless Nic to manage its
> activity. You need to have the Wireless Zewro Configuration Utility manage
> the Nic.
>
> The reason for this is that the thrid party Tool will not active and have
> the Nic connect properly until the currently logged on user is at their
> Desktop,...which requires a "cached account",...which doesn't exist because
> the user has never logged into that machine before.
>
> However the WZC Utility runs as a Service and will activate the Nic before
> the user attempts to log in,...therefore the machine is already actively "on
> the network" before the user actually logs in (just like a wired
> nic),...therefore the Domain controller is avaialable to authenticate the
> user and allow the cached account to be created.
>
> --
> Phillip Windell
> www.wandtv.com
>
> The views expressed, are my own and not those of my employer, or Microsoft,
> or anyone else associated with me, including my cats.
> -----------------------------------------------------
>
>
> "msteinhoff" <> wrote in message
> news:8D5AA542-C6C2-4D24-B475-...
> >I am having an issue when a new user attempts to logon to a laptop for the
> > first time using the wireless network. Here are some specifics:
> >
> > Laptop OS: Windows XP SP2
> > Server: Server 2000 SP 4 IAS/RADIUS for authentication
> > Windows Wireless Settings:
> > Network Auth: WPA
> > Data Encry: AES
> > EAP Type: PEAP
> > Properties:
> > Check next to Validate server certificate
> > no other checks
> > Select auth method:
> > Secured Password (EAP-MSCHAP v2)
> > Configure:
> > check next to Automatically use
> > my
> > Windows
> > logon name and password
> > no check next to Auth as computer when comp info is available
> > no check nex to auth as guest when user or computer info is unavailable
> >
> >
> > Problem details:
> >
> > Running a sniff on the traffic to the auth server showed that Windows is
> > sending the computer\login information for the person who previously
> > logged
> > into that device and successfully authenticated to the domain. The
> > following
> > is an example:
> >
> > local admin logs onto laptop changes wireless settings to match above and
> > logs off
> > new user attempts to connect ot the wireless
> > sniff shows the laptop sending the local admins infromation to the RADIUS,
> > not the user trying to login. login attempt fails
> >
> > If I connect the laptop to the wired network and have the new user login
> > to
> > that device, then they attempt to connect to the wireless everthing works
> > as
> > it should.
> >
> > These are training laptops and can potentially have a different user
> > loggin
> > into AD everyday, how do I resolve this?
> >

>
>
>

 
Reply With Quote
 
msteinhoff
Guest
Posts: n/a
 
      02-19-2009
I agree the configuration looks good. The problem that I have is that a user
who has not connected to the wireless before on that specific laptop cannot
connect. If I run an auth trace on the wireless controller and I see
credentials of the local administrator attempting to auth to the RADIUS
server, not the user that is attempting to login. I'll post that tomorrow.

"Robert L. (MS-MVP)" wrote:

> I don't see any issues with your configuration except "Network Auth: WPA".
> If you use IAS/RADIUS, it should be WPA-ENT. As I posted previously,
> "Whenever I have a problem with our WPA-Ent TKIP, I would check the IAS
> event log first".
>
> --
> Bob Lin, MS-MVP, MCSE & CNE
> Networking, Internet, Routing, VPN Troubleshooting on
> http://www.ChicagoTech.net
> How to Setup Windows, Network, VPN & Remote Access on
> http://www.HowToNetworking.com
> "msteinhoff" <> wrote in message
> news:8D5AA542-C6C2-4D24-B475-...
> >I am having an issue when a new user attempts to logon to a laptop for the
> > first time using the wireless network. Here are some specifics:
> >
> > Laptop OS: Windows XP SP2
> > Server: Server 2000 SP 4 IAS/RADIUS for authentication
> > Windows Wireless Settings:
> > Network Auth: WPA
> > Data Encry: AES
> > EAP Type: PEAP
> > Properties:
> > Check next to Validate server certificate
> > no other checks
> > Select auth method:
> > Secured Password (EAP-MSCHAP v2)
> > Configure:
> > check next to Automatically use
> > my
> > Windows
> > logon name and password
> > no check next to Auth as computer when comp info is available
> > no check nex to auth as guest when user or computer info is unavailable
> >
> >
> > Problem details:
> >
> > Running a sniff on the traffic to the auth server showed that Windows is
> > sending the computer\login information for the person who previously
> > logged
> > into that device and successfully authenticated to the domain. The
> > following
> > is an example:
> >
> > local admin logs onto laptop changes wireless settings to match above and
> > logs off
> > new user attempts to connect ot the wireless
> > sniff shows the laptop sending the local admins infromation to the RADIUS,
> > not the user trying to login. login attempt fails
> >
> > If I connect the laptop to the wired network and have the new user login
> > to
> > that device, then they attempt to connect to the wireless everthing works
> > as
> > it should.
> >
> > These are training laptops and can potentially have a different user
> > loggin
> > into AD everyday, how do I resolve this?
> >

>
>

 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
NetBIOS name resolution working over wired, not over wireless johndog Wireless Networking 0 02-15-2008 01:15 PM
VOIP over VPN over TCP over WAP over 3G Theo Markettos UK VOIP 2 02-14-2008 03:27 PM
802.11 X port-level authentication or user-level authentication zillah Wireless Networking 0 11-09-2006 10:00 AM
User Accounts become corrupt over wireless network. =?Utf-8?B?bXVycGh5NzA4?= Wireless Networking 2 07-10-2006 10:33 PM
User Accounts become corrupt over wireless network. =?Utf-8?B?bXVycGh5NzA4?= Wireless Networking 0 07-10-2006 10:15 AM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57