Click here to get back home

802.1x PEAP DHCP problem

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
802.1x PEAP DHCP problem George Spiro 03-07-2007
Posted by George Spiro on March 7, 2007, 12:32 pm
Please log in for more thread options
I am having trouble to acquire a IP address. My DHCP server is not
addressing my workstation any.

I followed pretty much exactly documentation of this microsoft whitepaper.

http://download.microsoft.com/download/f/d/d/fdd4d246-eabe-4a3e-a935-358532b5c168/StepSecureWirelessAcc.doc#_Toc100984847

The only difference is that I setup the DC / IAS / IIS / CA all on the same
server. My access point is a Proxim AP-700.

What happens when I try to connect to the access point it connects but says:
"Acquiring network address" for like 15-30 seconds.

After that timeout I get the message: "Limited or no connectivity" and I get
a invalid IP address of 169.X.X.X

On my access point I do see the logs that everything looks fine and I get
the following 2 lines in my IAS logs:

192.168.55.225,DOMAIN\george,03/07/2007,12:11:54,IAS,DC,4128,Proxim
AP,4,192.168.55.225,30,00-20-a6-55-fc-dc:AP,31,00-13-02-0b-f9-b1,32,AP,12,1400,5,2,61,19,4108,192.168.55.225,4116,0,4155,1,4154,Use
Windows authentication for all users,4129,DOMAIN\george,4149,Proxim access
to internet,25,311 1 192.168.55.100 02/24/2007 21:55:38
168,4130,DOMAIN.ORG/Users/George Spiro,4132,Secured password (EAP-MSCHAP
v2),4127,11,4136,1,4142,0

192.168.55.225,DOMAIN\george,03/07/2007,12:11:54,IAS,DC,4128,Proxim
AP,25,311 1 192.168.55.100 02/24/2007 21:55:38 168,4132,Secured password
(EAP-MSCHAP v2),4127,11,8100,0,4108,192.168.55.225,4116,0,4155,1,4154,Use
Windows authentication for all users,4129,DOMAIN\george,4149,Proxim access
to internet,6,2,4130,DOMAIN.ORG/Users/George
Spiro,4120,0x014C3333544230,4136,2,4142,0

I didnt setup the part EAP-TLS Authentication yet.

Any help would be great thank you and will answer any questions,

G.






Posted by pestocat on March 7, 2007, 11:37 pm
Please log in for more thread options
George,
Do you have the certificate on the RADIUS server. You need a certificate for
PEAP. What RADIUS server are you using? You could try using LEAP just to try
the process for authenication.



>I am having trouble to acquire a IP address. My DHCP server is not
>addressing my workstation any.
>
> I followed pretty much exactly documentation of this microsoft whitepaper.
>
>
http://download.microsoft.com/download/f/d/d/fdd4d246-eabe-4a3e-a935-358532b5c168/StepSecureWirelessAcc.doc#_Toc100984847
>
> The only difference is that I setup the DC / IAS / IIS / CA all on the
> same server. My access point is a Proxim AP-700.
>
> What happens when I try to connect to the access point it connects but
> says: "Acquiring network address" for like 15-30 seconds.
>
> After that timeout I get the message: "Limited or no connectivity" and I
> get a invalid IP address of 169.X.X.X
>
> On my access point I do see the logs that everything looks fine and I get
> the following 2 lines in my IAS logs:
>
> 192.168.55.225,DOMAIN\george,03/07/2007,12:11:54,IAS,DC,4128,Proxim
>
AP,4,192.168.55.225,30,00-20-a6-55-fc-dc:AP,31,00-13-02-0b-f9-b1,32,AP,12,1400,5,2,61,19,4108,192.168.55.225,4116,0,4155,1,4154,Use
> Windows authentication for all users,4129,DOMAIN\george,4149,Proxim access
> to internet,25,311 1 192.168.55.100 02/24/2007 21:55:38
> 168,4130,DOMAIN.ORG/Users/George Spiro,4132,Secured password (EAP-MSCHAP
> v2),4127,11,4136,1,4142,0
>
> 192.168.55.225,DOMAIN\george,03/07/2007,12:11:54,IAS,DC,4128,Proxim
> AP,25,311 1 192.168.55.100 02/24/2007 21:55:38 168,4132,Secured password
> (EAP-MSCHAP v2),4127,11,8100,0,4108,192.168.55.225,4116,0,4155,1,4154,Use
> Windows authentication for all users,4129,DOMAIN\george,4149,Proxim access
> to internet,6,2,4130,DOMAIN.ORG/Users/George
> Spiro,4120,0x014C3333544230,4136,2,4142,0
>
> I didnt setup the part EAP-TLS Authentication yet.
>
> Any help would be great thank you and will answer any questions,
>
> G.
>
>
>
>
>



Posted by George Spiro on March 8, 2007, 9:13 am
Please log in for more thread options
I have installed a certificate on the radius server. I am using IAS. Like I
mentioned I followed the whitepaper word for word.


> George,
> Do you have the certificate on the RADIUS server. You need a certificate
> for PEAP. What RADIUS server are you using? You could try using LEAP just
> to try the process for authenication.
>
>
>
>>I am having trouble to acquire a IP address. My DHCP server is not
>>addressing my workstation any.
>>
>> I followed pretty much exactly documentation of this microsoft
>> whitepaper.
>>
>>
http://download.microsoft.com/download/f/d/d/fdd4d246-eabe-4a3e-a935-358532b5c168/StepSecureWirelessAcc.doc#_Toc100984847
>>
>> The only difference is that I setup the DC / IAS / IIS / CA all on the
>> same server. My access point is a Proxim AP-700.
>>
>> What happens when I try to connect to the access point it connects but
>> says: "Acquiring network address" for like 15-30 seconds.
>>
>> After that timeout I get the message: "Limited or no connectivity" and I
>> get a invalid IP address of 169.X.X.X
>>
>> On my access point I do see the logs that everything looks fine and I get
>> the following 2 lines in my IAS logs:
>>
>> 192.168.55.225,DOMAIN\george,03/07/2007,12:11:54,IAS,DC,4128,Proxim
>>
AP,4,192.168.55.225,30,00-20-a6-55-fc-dc:AP,31,00-13-02-0b-f9-b1,32,AP,12,1400,5,2,61,19,4108,192.168.55.225,4116,0,4155,1,4154,Use
>> Windows authentication for all users,4129,DOMAIN\george,4149,Proxim
>> access to internet,25,311 1 192.168.55.100 02/24/2007 21:55:38
>> 168,4130,DOMAIN.ORG/Users/George Spiro,4132,Secured password (EAP-MSCHAP
>> v2),4127,11,4136,1,4142,0
>>
>> 192.168.55.225,DOMAIN\george,03/07/2007,12:11:54,IAS,DC,4128,Proxim
>> AP,25,311 1 192.168.55.100 02/24/2007 21:55:38 168,4132,Secured password
>> (EAP-MSCHAP v2),4127,11,8100,0,4108,192.168.55.225,4116,0,4155,1,4154,Use
>> Windows authentication for all users,4129,DOMAIN\george,4149,Proxim
>> access to internet,6,2,4130,DOMAIN.ORG/Users/George
>> Spiro,4120,0x014C3333544230,4136,2,4142,0
>>
>> I didnt setup the part EAP-TLS Authentication yet.
>>
>> Any help would be great thank you and will answer any questions,
>>
>> G.
>>
>>
>>
>>
>>
>
>



Similar ThreadsPosted
DHCP Authorisation - does it stop rouge DHCP servers? November 28, 2007, 6:46 am
DHCP QUEstion . June 6, 2006, 5:39 am
Re: DHCP Restrictions June 15, 2007, 12:51 am
Re: DHCP Restrictions September 5, 2007, 3:08 am
MS06-011 - DHCP Issue March 23, 2006, 6:07 pm
Re: Certificate-based DHCP authentication November 24, 2005, 4:03 pm
DHCP Management and Windows Firewall January 3, 2006, 3:39 pm
PEAP-TLS vs EAP-TLS June 6, 2006, 11:25 am
How to config windows firewall allow dhcp services? February 21, 2006, 4:57 pm
Could not install the Dynamic Host Configuration Protocol (DHCP)... August 1, 2005, 9:38 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap