Aironet - PI21AG PCI Adaptor - No Computer Auth before user login

Hi
I am running PEAP-MSCHAPv2 , all Clients are Windows Xp SP2 on an AD domain and all clients have wireless configuration assigned via Group Policy.
All machines except for 10 machines running the PI21AG PCI WLAN adaptors are able to authenticate using their computer account to the WLAN , allow login scripts , policy assignment etc to function prior to the use logging into windows. If you log in with a cached domain account , the machine will associate to the WLAN using the user account after login however scripts do not run and users who have not logged in before are unable as the PC has no network connection at the time of user login.
Affected machines have been rebuilt , settings applied manually, different driver versions have been applied, "Always wait for network" has been enabled in Group policy and registry keys have been mdified to extend timeout before policy assingment. Nothing so far has worked.
I am running the latest driver, all clients are using the XP Wireless supplicant and have common configuration. All machine including notebooks using the CB21AG PCMCIA adaptors can successfully authenticate using machine authwntication prior to user login.
I have noticed from looking at my WLC's that during boot and prior to user login that the affected machines probe for association , howver they never enter an authenticated state.
No authentication attempts passed or failed are seen in the RADIUS logs.
Any help or suggestions would be greatfully apprciated.
May Thanks
Leon

Thanks for the reply.
As stated I had PEAP conifgired correctly and many clients achieved the functionality that I was after.
The issue was specific to the Cisco PCI WLAN Adaptors , and after many hours on the phone to the TAC it looks like a change in driver version and a re-image of the customers SOE resolved the issue in the end.

Similar Messages

  • Dot1x machine auth before user auth required

    We are looking at setting up dot1x in our libraries however I have been asked to see if there is a way to force a switch port to require machine auth before user auth.  The reason for this is a problem we have that users will disconnect the ethernet cable from the library computer and plug it into theirs.  If they have an AD account, they could in theory authenticate on this port. We want to discourage them from disconnecting these ports as we then don't know the computer has been unplugged and then it is no longer on the network and doesn't get updates/ghosted.
    Also, would it maybe be better to just allow a specific group of user accounts to connect to these jacks, and if so what would be the best way?  Location settings on the port?
    We are using ISE 1.2 to do authentication for these switches.

    Hi Zach-
    There are several different ways to prevent non-domain computers from gaining access to the network. I will try to list a few of them starting with the easiest and least expensive/labor intensive methods:
    1. Do only Machine-based authentication. This eliminates the user from having to enter credentials and ISE will simply query AD for valid computer domain membership.
    2. Use EAP-Chaining. This is the only method that truly gives you user+machine authenticaiton. However, it does require that you push the Cisco Any-Connect client to all endpoints
    3. Deploy PKI and use EAP-TLS authentication with Digital Certificates. With this method only domain computers/users can get a certificate and ISE can still query AD for user or machine AD membership
    4. Perform Posture and check for something that is domain specific. For instance, a fake registry key or file that is being created when a machine joins to the domain. With this method ISE can still ask for User authentication but also require posture check. You can then set the policy that if posture fails but user auth succeeds then the user will only get guest access.
    I hope this helps.
    Thank you for rating!

  • HP ENVY x2 - 15 Detachable laptop - Stuck one step before user login

    Hi, I have had some automatic window updates in progress but it was stuck on 36% for 2 days and when I did force restart, it just shows screen before user login ( Battery and wifi icons on bottom corner), touch does not work, bleautooth keyboard never connects even I attach to laptop.... so it goes nowhere! I bought it couple of months back and have never had this kind of issue on any other windows machine I had in past. Note : I had enrolled for windows 10 sometime back, not sure anything related Can anyone help? Thanks   

     Request service under warranty. If you live in the US/CA, contact HP info Here. If you live in another part of the world, start here>>Contact HP 

  • Run NAC agent before user login - Win7?

    Greetings all and thx in advance for any advice! Environment details - ISE 1.2. Patch 5 and cisco NAC agent 4.9.3.
    I have all of the authen/authz policies working and functioning properly, however, I have run into an issue with the NAC agent running posture only after user login.  This is causing some grief, mainly that users required login scripts can't run successfully until posture is compliant and the more permissive dACL is applied.  I was hoping that posture would complete long before windows login was even an option for the user but for some reason I appear to require an interactive login to get the NAC agent to run posturing.  Any thoughts or ideas on this?  I tried the NAC agent installation with a couple of different user accounts on the windows hosts but without success, it will only posture once I have interactive login.  I went pretty deep on the removal of the posture conditions to simply checking a single windows service but it didn't make any difference.  Thanks for any advice!!
    IA

    Thanks for the reply Saurav, I should have clarified a design point.  I am not doing any user authentication, only doing a machine authen.  As I mentioned I can't seem to posture pre-user authentication even though I am not doing any user authentication.
    IA

  • When I restart my computer instead of the gray screen that is supposed to appear before the login screen it shows a screen with a lot of letter

    I upgrade my ssd for my macbook pro retina from the 256 to 480 GB but when I tunr it on or restarted the computer the gray screen that is suppost to apper dosent show insted a screen with lettler show before the login screen besides that the computer works fine. 

    I cannot decipher what is written on the images you have posted but they are reminiscent of what I have seen when a MBP is dealing with some totally incompatible software or perhaps in your case hardware.
    How and or who installed the larger SSD and what manufacture is it.  I suspect that is the problem.
    Ciao.

  • Configuring wireless card Cisco Aironet 350 PCI

    I'm not a newbie in linux but now faced with a trouble. I could not manage to set up the card properly. I just installed Arch 0.8 and it's not quite clear to me how to do this with Arch. I've read all available Arch's docs on this topic.
    So my situation's the following:
    I have the wireless card Cisco Aironet 350 PCI and I've been using it with Slackware for a year. It works quite fine. But now, when I decided to move to Arch - I cannot set it up. My card's using `airo` module and it is loading well. All the present network devices are recognized. I can see this by ifconfig -a.
    I have 2 NICs in my system:
    1) simple Ethernet card - eth0. Is switched off in rc.conf
    2) wireless. There are 2 different devices for it in my system: eth1 and wifi0 (and it's correct). I don't know why is it so and how about this with other wireless cards.
    For example I placed here network configs from my Slackware which works well with them and expect your advice on how to do the same with Arch.
    /etc/rc.d/rc.inet1.conf:
    ##IPADDR[0]="" #wired NIC is off
    ##NETMASK[0]=""
    ##USE_DHCP[0]="yes"
    ##DHCP_HOSTNAME[0]=""
    # Config information for eth1:
    IPADDR[1]="xx.xx.225.8"
    NETMASK[1]="255.255.255.0"
    USE_DHCP[1]=""
    DHCP_HOSTNAME[1]=""
    # Default gateway IP address:
    GATEWAY="xx.xx.225.254"
    /etc/rc.d/rc.wireless.conf:
    # Cisco/Aironet 4800/3x0
    # Note : MPL driver only (airo/airo_cs), version 1.3 or later
    00:0F:F8:*)
    INFO="Cisco/Aironet"
    ESSID="MoyEssid"
    MODE="Managed"
    KEY="xxxx-xxxx-xx open"
    Here  is the ifconfig and iwconfig output in Slackware:
    ifconfig:
    eth1 Link encap:Ethernet HWaddr 00:0F:F8:4D:EF:2A
    inet addr:xx.xx.225.8 Bcast:xx.xx.225.255 Mask:255.255.255.0
    UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
    RX packets:9384 errors:128278 dropped:0 overruns:0 frame:128278
    TX packets:1714 errors:0 dropped:0 overruns:0 carrier:0
    collisions:785 txqueuelen:1000
    RX bytes:3023621 (2.8 MiB) TX bytes:224182 (218.9 KiB)
    Interrupt:10 Base address:0xb800
    lo Link encap:Local Loopback
    inet addr:127.0.0.1 Mask:255.0.0.0
    inet6 addr: ::1/128 Scope:Host
    UP LOOPBACK RUNNING MTU:16436 Metric:1
    RX packets:0 errors:0 dropped:0 overruns:0 frame:0
    TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
    collisions:0 txqueuelen:0
    RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)
    wifi0 Link encap:UNSPEC HWaddr 00-0F-F8-4D-EF-2A-00-00-00-00-00-00-00-00-00-00
    UP BROADCAST RUNNING MULTICAST MTU:2312 Metric:1
    RX packets:9384 errors:128278 dropped:0 overruns:0 frame:128278
    TX packets:1714 errors:0 dropped:0 overruns:0 carrier:0
    collisions:785 txqueuelen:100
    RX bytes:3023621 (2.8 MiB) TX bytes:224182 (218.9 KiB)
    Interrupt:10 Base address:0xb800
    iwconfig:
    eth1 IEEE 802.11-DS ESSID:"MoyEssid" Nickname:"user"
    Mode:Managed Frequency:2.427 GHz Access Point: xx:xx:xx:5C:E5:00
    Bit Rate:11 Mb/s Tx-Power=20 dBm Sensitivity=0/65535
    Retry limit:16 RTS thr:off Fragment thr:off
    Encryption key:****-****-** Security mode:open
    Power Management:off
    Link Quality=63/100 Signal level=-64 dBm Noise level=-96 dBm
    Rx invalid nwid:11287 Rx invalid crypt:0 Rx invalid frag:0
    Tx excessive retries:0 Invalid misc:10331 Missed beacon:0
    wifi0 IEEE 802.11-DS ESSID:"MoyEssid" Nickname:"user"
    Mode:Managed Frequency:2.427 GHz Access Point: xx:xx:xx:5C:E5:00
    Bit Rate:11 Mb/s Tx-Power=20 dBm Sensitivity=0/65535
    Retry limit:16 RTS thr:off Fragment thr:off
    Encryption key:****-****-** Security mode:open
    Power Management:off
    Link Quality=63/100 Signal level=-64 dBm Noise level=-96 dBm
    Rx invalid nwid:11287 Rx invalid crypt:0 Rx invalid frag:0
    Tx excessive retries:0 Invalid misc:10331 Missed beacon:0
    Who is aware - please describe or give me a link on this, how the two devises eth1 and wifi0 are connected to each other and how to set them up in Arch.
    Thnx.

    Excellent! It works! Thank U very much.
    My conclusion - /etc/network-profiles/ is much more suitable way/place to set your wireless network parameters even it's quite steady.
    And now I have a couple of extra questions:
    1) What should I do with actual network parameters in rc.conf? Currently they looks like:
    lo="lo 127.0.0.1"
    #eth0="eth0 192.168.0.2 netmask 255.255.255.0 broadcast 192.168.0.255"
    INTERFACES=(lo !eth0)
    gateway="default gw 192.168.0.1"
    ROUTES=(!gateway)
    NET_PROFILES=(tier)
    and that looks and works OK. What about gateway? Should I comment it here or not?
    2)Though everything works fine now, I can see that wifi0 device is not listed by ifconfig now (only by iwconfig), but in my Slackware system it is. Don't have I to mention my wifi0 device in network profile's section:
    #WIFI_INTERFACE=wlan0   # use this if you have a special wireless interface
                            # that is linked to the real $INTERFACE
    Thnx!
    And sorry for ugly English

  • Windows 98 and Aironet 350 PCI Card

    I have a complicated question and would really appreciate any input anyone has. I have a network with 12 PC's that are running Windows 98 with Novell Netware. They all have Aironet 350 PCI cards in them. We recently decided to change an older PC out and took out it's Aironet card to install in the new PC which is a Dimension 4400. I install the card and the utilities and drivers and I can get the PC associated to the AP. I then install the Novell client and I can't get authenticated onto the network. I can't even get the Novell login to pop up. I can't even get out onto the internet which I can usually do even if I am not on the network. Neither my network admin nor I were here when these were originally deployed so maybe we are missing a step. Any help would be much appreciated. I would be glad to provide any additional info!
    Thanks
    Jamie

    Thanks for the further info John. I would usually say sure and do it. I am only leary because a week ago this card was happily working in another machine. A interesting point to mention is that when I go into the access point all of my machines on the AP having their IP address in a field called IP Addr./Name and the machine I am having an issue with says unassigned. The last time we had this particular issue we had the network on 40 bit WEP encryption and then got a new card for a machine that could only run 128 bit so we changed the encryption and everything has been fine since. Once again thanks for all of your help!
    Jamie

  • Upgraded MacBookPro6,2 to Lion and now computer freezes before login

    Hi everyone,
    As the subjed line says, I upgraded to Lion and everything smoothly (aparently), but after I tried to install Xcode for Lion the pc started getting slower and slower. The 10.7 Core libraries never installed (kept failing) and now the computer freezes before I can login. I tried to reinstall Lion (Pressing ⌘+R after hard powerdown) and following the prompts, but that failed. No reasons why, it just said user cancelled.
    Before I wipe out my hard drive, is there something else I can do? Any help is appreciated.
    Thanks

    I am typing this reply from my MacBook Pro after recovering from the problem above. This post is for anyone else who might have the same problem. These are the steps to follow to be able to log back in:
    Power down the computer and then press ⌘+R while powering up. This is called Lion Recovery, according to this knowledge base article: http://support.apple.com/kb/HT4718
    In the options presented, select Disk Utility and verify the hard drive (HD) and repair the permissions on it. If your HD is not OK after verifying it, you will need to repair the HD as well.
    Once the step above is complete, restart the computer.
    Log in as normal.
    Once you log in, it is important to find and solve whatever is causing the freeze.
    In my case, it was a botched Xcode installation. If you do not fix the problem, the computer will freeze again next time you restart it, so make sure you check everything and uninstall anything that you may have installed recently. Some Adobe applications have known issues as of this posting (July 2011), so definitely remove anything new from Adobe you may have installed after upgrading to Lion or in the last couple of weeks.
    Final note: If you cannot find the problem and your computer freezes again the next time you restart, you can regain access to it by following the steps above. Follow them, log in and make a backup of your important stuff and either go back to Leopard or contact Apple support for further instructions.
    Good luck!

  • How to clear just the computer name before getting image of the hard disk?

    Hi,
    I have a Win 7 PC with some applications installed on it and I don't have the installation files of the applications. Now I want to create an image of the C drive, and use it on other PCs. So I need to just clear the computer name and shutdown
    the PC and use an imaging software to make an image of the C drive, so when I deploy the image on a new computer, on the first startup screen it'll ask for JUST computer name.
    I tried to use sysprep but it look like clearing more data  than I want (just PC name). Also the AIK solution look like I have to have the installation files of all the softwares that I want to have on my computer.
    In one sentence: How to clear the computer name before getting image using a disk image tool (Acronis, Ghost,...)?

    Hi,
    Sysprep will do this job. But when the system boot up, it will generate new computer name.
    In general, you need boot to win pe after you run systprep. I think you can create a USB bootable device.
    In win pe, you can use ImageX or DISM tool to capture the image.
    I'm not fimilar with the tools you referred since they are not from Microsoft, so I cannot give any direction about it.
    For your information:
    http://technet.microsoft.com/en-us/library/cc749003(v=ws.10).aspx

  • Computer Crashed before I could make backup.

    My computer crashed before I could make a backup of my library. Can I some how recover on a different computer without a backup?
    Message was edited by: truthhunter87
    Message was edited by: truthhunter87

    Do you at least have your music, videos, photos etc on an ipod?

  • My computer crashed before I could unsync my iPod!

    Alright, so, my computer crashed before I could unsync my iPod from the iTunes installed on it and before I could save my music to CD. It's now dead and long gone-- a hopeless cause.
    IS THERE ANY WAY TO MOVE THE MUSIC FROM MY IPOD TO MY NEW LAPTOP?
    And to transfer the new things on my laptop to my iPod?
    Someone PLEASE help.

    Connect your iPod to your computer. If it is set to update automatically you'll get a message that it is linked to a different library and asking if you want to link to this one and replace all your songs etc, press "Cancel". Pressing "Erase and Sync" will irretrievably remove all the songs from your iPod. Your iPod should appear in the iTunes source list from where you can change the update setting to manual and use your iPod without the risk of accidentally erasing it. Also when using most of the utilities listed below your iPod needs to be enabled for disc use, changing to manual update will do this by default. Check the "manually manage music and videos" box in Summary then press the Apply button: Managing content manually on iPod
    You can also use a keyboard command to prevent your iPod auto-syncing with iTunes. While connecting the iPod to the computer on Windows with iTunes 7.3 installed hold down the Shift + Ctrl keys. This will stop the iPod from auto-syncing with iTunes and the iPod will appear in the source list. Wait until you are sure the iPod has mounted, and that it will not auto sync and then you can let the keys go. This may take between 20 to 30 seconds depending on your computer: iTunes 7.3 Keyboard Shortcuts for Windows
    Once you are safely connected there are a few things you can do to restore your iTunes from the iPod. If you have any iTunes Music Store purchases the transfer of purchased content from the iPod to authorised computers was introduced with iTunes 7. You'll find details in this article: Transfer iTunes Store purchases using iPod
    The transfer of content from other sources such as songs imported from CD is designed by default to be one way from iTunes to iPod. However there are a number of third party utilities that you can use to retrieve the music files and playlists from your iPod. You'll find that they have varying degrees of functionality and some will transfer movies, videos, photos, podcasts and games as well. Have a look at the web pages and documentation, this is just a small selection of what's available, they are generally quite straightforward. You can also read reviews of some of them here: Wired News - Rescue Your Stranded Tunes
    TuneJack Windows Only
    iPod2PC Windows Only
    iGadget Windows Only
    iDump Windows Only
    iRepo Mac and Windows
    iPodRip Mac & Windows
    YamiPod Mac and Windows
    Music Rescue Mac & Windows
    iPodCopy Mac and Windows
    There is also a manual method of accessing the iPod's hard drive and copying songs back to iTunes on Windows or a Mac. The procedure is a bit involved and won't recover playlists but if you're interested it's available at this link: Two-way Street: Moving Music Off the iPod
    Whichever of these retrieval methods you choose, keep your iPod in manual mode until you have reloaded your iTunes and you are happy with your playlists etc then it will be safe to return it auto-sync. I would also advise that you get yourself an external hard drive and back your stuff up, relying on an iPod as your sole backup is not a good idea and external drives are comparatively inexpensive these days, you can get loads of storage for a reasonable outlay.

  • HT1657 I rented a few movies and downloaded them to my computer.  Before they had been viewed, I updated my iTunes software and the movies were no longer in my library.  How can I access the movies as I have already paid for them?

    I rented a few movies and downloaded them to my computer.  Before they had been viewed, I updated my iTunes software and the movies were no longer in my library.  How can I access the movies as I have already paid for them?

    Try here >  iTunes Store: Transferring purchases from your iOS device or iPod to a computer
    iCloud doesn't support movies...
    iCloud backs up your:
    Purchased music, TV shows, apps, and books
    Photos and video in the Camera Roll
    Device settings
    App data
    Home screen and app organization
    Messages (iMessage, SMS, and MMS)
    Ringtones
    From here >  Apple - iCloud - Store and back up your content in iCloud.

  • My computer crashed before i was able to deactivate my Visual Communicator 3 software.  Please help!  I have my disc, but cannot activate my software again.  I have several projects that I cannot access. Please help!

    My computer crashed before I was able to deactivate my Visual Communicator 3 software.  Please help!  I have my disc, but cannot activate my program again.  I have projects that I cannot access. Please help!

    I wish I could help, but I am in a similar situation.
    I need to deactivate it because we are getting rid of the computer it is on and are buying a new one. When I go to Help there is no Deactivate option. The only options are: "Help", "Hide Coach", "Tip of the Day", "Adobe Website", "Technical Support Website", "Frequently Asked Questions", "Check for Updates", "Register", "Download e-License..." (Greyed out), "Return e-License..." (Greyed out) and "About Adobe Visual Communicator 3". I spoke with support through chat and they said my product was no longer supported.
    Patrick

  • Computer crashed before I got a chance to transfer purchases to Ipod!

    My computer crashed before i got a chance to transfer my whole ipod library. So long story short i paid for an audiobook and I never got the chance to transfer onto my ipod, now I have paid for it but I have never had the chance to listen to it.

    If you are now using iTunes on a different computer, or simply just had to replace your hard drive, once you sign in to iTunes, go to your account / purchase history.
    Next to the item you downloaded (although you never got to listen it it) you will see the "order number" for the audiobook you downloaded.
    Include that order number AND title of the audiobook in your problem report. Explain in as much detail as you can remember that your computer crashed sometime after your purchase.
    It is very possible that whatever tech receives your problem report can reset this download for your account.
    Once you get it again, make sure you backup your collection. I have all my stuff saved on an external hard drive.
    Best of luck to you!

  • My computer won't start it's loads the logo but than shuts off before the login part

    My computer won't start it's loads the logo but than shuts off before the login part

    Hello Tara-louise,
    I would be concerned too if my MacBook Pro was booting just to the gray screen with the Apple logo on it.  I recommend following the steps in the article below for the issue you are experiencing:
    Mac OS X: Gray screen appears during startup
    http://support.apple.com/kb/TS2570
    Thank you for using Apple Support Communities.
    Best,
    Sheila M.

Maybe you are looking for

  • How to get server hostname and port from web form

    Hi All, I need to find out server hostname and port number from 9i form. That is if the form was called via: http://myserver.com:1234/f90servlet?form=test, i would like to call some GET_XXX_PROPERTY(SERVER_HOSTNAME) that would return myserver.com and

  • How to Skip Print dialog window in smartforms

    Hi Experts, while printing the smartforms i dont want Print dialog window. I want as and when i pressed the print button it'll directly print with the specified printer. I tried with lot of option but it is not working for me . May be i missed some p

  • Need help reinstalling elements 10 to mac osx 10.5.8

    I have a mac osx 10.5.8 I had elements 10 on it never used it. going to class for it, now trying to use it and it is frozen and says there is an error in program. I uninstalled it and tried to reinstall it and it is unrecognizable. help. ??????

  • Shockwave Distribution: Exe-Installer deprecated

    I can't download the recent version of Adobe Shockwave Player from the distribution site ( http://www.adobe.com/products/shockwaveplayer/shwv_distribution3.html ) when I try the exe installer (slim exe or full exe). Both seem to install version 11.6.

  • BAPI_INB_DELIVERY_CHANGE

    Hey experts, i want to use function module BAPI_INB_DELIVERY_CHANGE. But i can't find a docu, how to use it. I want to update some standard fields in table LIPS. What have i to do? What strructure do have to extend or is there no need?    thx,      M