IBNS with two groups of XP Machines, one PEAP-MSCHAPv2 & one EAP-TLS

Hello,
I'm planning to implement a IBNS network. We have two groups of XP Machines. One group has machine certs and we're planning to check their certs using EAP-TLS. The second group of machines is managed by other departments, each having their own Active Directory, and configured with PEAP-MSCHAPv2. I'm not very familiar with this kind of setup, so hints are highly appreciated.
1. Can I assume that, when properly configured, we can differentiate the authorizations per group (for exemple, at least two VLANs one for group 1 and another one for group 2 - I must at least seggregate the users per group and can't mix them in the same environment, since they belong two different departments).
2. For the first group, no big issue. I can check against my central AD. For the users of the second group, since they can come from different departments, each having its own AD, can I differentiate them, by any means, to know which AD I'll have to query? Or do I have to query only one single AD? Is it required that all the users of group 2 belong to the same domain?
Thanks in advance for your help.

Hello,
I'm planning to implement a IBNS network. We have two groups of XP Machines. One group has machine certs and we're planning to check their certs using EAP-TLS. The second group of machines is managed by other departments, each having their own Active Directory, and configured with PEAP-MSCHAPv2. I'm not very familiar with this kind of setup, so hints are highly appreciated.
1. Can I assume that, when properly configured, we can differentiate the authorizations per group (for exemple, at least two VLANs one for group 1 and another one for group 2 - I must at least seggregate the users per group and can't mix them in the same environment, since they belong two different departments).
2. For the first group, no big issue. I can check against my central AD. For the users of the second group, since they can come from different departments, each having its own AD, can I differentiate them, by any means, to know which AD I'll have to query? Or do I have to query only one single AD? Is it required that all the users of group 2 belong to the same domain?
Thanks in advance for your help.

Similar Messages

  • I have a Mac Pro tower with two internal Hard Discs, each one 2TB. I purchased a 3TB Time Capsule. But it does not allow me to back up because it says there is not enough back up space available. Between the two HDs there are 3.3TBs. Can I daisy chain TC?

    I have a Mac Pro tower (OSX version 10.6.3) with two internal Hard Drives, each one 2TB.
    I purchased a 3TB Time Capsule. But cannot back up because it tells me there is not enough space.
    I have more than 3Tbs to store to the new TC.
    Can I daisy chain two TCs to store the 4TBs?
    How can I back up only the internal HD that is already full, without backing up the other one?
    How can I do back up using Time Machine to back up the 3.5Tbs?
    Do I need to purchase another external HD (that is not TC) to be able to back up all of my photos?

    Can I daisy chain two TCs to store the 4TBs?
    No, you cannot link to produce a single large partition.
    But you can have two separate backup jobs.. and use each partition. That is hard on TM but you can easily get a different backup software for it.
    How can I back up only the internal HD that is already full, without backing up the other one?
    In TM you do a different setup and exclude the other drive.
    But it is better to use an alternative software IMHO.
    How can I do back up using Time Machine to back up the 3.5Tbs?
    You would need to use a network drive of more than 4TB .. it would also take forever. This is just wrong way to do it. Although you can buy a NAS that will work with Time Machine and load it with disks 16TB is possible.. if you can get a second mortgage.. the fragile nature of TM on 3rd party devices.. would leave me in cold sweat if anything went wrong.
    TM is excellent at keeping incremental backups of files that keep changing.. as such you should use TM to backup your OS disk and main user directory.. exclude all files and directories that never change. Back them up separately.
    Do I need to purchase another external HD (that is not TC) to be able to back up all of my photos?
    Yes, that is a much better idea. You want to store photos safely and you want to store them in multiple places. If you have multiple TB of photos, dedicate a couple of disks to the backup. ie have at least two copies.. not in backup format.. in straight copy format if possible.. so you can keep one of the disks offsite.
    I would be using your MacPro internal disk access, to place the disk onto sata bus and do the copy disk to disk direct. Or even buy esata card.. or sata to esata converter cable so you can use esata box. That will beat any other transfer speed except thunderbolt for which you would need third mortgage. (The MORT in mortgage is significant).
    The great jurist Sir Edward Coke, who lived from 1552 to 1634, has explained why the term mortgage comes from the Old French words mort, "dead," and gage, "pledge." It seemed to him that it had to do with the doubtfulness of whether or not the mortgagor will pay the debt.

  • I am using Mail 5.3 with two separate gmail addresses. One is personal the other is business. When I send emails from the business address, any auto-replies I get COME TO THE PERSONAL INBOX. I imagine that this is a setting? Please help!

    I am using Mail 5.3 with two separate gmail addresses.
    One is personal the other is business.
    When I send emails from the BUSINESS address, any auto-replies/out of office notices I get come to my PERSONAL INBOX.
    I imagine that this is a setting? Please help!

    Edit the SMTP server list. Add a new one for the business account. Put the correct password and information for it. Give it a description so you will know which server is which. Mke sure the correct server is highlighted in the account selected and check the box to use only that server for that account. Do that for the other account also.

  • I just purchased an ibook for my mac for the first time and it started with two pages then switched to one with notes and i can't change it back. Anyone else having this problem?

    I just purchased an ibook for my mac for the first time and it started with two pages then switched to one with notes and i can't change it back. Anyone else having this problem?

    Up the top where the three buttons are (red yellow green) are three images. Click on the third image that looks like a notepad (not the first which is a library book), and that should get rid of 'Notes'. To read using two pages make the window bigger.

  • How to enter invoice with two different tax codes in one line?

    Dear friends,
    I have this PO for which I enter the invoice.
    I recieve later a subsequent debit for this PO from the transporter. This subsequent invoice has got extra debits, one with 21% VAT and one with 19% VAT, which means two items with two different tax codes.
    I want to enter this subsequent debit for each item of the PO, and I want to enter both debits in every item of the PO.
    How can I enter in one row in MIRO a debit with two different tax codes.
    Thank you.

    I want in the same line item to enter two tax codes.
    Do you Know if there is any way to do this?
    It is a subsequent debit and it has two items with two different tax codes. I want to enter the subsequent debit for a PO with many items and enter the value of the whole subsequent invoice. So there is the need to enter one line item with two tax codes.
    How can this be done?
    Thank you?

  • Report with two Command is empty if one of the two commands returns no data

    Hi all,
    I have a report with two Commands not linked together.
    If ONLY one of the two Commands returns no data, the full report is empty (although the other Command returns data).
    I'm using Crystal Report 2008 and the CRJ 12.2.205
    Have an idea?

    Hi Ted,
    how can I solve the problem, please? It is important.
    If I can help yourself, the problem is appeared in many reports since I updated the library (the old library version 11.8.4.1094 works fine with all). I'm waiting for your answer, please.
    Thank you very much.

  • I have one itunes account with two phones. when i phone one of the numbers both phones have started to ring, only when connected to wifi at home. How do i resolve this please?

    I have one itunes account with two phones assigned to it, sons and daughters, (5s). When i phone one of the numbers both phones have started to ring, only when connected to wifi at home. The problem does not occur when not connected to wifi. How do i resolve this please? texting is fine it is only when ringing one of the numbers.

    <http://support.apple.com/kb/HT6337>
    "To turn off iPhone Cellular Calls on a device, go to Settings > FaceTime and turn off iPhone Cellular Calls."

  • One job with two steps - how to create one single spool?

    Hello experts,
    I have created two queries in SQVI. One is based on the table BSIK, the other on on BSAK.
    The report layout is the same in both queries.
    Now I schedule one job in SM36/SM37 with two steps corresponding to my queries.
    I want my second step to append the spool created in the first step. Is that possible?
    In order to do this I unchecked "New spool request" in the request attributes for the second step of the job.
    I use the same printer, the same format (X_65_80), but it doesnt work.
    The help on the field says
    ".... name, output device, number of prints and the format must match..." - What "name" do they mean?
    "In addition, the existent spool order must not already be competed. This can occur if a spool is released for output...." - I use "send to SAP spooler only" option, is that what thay mean? How cen you have an "uncompleted spool" in the job.
    If anybody knows ho to do this (without development!), please advise
    Best regards,
    Fatima

    Hi,
    Please do following steps :
    1. Go to transaction code SM36
    2. Do as per below screen shots
    You can see Job steps is empty
    Click on (Check and Save)
    Next Screen
    You can see one step created
    Click on Create
    You can see above it is showing as Step 2
    Give again program name and variant
    Click on (Check and Save)
    You can see two steps are created
    Go back (green arrow)
    You can see know SAP is showing 2 Step(s) successfully defined which was earlier blank
    Click on
    Next Screen
    Now schedule job as per your requirement.
    Prerequisite create variants for both the programs as we need to mention the same .
    Hope, this solves your issue else revert.
    Regards,
    Tejas

  • Why video with two audio tracks imports like one track (main)?

    Ok, lets face one simple thing that is incredibly stupid in Premiere CC:
    - I make video with two audio tracks (screencast with system sounds and microphone, separated)
    - Import it to Premiere CC and see only one audio track, system sounds!
    - What should I do to see both of them?
    - Why Sony Vegas don't make me to go to support forums and make them both visible without extra actoins?

    Great first post!
    Ok, lets face one simple thing that is incredibly stupid in Premiere CC:
    Channel Map the Audio to do what you want it to do with t e source clip.
    Why Sony Vegas don't make me to go to support forums and make them both visible without extra actoins?
    You could have read the Premiere Manual or watched the Adobe TV Tutorials or gone to edit school  instead ...

  • How to ACS 5.0.0.21 Expresss integrate with Active Directory Standar 2003 and authenticate PEAP MSCHAPV2

    Hi:
    My name is Ivan, I have a trouble
    I have a ACS 5.0.0.21 express, and i have to integrate with Active Directory (AD)  2003 Standar. I should authenticate the users of the Domain in the LAN with PEAP MSCHPAV2, using the follow:
    Cisco WLC 4402 + Cisco ACS 5.0.0.21 + Active Directory
    I need to know if i should to install a certificate in the ACS 5.0.0.21 or some agent remote install  in the AD.
    I put in the ACS a external database with the AD, and i already select the users on the domain in the ACS Express.
    Please could you tell me all the steps to autenticate the users on the Domain using the ACS Express and the Active Directory,
    I would like to know wich are the configuration that i have to do in my ACS express to authenticate using PEAP MSCHAPV2
    Regards
    Ivan

    See the below URL - multiple config guides on what you want to do:-
    http://www.cisco.com/en/US/products/ps6366/prod_configuration_examples_list.html
    HTH>

  • How do I combine two groups of podcasts into one

    I have a particular podcast that I have been listening to for a long time (This Week in Tech). I decided to archive all of the episodes and pull them off of my machine. However, I have noticed that the first 20 or so are not grouped with the remaining ones. In iTunes if I click on 'Podcasts' in sidebar, the first 20 or so TWIT podcasts show up as a podcast called 'The Best Article Ever' where as the remaining 170 show up as they should as 'this week in tech'.
    I looked through all of the information in the 'get info' window and it does not contain the name 'The Best Article Ever'. However, if I 'Right-click' on one of the early podcasts, and select 'Show Description' instead of 'Get Info' then the resulting window shows up and indicates that the podcast name is 'The Best Article Ever'.
    I can not find any way to change this information in the 'Show Description' window.
    I am assuming that if I can, then the early podcasts will then be grouped with the newer ones.
    Any help if appreciated,
    John

    I found out how to do what I wanted and I'm giving my steps in hopes that it might help someone else.  I wanted to put several photos from a file onto a new blank image.  This is what I did.
    1.  Create a blank page.    File/New/ Blank File.   Put in the size.  I used 8x10.
    2.  Bring the photo  you want to use into Elements as you always do. It will list along the top next to the blank sheet.
    3.  Choose SELECT (top of screen)/ Select All.
    4.  Choose Edit/Copy   or Command "C"
    5.  Click on the Blank File.   Chose Edit/Paste  or Command "V"
    6.  Click on Image/ Transform or Command "T".  There should be a dotted line around your pasted image.  You can then move and adjust the image to how you want it.  When finished, press the check-mark on lower right of photo.
    7.   Repeat this with all the photos you want on the new blank file.
    8.  You will see on lower right of Elements,  the background layer and as many layers as you have photos.  These layers need to be permanently placed on the background layer. Go to Layers and press Merge Visible.  This will merge all layers to the background.
    9.  Save as and you are done.

  • Ranking one object (row) with two/multiple criteria - excluded from one set of results if ranked by the other criteria.

    Working in Numbers 3.2.2. I've figured out how to rank with one or more criteria, but I need help completing my formula...
    I have a table with each person (row) who have different values for two different products (Columns B and C). I want to rank each person by column B (top 5), then rank the remaining 5 by column C.
    I'm able to create the table that ranks by product A using the formulas:
    A2  =LOOKUP(LARGE(Totals::Product A,ROW()−1),Totals::Product A,Totals::A)
    B2  =LARGE(Totals::Product A,ROW()−1)
    C2  =LOOKUP(LARGE(Totals::Product A,ROW()−1),Totals::Product A,Totals::Product B)
    I need exclude Persons H, D, G, J, and A from the ranking of Product B for the remaining 5 slots. This is where I'm getting stuck... I've manually created the rest of the table showing the sorting of Product B, excluding the top 5 people from Product A, and the final results I'm after. (The green cells show the ranking pattern I'm after. (Yes, Person F appears to get shafted. That's why I'm doing this. ))

    Hello
    You may create a rank index column as follows so that you can sort or retrieve the data based upon it.
    Table 1
    A1  Name
    A2  N01
    A3  N02
    A4  N03
    A5  N04
    A6  N05
    A7  N06
    A8  N07
    A9  N08
    A10 N09
    A11 N10
    B1  A
    B2  806
    B3  206
    B4  705
    B5  749
    B6  169
    B7  28
    B8  80
    B9  385
    B10 733
    B11 125
    C1  B
    C2  925
    C3  803
    C4  115
    C5  189
    C6  925
    C7  191
    C8  699
    C9  64
    C10 510
    C11 738
    D1  rank index
    D2  =IF(B2-LARGE(B,5)>=0,B2*"1e8",C2)
    D3  =IF(B3-LARGE(B,5)>=0,B3*"1e8",C3)
    D4  =IF(B4-LARGE(B,5)>=0,B4*"1e8",C4)
    D5  =IF(B5-LARGE(B,5)>=0,B5*"1e8",C5)
    D6  =IF(B6-LARGE(B,5)>=0,B6*"1e8",C6)
    D7  =IF(B7-LARGE(B,5)>=0,B7*"1e8",C7)
    D8  =IF(B8-LARGE(B,5)>=0,B8*"1e8",C8)
    D9  =IF(B9-LARGE(B,5)>=0,B9*"1e8",C9)
    D10 =IF(B10-LARGE(B,5)>=0,B10*"1e8",C10)
    D11 =IF(B11-LARGE(B,5)>=0,B11*"1e8",C11)
    Tested with Numbers 2.0.5 under OS X 10.6.8.
    Good luck,
    H

  • Combining two separate libraries (with two different Apple IDs) into one

    My fiance is moving in this weekend, and we hope to get rid of her computer to make space. She has a fairly large iTunes library, some ripped from CD and about 100 purchased from iTunes. I want to move her library and combine it with mine on my computer. I've read through the help files for consolidation, backup, and moving libraries from one computer to another, but none seem to apply to this special case. Once we transfer her files, we plan to cancel her Apple ID account since it wouldn't be authorized on any computers anymore.

    Once we transfer her files, we plan to cancel her Apple ID account since it wouldn't be authorized on any computers anymore.
    You can't cancel the iTunes account.
    Besides, you still need it to authorize your computer to play the songs she purchased.
    To get the music onto your computer, just copy it over to yours, then File -> Add folder to library and select the folder whwenre you put the music.

  • EAP-TLS problems with Cisco AP541N and Server 2008 NPS

    Hi,
    I want to use EAP-TLS with my shiny new certificates issued by my new Windows CA, and what happens? Nothing works.
    I don't have a clue what I should do. I try to establish a EAP-TLS connection using my Windows CE mobile device, but my cisco AP541N logs this:
    Oct 18 15:42:58
    info
    hostapd
    wlan0: STA 00:17:23:xx:xx:xx IEEE 802.1X: Supplicant used different EAP type: 3 (Nak)
    Oct 18 15:42:58
    warn
    hostapd
    wlan0: STA 00:17:23:xx:xx:xx IEEE 802.1X: authentication failed - identity 'XXXXXX' EAP type: 13 (TLS)
    Oct 18 15:42:58
    info
    hostapd
    The wireless client with MAC address 00:17:23:xx:xx:xx had an authentication failure.
    NPS logs this:
    Name der Verbindungsanforderungsrichtlinie: Sichere Drahtlosverbindungen 2
    Netzwerkrichtlinienname: XXXXXX
    Authentifizierungsanbieter: Windows
    Authentifizierungsserver: XXXXX
    Authentifizierungstyp: EAP
    EAP-Typ: -
    Kontositzungs-ID: -
    Protokollierungsergebnisse: Die Kontoinformationen wurden in die lokale Protokolldatei geschrieben.
    Ursachencode: 22
    Ursache: Der Client konnte nicht authentifiziert werden, da der angegebene EAP (Extensible Authentication-Protokoll)-Typ vom Server nicht verarbeitet werden kann.
    I'm sorry it's german, but the gist is: The server can't process the authentication with the specified EAP type, which should be EAP-TLS.
    I think the NAK answer in my cisco AP logs is the problem. Well, not the problem, since it is the standard procedure in the EAP request / challenge, I think, but somebody messes up with it.
    Did anybody encounter something like this before? Or just knows what to do?
    Thanks in advance
    Lenni

    Joe:
    Having NPS, you have the options to configure PEAP-MSCHAPv2 or EAP-TLS.
    EAP-TLS: mandates a certificate on the server as well as a certificate on every single machine for authentication purposes.
    PEAP-MSCHAPv2: mandates a certificate on the server only. Users connecting to the wireless network must trust the certificate (or, user devices can be configured to escape this trust and connect even if the server cert is not trusted).
    for PEAP-MSCHAPv2, Your options are:
    - Buy a certificate for the server from a trusted party (Verisign for example [which was bought later by Symantec]). This way all devices will - by default - trust the server's cert.
    - Install local CA. Install a cert on the server and then push the root CA cert for your CA to all client device so they trust this issuer.
    - If both up options are not valid for you, what you can do is to configure every single client to ignore the untrusted cert and proceed with the connectoin. (This is a security concern though. not recommended unless really needed).
    You must get a cert on the server and all clients must trust that certificate's issuer. Otherwise you'll not be able to user PEAP.
    HTH
    Amjad
    Rating useful replies is more useful than saying "Thank you"

  • Report with two layout

    Hi,
    I have a report with two different layouts that prints one after the other. I would like display the column hading for each layout for all the pages that records.
    To say in detail if a first layout prints fo 10 pages the corresponding columns names should be displayed in all the 10 pages. And if the second layout for 2 pages then the 2 layout headers should be displayed.
    Kindly let me know how to achieve this.

    To say in detail if a first layout prints fo 10 pages the corresponding columns names should be displayed in all the 10 pages.
    set the property to print on all pages
    And if the second layout for 2 pages then the 2 layout headers should be displayed.
    i didnot understand this

Maybe you are looking for

  • How to change the Profit Center in Sales Order

    Hi Gurus, Previously they setted the profit center (YB999) in sales order, now i want to change the profit center and need to give the amount into this profit center 100500. So, could you guide me how to change the profit center in sales order. Thank

  • Constant kernel panic on my Late-2011 MacBook Pro, help!

    Hi all, Okay, so whenever I'm running heavy tasks on my computer (rendering in Premiere, gaming etc.), after awhile my computer panics . By awhile, it ranges from 2 minutes up to about 2 hours. I'm not entirely sure what's causing it, but looking at

  • I want to display the message in jsp .

    I display the data retrieve from the database.if the data base have no record,i want to display a message to user.I write only one jsp. i used the JOptionPane,first time it takes more time to execute, after it execute normally,i am not satisfy for th

  • Problem with storage

    the situation shown in the picture happened after 10.10.3 yosemite update pls help me how can i resolve this problem

  • One track played out of order

    I've noticed this problem since one of the last updates: I have my settings on shuffle by album and the albums normally play from 1 to the end. However, certain albums skip a track in the middle and play it last. ex. 1-4, 6-10, 5 (My Morning Jacket,