IPad 802.1x and Microsoft RADIUS

Is anyone running iPad 2's in the enterprise using Microsoft RADIUS server? Now I understand that you can't use device certs because iPads cannot be joined to the domain, but I can use user certs. Now I read that iOS support PKCS#1 and #12, but I do not have this option on my CA for a cert request? Can someone share some tips on how they deployed these devices on the enterprise network? I could really use some help here. Thanks.

> [email protected] wrote:
>
> > You can do 802.1x authentication in Windows XP and 2000 with service
pack
> > 3 or above withou the Odyssey client. You can see this when you right
> > click on your network card, choos properties and you should see an
> > authentication tab if you have XP or 2000 with the right service
pack.
> > This is built into Windows and will use the users login name and
password
> > for authentication.
>
> Yes, I'm quite aware of that. I just didn't understand what you meant
by
> "override" in this context. The bottom line is that yes, you can use
OK. As long as I can use the Novell Client and Windows for
authentication. The testing that we are doing is using Direct XML on the
Novell Server and Remote Loader on an AD server with IAS. The user names
and groups are synchronized to AD. THe authentication with then happend
at the AD server with IAS.
> the Windows client to authenticate against 802.1x compliant RADIUS
> servers, and NO, Novell's is not 802.1x compliant, and never will be.
> It's *possible* (but not confirmed) that Novell may be providing
> detailed and supported steps to get freeRADIUS working for such tasks,
> though. That's all I can tell you as that's all I know.
>
> --
> Jim
> NSC SYsop

Similar Messages

  • Can the iPad utilize Dropbox and Microsoft Word Documents?

    Now a PC user for entire life and want to move to tablet. Now use Dropbox as main storage and have many, many documents, etc. there. Would want to continue this use. Can I do that with iPad?

    I personally would answer this question with, "Yes & No"
    Yes, Dropbox is supported on the iPad as well as Microsoft Documents (when you use third party applications like Quickoffice or iWork), However I have had some issues finding apps that have full support of those documents. For instance, If I want to search something in a PDF document on my iPad for a certain word or phrase. I have not been able to do so yet. Not using the Dropbox application or Quickoffice Pro.
    So it depends on what you are doing with your documents. If you are just viewing, sharing and making minor edits to them, Then I don't think you will have any issues, But if you want to go more in depth with your documents, You may have some trouble.

  • Ironport S170 and Microsoft RADIUS

    I'm trying to setup management logins for the IronPort S170 using RADIUS.  I have the Windows server configured and the server information is in the S170, but I'm having trouble with the Group Mapping.  Under the RADIUS Class Attribute, what is an example of something that would go there?  Is it an AD group?  If not, is it some attribute number that I need to configure on the AD user object?  If so, where?  TAC has no idea how to do this. 

    This error occurs when the user’s account is not stored in reversible encryption.
    CHAP requires that the secret be available in plaintext form. CHAP cannot use irreversibly encrypted password databases that are commonly available. If the RADIUS server does not have access to the plaintext password, it cannot perform the one-way hash to verify the user and the authentication will fail. By default, Microsoft Active Directory does not store user accounts with reversible encryption.
    Reversible encryption is a user class attribute and is not enabled by default in the Active Directory. You must enable this setting manually on each account or through Group Policy Objects when dealing with multiple users.
    ~BR
    Jatin Katyal
    **Do rate helpful posts**

  • WLC 5508 and Microsoft Radius Server 2008

    Hi, I am trying to setup WLC 5508 for a customer who want to use MS NPS for Radius authentication, however there aren't many good documents showing how to configure the MS NPS.
    I have couple of questions:
    1, Does WLC 5508 support MS NPS on Server 2008 R2?
    2, Are there any good document showing how to configure this?
    Thanks

    Hadisharifi,
    There is no single document that we can pick for configuring WLC and NPS. However, you may visit the below listed document for NPS  and WLC side configuration:
    Configure the WLC for RADIUS Authentication through an External RADIUS Server
    http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a0080665d18.shtml#c2
    Fo the NPS side configuration, you may consider the attached document.
    Regds,
    JK
    Do rate helpful posts-

  • TS1506 I just updated my IOS to 7.1 and now I can't open Microsoft attachments - I used to always do it. Help - I use my iPad for work and now can't see any attachments.

    I just updated my IOS to 7.1 and now I can't open Microsoft attachments - I used to always do it. Help - I use my iPad for work and now can't see any attachments. I've tried opening straight into other apps and just get error messages, and I the mail preview there is just a grey screen telling me the file name and size. It worked fine until I did the IOS upgrade

    Troubleshooting apps purchased from the App Store
    http://support.apple.com/kb/TS1702
    Delete the app and redownload.
    Downloading Past Purchases from the iTunes Store, App Store and iBooks Store
    http://support.apple.com/kb/ht2519
     Cheers, Tom 

  • I want replace my desktop with a iPad to do emails and Microsoft office work. Can this be effectively done? What's the downside if any?

    I want replace my desktop with a iPad to do emails and Microsoft office work. Can this be effectively done? What's the downside if any?

    I'll go down your list one by one.
    1. Access mail - which I know that the iPad can do.
    Enough said.
    2. Save an excel or word or ppt of PDF attachment for review.
    You can view these types of documents natively on the iPad as Tgara has mentioned.
    3. Open an review and maybe change a excel or word file.
    There are many apps that allow this.  I personally prefer Apples iWork programs, Pages, Numbers, Keynote.  They tightly integrate with iCloud.
    4. Resave such above files.
    With Pages, Number, Keynote you can save/resave files in iCloud and locally.  Also you could use dropbox to save your files on dropbox and provide a way for you to share a folder with coworkers/family and they can add/view/review files from there and you can see the changes on your device.
    5. Reply to a mail attaching a file.
    This is possible in many ways.  From dropbox, or another app you can email files with the share button.
    6. Be able to rename files and store them in specific folders.
    This goes back to dropbox/iCloud.  iOS doesn't really have a traditional file system.  If you save a PDF it isn't saved anywhere you can just open it.  You would have to open an app that supports view PDFs and select the PDF you wish to view.  The same goes for documents, spreadsheets and etc.
    Hopefully this helps answer your questions.

  • IPad on a Windows Network and Microsoft SharePoint

    I have just bought an iPad for work. I connected to our corporate Wifi no problems. I want to use the device to connect to our Microsoft SharePoint, which I can do, but I keep getting asked for a username and password when I browse different pages. Is there any way to stop this. Can Safari some how remember my username and password so I don't have to keep typing it in.

    Are you just navigating to pages within the same site structure. We are currently using an iPad with SharePoint and only get asked for username and password if we loose connection to our server. Basically, we are using it to gather data by having the users to fill in several custom list forms so most of the time we are only navigating to a few pages within this site but I am able to navigate to other parent and subsites without being asked for credentials. We are running on Sharepoint 2007 server.

  • IPad and microsoft office

    dears
    if i hava any word or excel document, can i open it on the ipad ?

    You can open them (read-only) with either an add-on app like goodreader or by emailing them from your pc to your iPad as attachments and opening the email attachments.

  • Integration between WLC 5508 and Microsoft NPS 2008

    Hi guys,
    Any of you, have working guidance for WLC 5508 and Microsoft NPS 2008 integration?
    I managed to configure Wireless 802.1x feature (PEAP) but it failed. I'm running software ver. 7.0.116.0.
    Is there any bug related 802.1x on this software version?
    thanks in advance.
    BR
    shendy

    Hi Shendy,
    I am not aware about any bug related to this. I think you better check all configuration and make sure it is fine.
    Logs from NPS and WLC (and possibly from the supplicant) may guide you where the problem resides.
    What does the NPS logs tell about the reason of the authentication failure?
    What does the WLC logs say about the failure (check show msglog and show traplog).
    - Make sure the Radius server added correctly with correct IP and correct shared secret on WLC.
    - Make sure that the radius is configured correctly to allow PEAP-MSCHAPv2.
    - Make sure WLC is added successfully to WLC with correct IP address and correct shared secret.
    - Make sure the clients are correctly configured and the server's (NPS) certificate is trusted on the clients.
    HTH
    Amjad

  • Switch Cisco and Microsoft NPS

    Hi,
    I configure 802.1x wich Cisco Switch and Microsoft NPS Radius but the client cannot connect. I debug radius on switch and receive the debug attached.
    Whats the problem??
    Thanks

    Hi,
    Looks like that switch ip address is 192.168.233.250
    Please add this nas-ip-address 192.168.233.250 in the condition on the NPS server.
    Also, could you please provide me a error message from the event viewer?
    Attached is the document to configure NPS with cisco devices.
    HTH
    JK
    Plz rate helpful posts-

  • Hello! I have in my home 2 iMac, 2 iPad, 2 iPhone, and 1 air base extreme. I don't succeed to connect more than one divice from similar type. I tried everything what I knew. I build another network, etc...

    Hello! I have in my home 2 iMac, 2 iPad, 2 iPhone, and 1 air base extreme. I don't succeed to connect more than one divice from similar type. I tried everything what I knew. I build another network, etc...
    So only one imac, only one ipad..and so on simultain.
    More over, all the divices are conect through wifi to air base but are not receiveing internet as i told above.
    I need to disconnect one device to have internet on the second one from the same type!
    Could somebody help me?
    Many Thnaks,
    dan

    If your network configuration is:
    Cable modem > (Ethernet cable) > [WAN] AEBS > (wireless) > Macs, then
    AirPort Extreme Base Station Setup (AEBS) w/High-Speed Cable Modem
    Modem/Router Power ReCycling
    - Power-off the Cable modem, AEBS, & computer(s). (If possible, leave the modem off overnight.)
    - Power-on the Cable modem; Wait at least 30 minutes.
    - Power-on the AEBS; Wait at least 5 minutes.
    - Power-on the computer(s)
    Perform a "hard" reset of the AEBS.
    - (ref: http://docs.info.apple.com/article.html?artnum=107451)
    Setup the AEBS
    With the network components powered down, set up the AEBS, using the AirPort Admin Utility, connect your computer directly (using an Ethernet cable) to the LAN port of the AEBS, and then, try these settings:
    AirPort tab
    - Base Station Name: <whatever you wish or use the default>
    - AirPort Network Name: <whatever you wish or use the default>
    - Create a closed network (unchecked)
    - Wireless Security: Not enabled
    - Channel: Automatic
    - Mode: 802.11b/g Compatible
    Internet tab
    - Connect Using: Ethernet
    - Configure: Using DHCP
    - WAN Ethernet Port: Automatic
    Network tab
    - Distribute IP addresses (checked)
    - Share a single IP address (using DHCP & NAT) (enabled)
    Once you verified that you can get Internet access for all of your computers, you should secure your wireless network. To do so, I suggest that you make these changes:
    AirPort tab (optional)
    - Create a closed network (checked)
    Change Wireless Security
    - Wireless Security: WPA Personal
    Base Station Options - WAN Ethernet Port
    - Enable SNMP Access (unchecked)
    - Enable Remote Configuration (unchecked)
    - Enable Remote Printer Access (unchecked)
    Wireless Options
    - Transmitter Power: 10%
    Access Control tab (optional)
    - + <add the computer(s) that will access this wireless network>

  • Cisco Systems vs "CSIRO" 802.11a and 802.11g infringed upon the '069 patent

    Hi,
    any news about Cisco Systems and the "CSIRO" 802.11a and 802.11g infringed upon the '069 patent ?
    http://www.buffalotech.com/products/wireless/
    Dear Customer
    As you may be aware, Commonwealth Scientific and Industrial Research Organisation ("CSIRO") sued Buffalo, Inc. and Buffalo Technology (USA), Inc. ("Buffalo"), for alleged infringement of United States Patent No. 5,487,069 ("the '069 patent"). Subsequently, CSIRO also asserted its patent against the entire wireless LAN industry, including, Microsoft, Intel, Accton, SMC and Netgear.
    In it's lawsuit against Buffalo, CSIRO claimed certain Buffalo wireless networking products compliant with IEEE standards 802.11a and 802.11g infringed upon the '069 patent. Buffalo believed at that time and continues to believe that there are no grounds for CSIRO's allegations of infringement. The United States district court, however, found Buffalo to infringe the '069 patent and enjoined the importation and sale of Buffalo's IEEE 802.11a and 802.11g compliant products.
    CSIRO's lawsuits are against the entire wireless LAN industry and could affect the supply of wireless LAN products by any manufacturer, not just Buffalo. The entire industry is resisting CSIRO's attempts to enjoin the sale of wireless LAN products. Recently, Microsoft, 3COM Corporation, SMC Networks, Accton Technology Corporation, Intel, Atheros Communications, Belkin International, Dell, Hewlett-Packard, Nortel Networks, Nvidia Corporation, Oracle Corporation, SAP AG, Yahoo, Nokia, and the Consumer Electronics Association filed briefs in support of Buffalo's position that injunctive relief is inappropriate in this case.
    During the period of time that the injunction is in effect (10/1/2007), Buffalo cannot offer for sale, sell, import, or use its IEEE 802.11a and 802.11g compliant products in the United States. A list of the products covered by the injunction is attached here . The injunction does not prohibit sales of pre-existing inventories of products by Buffalo's customers. In addition, Buffalo has secured CSIRO's agreement to permit the replacement of defective products under warranty. None of Buffalo's other products are currently affected by this injunction.
    While Buffalo believes that it will be successful in reversing the district court's decision and will obtain a stay of the injunction pending a decision on the merits, the Court of Appeals has not yet issued a decision. Should the Court of Appeals issue a decision staying the injunction, you will be promptly notified. After the stay is issued or a favorable decision on the merits is obtained, Buffalo will be able to resume the supply of IEEE 802.11a and 802.11g products
    Please rest assured that Buffalo continues to stand behind their products and will continue to support all of our loyal customers as it relates to product warranties, technical support and the like without interruption.

    I suspect after reading the patent and the litigation that you mentioned above, that the US District Court decision will be reversed as the patent appears to be very vague in its contsruction and verbage. Furthermore, the intent to hold the IEEE hostage on the ratification of 802.11n will not bode well in the court's eyes. If in fact the case is reversed, I believe that the members of CSIRO will be in danger of lost profits litigation from Buffalo. Stay tuned to this bat channel.

  • How do I wirelessly synch my Notes using iCloud among iPad, iPhone 5S and Outlook 2013 running on Windows 8.1

    How do I set up my devices to wirelessly synch my Notes using iCloud among iPad, iPhone 5S and Outlook 2013 running on Windows 8.1?

    Hey bwind,
    You will want to first create an iCloud account, if you haven’t already:
    Creating an iCloud account: Frequently Asked Questions
    http://support.apple.com/kb/ht4436
    Next, sign in to that iCloud account on your iPhone and iPad, and turn on the syncing for notes:
    iCloud - iPhone
    http://help.apple.com/iphone/7/#/iph3c79652c
    iCloud - iPad User Guide
    http://help.apple.com/ipad/7/#/iPad995bbafe
    Then you will want to download the iCloud Control Panel for Windows:
    iCloud Control Panel 3.1 for Windows
    http://support.apple.com/kb/dl1455
    You will find your notes in their own section on Outlook:
    iCloud: Notes overview
    http://support.apple.com/kb/PH12081
    On your Windows computer, your changes are pushed to Microsoft Outlook in the Notes folder of your iCloud email account. You can see your iCloud notes by expanding your iCloud email account in the Outlook folder pane (also called the navigation pane), then selecting the Notes folder in the email account.
    Take care, and thanks for visiting the Apple Support Communities.
    -Braden

  • MAB, 802.1x and ACS 4.2

    Hi all,
    Currently i'm using an ACS4.2 as radius server, some switch 2960-s ios 12.2.(55)se5, ipphone Alcatel iptouch 4018 and i would like to assign dinamic vlan to some specific users/laptop Daisy-chained to ip phone.
    Logic connection is:   users laptop---->ipphone---->switch---->radius
    What i need is:
    if I connect MY laptop to the ipphone port, i receive a specific vlan ( vlan 58 )
    if SOMEONE else ( i.e. a consultant ) connect his laptop to the SAME ipphone port (if available) he has to receive a different vlan ( vlan 1).
    I've been able to reach the goal using MACRO but it tooks too much time to authenticate ( approx 1 min ) so i give up and tried a different faster  way ( 802.1x and MAB ).
    i've been able to authenticate the ip-phone using 802.1x auth and to receive the correct vlan when i connect MY laptop (MAB auth)  but i was not able to provide the VLAN 1 to the Consultant when he connect his laptop even if the "authentication event fail action authorize vlan 1"  is configured.
    I used the dot1x auth-fail vlan  because i'm not able to use MAB or 802.1x auth on external laptop. I also tried with guest vlan with no luck.
    In both case the "consultant" remain in "auth failed"
    Here my current configuration
    dot1x system-auth-control
    dot1x guest-vlan supplicant
    identity profile default
    interface GigabitEthernet1/0/1
     switchport mode access
     switchport voice vlan 30
     authentication host-mode multi-auth
    authentication event fail action authorize vlan 1
     authentication order mab dot1x
     authentication port-control auto
     mab
     dot1x pae authenticator
     dot1x timeout tx-period 2
     dot1x max-reauth-req 1
     storm-control broadcast level 2.00
     storm-control multicast level 2.00
     spanning-tree portfast
    On ACS side i have 2 groups
    first Group authenticate the iphone and supply the voice vlan ( vlan 30)
    Second Group authenticate using MAB and supply the vlan 58
    is there a different way to accomplish this task?
    Thank you in advance

    hi,
    any ideas?
    thx

  • 802.1X and CAT Express 500

    Hi guys,
    I want to know if the Cat Express 500 support dynamic vlan assigment through 802.1X.

    Hi,
    You can do the vlan arrisgnment using 802.1x on CE500. The configuration for 802.1X and Radius authentication server can be done with the help of Cisco Network Assistant (CNA). In the menu Network Security Settings you have to put the
    security level on high. There is the possibility to configure the IP address of the RADIUS server and the RADIUS key.
    In case you don?t have the CNA, you can download it for free from:
    http://www.cisco.com/cgi-bin/tablebuild.pl/NetworkAssistant
    HTH, Please rate if it does.
    -amit singh

Maybe you are looking for

  • Do i need a power converter for macbook in the philippines

    i was wondering if i needed a power converter to charge my macbook in the Philippines or do i just need the 3 to 2 prong adapter

  • Sudo purge isn't working

    After I type it into terminal i get the warning message: "WARNING: Improper use of the sudo command could lead to data loss or the deletion of important system files. Please double-check your typing when using sudo. Type "man sudo" for more informati

  • J2ME Device Table / Matrix vanished from sun website

    No so long ago Sun hosted a matrix / table of devices which supported J2ME. This was a very cool resource as it made it very easy to find out which devices supported what features. I found these items in the web archive : http://web.archive.org/web/2

  • Pre bought YouView box

    I am disapointed about the misleading informaiton presented on the TV screen of my YouView box.  I got a YouView box from PC World when they first came out, i did not have BT at the time. I recently got BT and when i re-connected my box i begun to se

  • Viewing java code in Eclipse

    This question of mine is not directly related to Java but I couldn�t find a better place to post this question. I have a java application contained in 2 zip files. I am viewing the files in eclipse. I created a project and extracted both the zip file