New Intel Wireless Pro set let bypass PEAP user authentication

Hello.
I have a critical situation. We use PEAP/MSCHAPv2 for client and user authentication. Wireless users and clients will be authenticated by the ACS by asking a ADS usergroup membership. Valid users and clients have access to LAN ressources protected by the wlan controller. If the wireless client use the WZC and the logged on user is not a member of the user group he will not be authenticated and have no access through the wlan controller. But if the wireless client can use the actual "Intel Wireless Pro Set" and the user is not a member of the ADS group the ACS drop the user authentication request. But some seconds later the user will have nevertheless access to internal resources.
In this case I think the user authentication request will not right handled by the ACS so authenticated client will have access through the wlan controller and a not ACS authenticated user will have access to lan ressources by his local cached user credentials.
Is there a possible security leak or have I a configuration problem?
Best regards
Olaf Bachmann

Hi irisrios.
PEAP "Fast Reconect" is disabled on ACS side.
But in the meantime we made some tests with cisco ACS and nortel wlan controller. If the wlan client use a wireless profile, generated with the Intel Proset (!! full installation incl. andmin tools and pre-logon authentication!!) then a user who is not a member of the wlan user group have access to lan resources.

Similar Messages

  • Bypass PEAP user authentication

    Hello.
    We use PEAP/MSCHAPv2 for client AND user authentication. Wireless users and clients will be authenticated by the ACS by asking a ADS usergroup membership. Only authenticated users on authenticated clients should have access to LAN ressources protected by the wlan controller. If the wireless client use the WZC and the logged on user is not a member of the user group he will not be authenticated and blocked by the wlan controller. But if the wireless client use the actual "Intel Wireless Pro Set" AND the user is not a member of the ADS group the ACS drop the user authentication request, but few seconds later the user will have nevertheless access to internal resources.
    In this case I think the user authentication request will not right handled by the ACS so authenticated client will have access through the wlan controller and a not ACS authenticated user will have access to lan ressources by his local cached user credentials.
    Is there a possible security leak or have I a configuration problem?
    Best regards
    Olaf Bachmann

    This is not a security leak but a configuration issue. If the client utility and the ACS, ADS database is correctly configured then you will not see any issues.

  • Trying to load pre-2006 lso files into Logic 8 on my new intel Mac Pro

    I'm trying to load pre-2006 lso files into Logic 8 on my new intel Mac Pro, but they crash the app every time. files saved 2006 and later load OK. Anybody shed any light on this or know of a fix (other than the laborious work-around of re-saving all early lso's in logic 8 on the PPC and physically moving them via a portable drive to the new machine)?
    (BTW, those files also crash the Logic 7 installed on the intel Mac.)

    Upon further work with my migration, I find I was incorrect in the time frame assertion of these failed files: apparently, the creation/modification dates have nothing to do with it and the reality is that some files fail at random, while others load just fine. right now it looks to be about 50/50 Beats me why this is.
    Anyway, for those interested, I've discovered a very helpful key to the quick processing of file data for a plethora of files (i. e. re-saving the "bad" lso files as Logic 8 projects on the older CPU and moving them over to my new machine), and that is the 'control key/launch' of the app. I hadn't realized that Apple had added this feature to Logic to enable easier work on multiple song files when one does not require the audio.
    For those who don't know about it, the 'control key/launch' provides an option to disable the core audio at app start-up, thus allowing files to load instantly without loading the plug-in library files associated with tracks - great for copying MIDI data between song files, or in this case, re-saving a batch.
    Still puzzled, though, as to why so many older lso files crash Logic when they attempt to load on my new CPU.

  • I have a new mac book pro but cant find a user manual?

    I have a new mac book pro and cant find a user manual?

    being a windows user I too looked for a book as I had pretty much all large OS changes like XP to w7Pro.... so barnes and noble has what I found to be an excellent book after looking through many at bookstore...
    "OS X Mavericks The Missing Manual" which covers OS X 10.9.1 first edition was dec 2013 so recent book 850 plus pages of info and pictures very easy read and the views make it simple to follow.
    Me I like technical info but this book is for everyone with sections on just about every topic the OS has.
    I do believe I paid like $35 (US) but well worth it as I hadn't touched an Apple since 1988 with truly floppy discs we used to punch nothces in.
    Author is a N. Y. Times writer who wrote many a "Missing Manual" as I can't remember the last time anything came with a manual. I had a $4600. windows machine built by Puget Systems and others over the years from Falcon Northwest.... none came with manuals other than similar to Apples quick info foldout.
    Good luck

  • New Intel Macbook pro or a PC laptop

    Hello everyone. I currently have a 2003 Powerbook G4 Ti 1.0Ghz. It works greate. Now the problem is that I am in the Army and I use lots of military programs that only run on PC's. I have been using Virtual PC 7 to run some of them, but there are some that require a lot of memory and speedlike Falcon View and Performance planning software for Army helicopters. I am also separated from my family and currently use Skipe to do video conference with them. She has a PC laptop. So no Ichat there.
    The question is, Are the new Intel laptop able to run Xp and Mac os X at the same time . Is that program Bootcamp really good. Can I start the laptop in Mac to use all my applications and games and then restart in PC mode to work with Pc software or talk to my family?
    Do I need an external hardrive to operate in Xp? Or... should (as much as I dont want to) I get a PC laptop.
    Also I currently have a lot of Mac applications, are those going to work with the intel chip or I need to get an intel version. Lots of money there.
    Thanks in advance.
    Gonzo

    hi you can use bootcamp to start your macbook/macbook pro in windows xp/vista or mac os x. Or you can use a program like parallels which can run osx and windows side by side. AFAIK you don;t need an external hard disk to run windows - bootcamp just creates a virtual partition.
    As for the mac ppc applications that you have - some may have intel (universal binary) upgrades or updates. It depends on the programs...some you'll have to pay for others might be free upgrades.
    However, i currently use some old mac ppc software on my intel mac and in general it runs fine. I know that programs like photoshop for example do run slower on intel machines than ppc but it's marginal apparently. Basically non-intel software runs on intel mac's in an emulation called Rosetta which automatically enables tha applications to run.
    http://www.parallels.com/
    Do check with the relevant software co.'s websites about their products and availability of UB (universal binary) version/updates.
    I'd personally recommend a macbook pro. Beautiful machine. runs xp well from what i've seen. runs intel and non-intel mac software well. you can run os x and win xp simultaneously. And by the way, skype exists for mac os x - and it runs great - i talk to my pc friends using it...no problem.
    Hope that helps
    Rounik

  • Wireless PEAP users authenticated by TACACS+

    Hello,
    I have the following scenario, access points 1214 (fat AP) connected to ACS (RADIUS) and the ACS integrated with Novell LDAP as external database.
    The wireless users use PEAP for authentication, here the problem when I tried to connect wirelessly with username and password configured locally on the ACS database it works fine but if I use a username and password listed on the Novell LDAP I got the error ?Auth type not supported by External DB? .
    Note:
    For VPN users, I can connect and access the network resources from outside with username and password listed on Novell LDAP database (integration between ACS and Novell LDAP is fine). Maybe this note could help you!!
    Regards,
    Belal

    Hello Darran,
    Thx for your feedback..
    now i'm trying to configure EAP-TLS but as stated in the configuration guide i should have CA certificates for both ACS and the wireless users. here the question, shall i have CA server or thers is another way to complete the task (use local generated certificate for example if possible) ?
    Regards,
    Belal

  • M70-151: Intel Wireless Pro 2200BG Connection

    Hi
    I have a new Toshi Notebook M70-151 but the connection to my Zyxel WLAN Router ist very buggy.
    here are a list of PINGs to the router
    Antwort von 192.168.1.1: Bytes=32 Zeit=105ms TTL=254
    Antwort von 192.168.1.1: Bytes=32 Zeit=2ms TTL=254
    Zeitberschreitung der Anforderung.
    Antwort von 192.168.1.1: Bytes=32 Zeit=2ms TTL=254
    Antwort von 192.168.1.1: Bytes=32 Zeit=999ms TTL=254
    Antwort von 192.168.1.1: Bytes=32 Zeit=164ms TTL=254
    Antwort von 192.168.1.1: Bytes=32 Zeit=2ms TTL=254
    Antwort von 192.168.1.1: Bytes=32 Zeit=3ms TTL=254
    Zeitberschreitung der Anforderung.
    Antwort von 192.168.1.1: Bytes=32 Zeit=796ms TTL=254
    Antwort von 192.168.1.1: Bytes=32 Zeit=2ms TTL=254
    Antwort von 192.168.1.1: Bytes=32 Zeit=2ms TTL=254[/code]
    (German: Antwort=Answer, Zeit=Time, Zeitberschreitung der Anforderung= not answered)
    I have seached lots of other boards - most advise to install the latest INTEL drivers/software. I have done that but there is no change in behaviour.
    Here are some words to my environment:
    - Driver/Software: latest INTEL : 9.0.3.9/9.0.3.0
    - Signalpower: very good
    - from my home PC and a WLAN USB Stick a got permanent fast (2-3ms) PINGs to the same router
    - have played with all Hardware Settings (b/g band, WLAN power, changed channels, ...)
    Who can help me?
    Thanks :-)

    Berk,
    I did look around other support forums and finally I have done two things. One is updated the driver to 9.0.3.9 which is the latest driver. It comes bundled with the Intel Proset software. Just install the driver.
    Secondly, although the TRANSMIT POWER in the Wireless adapter configuration is set HIGHEST and the default radio button is checked, just uncheck the same and set it to HIGHEST. This does not make sense but it seems to have improved my ping times considerably, although not constant ping times of 2 ms. Moreover when I access the internet the speeds shoots up to 54 Mbps and when idle drops to 32 Mbps. This is just the way Intel has made its hardware and software. See if the above improves your experience and let us know your findings.

  • Upgrade Logic 6 to Logic Pro 9 on new intel MacBook pro problem

    I have a new Macbook pro OS 10.6.1 intel. I've loaded Logic 6 and it works ok with the XS key. However the upgrade to Logic 9 (which installed fine) crashes unexpectedly on opening.
    The error message is:
    Dyld Error Message:
    Library not loaded: /Library/Frameworks/XSKey.framework/Versions/A/XSKey
    Referenced from: /Applications/Logic Pro.app/Contents/MacOS/Logic Pro
    Reason: image not found
    Can anyone help please?
    John

    Upgraded from Logic 6 to 7 to 8 with no problems and are working fine.Logic Pro 9 gives same message error
    Dyld Error Message:
    Library not loaded: /Library/Frameworks/XSKey.framework/Versions/A/XSKey
    Referenced from: /Applications/Logic Pro.app/Contents/MacOS/Logic Pro
    Reason: image not found
    Thanks for any ideas/help
    Oscar

  • Can No longer import video on new intel Mac Pro Tower

    Help...I am a teacher and my students cannot use our brand new computers to import footage. No problems with old G5. FOr some reason i-movie will not recognize a camera is attached on the new mac pro's
    Is there something I am doing wrong. The camera is a cannon GL2 we have been using for years. Tried multiple cables and machines. all have the same issue.

    Make sure all of your applications are updated by using the Apple Software updates.
    Then, try deleting the imovie preference file. Close Imovie. Then locate a file named com.apple.imovie.plist and get rid of it. Then empty the trash.
    Most importantly, after the updates and the deleting, run a permissions repair with disk utility and restart. That may do it. The files you need to delete are found in:
    /Users/YourName/Library/Preferences/com.apple.imovie.plist
    Sue

  • Using MBSSID - new 1252 wireless APs not letting hosts connect

    Solution:
    After spending a few weeks working with Cisco in trying to figure out why new 1252 APs weren't getting a DHCP address from our Juniper SSG5 firewall (on different VLANs for each SSID), I finally got to a Cisco tech who knew the answer, so am posting it here to perhaps help someone else.
    Using MBSSID, according to the first tech, only one can be in open authentication mode (e.g. no WEP, WPA, etc.) You can have multiple SSIDs that utilize the same method of authentication, just not more than one of them open.
    Using MBSSID, on some wireless NICs that are apparently somehow sensitive to it, only one SSID can be in guest/broadcast mode. This ultimately was the solution to our connectivity issue.
    It would be good to have documented what those NICs are that experience this problem.

    gcgeorge wrote:
    Hi Fiedi,
         Thanks for you reply.
         The guests are both configured to use a bridged adaptor on the wireless adaptor.
         I am currently using the rac1-priv IP address (192.168.0.101), and it does not work. If I try the public or VIP addresses, they do not work either - presumably since they are on a different subnet.
         Thanks
         Gavin
    You will not be able to connect through private network as there isn't listener listening in that IP.
    Try change your wireless IP to network 192.168.2.x and try to ping the guests public IP
    Cheers

  • Applications need to be Force Quit most of the time on new Intel Mac Pro.

    Most all of my ILife and Apple applications now need to be Force Quit. What can I do to restore a normal Quit of my applications?

    Thanx, howwow.
    But, been there, done that. Along with Zapping PRAM; TechTool; and Cocktail. Is there some plist or other prefs file that got corrupt?

  • Postscript fonts on Intel MacBook Pro

    I used a lot of postscript font families on my old Powerbook. Will these font packages function properly with the Intel processor? Do they use Rosetta, or are fonts already "universal" in design? Any problem with Word in particular, which is already a little buggy under Rosetta?
    Thanks!
    MacBook Pro 2Ghz   Mac OS X (10.4.6)  

    I have a new Intel MacBook Pro 17" running Tiger 10.4.7 and am pulling my hair out because of the MS Word crashing because of a font problem.
    Have already lost countless hours trying to identify the source of the problem when all comes crashing down. Have narrowed it down to Word 2004 and a particular font that is used in ALL my old documents. The font checks OK in several font checking utilities. But Word crashes and brings the whole system down with it when trying to SAVE.
    Obviously from past posts this crash does not appear limited to just one particular font or font style. If the problem is truly something in apple system software, I think they need to fix this QUICKLY! Apple.. are you listening!!! WE CAN'T WORK TILL YOU FIX THIS!
    cheers,
    SF

  • Pairind an apple Key board and mouse from my Mac pro G5 to a newer Intel Xeon. Have OS 10.6.8 with all updates for Bluetooth. Still no luck setting up as new divice. Help.. Thanks Out There...

    I have an wireless Apple Keyboard and Mouse from my G5 Pro Mac, 2006. I would like to use it on a newer Intel xeon with blue tooth. Initally I was able to set them up.. Today Is another story. I have delete them as devices and have had no luck setting them up.. Help.. Many Thanks folks I am sure one of you good souls can help me out.. I have loaded the updates and am running 10.6.8. Are there issues using early apple wireless keyboards and a mouse.

    I have an wireless Apple Keyboard and Mouse from my G5 Pro Mac, 2006. I would like to use it on a newer Intel xeon with blue tooth. Initally I was able to set them up.. Today Is another story. I have delete them as devices and have had no luck setting them up.. Help.. Many Thanks folks I am sure one of you good souls can help me out.. I have loaded the updates and am running 10.6.8. Are there issues using early apple wireless keyboards and a mouse.

  • I own Logic Pro 7( I used to have a PowerPC  and need to upgrade to Logic Pro 9 (new Intel chip, system 10.8) .  Do I need to buy a whole new set or do I upgrade for less cost?

    I own Logic Pro 7( I used to have a PowerPC  and need to upgrade to Logic Pro 9 (new Intel chip, system 10.8) .  Do I need to buy a whole new set or do I upgrade for less cost?

    The cost of the Full Logic Pro 9 from the App Store is less than the cost of the discontinued Boxed Upgrade set for Logic Studio (if you could find one) ... so you might as well purchase the full Logic Pro 9 from the App store and be done.

  • Acrobat XI Pro performance with new Intel Core M processor

    EDIT 21-Feb-2015: the issue seems to be with the power limitation of the new Intel Core M Broadwell processor. Enabling it in "full performance" mode significantly increases the performance. Nonetheless, in whichever power mode the computer is set, Microsoft Reader has no issue with any of the operations listed below.
    Hi,
    I'm running Acrobat XI Pro on Windows 8.1 64-bit with high-res display (3200x1800, Lenovo Yoga 3 Pro), which uses the new Intel Core M Broadwell processor.
    Zooming in and out and panning on the main application is very laggy, and full screen is EXTREMELY laggy. Also very noticeable delays in scrolling and page to page.
    The computer is brand new, out of the box, no viruses or other software dragging the system down. Also, if I open the same files on the Microsoft Reader app, there is no lag at all in doing these operations.
    I have found on the forum that some people have had lag and disabled Protected View and Enhanced Security. However, Protected View is not enabled on my installation, and disabling Enhanced Security has no effect.
    Right now I would say that the zoom/pan performance is worse even than on Reader on a 5 year old Windows XP machine I tried to compare to.
    Is there some other settings in Acrobat XI that could cause this issue?
    Thanks!
    P.S. I couldn't find a more appropriate group other than "Acrobat Installation & Update Issues" as I didn't find a troubleshooting group or anything like that, but can re-categorize.

    Hi Antonio,
    You might want to file a Bug report at: https://www.adobe.com/cfusion/mmform/index.cfm?name=wishform&loc=en
    Regards,
    Rave

Maybe you are looking for

  • Slow response when using Xcelsius web service connection witn input values

    We've been very successful in using the Xcelsius Web Service Connection. We've recently moved forward toward using input values when calling a web service and having issues with response time. Without input values, it takes 3 - 6 seconds to retrieve

  • Query related to BW - BEx

    Hello Experts, We have BEx configured in one of our system and it has been refreshed from production recently. When user try to login it to SAP Query Designer: they get below prompt > Terminate : The BW server has deactiviated this version of Query d

  • Magic Trackpad - no "set up bluetooth trackpad" option in preferences

    Just bought a magic trackpad, updated to 10.6.4, laptop finds the magic trackpad (verified by looking at bluetooth panel), but I can't set it up/ connect. When I go to the trackpad section in preferences, the option that the instruction manual talks

  • Task Group

    Which t-code is used to create & Maintain a Task Group? When I use PP01 it says 'this object type cannot be maintained from basic transcation'. I know we can do the changes in IMG for this object type to be maintained, but is their any other T-code,

  • [solved] starcraft2 fails to update to patch 1.03

    Hi All, I have installed starcraft2 using the unstructions on this page: http://wiki.archlinux.org/index.php/Starcraft2 Installing the game goes fine, until the game downloads patch 1.03. Then I get the message "The program BlizzardDownloader.exe has