Securing a wireless network with 802.1x + WPA

I'm currently in the process of designing a new wireless network and am looking to do both authorization from a RADIUS server (Active Directory) and encryption using WPA. Rather than setting a pre-shared key and distributing it to all the users I would rather have the AP automatically distribute the encryption key after the user has authenticated. Is this possible? If so, which Cisco AP's support this functionality?

I don't think you can do that. You might want to think about the following (if you have all Windows clients)
- Use PEAP machine authentication and push out the config (over the wire) via GPO
- Configure a domain controller with PKI (Certificate Services) and machine auto-enrollment. Use EAP-TLS for authentication, and push out the wireless config via GPO
- Use WPA with PSK and push out the config via GPO.
The only problem is that your wireless client config would need to be pushed out over the wire (not wireless) via GPO. This also assumes that your wireless supplicant is Wireless Zero Config (and not the Intel PROset or Cisco Aironet stuff).
I'm afraid you're going to have to touch the machines one way or the other, but you can touch them remotely (via GPO) or touch the manually to configure the wireless settings.

Similar Messages

  • Extending home wireless network with 802.11b/g Airport Expresses

    Home Setup: iMac with iSight G5 2.1GHz PPC, OS X Leopard 10.5.8, 2.5GB memory, 2 Airport expresses-802.11b/g.
    Up to just recently, I was able to use my AE's to create a whole house wireless network: one as my main network connected to my cable modem, and the other as a wireless network extender. My extender got pulled out one day accidentally, and when I went to plug it in it wouldn't reconnect to my network...and so the problems began. Airport Utility used to give the option of "Extending the Wireless Network", but no more.
    I've done a lot of searching through the forums regarding this issue, read through the sage advice by superusers Tesserax and Bob Timmons, and attempted to set up my main AE as my "WDS Main" AE and the other as my "WDS Remote". The WDS main connects fine to the internet, but the WDS remote continues to show a flashing amber light and inability to extend my wireless network. I've done soft and hard resets to the remote AE (which transiently gives me a green light, then back to flashing amber), network diagnostics using the Airport utility, but still no luck. The AE wireless extender continues to flash amber and is nonfunctional.
    AE Wireless extender settings reported:
    -WIreless Mode: Create a wireless network
    -Connect using: Ethernet
    AE Errors reported:
    -Ethernet Unplugged
    -Default Settings
    I setup the AE Wireless extender as a WDS Remote, it resets and shows "Normal" without problems reported in the summary window of Airport Utility. Connection indicated as "Airport (WDS)" and Wireless Mode reads "participate in a WDS network", but the AE is still flashing amber and will not connect to the internet or Main WDS wireless network.
    Went to the Genius Bar at the local mac store...they couldn't help at all.
    I'm out of answers...help?!
    Allan

    There are basically two "flavors" of WDS that the AirPorts support: static & dynamic.
    o A static WDS allows for a main, relay, and remote base stations in the configuration. This only operates in the 802.11g radio mode. Its advantage is it is well suited when you are trying to cover a considerable linear range ... like a rectangular house where the Internet connection comes in at one of the shorter sides and you want wireless at the other end. The biggest disadvantage of this type of WDS is that for every base station added, you lose half the overall bandwidth.
    o A dynamic WDS allows for only a single main and multiple remotes. Think of a wheel with the main at the center and the remotes as spokes of the wheel. The advantage of this type of WDS is it operates in the 802.11n radio mode and doesn't suffer a significant bandwidth loss like the static version.
    As a minimum, a dynamic WDS requires two 802.11n AirPorts (or Time Capsules). You can create a static WDS with either all 802.11g AirPorts or a mix of 802.11n & 802.11g AirPorts. Note; however, you cannot create a dynamic WDS with mixed mode base stations.

  • Network diagnostics asks for password for wireless network with no security

    hi
    I am trying to connect my Mac Pro to a wireless network which has no security settings. Other Macs in the house connect to the network with no problem, but the Mac Pro doesn't. I am setting up a new network as I have moved house. In the previous house the wireless worked fine on the Mac Pro.
    When I click on the Airport Icon in the menu bar, the search wheel shows and it finds the network, but when I click on the name of the network typically it doesn't connect. Occasionally it does connect, and I briefly have internet access, but then the number of bars on the Airport Icon gradually reduce and then I can't connect again.
    When I run Network Diagnostics from Safari, it finds the network also, but then typically asks for a WEP password for the Wireless Network when I haven't added any security to the network (occasionally it doesn't ask for a password and I can connect briefly)
    I have tried resetting my Time Capsule and creating a new wireless network with a different name, but still experience the same issues.
    I wonder if someone has any ideas as to what might be going on, and how I might be able to troubleshoot this.
    Thanks
    Nick

    It is one of mine. Yes. It connects to it no problem, just doesn't connect to the actual internet. Network diagnostics has all green lights until the ISP and/or Internet point. If I walk through diagnostics, it will get to the point where it says that the network requires a WEP password. I don't know why it does that because my network is not password-protected (husband claims it doesn't work well with his VPN system to get into work network). If I leave it blank, the connection will work. Eventually, after the computer is put to sleep, I will have the same problem upon waking up. I just tried renaming the network and removing all preferred networks and rebooting. Let's see how that works.

  • Creating a seamless wireless network with 2 AExpress units

    I have 2 Airport Express units in different parts of my house. I have struggled for YEARS trying to get them to create one seamless wireless network with the same name that I could float between. I have never been able to get that to work. anyone?
    I know that some of the problems MAY have to do with the non-apple router settings, but I just have never gotten a clear response form anyone about weather it is doable, and/or worth doing. I would settle for 2 seperate wireless networks that didn't compete with each other and/or constantly need re-booting to stay active. I am generally the most tech savvy person I know and am consulted on IT by friends and colleageus regularly, but I just cannot figure this one out..
    I am totally capable of setting this up, both in the router and the AE units, if someone can just tell me that;
    1) yes it is possible and it will work, and
    2) just set it up like this...

    Thanks for the clarification.  Check your AirPort Express devices one at a time, but other than different device names to avoid confusion.....AirPort Express 1, AirPort Express 2....for example, the settings should look this:
    Open AirPort Utility , select one AirPort Express, click Manual Setup
    Click the Wireless tab below th row of icons
    Wireless Mode = Create a wireless network
    Wireless Network Name = Your choice
    No check mark needed next to "Allow this network to be extended"
    Radio Mode = 802.11n (802.11 b/g compatible) a good choice, but you can choose other combinations by holding down the option key on your Mac while you click on the selection box
    Channel = Automatic
    Wireless Security = WPA2 Personal an excellent choice if all of your devices are compatible with this setting
    Wireless Password = Your wireless password
    Confirm Password
    Click the Internet icon
    Connect Using = Ethernet
    Connection Sharing = Off (Bridge Mode)
    Update to save settings
    Configure AirPort Express 2 exactly the same way and Update to save settings
    Then, power down the entire network.....all devices....order is not important
    Wait a moment, then start the modem/router first and let it run 2-3 minutes by itself
    Start each AirPort Express the same way
    Start each other network device one at a time about a minute apart
    Check for proper network operation
    IF....you did not have your AirPort Express devices in Bridge Mode before.....that is the reason why you are having issues now and also is the reason why the "roaming" network was not working.....assuming that there was a reasonable overlap in wireless coverage between the 2 Express devices, of course.
    If you want to try the "roaming" setup again, assign the exact same wireless network name, security and password to both Express devices and confirm again that both are setup in Bridge Mode as the very last step before  you click the Update button in AirPort Utility.
    Power down the entire network and start up in sequence as well as in the example above.

  • I am unable to join my existing wireless network with new AirPort Express

    I am unable to join my existing wireless network with new AirPort Express.
    I am using a DLink DI-524 Router, Windows 7 (64), and the AirPort Express.
    AirPort Utility will not recognize the AEX wirelessly, it will only recognize it when it is connected by Ethernet. I can then configure the AEX and verify that the settings stick once disconnected and then reconnected. However, even after that, it will not recognize the AEX once disconnected from the Ethernet cable.
    I followed the suggestions of several other threads on these forums. But I am unable to get the AEX to work.
    Any suggestions? Thanks in advance.

    Welcome to the discussion area!
    It's almost always a security setting that causes problems when the Airport Express (AX) tries to join a third party wireless network. The AX usually does not "join" correctly and that's why you can't see it on your wireless network using AirPort Utility.
    Using an ethernet cable is still the more reliable way to configure and adjust the AX, but if you are want to try to configure it using wireless, you must return the AX back to factory defaults as follows:
    Power down the AX
    Hold in the reset button +and keep holding it in+ as you plug the AX back in to power
    Release the reset button after 10 seconds
    When it is set to factory defaults, the AX broadcasts a wireless signal with a network name like "apple network xxxxxx" where the "x's" are either letters or numbers. You must look for this network by clicking on the fan shaped Airport icon at the top of the screen. If you don't see this network, then click Join Other Network to search that way. Unless you connect to this network, you will not be able to configure the AX using wireless.
    Do you know the exact security type that your D-Link router is using? That is the key element in the process.
    Open AirPort utility, click Manual Setup
    Click the Base Station tab to establish a name for the AX, device password and adjust time zone settings
    Click the Wireless tab
    Wireless Mode....Join a wireless network
    Wireless Network Name...must exactly match your D-Link wireless network name
    Enable ethernet clients if you want the port to be active (your D-Link must be compatible with ProxySTA for this to work)
    Wireless Security...exact setting of the D-Link network. WEP security causes a lot of issues. Try to use WPA/WPA2 Personal, which is far more secure.
    Wireless Password...must match the D-Link network
    Click the Music icon to enable AirTunes
    Click Update to save settings
    Any luck?

  • Unable to create a wireless network with my airport express.  Please help!

    I am trying to setup a wireless network with an airport express, and connect to it with my Macbook. I just bought both of these and haven't been able to get wireless to work.
    I initially plugged the ethernet cable from my cable modem into the airport express and plugged it into the wall. The macbook detected it when I opened airport utility, but the express had a flashing amber light and I was unable to connect. I then unplugged the express and re-started the cable modem. This time, the airport express showed a solid green light -which should mean that it is working correctly. However, the macbook did not find the airport express device when i searched for it using airport utility. I am able to connect the macbook directly to the cable modem, after re-starting the modem, and access the internet so at least some of the systems are go.
    Any ideas? Thanks in advance for your help.
    Tom

    Is the issue that you cannot access the 802.11n AirPort Express Base Station (AXn) with the AirPort Utility that is running on your Win7 PC? ...  or that once you have configured the AXn, the PC is unable either to find the new wireless network or can find it but cannot connect to it?

  • Extending an existing wireless network with an airport express

    My wireless signal is quite weak in my room so I'm looking for a way to extend the range of the network by using an airport express. I understand i can't do this wirelessly but is it possible to run an ethernet cable from my existing router to the airport express in my room and then have a stronger signal in my room?
    Thanks in advance!

    Welcome to the discussion area, Aaron!
    If you connect an ethernet cable from your existing router to the AirPort Express, and then configure the Express to "Create a wireless network" with the same name, security settings and password, this will in effect, extend your current wireless network.
    The Express must be configured as a "bridge" to operate correctly on your network when you do this, meaning that the setting for Connection Sharing on the Express will be set to "Off (Bridge Mode).

  • Windows phone security on wireless networks

    I am a post-doc at large medical center, and requested access to our secure wireless network due to the nature of my work. I was told by our IT support desk analysts that Windows
    Phone is not supported at our medical center (at all), because Windows phones are "too insecure to put on our network." Because of this, I either have to get rid of my brand new Windows Phone to get an android or I will never be allowed to have access
    to the secure Wi-Fi as necessary for my job. Any thoughts or suggestions? This seems to be a serious limitation of Windows Phone.

    Your support desk is outright lying to you. There is no issue with Windows Phone security on wireless networks, they just don't want to support your phone. It might be possible that Windows Phone doesn't support the particular kind of wireless encryption
    that your org uses, but I'm pretty sure that was all solved with Windows Phone 8.
    In fact, Windows Phone is more secure in some ways because unlike iOS and Android, you cannot override security certificate problems.

  • Can I extend my wireless network with my old Airport?

    Can I extend my wireless network with my old Airport? I have the airport extreme 802.11n & my old Airport (translucent white) base station. Can I mix the two to expand my range?

    No problem; ask as many questions as you need to.
    How do I reconfigure the Snow as a bridge to allow the AEBSn to continue to provide both NAT & DHCP services for the entire network?
    I don't have a Snow to verify this, but it should be similar to the later base stations when using the AirPort Admin Utility.
    To set up the Snow base station as a bridge, either connect to the Snow's wireless network or temporarily connect your computer directly (using an Ethernet cable) to the Ethernet port of the Snow, and then, using the AirPort Admin Utility (located in the \Applications\Utilities folder), make these settings:
    Network tab
    o Distribute IP addresses (unchecked)
    o Apply the new setting.

  • I have a mid-2010 iMac and just purchased a 2TB TC, can't join existing wireless network with AC standard so attached to iMac via ethernet with TC wifi turned off.  How do i access TC now? not showing up in disk utility or on desktop. working fine with TM

    I have a mid-2010 iMac and just purchased a 2TB TC, I just found out that it can't join existing wireless network with new AC standard so attached to iMac via ethernet with TC's wifi turned off.  How do i access TC now? not showing up in disk utility or on desktop. It is working fine with TM.  My cheeper seagate drives etc kept crashing, so i didnt trust cheeper back up options anymore.  Connected those drives to TM via firewire and could see the drives and access them.
    Also, I didn't want to bridge TC with my new fios router that I paid 100 dollars for, to get N speed and also paying 10 dollars more a month for fast speed.  I heard that bridging slows down everything and then there can be port issues with mail etc.  I connect to the internet via airport only and it is pretty fast. Getting over 50mbs downloads and over 30mbs uploads.  Plus everything in my home it connected to my fios router, airport express for music streaming, two apple tvs, vuezone camer system.  I really didn't want to monkey around too much with my system.  But are there other options to connect the new TC.  Can't find info anywhere for this and called apple who gave me the info above.  after hanging up, i see that i cant access my TC and I am wondering if i would have to reset it to turn wifi on again to make changes to the drive, turn off blinking light  or repair it in disk utility if it should become corrupted.
    For other with similar issues i did solve some other problems: when i connected it to my ethernet port on my iMac wifi stopped working.  Found that I had to turn off the ethernet in the system>network screen, but then TM didn't see the TC so i restarted after changes and then it saw it.
    Now a rant.  I can't believe in this wireless age that Apple would make a product that cant join a wireless net work.  The apple rep said i could return it and look for the previous TC that would join an existing wireless network.  Are we going backwards?
    Thanks!
    lennydas

    Ok... it is getting a bit clearer but there are still some questions.
    I connect to the internet via airport only and it is pretty fast.
    I was assuming airport in this statement in your first post meant the TC or the Express.. but I now realise we are still in the mass confusion stage where apple calls everything wireless an airport. So what you mean is the airport internal card of the computer??
    Also, I didn't want to bridge TC with my new fios router that I paid 100 dollars for, to get N speed and also paying 10 dollars more a month for fast speed.  I heard that bridging slows down everything and then there can be port issues with mail etc.
    I think this is mistaken.
    Putting the TC in bridge mode plugged into your FIOS will not slow the network.. nor will it cause mail or port issues.. in bridge the TC is just a fancy WAP and switch plus the network hard drive.
    If the computer is close it will be faster than the FIOS.
    You can run both wireless networks with different names.. so it is clear which is which. But you can also setup roaming so the computers themselves pick which is the best wireless.
    I tried extending the wireless net work and tried joining wireless network, but the TC kept crashing and I had to keep resetting the TC.  the Apple support person said these, extend wireless network and joint wireless network, are no longer a connection option with the new TC because of the new AC protocol.
    Thanks again!
    You cannot extend to a non-apple wireless router.
    You cannot use join a wireless network because when you do the ethernet ports will be cut off.
    But that has not changed.. I don't think Apple support is correct.. there has been no change with the AC model.. it is simply a fact that apple routers do not work in join wireless mode other than as a dumb client. The same applies to AC as to the earlier version.. but I have asked another person to check this.
    Join in the express is the only apple router that still allows an ethernet connection.
    For now you best use of the TC is bridged to the FIOS. Wireless you can sort out between several options.

  • How do I set up a wireless network with an AirPort Extreme base station and two airport extreme but between apple devices either by ethernet

    How do I set up a wireless network with an AirPort Extreme base station and two airport extreme but between apple devices either by ethernet

    This Apple support document provides good general information on configuring different types of neworks using multiple AirPort routers.
    http://support.apple.com/kb/HT4145
    In particular, you would want to focus on the information regarding a "Roaming Network"

  • I've got a wireless network with one iMac and a Vista PC, on the Vista PC is through USB a printer connected. How can i print from my iMac to that particular printer ?

    I've got a wireless network with one iMac and a Vista PC, on the Vista PC is through USB a printer connected. How can i print from my iMac to that particular printer ?

    You need to turn on Printer Sharing on both the PC and OS X. I can't help you on Vista but in OS X it's System Preferences - Sharing - check the Printer Sharing box.

  • Is there a way to play on the same wireless network with 2 different xbox 360 accounts?

    Is there a way to play on the same wireless network with 2 different xbox 360 accounts?

    Not sure what your question has to do in respect to Apple networking, but if you're asking can you use your Xbox 360 on a wireless network (regardless of the router's manufacturer) to access different Xbox Live! accounts, then the answer is yes.

  • HP LaserJet M1120 MFP will not print on wireless network with Windows 8.1 operating system

    The printer worked on the wireless network with Windows 8.
    I have been advised that it does not work with windows 8.1 because a driver is required. However this is not available to download.
    It is ridiculous that by having the latest operating system I am unable to use the HP printer on the wireless network
    When will HP have the driver to download?

    Check the support site here.
    http://h30434.www3.hp.com/t5/Printer-All-in-One-Software-Drivers/HP-LaserJet-M1120-MFP-will-not-prin...
    Make sure you have the firmware update also.
    Say thanks by clicking the Kudos Thumbs Up to the right in the post.
    If my post resolved your problem, please mark it as an Accepted Solution ...
    I worked for HP but now I'm retired!

  • Wireless networking with an iBook G3

    I'm having trouble connecting to the internet using an Asus WL-167G USB2.0 WLAN Adapter. The other computers on our network are Windows XP and our router is a Belkin wireless-G. I'm also new to Macs which doesn't help. Any help would be much appreciated.

    Hi, Fiona. Welcome to Apple Discussions.
    Part of the problem may be that an iBook G3 is equipped with USB 1.1. While most USB 2.0 devices are backwards-compatible with USB 1.1, it may be that the USB 1.1 connection is simply not fast enough to support wireless networking with your adapter.
    I recommend the original AirPort card for wireless networking with a G3 iBook, even though they are becoming scarce (and expensive). They are the easiest and best solution.

Maybe you are looking for

  • Installing Adobe Reader error code 1328

    Installed what I thought to be Adobe Reader but it was not.  It was a paid site displaying Adobe Reader. Now when down loading and attempting to install the correct Adobe Reader I receive an error code 1328.  Error applying patch to file C:\config.Ms

  • New aluminum keyboard, 1st Gen MacPro

    Curious about this.. I applied some kind of update after getting this keyboard for Christmas, firmware I guess. It works fine, but I am curious about the F17,18,19 keys. WOW doesn't seem to recognize them. Could be WOW but when I go into System Prefe

  • Ipod 5 not turning on

    So last night my ipod just shut down and it was fully charged. When I try to turn it on it wont even blink. I know i didnt shut the power. What should i do?

  • Need BAPI for G/L balance By cost center

    Hi all , i need a bapi or function module that returns G/L balance in  a given cost center (s) . so is there any thing like this in SAP  . thanks

  • Can I Change the Default TEMPLATE & Tracks ...

    Hey everyone. I would like to create a new podcast without having to change such a large amount of things with each track, adding more tracks, turning off ducking, etc. Is there a way that I can create a template that will the a custom amount of trac