WPA - Enterprise oddities, any suggestions?

We have a WPA/WPA2 Enterprise (PEAP) network and are having trouble with our users iPhones. (They work fine on the open network SSID, but would like to migrate to the somewhat more secure WPA or WPA2 model.)
Apple iPhones 2.2.1 [5H111]
Apple iPods 2.2.1 [5H11a]
Cisco APs 12.3(8)JA2 or 12.3(3)JEC2 (same results) (WPA TKIP and AES support enabled)
OUR STANDARD AP CONFIG: and our results
OPEN SSID (hidden) = iPhones works fine
WPA2 SSID (broadcast) = iPhones fail to connect (occasionally after certificate)
(BUT iPods work just fine!, as does Ubuntu, XP, etc.)
TESTED config 1: (but this setup is incompatible with our network design)
OPEN SSID (broadcast) = iPhone works
WPA2 SSID (broadcast) = iPhone works
TESTED config2: (not desired configuration)
OPEN SSID (broadcast) = iPhone Works
WPA2 SSID (hidden) = iPhone Works
The Standard config needs to be implemented and supported for a variety of reasons. (We use .1X to move clients to various VLANs behind that SSID so can't enable multi-broadcast on our equipment.) We need to broadcast our WPA network SSID instead of the OPEN SSID, but are having issues.
As this problem ONLY seems to impact our iPhone users, and not iPods, (with the same version of software) suspect there may be a simple setting on the phones or APs that we are missing. Anyone else ran into this and have any pointers?

We have also noted the very same problem with 1G iPod Touch. (Several users pointed this out after deployment.)
We have implemented a work-around by having a WPA2#2 SSID as a hidden so these iPhones and iPods can attach to the network. This now allows them to associate without a problem.
However on the hidden ID they seem to connect/disconnect from the network, and may require a user to go to the networks area to get connected after the device is left alone for some time.

Similar Messages

  • AP541N - WPA Enterprise - Failed to connect

    Hi,
    I am trying to configure an AP541N with WPA Enterprise. My RADIUS server is an MS ISA 2003 and is already working fine with other devices (I have a ASA5510 also configured to use RADIUS authentication with this server). When I try to connect, I am getting the following error message on the event log of the AP541N:
    Aug  4 18:37:36
    info
    hostapd
    wlan0: IEEE 802.11 STA 00:19:d2:9e:7a:81 deauthed from BSSID 00:21:29:01:60:e0 reason 1
    Aug  4 18:37:36
    info
    hostapd
    wlan0: STA 00:19:d2:9e:7a:81 IEEE 802.1X: Supplicant used different EAP type: 1 (Identity)
    Aug  4 18:37:36
    warn
    hostapd
    wlan0: STA 00:19:d2:9e:7a:81 IEEE 802.1X:  authentication failed - identity 'MYDOMAIN\myuser' EAP type: 0  (Unknown)
    Aug  4 18:37:36
    info
    hostapd
    The wireless client with MAC address 00:19:d2:9e:7a:81 had an authentication failure.
    Aug  4 18:37:36
    warn
    hostapd
    wlan0: STA 00:19:d2:9e:7a:81 IEEE 802.1X: could not extract EAP-Message from RADIUS message
    However, I do not see any error message on the ISA side. It actually tells me that the authentication happens fine. Any suggestion how I could troubleshoot this problem?
    Thank you in advance for your help and have a great day,
    Alex

    After investigation, I found that my ISA server was not configured properly. Here is the URL I used to configure it properly: http://technet.microsoft.com/en-us/library/cc779009(WS.10).aspx

  • Problems connectig using WPA Enterprise with Leopard

    I updated my software yesterday, but today i could not log on to the network at my university. There were no problems with the Windows XP pcs I tested. It wonder if it might have something to do with the password reseting itself - when I enter the network preferences screen the password section is blank even if I ask Leopard to remember it.
    It seems to accept my password and shows signal strength varying from between two points and full strength, but is listed as disconnected by network diagnostics.
    If any of you have experienced similar problems any help would be appreciated.
    -jonsef-

    Welcome to Apple Discussions.
    If you are using WPA Enterprise to connect, it's likely that you did so using 802.1X under Mac OS X 10.4 before installing Leopard. This mechanism has changed in Mac OS X 10.5 and it is clearly not performing as expected, and causing serious problems for enterprise and higher education users.
    Insert the string <802.1X> in the Search Box in the upper right corner, and you'll see a number of posts about this issue by academic computing staff personnel, who are working cooperatively to identify the issues involved, and find workarounds until the matter can be addressed by Apple.
    I suggest also that you contact an AppleCare representative at (800) APL CARE and initiate a case. Be prepared for very long wait on hold times, possibly 45 minutes or more. They are flooded with requests, but it's important that additional pressure be placed on them to escalate these reported cases for resolution.

  • Mountain Lion won't connect to WPA-Enterprise

    Configuration: Macbook Pro (8,2) running OS X 10.8.3.
    My office's "IT Guy" changed our Wifi network recently, with the surprise side effect that the Mac users are now offline, including me.  The odd thing is that my iPhone connects very nicely, as does my Windows (Bootcamp).  When I'm booted into Windows and connected, here is the information I can glean from the network manager:
    Security Type: WPA-Enterprise
    Encryption Type: TKIP
    NW Authentication Method: PEIP
    He suggested I buy a little USB stick that would connect me, but that is over my "lame-ness" limit.  The fact that the iPhone can connect but the Macbook can't is a little worrisome.  Do I have any hope, assuming that firing the IT Guy and buying the USB stick are both off limits?

    I had a similar situation happen to me today. Connecting to an Enterprise WPA2 network, and it authenticated correctly via PEAP (MSCHAPv2) but still would not show a good Connected status.
    What seemed to work was to go into Network preferences, click the Advanced button, Select TCP/IP tab, and click Renew DHCP Lease.
    Not sure why the MacBook did not connect, while the iPhone did, but this seemed to give the connection a good Connected status and the exclamation point on the WiFi network went away.
    And it's been 15 minute and the user has not come back to bug me again!

  • I'm trying to connect my MacBook Pro running on OS 10.8.2 to a Linksys EA3500 router and when I go to click on the set up icon I get an "unsupported operating system". Any suggestions on what to do? The Linksys site is useless.

    I'm trying to connect my MacBook Pro running on OS 10.8.2 to a Linksys EA3500 router and when I go to click on the set up icon I get an "unsupported operating system". Any suggestions on what to do? The Linksys site is useless. Do I need some kind of upgrade?

    Don't use the CD software its not necessary.
    Infact put it in the trash.
    Your router will have an IP address in the range 192.168.1.1
    Connect your router to your Mac via Ethernet cable (They usually supply one with the router and don't worry which end goes where the Mac LAN socket is bi-directional)
    Also connect your router to your telephone line.
    Now open your Web browser Safari . Type in the IP address above and a Javascript control panel will launch
    Enter the default password and username (They are on a label on the router )
    Your now have the ability to set up your router.
    Your will need the password and user name supplied to you by your ISP at a minimum.
    Enter these and most modern routers automatically configure the basic networking setting.
    You now need to go to the security setting and set this as WPA2 Personal (NOT Enterprise) or WPA2 with AES and TKIP which ever it refers to and create a pass-phase. WRITE it down
    You should be online.
    Now remove the cable and connect to the Wifi and enter that passphase.

  • TS1398 iPad unable to connect to Wi-Fi...while my other devices connect fine...any suggestions?

    My iPad can no longer connect to Wi-Fi (anywhere)...at home, I get a message that says "Cannot scan for networks" -- and at my office...I get a message that says "Unable to join the network".  Other mobile devices are connecting fine at both home and office.  Any suggestions?

    Look at iOS Troubleshooting Wi-Fi networks and connections  http://support.apple.com/kb/TS1398
    iPad: Issues connecting to Wi-Fi networks  http://support.apple.com/kb/ts3304
    iOS: Recommended settings for Wi-Fi routers and access points  http://support.apple.com/kb/HT4199
    Additional things to try.
    Try this first. Turn Off your iPad. Then turn Off (disconnect power cord) the wireless router & then back On. Now boot your iPad. Hopefully it will see the WiFi.
    Go to Settings>Wi-Fi and turn Off. Then while at Settings>Wi-Fi, turn back On and chose a Network.
    Change the channel on your wireless router (Auto is best). Instructions at http://macintoshhowto.com/advanced/how-to-get-a-good-range-on-your-wireless-netw ork.html
    Another thing to try - Go into your router security settings and change from WEP to WPA with AES.
    How to Quickly Fix iPad 3 Wi-Fi Reception Problems
    http://osxdaily.com/2012/03/21/fix-new-ipad-3-wi-fi-reception-problems/
    If none of the above suggestions work, look at this link.
    iPad Wi-Fi Problems: Comprehensive List of Fixes
    http://appletoolbox.com/2010/04/ipad-wi-fi-problems-comprehensive-list-of-fixes/
    Fix iPad Wifi Connection and Signal Issues  http://www.youtube.com/watch?v=uwWtIG5jUxE
    Fix Slow WiFi Issue https://discussions.apple.com/thread/2398063?start=60&tstart=0
    Unable to Connect After iOS Update - saw this solution on another post.
    https://discussions.apple.com/thread/4010130
    Note - When troubleshooting wifi connection problems, don't hold your iPad by hand. There have been a few reports that holding the iPad by hand, seems to attenuate the wifi signal.
    ~~~~~~~~~~~~~~~
    If any of the above solutions work, please post back what solved your problem. It will help others with the same problem.
     Cheers, Tom

  • LaserJet CP1525nw & WPA-enterprise

    We bought a LaserJet CP1525nw printer because of its airprint support for printing from our iPads. Our wireless network uses WPA-enterprise security.
     We are unable to connect the printer to the wireless due to the enterprise authentication. ipad is unable to find the printer.
     We need  printing from the iPads, ePrint does not offer.  Any help would be much appreciated. Firmware 20110329.

    Hello,
    If you have not already, I might recommend going here and then looking at the link for iPad printing for ePrint/Airprint or ePrint Home and Biz.  Good Luck!
    http://h10025.www1.hp.com/ewfrf/wc/document?docname=c02784317&tmp_task=useCategory&cc=us&dlc=en&lang...
    I worked for HP but my posts and replies are my own....Thank you!
    *Say thanks by clicking the *Kudos!* which is on the left*
    *Make it easier for other people to find solutions, by marking my answer with (Accept as Solution) if it solves your issue.*

  • Extend WPA Enterprise

    Does anyone know if there is any way I can connect my Time Capsule to my University wireless network?
    I live right opposite my university and if I put my laptop on my window sill I can connect to the wireless, but can't connect from my desk... I was wanting to put my time capsule on my window sill, use that to connect to the Uni wireless and thus extend the connection into my room...
    Does anyone know a way to achieve this? My Uni uses WPA Enterprise encryption...
    Many thanks.
    Andrew.

    One possible option, with your existing equipment, would be to reconfigure your Mac as a "software" router by employing OS X's Internet Sharing feature. In this case you would be sharing the Mac's wireless Internet connection through its Ethernet port. Theoretically, you could then connect the TC to the Mac's Ethernet port; reconfigure the TC as a bridge, and then connect clients to the TC.
    Personally I haven't tried this to verify that it would work. Mainly because using a Mac as a software router is extremely limited as far as features that this would provide.

  • WPA Enterprise won't authenticate

    I just upgraded my MacBook from Tiger to Leopard (latest upgrades installed). However now I can no longer access the wireless network at work. Each time I try the authentication fails. I should mention that when I had Tiger and connected it always gave me a warning about the certificate which I just clicked away and everything worked fine. With Leopard I don't get that warning, and don't get a connection. Nothing else has changed, and I can't remember the certificate message I got in Tiger.
    Any ideas?

    Don't know the answer to your question I'm afraid but what's the difference between WPA enterprise and WPA personal, and would I gain anything by using enterprise at home?

  • Wpa enterprise help

    I have a MacBook, that is running leopard. I am having trouble connecting to my schools wpa enterprise wireless. I am regestered to access the wireless, but am having trouble connecting. I think my problem is that i dont know how to tell the computer which domain on the wireless network. The connection i am trying to get has many domains.

    Ok, sorry for the super delayed response but I didn't have access to my laptop, then I was busy with midterms. I successfully connected manually with wpa_supplicant with this config file:
    [phil@pwned network.d]$ cat /etc/wpa_supplicant.conf
    ctrl_interface=/var/run/wpa_supplicant
    eapol_version=1
    ap_scan=1
    fast_reauth=1
    network={
    ssid="uw-secure"
    scan_ssid=1
    key_mgmt=WPA-EAP
    eap=PEAP
    identity="rofl"
    password="lolol"
    phase1="peaplabel=0"
    I then updated my uw-secure file so that it referenced the new wpa config file:
    [phil@pwned network.d]$ cat uw-secure
    CONNECTION="wireless"
    DESCRIPTION="secure uw"
    INTERFACE="wlan0"
    IP="dhcp"
    SECURITY="wpa-config"
    SCAN="YES"
    WPA_CONF="/etc/wpa_supplicant.conf"
    I then tried to connect with netcfg, and I got this:
    [phil@pwned network.d]$ sudo netcfg uw-secure
    :: uw-secure up
    wlan0 Interface doesn't support scanning : Device or resource busy
    wlan0 Interface doesn't support scanning : Network is down
    wlan0 Interface doesn't support scanning : Network is down
    wlan0 Interface doesn't support scanning : Network is down
    wlan0 Interface doesn't support scanning : Network is down
    - Network not present.
    any help would be appreciated.

  • WPA Enterprise Connectivity

    Hi - I'm currently in Baton Rouge, LA and attend school at LSU. Our wireless network, lsusecure, is WPA Enterprise, which is supposed to be compatible with iPhone 2.0. The problem is, I can't seem to connect to the network. I enter my LSU username and password, which works for connecting on a computer, and it consistently says "connecting to lsusecure" but nothing ever happens. I was just wondering if I will have to enter in more information about the network rather than just using my regular login information. If anyone could help, I would greatly appreciate it, as Tech Services at LSU currently has no information on how to connect.

    Guidedbyvoip, sorry your IT Dept is no help.
    But, here at LSU, we are here to help! Hope these directions can work for you as well, instead of needing a 3rd party config util!
    ccastl1, please follow the following directions to configure your iPhone to connect to our LSUSECURE wireless network.
    Note: The device must be updated to firmware 2.0 in order to connect to lsusecure
    1. Select "Settings"
    2. Select "Wi-Fi"
    3. Make sure Wi-Fi is turned on. If the device is connected to any other network other than lsusecure (it will usually connect to lsuwireless first) you must remove that network before connecting to lsusecure.
    4. Select the network it is connected to by pressing on the blue arrow to the right of the name.
    5. Select "Forget this Network"
    6. Choose "Forget Network"
    7. Select lsusecure
    8. Enter your PAWS Username & Password and press "Join" at the bottom right of the keyboard.
    9. Accept the certificate by pressing "Accept"
    You are now connected to lsusecure!
    Please contact us directly if you have any further questions or problems!
    Thanks!
    < Message was edited by: Host to remove email address>

  • Cannot switch between WPA2 and WPA Enterprise WiFi locations.

    Hello Everyone,
    I have two Wifi locations I use, a WPA2 and a WPA Enterprise. When I switch locations from one to the other it looks as if that the Airport express resets but does not let go of the active location. I have to manually turn airport off and then on again to have it kick in. Anyone experience this and have a work around?
    Thanks in advance,
    K.

    Look at iOS Troubleshooting Wi-Fi networks and connections  http://support.apple.com/kb/TS1398
    If none of the above suggestions work, look at this link.
    iPad Wi-Fi Problems: Comprehensive List of Fixes
    http://appletoolbox.com/2010/04/ipad-wi-fi-problems-comprehensive-list-of-fixes/
     Cheers, Tom

  • Connecting MBA to domain using WPA Enterprise

    Hi guys!
    I'm having "the usual" new MBA WiFi-problems, meaning my MBA keeps dropping the WiFi connection occasionally, but that's going on in another thread.
    I don't know whether this is a related problem, but I can't seem to connect the MBA to the WiFi network at the office at all. The network connection dialog tells me my connection needs WPA Enterprise credentials, but no matter what I write, I won't get connected.
    So I'll start with the basics. This works for every other device I have (PC laptop, iPhone, iPads and so on):
    Username: \\MyDomain\MyUserName
    Password: MyPassword
    But not for the MBA. For the domain/username, I've tried single \´s and /´s and just about any combination just in case this is a "Mac syntax thing" (this is my first Mac laptop), with and without the MyDomain part, lowercase, uppercase, quotation marks around the password (as I saw mentioned in some thread in the case of alphanumeric WEP, or some such), but nothing works. I don't remember the exact error message, but it has to do with the authentication server perhaps not being available.
    Apparently others have had problems with the WPA Enterprise connections as well, but could somebody just confirm that the \\MyDomain\MyUsename -syntax I'm using is indeed correct.
    Cheers,
    Kim

    Marc,
    I'm suprised that WPA works over WDS. I had thought that because WPA cycles the encryption key with each message transmission that the two Airport devices would quickly get out of sync.
    But I do respect Alan's opinion, so I'd give in to his statement that it does work, I'll be searching through the update readme's to see when it started working.
    You could always drop back to WEP encryption. Unless you have the FBI next door listening in and analysing all your network traffic, it's not going to be broken.
    WPA changes the encryption key with each wireless message, WEP doesn't. So in theory, with WEP, someone could analyse all your network traffic, looking for patterns. You can work out just how hard that is.
    If you choose an obvious password (like from a dictionary) it won't matter if you're on WPA instead of WEP, the Feds / hackers will be in in a short time.

  • Why does the WPA Enterprise Wifi Network not get displayed?

    I wanted to connect to the wifi of my university via eduroam and was not able to even get the eduroam network displayed in the list of Wifi networks. I'm sure that it was there, because I tried it on several spots and my laptop was always able to find it and connect to it. Could it be that WPA Enterprise is not supported? It's quite standard already, isn't it?
    There would be a second option to connect to an open network and add a VPN tunnel, but I could not find any vpn-Application for Firefox OS.
    Did I oversee something or is there really no possibility to access any of my university networks?
    I am using an Alcatel One Touch Fire (German language set) with current Firefox OS 1.1.0.0-prerelease

    It seems to me that WPA Enterprise is not currently enabled in Firefox OS.
    There are several bugs regarding this feature, among others: https://bugzilla.mozilla.org/show_bug.cgi?id=790056
    Regarding VPN, there is a recent thread, which also indicates that this feature is not currently supported. See the discussion here:
    https://support.mozilla.org/en-US/questions/967948
    It also lists the bug-id related to this features.

  • WPA enterprise on N9

    Hello,
    when I try to connect to my university network (WPA enterprise) with my N9, it asks me for a password for their certificate.
    It uses WPA2, TTLS PAP and a certificate. I installed the certificate chain and can view them in Settings -> Security -> Certificates.
    Do you have any idea what the password for the certificate is? My university says that there should not be any.
    I tried to select the certificate in Settings -> Security -> Certificates and to click on the bottom right button and then "Change password" but it just gives me "Keine" (none) in a small box at the top.
    Thanks in advance
    Ole
    PS: I just saw there is a Meego section, too, sorry.

    juhanima wrote:
    If the WiFi setup doesn't require a user certificate, you should select "None" for a certificate when defining the connection. The CA certificate(s) you installed earlier are used automatically as long as they are enabled for WiFi usage.
    Here are the settings for the network for a Nokia N82. Maybe, this will help shed some light on the issue. FYI - I could not make these settings work for my Nokia N8 as well. The IT help desk says they are unable to solve the issue.
    juhanima wrote:
    The connection dialog is supposed to show only actual user certificates to choose from, but it is a known bug in the current N9 FW that if you install something that is not a CA certificate it is taken for a user certificate by default and shown as an option in the connection dialog. The bug will be fixed in the next FW update I believe.
    I have only installed one CA certificate (the one which can be found at the link I provided above). It does not ask for any password when I install it.  When I go to Certificate Manager and try to change the password it informs that there is no password for the certificate. 
    juhanima wrote:
    On the other hand, if the connection does require a user certificate you should have received one from the network's administrator in a PKCS#12 package with a password. You need the password when installing the package and later when using the private key related to the user certificate. But it sounds like this is not the case, so just select "None".
    Hope this helps.
    Juhani Mäkelä
    Harmattan certificate manager maintainer
    So I did choose "None" as certificate. EAP Type - PEAP and EAP MSCHAPv2 as the EAP method. I could not connect to the network using these settings.  The certificate was installed at this point. If I try connecting using the certifcate it asks me for the password. So, right now, it is a problem connecting to the network. Would appreciate any help in this regard.
    Cheers
    Rahul

Maybe you are looking for