Yet another PEAP question...non-Cisco cards...

So, we are about to embark on building a wireless network infrastructure using 1220 AP's. So far all wireless clients use Cisco cards and Win2k.
People are interested in all sorts of wireless devices now, some including built in wireless nics or no pci or pcmcia card slots.
We have ACS 3.1.1. Can we use PEAP in our situation with a client using say a Compaq tablet PC with an integrated NIC? Or, how about a desktop PC running Win2k using something other than a Cisco card? If so, what are the required pieces? PEAP supplicants? etc?
Thanks!

Hi ,
In short answer is
a) If ACS supports eap-chap ( which microsoft supports ) , you can use
non cisco card with microsoft supplicant and will work fine
I believe acs 3.2 will support is , I am not sure on acs3.1.1
b) You can buy 3rd party supplicant like meeting house etc and can use
non cisco card
http://www.cisco.com/warp/public/779/smbiz/wireless/wlan_security.shtml
http://www.cisco.com/en/US/partner/products/hw/wireless/ps458/prod_bulletin09186a0080100194.html
http://www.cisco.com/en/US/partner/products/hw/wireless/ps430/products_qanda_item09186a008010018c.shtml
PEAP is hybrid process ( combination of leap and eap tls )
To download server side certificate on ACS you can use eap tls doc.
Depending on AP use either of following doc
http://www.cisco.com/univercd/cc/td/doc/product/wireless/airo_350/accsspts/ap350scg/ap350ch8.htm
http://www.cisco.com/univercd/cc/td/doc/product/wireless/airo1100/accsspts/i1224ja/i1224icg/ivicgaut.htm
You have to careful while selecting the client supplicant , you can choose Cisco peap supplicant or Microsoft peap supplicant
You can have Microsoft peap supplicant or Cisco Peap supplicant .
If you have windows 2000 OS , than if you load service pack3 , Microsoft peap supplicant is installed . On top of this if you install ACU 5.05 microsoft supplicant wil be overwritten by Cisco supplicant .
In case of XP , if you install service pack 1 , it will install microsoft peap supplicant , if you install ACU 5.05 it will be overwriteen by Cisco Peap supplicant .
Microsoft peap supplicant send eap-Chap in EAP tunnel and Cisco support EAP-GTC in eap tunnel .
with non cisco card it depends on which radius server and database you are running .
At present ACS 3.1 supports EAP-GTC so it will not interoperate with Microsoft supllicant . In later release ACS will have support for EAP-Chap so
that you can use 3rd party card with Microsoft supplicant and ACS3.2
http://www.cisco.com/warp/public/779/smbiz/wireless/wlan_security.shtml
http://www.cisco.com/en/US/products/hw/wireless
Nilesh

Similar Messages

  • Yet another academic question - Latest Graphics Cards

    For those of you with the latest towers and graphic cards -
    Is there any option to effectively chroma/luma clamp the output from these ?
    Or if not is there the ability to adjust values in a meaningful way ...
    With nVidia software or with some third party application ?

    ok - I've headed over to nVid's site and got this snippet
    "Video Color Correction
    Corrects differences in color characteristics of RGB monitors and TV monitors and ensures videos are not too dark, overly bright, or washed out regardless of the video format or display.
    Integrated TV Output
    Provides world-class TV-out functionality (Composite/S-Video/Component) up to 1080i resolution."
    Can anyone have a quick squiz in the nVidia app to see if the above can be got at or altered -
    or is it a blanket, "We know better than you - so we have set it up to compensate for your own ineptitude."
    lol, no offense meant.
    cheers
    edit: What there ?
    RGB's, gamma, luminance values - sorry don't have access to check it for myself. tia

  • Is "client power management" understood by non-Cisco cards?

    I would like to tailor the "power client" IOS command to instruct WiFi adapters to limit their max transmiting power.
    Will this be understood by non-cisco cards? In other words: is this a standard 802.11 power management command?
    I am a little bit confused, because the documentation says that in order to use this command, "Aironet extensions" must be enabled....

    What you are describing is often referred to as DTPC (Dynamic power control or Dynamic transmit power control). The following link shows the syntax for it. It only works with clients that support DTPC. This is a capability of clients that support CCX (v4 I believe). Most modern client adapters support CCX, as long as you are using their client software (such as ProSet for Intel). If you tell us what cards you have I can try to find if they support CCX and DTPC.
    http://cio.cisco.com/en/US/products/hw/wireless/ps430/products_configuration_guide_chapter09186a0080606d4a.html#wp1034946
    - Eric

  • Another peap question ...

    Who is really using peap right now? =) And does it really works perfect?
    I play around since about 2 month with peap and i got it working 2 times.
    Now i have to implement it at a customer site. yeah =)
    I have now ACS 3.2 AP1100 and i got it work againts AD one time on ONE laptop (2k SP3) with cisco card. I have also another laptop with orinocco nad xp and there it doesnd work.
    The one nb with worked went in standby mode then i wake him up and then i have to reenter the username and password. Doesntwork!! disable the card avtice the card doesnt work.
    Yesterday i have tested it with an AP350 vxworks and an upgraded AP1200 from vxworks to ios doesnt work (same config as 1100)?!?!?
    i cant find any REALLY usefull documentation how to !! configure PEAP RIGHT, on the cisco site there is an document with how to config an ap1100 and there are screen shots of an ap350 =) the newest ios also hase some new features (wpa and so on) which i dont know which is to activate witch not.
    im really a bit frustrated.
    Has anybody got Peap really working with: AP1100 ACS 3.2 (not really out now but i got it for tests (mschapv2) i have also tested it with 3.1 i got it running ONCE!) and laptops with 2k and xp?
    hope somebody could help me =)
    regards Bernhard

    Peap will work absolutely fine in AP 1100 with ACS 3.2 . But I have come across scenarios in which there are issues when using the 3.2 Beta version.
    I think the follwoing is the document you are referring to ( The screenshot is for 350AP):
    http://www.cisco.com/warp/public/cc/pd/witc/ao1200ap/prodlit/peapr_tr.htm
    Eventhough the screenshot is for AP350, this is applicable to the AP 1100 also. The same procedure can be followed.

  • MS Peap,XP SP1,Non Cisco Card, ACS 3.2,Ap1200

    Hi,
    I am trying to set up MS Peap with the required hardware. I have read through the document ID:43486. In this, the software they use to test for AP1200 was 12.01T.
    My query is that I am running 12.2(13)JA3 the latest and greatest on Ap1200. Will it work for Peap or I can only setup Peap with the 12.01T.
    Can you please recommend any documentation. Since a month I am trying to get it working.
    Hardware:
    ACS 3.2
    Linksys Wireless Card
    Xp Sp1
    Regards
    Khaleefa Mahmood

    Yes, 13JA3 works with PEAP just fine.

  • Yet another pointless question about the practically non-existent iMac G5 Apple Hardware Test (AHT) disk.

    I have a 17" iMac G5 (iSight model) also known as model A1144, PowerMac12,1 or MA063LL/A.
    Where do I download the Apple Hardware Test (AHT) disk for this machine? Apparently nowhere. However, it would really help me on my quest if I knew what I was looking for.
    Does anyone know what AHT version is compatable with my machine? 2.2.1? 2.3.1?
    How about the part number on the disk? I have some Intel disks that say 2Z691-5734-A that (obviously) won't work.
    Is the AHT on Disk 1 or Disk 2? I'm starting to think there never was an AHT for this model.
    Where do I get those ASD disks the so called "geniuses" have?

    Disk 1: 2Z691-53179-A
    Disk 2: 2Z691-5493-A
    Compatible with eMac (2005), iBook G4 (Late 2004), iBook G4 (Mid 2005), iMac G5 17-inch (ALS), iMac G5 20-inch (ALS), iMac G5 (17-inch iSight), iMac G5 (20-inch iSight), iMac (Early 2006 17-inch), iMac (Early 2006 20-inch), Mac mini, Mac mini (Late 2005), Mac mini (Early 2006), MacBook Pro, Power Mac G5 (Early 2005), Power Mac G5 (Late 2005), PowerBook G4 (15-inch Double-Layer SD), PowerBook G4 (17-inch Double-Layer SD)
    http://www.welovemacs.com/2z69153179a.html
    AHT I think was on a seperate CD.
    Thanks Kappy, if v2.2.1 then search for...
    018-1680-A.dmg

  • Yet Another Workflow Question

    Ok I too, like many others here, am new to the Mac (thanks to Apple's I'm a Mac, I'm a PC ads that my wife couldn't get enough of). I have done some searching around and I see that there are quite a few iMovie workflow questions out there. I have not quite found what I am looking for however, so I thought I would make my first post tonight. So here it goes...
    I have 3 different ways I capture video:
    1. Canon Vixia HF10 (HD)
    2. Canon Powershot (SD)
    3. Blackberry Storm (SD...I know it isn't a good phone)
    I record everything to SD cards. I am wanting to know the best way to store my raw video for editing at any time. Do I copy the AVCHD file structure (for the Vixia) and .avi files (for the other non HD) to my hdd, or do I just import into iMovie '09 and let it reside there, or both? I noticed that iMovie had an archival option (which appears to just copy the AVCHD structure to my hdd), which is why I ask. I want to always keep my raw video in case I decide to go back later and create a new video.
    After I have the raw video archived, I would like to know the best way to use iMovie. Depending on where I end up storing the raw video, should I keep the imported video in iMovie once I am finished with a project, and then reimport it at a later date if need be? Or, do I leave it in iMovie as events? I guess this all rely depends on the first question...where do I store the raw video for archival purposes...
    Finally, when exporting my iMovie project, should I store that in more of a, pardon the Windows reference, "My Videos" folder with a original size, web optimized size, and ipod optimized size? Thus, keeping the actual exported version of the project separate from the raw video?
    I hope I have asked the right questions here. I appreciate any and all help I can get!
    Ron

    Welcome Ron to the  iMovie boards..
    very interesting : 'switchers' care sooo much for 'storage strategies' ..
    the by Apple intended workflow/concept for iApps is:
    any 'photocam' related material (still or movin') comes-in via iPhoto, and is stored in an iP Library (=you can tell iP to create 2/many Libs, if you prefer to organize manually....)
    any 'camcorder' related material HAS to be imported by iM - why? because, iM has some internal routines to make such material editable (codecs, thumnails, stuff....). the same material as 'file by Finder' does not import.. in most cases!
    storage..
    iP stores in its Library (local/internal HDD and/or ext. HDD)
    iM stores in Events (local/internal HDD and/or ext. HDD)
    to make Projects/Albums accessible to any iApp, you should keep your fingers off that structure.
    Erasing Events 'kills' projects.
    allthough, once 'shared to media browser' there's a 'copy' of your project WITHIN the project file. (= the socalled Media Browser is no single Folder somewhere hidden in the system)
    there's this Spacesaver feature to erase any Event content which is not in use in any project to keep Events lean.
    use the Archive feature from within iM to keep things easy and convenient.. if you miss a single file of the SDcard file-structure, the whole card's content is kaputt ..
    summary:
    • use iApps as intended.
    • use iP for cameras, it stores 'raws' (the avi too)
    • use iM for camcorders, use Archive to store raws..
    • purchase a dozend of HDDs to store your material..

  • Yet another standby question...

    Hi gurus,
    Please help to resolve the quiz. I have completed manual physical standby installation. It is up and running. I then decided to install Grid Control and to use Data Guard for the standby creation. I've successfully installed GC, deployed all agents, I can see my previous standbys, life is good in short. Now, when I am trying to create the second standby for my production database using the Data Guard I stuck on a logical question:
    On the step 3 of Data Guard standby creation, there is a note, saying:
    The instance name (also referred to as the SID) must be unique on the standby host.
    Yeah, fair enough. But i can't understand what should I do next? I have:
    db_name YELLOW - primary prod
    db_name YELLOW - standby prod 1st
    and i need db_name YELLOW - standby 2nd
    But I can't create it on the same server where the first standby resides.. What options do I have? Do I need to create the second standby on another server? Do I need to kill 1st standby? Is there any way to avoid this conflict? I am confused. I have no equipment for TWO standby servers... I thought I can install there up to 9 standbys.. But it seems to be a problem.. And definitely, I cannot give my second standby other name than YELLOW as all my applications are strongly tied on db_name...
    Friends, please clarify this if you can. I am kinda lost in here..
    Thanks as usual,
    Maria

    well, that's a good question! :)
    because I don't have spare server for the standby. the question is not about: 'should I or should not put more than one standbys in one server' , but more about: 'is there any way to put two standbys with the identical db_names in one server'. I know that I probably sound unprofessional, but I just wanna know.. If the answer is 'no way', I will kill the first standby then and recreate the second one using DG with the correct name.
    Thanks for writing to me,
    M.

  • Site survey on non cisco card

    We currently own several Cisco aironet cards which we do site survey's with. As a company standard our laptops were replaced with new laptops which did not include type II pcmcia slots. Is their a solution for the express 34/54 slots to work with the Cisco aironet site survey software?

    I have seen PCMCIA to USB adapters but I think they need to be cutom made for each type of PCMCIA card. Does anyone know of a suitable adapter?

  • What Non-Cisco Cards or Built-in Cards work with LEAP?

    I have just installed ACS and LEAP and have several Laptops in my office that have built in Wireless NIC's. I have read many posts that say this one or that one works with the right drivers, but none that list all the one's that will work with LEAP. Thanks for any assistance you can give.
    David Beaver

    http://www.cisco.com/en/US/partners/pr46/pr147/partners_pgm_partners_0900aecd800a7907.html
    Cisco Compatible wireless clients will feature the Cisco Wireless Security Suite, which includes the Cisco EAP (LEAP) 802.1X authentication type. Customers can implement the award-winning Cisco security solution across Cisco clients and those of other suppliers. The program provides complete support for Cisco VLANs, providing benefits such as flexible security schemes in a mixed client environment and optimized performance in Cisco VLAN deployments. And because Cisco Compatible wireless clients are IEEE 802.11 compliant and Wi-Fi certified, they are fully compatible with other Wi-Fi certified products.

  • Yet another CENTERing question

    Yes, I've looked through tons of the centering questions
    already posted here, but couldn't find precisely what I need to do.
    Basically, I'd like to have the center section a fixed (or minimum)
    width and the two side sections liquid. I know how to do this with
    tables, but am learning CSS (have built a couple sites already) and
    would like to do this in CSS. There must be a way!
    Here's the comp of the layout:
    http://www.evfreefullerton.com/pdf/EvFree_index.pdf
    I'd like those edges to expand with the browser window and
    the center section to remain in the center regardless of window
    size, does that make sense?
    Help!

    On Thu, 16 Aug 2007 01:52:31 +0000 (UTC), "suebeee"
    <[email protected]> wrote:
    >Yes, I've looked through tons of the centering questions
    already posted here,
    >but couldn't find precisely what I need to do. Basically,
    I'd like to have the
    >center section a fixed (or minimum) width and the two
    side sections liquid. I
    >know how to do this with tables, but am learning CSS
    (have built a couple sites
    >already) and would like to do this in CSS. There must be
    a way!
    >
    > Here's the comp of the layout:
    >
    http://www.evfreefullerton.com/pdf/EvFree_index.pdf
    >
    > I'd like those edges to expand with the browser window
    and the center section
    >to remain in the center regardless of window size, does
    that make sense?
    >
    > Help!
    use a wrapper for the whole page and centre it with
    margin:auto
    like this:
    <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0
    Transitional//EN"
    http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
    <html xmlns="
    http://www.w3.org/1999/xhtml">
    <head>
    <meta http-equiv="Content-Type" content="text/html;
    charset=utf-8" />
    <title>Untitled Document</title>
    <style type="text/css">
    <!--
    body {margin:0; padding:0; background-color:#CCCCCC;}
    #wrapper {width:750px; background-color:#FFFFCC; margin-left:
    auto;
    margin-right: auto; padding: 5px;} /* it's the two margin:
    auto that
    centres the block on the page */
    -->
    </style>
    </head>
    <body>
    <div id="wrapper">
    <div id="content">
    <h1>Page Title </h1>
    <p>test text It is the star to every wand'ring bark,
    within his
    bending sickle's compass
    come; love's not time's fool, though rosy lips and cheeks.
    Oh, no,
    it is an ever fixed
    mark love alters not with his brief hours and weeks, admit
    impediments; love is not
    love. It is the star to every wand'ring bark, or bends with
    the
    remover to remove.
    <p>Within his bending sickle's compass come; if this be
    error and upon
    me proved, oh,
    no, it is an ever fixed mark. </p>
    <p>
    <!-- END content --></div>
    <!-- END wrapper --></div>
    </body>
    </html>
    ~Malcolm N....
    ~

  • Yet another photo question -- better to stream or sync?

    I plan to purchase an ATV this weekend and need help choosing between the 40 and 160 models. Though I've read dozens of posts, I'm still confused whether streaming or syncing photos will work best for me. My understanding is that I will only need the 40GB if I stream (ignoring other HD uses).
    My photo setup: I currently have about 10,000 pix stored on a NAS drive and add to them weekly. My itunes runs on a PC (sorry) and I manage photos with Adobe Lightroom and Photoshop.(I do not have Photoshop Elements). Network is hardwire 100MB.
    My goals:
    1. To view my pix on ATV with the least additional workflow relative to my current habit of downloading and managing images in Lightroom (i.e. need to transfer or rename files to view them in ATV, etc.)
    2. To have the best possible viewing performance (i.e. no lag, easy to find pix, etc.)
    3. Spend as little as possible (i.e. no new software, 40HDD)
    How does streaming compare to syncing given my needs?
    What size drive?
    Thanks in advance for the help. Sorry if the answer is obvious.
    Ken

    Welcome to the  Discussion Forums.
    In most cases setting up your itunes as a syncing or primary library is a better option, it gives you much more functionality. What you should remember is that even in the role as a primary library you do not need to sync all your content as you have the option with a primary library of syncing or streaming your content.
    This doesn't apply to photos though, so if you set itunes up as a primary library you must sync your photos, if you set it up as a secondary library you can only stream them.
    Question to ask yourself is how many of the photos will you want on the tv, I have about 14,000 photos but only have about 4,500 on the tv. Many of my photos were taken on digital cameras as far back as 1995 when photo file size was quite small hence I have about 4 GB of photos on the tv.
    I sync very little else and 4 of my 5 tv's are 40 GB and the other tv doesn't really have anything different on. You do use a little space for temporary storage of purchases and rentals you make via the tv, but I rarely ever have more than 10 GB of such content at any one time.

  • Yet another ramdisk question

    What I am trying to achieve is to load the system  into ram, then turn off the hard-disk: ( hdparm -Y ). I want to do this in the hope to extend battery time. I want to make it in a way that I can choose between normal and powersave mode during boot up ( grub ). In the powersave mode I would only use the console ( no X ), mostly programming, ircing, nothing memory/cpu intensive. I thought about mounting a usb-pen drive where I can save my work, and during boot, i could resync the work directory with the hdd. I have 2gb of ram, which I think is enough to handle the task. I only need help in how to set up the system to run in ram, the other stuff i can figure out. If anyone have done something similar or you can help me reply. Thanks.

    When I raised a question on the www.linuxquestions.org forum about offloading some apps into RAM, one of the moderators suggested that I take a look at how Puppy Linux works. You might want to look into this. Apparently Puppy Linux can load itself entirely into RAM with each session, then copies critical data, including your configuration files, onto your hard drive when you shut down.
    You could play around with Puppy Linux to see how it works, and you could probably get some good ideas from the scripts that are used to do all this.
    Last edited by dhave (2009-03-12 13:34:41)

  • Yet another wireless question

    I am attempting to add a wireless nic card to a g3 blue and white. It is running Mac OS 10.2.8.
    From the previous discussions I have read about wireless in this forum I was under the impression that either a
    Buffalo WLI2-PCI-G54S (broadcom chipset?) or a Belkin F5D7000 card would work.
    Needless to say I have had no luck with either card. I have purchased (new) both cards, installed them in the each open PCI slots (#1 is occupied by the monitor card) and they are not recognized. At least as far as I can tell (what is this mysterious 'airport' thing I'm supposed to be looking for?).
    I open the System Preferences-->Network and there are three things listed under Show: Internal Modem (installed that earlier) Built in Ethernet and Network Port Configurations.
    Went into Applications->Utilities->Airport with no luck either.
    Any suggestions would be appreciated.
    Thanks
    G3 Blue and White   Mac OS X (10.2.x)  

    I am not sure with the buffalo, but i know that with the belkin F5D7000 they used a number of different chipsets on the card only the version that had "broadcom" on the big black chip will work. I have a Belkin F5D7001 that i use in both 10.3 and 10.4 In both cases it is seen as an air port extreme card. It only worked in 10.3 after i did all the updates. It is unsuported by belkin in macs but works fine. It may not work in 10.2 though depending on weather or not you can install the airport extreme update. It did not show up in my system profiler after a recent fresh install of 10.3 until i did all the updates (over wired ethernet) after that the wireless card worked right away.

  • Yet another RESETLOGS question

    I have read the threads here about the RESETLOGS command.
    I know we have to do it after an incomplete recovery.
    I know it ensures that log files applied in recovery can never be used again.
    It permanently deactivates all transactions that existed in the non archived log files so that they can never be recovered ...
    What I would love to know is what happens if we didn't use this command?
    I read here that Ïf these transactions were not purged, the log files would create bad archived logs.
    Could anyone explain this a little better than the documentation does? What precisely would a bad archive log be?
    Thanks.
    DA

    I know it ensures that log files applied in recovery can never be used again.
    It permanently deactivates all transactions that existed in the non archived log files so that they can never be recovered ...
    Issuing a resetlogs simply resets the log sequence counter. But it doesn't 'deactivate' something to prevent future recoveries. Indeed, even back in 7.3, it was possible to perform a 'recovery through resetlogs' or, as I preferred to call it, 'recovery despite resetlogs': provided you had a copy of the controlfile from before the resetlogs and a manually-produced "precautionary backup" of your online redo logs from before the resetlogs, you could perform a recovery using archives that were produced from before and after the resetlogs. 10g has institutionalised this capability, in fact: it now includes a %r variable in the log archive format so that the resetlogs incarnation is recorded so that you don't even need to have a prior backup of the controlfile: you can recover almost as if the resetlogs had never happened.
    Certainly the transactions that were not replayed at the point you performed the resetlogs cannot be replayed. But that's done by 'branching' the redo rather than 'deactivating' it. The record shows that incarnation 1 ran until SCN 19346, at which time incarnation 2 was created. Future recoveries relying on your pre-resetlogs archives know to stop applying redo from incarnation 1 at 19346 and to switch to incarnation 2 redo after that time.
    If you didn't issue a resetlogs, you wouldn't be able to open your database. Simple as that. You cannot have some redo left in the redo stream which has been un-replayed and open the database normally as if nothing had happened. A resetlogs usually means you have chosen to perform a recovery that has resulted in the loss of committed data (from the time after the point you chose to halt recovery). The resetlogs starts the log sequence from a new starting point and increments the incarnation key of the database so that it's obvious that at point X, deciding to lose committed data was something you chose to do.
    You can replay all redo, lose no committed data, and not do a resetlogs; or you can replay some of the redo, lose committed data and do a resetlogs. But you are simply not allowed to choose to lose committed data and then behave as if nothing had happened.

Maybe you are looking for