802.1x EAP PEAP MSCHAPv2 on Windows 7 Client.
I have problems autenticate a w7 client at our Enterprice WiFi network. XP, Apple clients and all SmartPhones works fine... We use Radius assigned Vlans based on username and ream routed on our Meru Network to Navis radius as centralied point of autentication. Navis proxes client autenticatinon recuest to the customers Radiuses based on the realm. Windows 7 32 client use the radius CA (installed and ticked) and EAP PEAP MSCHAPv2 in the SSID settings. The customer radius is an Freeradius. In autentication logs we se that the client sends the Maschinename, eg. Machine-x200/username@realm even we in the client settings, under SSID Propirties, Security, MS Protected EAP(PEAP), Settings and EAP-MSCAPv2 Configuration, have removed tick on the default setting: Use Autom. Windows-username... AND under Security Advanced (back one step), in the 802.1X Settings, choose User autentication only! (not user and maschine, mascine only or guest) and we have saved corectly username@reame =(username here) and password... in the username password Setting. Is it possible edit or change the way the client PC is sett up to prevent this? Is there any way make a policy setting? or is there other solutions? I have teste te Cisco: PEAP option too, but stil noe autenticatoin from Radius Thanks
January 24th, 2011 1:12pm

Hi, As I know, this goal cannot be achieved. Reference: Use the 802.1X Wizard to Configure NPS Network Policies · For authentication using Extensible Authentication Protocol – Transport Layer Security (EAP-TLS), select Microsoft: Smart Card or other certificate, click Configure, click OK, and then click Next. · For authentication using Protected Extensible Authentication Protocol – Transport Layer Security (PEAP-TLS), select Microsoft: Protected EAP (PEAP). In Eap Types, click Add, click Smart Card or other certificate, click the Move Up button to position a smart card or other certificate at the top of the list, click OK, and then click Next. · For secure password authentication using Protected Extensible Authentication Protocol – Microsoft Challenge Handshake Authentication Protocol version 2 (PEAP-MS-CHAP v2), select Microsoft: Protected EAP (PEAP). In Eap Types, click Add, click Secured password (EPA-MSCHAP v2), click the Move Up button to position the secured password authentication type at the top of the list, click OK, and then click Next. Regards, Sabrina TechNet Subscriber Support in forum. If you have any feedback on our support, please contact tngfb@microsoft.comThis posting is provided "AS IS" with no warranties or guarantees, and confers no rights. |Please remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
January 25th, 2011 2:55am

Thanks, I can not find howto run the 802.1X Wizard to Configure NPS Network Policies, and cant find or find NPS, I have looked into many forums, and find where og ho in my Norwegian version of W7 Prof. GmssiGmssi
January 27th, 2011 9:13pm

Hi Gmssi, You have posted a thread in English language forum. If you prefer using a language other than English, please submit a new service request on our Support Website so that the appropriate Microsoft engineer can assist you to resolve the problem in a more timely and convenient manner. For your convenience, I have included the following link here: http://support.microsoft.com/default.aspx?scid=/international.aspx Regards, Sabrina TechNet Subscriber Support in forum. If you have any feedback on our support, please contact tngfb@microsoft.comThis posting is provided "AS IS" with no warranties or guarantees, and confers no rights. |Please remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
January 28th, 2011 6:13am

Hi English is fine! this qind of Q. is there no support one te Norwegian pages! My Norwegian W7 is just different i the terms... My main problem is ther a way configing wlan settings to connect without sending mascinename/username... and do that in a file, scrip or policy with our Freeradius... All other equipment we use work fine, NOT W7 clients... - I used tre seconds setting up the Mac Book PRO, today! And now I soon used tre weeks find hoto make a workaround with W7... As I understand, NPS is not running on my PC client an in the forums it is refferd in may ways, the 802.1x wissard to, but not where I do find it....how do I run it... Install it. Do I nead to enable something? somewere In my MMC Snap-in there is not ther corect modules... Best RegardsGmssi
January 28th, 2011 4:25pm

Network Policy and Access Services (NPS) Tools (has no remote connectivity functionality) The NPS.msc can only be run locally on the server that holds the NPS role.
Free Windows Admin Tool Kit Click here and download it now
February 9th, 2011 7:17pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics