Questions tagged [802.1x]
23 questions
2
votes
1 answer
802.1x dynamic VLAN assignment not assigning VLAN
I recently dived into 802.1x authentication with dynamic VLAN assignment.
My current setup contains of:
- A client
- A SG220 Cisco switch (the supplicant)
- A freeradius (authenticator) based on an LDAP AD
- A FortiGate for firewall purposes and…
martijn
- 21
2
votes
0 answers
Virtual machines not working with 802.1X - Linux Bridge
I am experimenting 802.1X in my home lab. I have most stuff working but one problem I have is with virtual machines not being able to authentication onto the network using 802.1X. There is very little information online about it but from the odd…
Tipex
- 91
2
votes
1 answer
Still suffering from Windows NPS May 2022 Certficate Update
in May 2022 Microsoft changed the way that client certificates are mapped to AD accounts, causing 802.1X EAP-TLS computer account authentication to stop working.
Here is an additional resource with detailed background info on the Schannel<=>Kerbers…
namezero
- 181
2
votes
0 answers
Secure Diskless System - NFS as root
I've created a diskless Debian installation with root filesystem over NFS, and boot loader on a USB (this computer has issues booting from PXE for some reason). My setup is similar to the one described on the ArchLinux Wiki.
This has been working…
manutenfruits
- 121
- 3
1
vote
0 answers
eapol_test results aren't the same between Debian and Windows
In order to troubleshoot miscommunication between Windows PCs and FreeRadius 3.2.7.1, here for full story , i'm using eapol_test cli to validate EAP-TLS against FreeRadius. Used certificates in my context are delivered by on-prem Windows…
motorbass
- 433
- 9
- 19
1
vote
0 answers
Windows Server 2016 NPS with EAP TLS, Windows 10/11 clients, incorrect cipher?
G'day everyone!
I'd like to switch from PEAP-MSCHAPv2 user/password auth to certificate-based auth on my network. The current setup has been working for years without issues: two Windows 2016 domain controllers with NPS role, and Windows 10 +…
DominikP
- 92
1
vote
1 answer
Ubuntu 22.04 LTS: EAP-TLS not working
I'm setting up RADIUS server using FreeRADIUS and self-signed certificate. Tested using eapol_test and successfully logged in. But when I'm trying to add a PC running Ubuntu 22.04 LTS to the network, it failed to pass EAP-TLS authenticate. But if I…
RichardLiu
- 173
1
vote
0 answers
How to configure MACSEC Key Agreement (MKA) with hostapd & wpasupplicant?
I'm trying to setup MKA between some clients (using wpa_supplicant) and an authenticator (using hostapd).
Additionally I have a RADIUS server(using FreeRADIUS) that is going to be handling the authentication side of things.
So:
RADIUS server has…
A. Trevelyan
- 500
1
vote
0 answers
Any way to do virtual 802.1x inside Linux?
I'm trying to test out 802.1x in a virtual environment but I haven't been able to find any good resources/guides on how to do that.
The scenario is something like this:
I have a Linux host machine (OS: ubuntu jammy) with a couple of lxc containers…
A. Trevelyan
- 500
1
vote
0 answers
802.1x NPS Machine authentication
We are trying to implement 802.1x to authenticate wirelless users (Aruba Controller) through RADIUS (Windows server 2019 NPS),
For mobile phones and guests devices, we have successfully configured the authentication via user (AD Account) , but for…
Oualid ZAKOUR
- 31
- 1
- 3
0
votes
0 answers
Freeradius LDAP user group on radius accounting field
I have an freeradius 3.0.13.
I use it to authenticate WiFi users via 802.1x
The authentication is via ntlm and I use the ldap module to retrieve the user's memberOf info.
I wish to use freeradius to forward accounting informationio post…
Virivé Fabio
- 1
- 1
0
votes
0 answers
802.1X Authentication To Child Domain Controller
I have a forest domain environment using 802.1X to authenticate client domains. I have a child domain that gets disconnected every now and then due to weather and various other issues. Because of this I have a server joined to the top level domain…
JukEboX
- 899
- 4
- 20
- 55
0
votes
0 answers
How do I resolve the error "eap: ERROR: EAP-Identity Unknown" on freeradius with EAP-TEAP?
So I am trying to implement 802.1X authentication using freeradius as my RADIUS server. For the authentication method I have chosen EAP-TEAP. My client device (a Windows 11 PC) has the machine and the user certificate installed. Previously, just…
0
votes
0 answers
Meraki AP to FreeRADIUS stuck on Access-Request
I'm currently facing some troubles while trying to set up a Lab between Windows 11 PC (with Credential Guard & TLS 1.3 enabled by default) and a FreeRADIUS server using EAP-TLS.
Basically, it looks like
Where Win 11 PC is configured to use…
motorbass
- 433
- 9
- 19
0
votes
0 answers
Network policy server - Event 4402. Machine is sending it's own hostname as the doman name
We are seeing this error fairly regularly when a user tries to connect to our production SSID, there is no correlation I can find that causes the error. The setup is wireless authentication using 802.1x, we have a Cisco 9800 WLC and Windows 2022…
Jarad Downing
- 101