Wireless Access

last person joined: 21 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Wired Dot1X and PEAP

This thread has been viewed 3 times
  • 1.  Wired Dot1X and PEAP

    Posted Mar 05, 2014 02:49 PM

    Hi friends!

     

    I have a CPPM but not added to the domain (I got AD defined in to do a bind)

     

    I get this error with my wired dot1x anyone come across this?

     

    winbind.png



  • 2.  RE: Wired Dot1X and PEAP

    EMPLOYEE
    Posted Mar 05, 2014 02:50 PM

    What privileges does your bind account have in AD?

    You should really join CPPM to the domain.



  • 3.  RE: Wired Dot1X and PEAP

    Posted Mar 05, 2014 02:52 PM

    yep you are right I know, well I got this "political problem" there are you using wired dot1x where you are?



  • 4.  RE: Wired Dot1X and PEAP

    Posted Mar 05, 2014 02:52 PM

    oops - not sure what privilidges the account has need to check with wintel guys



  • 5.  RE: Wired Dot1X and PEAP
    Best Answer

    Posted Mar 05, 2014 02:58 PM

    CPPM has to be joined to the domain to read the MSCHAPv2 credentials....wired or wireless authentications.



  • 6.  RE: Wired Dot1X and PEAP

    Posted Mar 05, 2014 03:06 PM
    Thanks all very much appreciated!


  • 7.  RE: Wired Dot1X and PEAP

    Posted Mar 05, 2014 03:07 PM
    So am I right in thinking this is a kerberos thing?


  • 8.  RE: Wired Dot1X and PEAP

    Posted Mar 05, 2014 03:23 PM

    It is just the way AD stores the user passwords .  Because of this, joining the domain is necessary in order to interpret/read it.  

     

    If you're having "political" issues joining the domain, tell your administrators that they can join it to the domain for you.  The account and credentials used to join it to the domain are only used during the join.  Subsequent logon authentications are done with the bind account.  This account can have minimal rights in AD; typicaly configured as a "normal user".  



  • 9.  RE: Wired Dot1X and PEAP

    Posted Mar 05, 2014 03:27 PM
    Thanks for the advice and understanding, it never ceases to amaze me how sometime people resist change but there you go!