WinXP/2k - 802.1x -FreeRadius : Authenticating before user logs in

B

blaqb0x

hi,

This is my situation. I'm using HP 2650/26226 switches (which support
802.1x port-based authentication ) and they are authenticating to FreeRADIUS
using PEAP and MD5-challange. However, on the FreeRADIUS server I am
authenticating only the MAC address of the supplicants by re-writing the
username as the MAC address. So in my authentication database the usernames
are MAC addresses of all my machines. This works great. However, the
authentication on Windows machines only gets initiated after someone logs
in. So if a machine is rebooted and doensn't get logged into, it will not
initiate authentication and not get on the network. I 've tried to set
"Authenticate as computer when computer information is available" and
"Authenticate as guest when user or computer information is unavailable"
and neither work. When do these 2 options do anyway? What credentials does
it send?

Any links, insight, or thoughts on the subject would be appreciated.

Thanks,
 
R

Ryan Hanisco

These options are there when you are using IAS, the windows version of
RADIUS. If you are doing EAP and have certificates installed, then the
workstation can log itself into the network and obtain an IP address as the
machine account. This allows GPOs, SUS, and things like that to operate at
the machine level.

You may be able to get that to work under PEAP, but I have not tried that,
and EAP is a much better way to authenticate hardware anyway.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top