Questions tagged [802.1]

IEEE Standard for port-based Network Access Control

141 questions
5
votes
1 answer

Multiple Valid Certificates in Windows 7 breaking Wired 802.1x Deployment

I have a Wired 802.1x deployment using TLS machine authentication on Windows 7 (built-in 802.1x supplicant) with the necessary certs (FreeRadius v2.2.3 generated on Linux). Cisco C2960 POE switch is being used. On Windows 7: The Root CA exists in…
5
votes
3 answers

How to get decent WiFi despite a virtual Faraday cage

One of my clients is the local branch of an international airline. They have a small office in the secured area behind the ticket counters, and timeshare space at the ticket counter. I need to add a ticket printer out front, which I cannot (for…
MT_Head
  • 173
  • 7
5
votes
2 answers

Using 4 wifi channels rather than 3

I have a wifi deployment with about 60 access points, currently limited to channels 1,6, and 11. This is a college campus, and the residence halls can get quite noisy, from an rf perspective. We typically have about 30 devices per access point, but…
Joel Coel
  • 12,910
  • 13
  • 61
  • 99
5
votes
3 answers

Can a non-VLAN-aware switch pass 802.1q tagged packets?

Let's say I have a incoming connection which is fixed 1Gb/s with tagged packets. And lets say that I need to connect that connection to a device which is a 10/100 device, which deals with the tagged packets. Can I use a dumb (ie: non-VLAN-aware)…
David Mackintosh
  • 14,223
  • 6
  • 46
  • 77
4
votes
3 answers

Set 802.1Q tagged port on VLAN1 on Dell PowerConnect switch

I'm having big troubles when adding this Dell switch to my network. Here we use several VLANs to segment traffic. All switches (3com and DLink mostly) have configured the same VLANs, most ports are 'untagged' and belong to a single VLAN, except for…
Javier
  • 9,078
  • 2
  • 23
  • 24
4
votes
2 answers

802.1q PXE boot

I've been using CrucibleWDS for the past year to image machines in my environment. My dhcpd.conf file lists the PXE boot information for clients attached to the particular network I use for imaging. For efficiency's sake I'd like to merge that…
Adam
  • 45
  • 1
  • 4
4
votes
3 answers

Wireless LAN interference

I have set up at wireless LAN network in a small office, connected to a ADSL connection. Using a wired connection between a computer and the router, I get the expected ~8.5 Mbps down, and ~1 Mbps up. Using wireless connection, I get ~400 Kbps down,…
hstr
  • 143
  • 7
4
votes
5 answers

802.1x PEAP GPO that trusts self-signed CA certificate

I am working on a Freeradius backed 802.1.x authentication infrastructure for our wireless clients. I am using a rather generic Freeradius configuration with EAP-PEAP. Our clients are predominantly Windows XP SP3 machines but a few Windows 7 32 and…
user62491
4
votes
2 answers

802.1X needs single port per device?

We are planning to implement 802.1X. What is not clear is whether a switch supporting 802.1X can successfully and correctly authenticate multiple devices connected to the same switch port (e.g. if we have a department using a hub with a bunch of…
Alex
  • 1,768
  • 4
  • 30
  • 51
4
votes
2 answers

How can I offer 2.4 ghz wi-fi in a building with strong interference?

I have a few access points on one floor of a high-rise building. They support both 2.4 ghz and 5ghz. When I used 2.4 ghz, the channel management features did not seem to work and we experienced frequent problems. When I switched to 5 ghz the…
SLY
  • 1,286
  • 1
  • 13
  • 28
3
votes
0 answers

Active Directory expired certs causing issues with 802.1x authentication

We are in the process of rolling out 802.1x in our environment. With that said, there are quite a few clients that revert back to an older (expired) certificate which prevents them from authenticating and getting network access. Can the expired…
wam6187
  • 31
  • 2
3
votes
1 answer

Verifying RADIUS server is sending the correct certificates?

How can I see the TLS (SSL) certificates that my RADIUS server is using, to make sure it is sending the correct certificate and chain? I am implementing 802.1x authentication with a RADIUS server, but I have certificate acceptance problems on some…
Jan Fabry
  • 836
  • 1
  • 10
  • 18
3
votes
0 answers

Cisco SG300 switch does not send RADIUS messages to server for 802.1x

I want to eventually configure the SG300 to authenticate wired clients with 802.1x and Microsoft NPS (RADIUS). I am currently testing this setup using a single port (Port 7) on my SG300, a test machine, and an AD based Network Policy Server. The…
3
votes
1 answer

Configure FreeRADIUS with Active Driectory allow specific group of users to authenticate

In order to authenticate WiFi clients I use a FreeRADIUS server configured to check for user credentials in an Active Directory environment. Currently all users with a valid account are authenticated but I want a specific set of users, configured in…
Debian
  • 51
  • 2
  • 5
3
votes
1 answer

OpenVPN to host tap device having very large MTU

Question What is the minimum set of server and client configuration directives that I need in order to satisfy the following conditions? Virtual layer 2 ethernet network that will not be bridged with any other interfaces. VPN clients can exchange…
Iron Savior
  • 868
  • 1
  • 7
  • 14
1
2
3
9 10