Questions tagged [802.1x]

7 questions
2
votes
0 answers

Secure Diskless System - NFS as root

I've created a diskless Debian installation with root filesystem over NFS, and boot loader on a USB (this computer has issues booting from PXE for some reason). My setup is similar to the one described on the ArchLinux Wiki. This has been working…
1
vote
0 answers

802.1x NPS Machine authentication

We are trying to implement 802.1x to authenticate wirelless users (Aruba Controller) through RADIUS (Windows server 2019 NPS), For mobile phones and guests devices, we have successfully configured the authentication via user (AD Account) , but for…
0
votes
0 answers

Windows client doesn't detect 802.1x on wired connections

We have 802.1x enabled for our wired connections and clients connect and authenticate fine (we also have a guest network for the unauthenticated). That is - MOST clients authenticate fine. I have one Windows 10 machine that refuses to authenticate…
Shaamaan
  • 327
  • 2
  • 7
  • 21
0
votes
0 answers

802.1x EAP-TLS certificates protection

I am trying to configure the network in my small office so that only specific devices can connect to the Ethernet ports. I have read that it is best to use 802.1x and EAP-TLS as the most secure method. I am trying to configure this with freeRADIUS…
bLAZ
  • 105
  • 1
  • 6
0
votes
1 answer

Simple way to secure a wired link with 802.1x in "peer to peer" mode without server

I have an Ethernet link between two Linux hosts with a static IP config using systemd-networkd on the both sides without router, DHCP server, etc. Is there a simple way to add a basic 802.1x security with only a shared passphrase (without…
0
votes
1 answer

802.1x Wireless with certificates for AADJ/Intune devices without user affinity

I can setup certificate distribution and wireless profiles in Intune for devices with user affinity and this works fine. The user account is synchronised with our on site AD server and NPS has an account to use for permissions. However for…
0
votes
0 answers

Wireless EAP / Freeradius, is there a way to check Mac Address in LDAP?

So we have EAP-PEAP over MSCHAP working. What I'd like to do is have a MAC Address check, for the purpose of making sure people aren't putting their credentials into random devices. I know SCEP would be the better option here, but this is where…