networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 5 posts ] 
Author Message
 Post subject: 802.1x experiences
PostPosted: Tue Apr 17, 2012 2:01 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Fri Apr 25, 2008 2:16 pm
Posts: 1363
Location: Jacksonville, FL
Certs: CCNP, CCNA:Sec, MCSE
Has anybody done an 802.1x wired implementation using Windows 7 clients? I'm looking for any gotchas, experience, tips, etc.

_________________
"A problem well stated is a problem half solved". (Charles Kettering)


Top
 Profile  
 
 Post subject: Re: 802.1x experiences
PostPosted: Wed Apr 18, 2012 12:45 am 
Offline
Post Whore
Post Whore

Joined: Sun May 15, 2011 4:16 pm
Posts: 1423
Location: Belgium
Certs: CCNA Security, CCNP
Yes, I have.

Gotchas and tips:
- ARP Spoofing can get tricky in combination with 802.1x due to timers: http://www.networking-forum.com/viewtopic.php?f=36&t=30029.
- DHCP Snooping works great, but the 'no ip dhcp snooping information option' has to be used for most DHCP servers as 802.1x information is sent with the DHCP packets otherwise and the server can't figure out what this means.
- If authentication doesn't work or takes a long time, fiddle around with the timers. Windows 7 usually works though.
- 'debug radius brief' is your friend (assuming RADIUS is in play, which should be the case). As are 'term mon' andd 'show dot1x interface <int> detail'. Note that without 'detail' it's a different command here: with it, it shows you if authentication works for a connected client.
- In general most computers will work fine, if not, check for correct credentials and the service 'wired autoconfig' in Windows (which enables 802.1x). I've noticed a remarkable trend: infected/garbage-filled computers tend to have issues more often and sometimes don't send 802.1x credentials out every time a cable is plugged in. I personally call this 'added security' :-)
- Check your IOS version. Depending on how complex your 802.1x config is going to be, you may need a more recent IOS.

_________________
http://reggle.wordpress.com


Top
 Profile  
 
 Post subject: Re: 802.1x experiences
PostPosted: Wed Apr 18, 2012 8:20 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Fri Apr 25, 2008 2:16 pm
Posts: 1363
Location: Jacksonville, FL
Certs: CCNP, CCNA:Sec, MCSE
Are you using the native supplicant on Win7? Are you doing user or computer-based authentication?

_________________
"A problem well stated is a problem half solved". (Charles Kettering)


Top
 Profile  
 
 Post subject: Re: 802.1x experiences
PostPosted: Wed Apr 18, 2012 8:32 am 
Online
Post Whore
Post Whore
User avatar

Joined: Mon Jun 15, 2009 9:48 am
Posts: 2891
Location: Lynchburg VA
Certs: CC\NP\DP\IP\NA-Security\NA-Voice
are you doing anything fancy with your 802.1x setup? or just access/no access?

_________________
Freedom to all the people. Brave, true and strong.
Freedom to all the people. Unless I think you're wrong

dhimes.com


Top
 Profile  
 
 Post subject: Re: 802.1x experiences
PostPosted: Wed Apr 18, 2012 8:39 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Thu Dec 30, 2010 2:05 pm
Posts: 1133
Location: Stockholm, SE
Certs: CCNP, CCNP SP, CCDA, CCNA DC, CCNA W, HP MASE
I did an .1x project recently and we decided on using Cisco AnyConnect as suplicant, but that was most due to a vast amount of WinXP machines and to have unison functionality on both XP and W7.

The 'show authentication session' and subcommands are great for troubleshooting.

_________________
som om sinnet hade svartnat för evigt.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 5 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: Exabot [Bot] and 11 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group