 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Answers &#187; Radius</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/tag/radius/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers</link>
	<description></description>
	<lastBuildDate>Tue, 21 May 2013 16:56:46 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>NPS RADIUS auth problem</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/nps-radius-auth-problem/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/nps-radius-auth-problem/#comments</comments>
		<pubDate>Tue, 19 Apr 2011 11:38:16 +0000</pubDate>
		<dc:creator>I486dx266</dc:creator>
				<category><![CDATA[IAS Server]]></category>
		<category><![CDATA[Radius]]></category>
		<category><![CDATA[Radius Server]]></category>
		<category><![CDATA[RODC]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[We have an NPS RADIUS auth. problem. Currently we are running a site with 1 RODC and 1 RWDC in paralell as we are transfering all the services to the new RWDC and preparing to demote the RODC. What is left to transfer before i demote RODC is NPS. We were testing RADIUS yesterday evening [...]]]></description>
				<content:encoded><![CDATA[<p>We have an NPS RADIUS auth. problem. Currently we are running a site with 1 RODC and 1 RWDC in paralell as we are transfering all the services to the new RWDC and preparing to demote the RODC. What is left to transfer before i demote RODC is NPS. We were testing RADIUS yesterday evening by powering of the old RODC and switching RADIUS server IPs on the APs. I installed NPS on RWDC and ”copied” the settings to match RODC. Made a wireless policy and created the RADIUS client entries. Checked Shared secret on both AP and NPS. Added RWDC to RAS and IAS servers group, rebooted and requested RAS and IAS server certificate. Checked certificates. Trusted Root Certification Authorities match and Intermediate Certification Authorities match on both DC&#8217;s. BUT&#8230; We can’t get the clients to auth. The clients Wifi NIC hangs on ”confirming identity” when RADIUS server is set to the RWDC in the AP the client is connecting to. RODC or our backup NPS in a remote site works. Must be something i’m missing&#8230;<br />
Ran wireshark on the client NIC as it was connecting.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/nps-radius-auth-problem/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tacacs and authentication on Cisco routers</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/tacacs-plus-authentication/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/tacacs-plus-authentication/#comments</comments>
		<pubDate>Tue, 28 Dec 2010 07:58:45 +0000</pubDate>
		<dc:creator>Ekansh</dc:creator>
				<category><![CDATA[ACS]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Cisco Routers]]></category>
		<category><![CDATA[Radius]]></category>
		<category><![CDATA[Telnet]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[We have ACS 3.X server for tacacs + and radius authentication in our lan switches. right now i am able to login through tacacs+ only. I want to enable tacacs+ as well as local telnet login . This will help me to login in switches if the tacacs will fail.]]></description>
				<content:encoded><![CDATA[<p>We have ACS 3.X server for tacacs + and radius authentication in our lan switches. right now i am able to login through tacacs+ only. I want to enable tacacs+ as well as local telnet login . This will help me to login in switches if the tacacs will fail. <br/><br/></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/tacacs-plus-authentication/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>RADIUS Server Authentication</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/radius-server-authentication/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/radius-server-authentication/#comments</comments>
		<pubDate>Sat, 20 Nov 2010 15:28:48 +0000</pubDate>
		<dc:creator>Wireless90</dc:creator>
				<category><![CDATA[Network Policy Server]]></category>
		<category><![CDATA[Radius]]></category>
		<category><![CDATA[Radius Server]]></category>
		<category><![CDATA[Windows Server Authentication]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Hi Im in a dilemma on how this process works,especially about the shared key. Im currently learning Fundamentals of Network Security and came across this chapter on access-control protocols where they talk about RADIUS,TACACS+ nad Kerberos. I have never set up a Radius system before. This is what the book says that got me confused. [...]]]></description>
				<content:encoded><![CDATA[<p>Hi Im in a dilemma on how this process works,especially about the shared key.</p>
<p>Im currently learning Fundamentals of Network Security and came across this chapter on access-control protocols where they talk about RADIUS,TACACS+ nad Kerberos.<br />
I have never set up a Radius system before. </p>
<p>This is what the book says that got me confused.<br />
&#8220;The shared secret is never sent out in the network&#8221;.</p>
<p>If its never sent out how dpes the authentication happen? How does the R.Server knows that the R.Client is trustable by not exchanging secret key? How is the password encrypted?</p>
<p>These are the 2 websites that got me even confused. 1 stated that the secret key is used for encryption with MD5 together with a random Request Authenticator string and then the resulting  hash would be XORed with the password.</p>
<p>The other stated the password would just directly go through a MD5 algorithm.</p>
<p>http://www.untruth.org/~josh/security/radius/radius-auth.html</p>
<p>http://www.giac.org/resources/whitepaper/access/157.php</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/radius-server-authentication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Deploying IP address authentication in Radius server</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/deploying-ip-address-authentication-in-radius-server/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/deploying-ip-address-authentication-in-radius-server/#comments</comments>
		<pubDate>Tue, 20 Apr 2010 07:48:55 +0000</pubDate>
		<dc:creator>Akashost</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[IP address]]></category>
		<category><![CDATA[IP Address Authentication]]></category>
		<category><![CDATA[Radius]]></category>
		<category><![CDATA[Radius Server]]></category>
		<category><![CDATA[Radius Server Windows 2003]]></category>
		<category><![CDATA[Windows Server 2003]]></category>
		<category><![CDATA[Wireless]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Dear All, Please provide me a solution, where we want to bind IP address with MAC ID of the wireless client and should be authenticated by Radius Server. Is this solution exist? I will be very thankful if you could provide me the solutions.   Akash  ]]></description>
				<content:encoded><![CDATA[<p>Dear All,<br/><br/> Please provide me a solution, where we want to bind IP address with MAC ID of the wireless client and should be authenticated by Radius Server.<br/><br/> Is this solution exist?<br/><br/> I will be very thankful if you could provide me the solutions.<br/><br/>  <br/><br/> Akash<br/><br/>  <br/><br/></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/deploying-ip-address-authentication-in-radius-server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Guest Access on an 802.11x network</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/guest-access-on-an-80211x-network/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/guest-access-on-an-80211x-network/#comments</comments>
		<pubDate>Sun, 19 Oct 2008 11:15:38 +0000</pubDate>
		<dc:creator>Jrubinstein</dc:creator>
				<category><![CDATA[802.1x authentication]]></category>
		<category><![CDATA[Radius]]></category>
		<category><![CDATA[VLAN]]></category>
		<category><![CDATA[Wireless Access Protocol]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I am trying to set up 802.11x security on our network. The domain machines authenticate fine but a guest machine isn&#8217;t able to get access. I have set up a policy for it on the Radius server using it&#8217;s Mac address and the Wireless access point recognises the assigned VLAN but lists it as not [...]]]></description>
				<content:encoded><![CDATA[<p>I am trying to set up 802.11x security on our network.  The domain machines authenticate fine but a guest machine isn&#8217;t able to get access.  I have set up a policy for it on the Radius server using it&#8217;s Mac address and the Wireless access point recognises the assigned VLAN but lists it as not allowing forwarding, consequently the guest machine can&#8217;t get anywhere even on it&#8217;s own VLAN.</p>
<p>Any suggestions gratefully recieved.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/guest-access-on-an-80211x-network/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AP-5131 WAP RADIUS Configuration?</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/ap-5131-wap-radius-configuration/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/ap-5131-wap-radius-configuration/#comments</comments>
		<pubDate>Tue, 29 Jul 2008 16:22:53 +0000</pubDate>
		<dc:creator>erin0201</dc:creator>
				<category><![CDATA[Radius]]></category>
		<category><![CDATA[WAP]]></category>
		<category><![CDATA[Wireless Access Points]]></category>
		<category><![CDATA[Wireless networking]]></category>
		<category><![CDATA[Wireless security]]></category>
		<category><![CDATA[WLAN]]></category>
		<category><![CDATA[WLAN access points]]></category>
		<category><![CDATA[WLAN management software]]></category>
		<category><![CDATA[WLAN protocols]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[New Discussion Post by]]></description>
				<content:encoded><![CDATA[New Discussion Post by ]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/ap-5131-wap-radius-configuration/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Hardware needed for implementing a call termination company?</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/hardware-needed-for-implementing-a-call-termination-company/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/hardware-needed-for-implementing-a-call-termination-company/#comments</comments>
		<pubDate>Thu, 03 Apr 2008 13:25:22 +0000</pubDate>
		<dc:creator>Unified Communications ATE</dc:creator>
				<category><![CDATA[GSM]]></category>
		<category><![CDATA[Radius]]></category>
		<category><![CDATA[VoIP]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I plan on implementing a call termination company in Latin America and I have looked at the Hypermedia GSM gateway as a potential component. Is there any additional hardware I need in order to start selling minutes? Do I need a billing/RADIUS solution and how would this work? Would the radius solution authenticate with the [...]]]></description>
				<content:encoded><![CDATA[<p>I plan on implementing a call termination company in Latin America and I have looked at the Hypermedia GSM gateway as a potential component. Is there any additional hardware I need in order to start selling minutes? Do I need a billing/RADIUS solution and how would this work? Would the radius solution authenticate with the hypermedia gateway?</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/hardware-needed-for-implementing-a-call-termination-company/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco AcessControlServer &#8211; Authentication</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/cisco-acesscontrolserver-authentication/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/cisco-acesscontrolserver-authentication/#comments</comments>
		<pubDate>Wed, 26 Mar 2008 22:10:32 +0000</pubDate>
		<dc:creator>Stefan600</dc:creator>
				<category><![CDATA[Access Control Server]]></category>
		<category><![CDATA[ACS]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Radius]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Hi I&#8217;m configuring a Cisco ACS for our diploma thesis and now i have this problem: The Authentication of the IETF Radius-server operates properlym but the authentication of the nac doesn&#8217;t work. All clients come in my quarantine-vlan. In the logs there is the SharedRAC: Quarantine_RAC displayed. I had configure 3 components in &#8220;Shared Profile [...]]]></description>
				<content:encoded><![CDATA[<p>Hi<br />
I&#8217;m configuring a Cisco ACS for our diploma thesis and now i have this problem:</p>
<p>The Authentication of the IETF Radius-server operates properlym but the authentication of the nac doesn&#8217;t work. All clients come in my quarantine-vlan.<br />
In the logs there is the SharedRAC: Quarantine_RAC displayed.</p>
<p>I had configure 3 components in &#8220;Shared Profile Components &#8211; RADIUS Authorization Components&#8221;:</p>
<p>Healthy_RAC:<br />
IETF Session-Timeout (27) 3600<br />
IETF Termination-Action (29) RADIUS-Request (1)<br />
IETF Tunnel-Type (64) [T1] VLAN (13)<br />
IETF Tunnel-Medium-Type (65) [T1] 802 (6)<br />
IETF Tunnel-Private-Group-ID (81) [T1]secure_lan</p>
<p>Quarantine_RAC:<br />
IETF Session-Timeout (27) 3600<br />
IETF Termination-Action (29) RADIUS-Request (1)<br />
I ETF Tunnel-Type (64) [T1] VLAN (13)<br />
IETF Tunnel-Medium-Type (65) [T1] 802 (6)<br />
IETF Tunnel-Private-Group-ID (81) [T1] quarantine</p>
<p>Transition_RAC:<br />
IETF Session-Timeout (27) 30<br />
IETF Termination-Action (29) RADIUS-Request (1)</p>
<p>After that i created a Network Access Profile named nac_802.1x. For Testing i disabled the machinepostures in the authentication.</p>
<p>my authoriziation rules:<br />
*User Group: student<br />
System Posture Token: Healthy<br />
Deny Access: No<br />
Shared RAC: Healthy_RAC<br />
ACL: deacitvated</p>
<p>*If a condition is not defined or there is no matched condition: Quarantine_RAC</p>
<p>Has anyone an idea what the problem is?<br />
In windows xp i selected 802.1x peap authentication with eap-mschapv2. Also i checked that the pc is authenticated as a computer.</p>
<p>Here&#8217;s a cut of the acs-log file(Passed Authentications):<br />
http://www.datei-upload.eu/file.php?id=e532ee9671a10ba82567b d156f12ebf8</p>
<p>In the logs there occur three times the Healthy_RAC, there i configured the option &#8220;If a condition is not defined or there is no matched condition&#8221; to Healthy.</p>
<p>One more question.. is the CTA Client for the postures needed? some people said that it&#8217;s not, but others say it&#8217;s important.</p>
<p>in advance. thanks for answers</p>
<p>__________________</p>
<p>http://net08.wordpress.com/</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/cisco-acesscontrolserver-authentication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Poblem Setting Radius Attribibute 22 (Framed-Route)</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/poblem-setting-radius-attribibute-22-framed-route/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/poblem-setting-radius-attribibute-22-framed-route/#comments</comments>
		<pubDate>Thu, 01 Nov 2007 05:30:21 +0000</pubDate>
		<dc:creator>Rounds1981</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[Radius]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Windows 2000 Server]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Hello, Can anybody tell me where to set the radius attribute 22 (framed-route) on a windows 2000 IAS server. Thanks]]></description>
				<content:encoded><![CDATA[<p>Hello,</p>
<p>Can anybody tell me where to set the radius attribute 22 (framed-route) on a windows 2000 IAS server.</p>
<p>Thanks</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/poblem-setting-radius-attribibute-22-framed-route/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Can&#8217;t Find IAS Attribute 22</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/cant-find-ias-attribute-22/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/cant-find-ias-attribute-22/#comments</comments>
		<pubDate>Thu, 18 Oct 2007 02:45:59 +0000</pubDate>
		<dc:creator>Rounds1981</dc:creator>
				<category><![CDATA[IAS]]></category>
		<category><![CDATA[Radius]]></category>
		<category><![CDATA[Windows 2000 Server]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Hello, I am trying to create a new Remote Access policy. The policy will be for a single user, whose account will be used to log on from a 3G Wireless router, with other computers behind it. To achive this without using NAT on the router I need to set up some attributes under the [...]]]></description>
				<content:encoded><![CDATA[<p>Hello, I am trying to create a new Remote Access policy.  The policy will be for a single user, whose account will be used to log on from a 3G Wireless router, with other computers behind it.  To achive this without using NAT on the router I need to set up some attributes under the advanced tab of the profile I have created.  These include<br />
Attribute 8 &#8211; Framed IP Address<br />
Attribute 9 Framed IP Netmask<br />
Attribute 22 Framed Route</p>
<p>The problem is that I see no setting for Attribute 22 &#8211; Framed route.  Anyone know how this can be set on a windows 2000 server?</p>
<p>Thanks for any help</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/cant-find-ias-attribute-22/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 3/24 queries in 0.033 seconds using memcached
Object Caching 958/1078 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-05-21 19:01:00 -->