802.1x for 3com 3870 switches just not working :(
Web Server forum
Back To The Forum Home!Search!Private Messaging System

Web Server Talk Web Server Talk > Web Servers reviews > IIS server support > Radius Server > 802.1x for 3com 3870 switches just not working :(




  Last Thread   Next Thread Next
  Show Printable Version Email this Page Subscribe to this Thread      Post New Thread    Post A Reply      

    802.1x for 3com 3870 switches just not working :(  
DrSpook


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
01-14-06 03:26 AM

We have some new 3com 3870 switches that support 802.1x network access
authentication.

* I've set up 2 w2k3SP1Enterprise DCs with an enterprise root CA on DC1 &
IAS on both.  I also entered their IPs in the 3870's radius settings & did
shared secret etc.
* I've auto-enrolled the default IAS & RAS Server certificate on both DCs
* I've setup IAS as per the "deploying IAS for wired 802.1x" MS guide.
* I've set a GPO to add the rootCA to the trusted roots on client pcs
(imported the c:\rootca.crt file into the policy for this).
* I've set up a xpsp2 client to require 802.1x with MS-PEAP_CHAPv2, verify
server cert & supply windows user & pw.  I also verfied that the rootCA was 
i
nthe trusted roots on the client.

Here's what happens when logging onto the xpsp2 client as "domain\fred"
where fred is a valid user:
1. if i set a remote access policy to deny access to (valid) user fred then
fred is denied access & an IAS "access denied" event is generated on the IAS
server's event log.
2. If I grant fred remote access then no events are generated in the event
log & fred can't access the network
3. if i change the default connection policy to allow all connections rather
than "authenticate on this server" then fred can access the network & an "IA
S
access granted" event is generated on the IAS server.
4. in the above scenario, but with "send windows user & pw" unticked on the
client, I can supply any password at all & fred gets network access.

I've reinstalled my test environment twice & am now far too close to see the
wood for the trees.  Any help would be greatfully received.

Thanks in advance & hoping I've not done something daft....

Andy Booth, Senior Network Support Officer, Royal National Institute of the
Blind (UK)





[ Post a follow-up to this message ]



    RE: 802.1x for 3com 3870 switches just not working :(  
DrSpook


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
01-25-06 01:37 PM

Problem solved - use v3.0 firmware on the 3870s!  Confirmed by reinitialisin
g
the switch & reconfiguring.

No reference to this problem in the release notes for v2.03, v2.5 OR v3.0...
.





[ Post a follow-up to this message ]



    Sponsored Links  




 





   All times are GMT. The time now is 04:31 PM.      Post New Thread    Post A Reply      
  Last Thread   Next Thread Next


Most Popular forums 

Forum Jump:
Rate This Thread:

Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is OFF
vB code is ON
Smilies are ON
[IMG] code is OFF
 
Medical and Health forum | Computer Games Reviews | Graphics design forum

Back To The Top
Home | Usercp | Faq | Register