WinXP/2k - 802.1x -FreeRadius : Authenticating before user logs in

  • Thread starter Thread starter blaqb0x
  • Start date Start date
B

blaqb0x

hi,

This is my situation. I'm using HP 2650/26226 switches (which support
802.1x port-based authentication ) and they are authenticating to FreeRADIUS
using PEAP and MD5-challange. However, on the FreeRADIUS server I am
authenticating only the MAC address of the supplicants by re-writing the
username as the MAC address. So in my authentication database the usernames
are MAC addresses of all my machines. This works great. However, the
authentication on Windows machines only gets initiated after someone logs
in. So if a machine is rebooted and doensn't get logged into, it will not
initiate authentication and not get on the network. I 've tried to set
"Authenticate as computer when computer information is available" and
"Authenticate as guest when user or computer information is unavailable"
and neither work. When do these 2 options do anyway? What credentials does
it send?

Any links, insight, or thoughts on the subject would be appreciated.

Thanks,
 
These options are there when you are using IAS, the windows version of
RADIUS. If you are doing EAP and have certificates installed, then the
workstation can log itself into the network and obtain an IP address as the
machine account. This allows GPOs, SUS, and things like that to operate at
the machine level.

You may be able to get that to work under PEAP, but I have not tried that,
and EAP is a much better way to authenticate hardware anyway.
 
Back
Top