Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

802.x wireless login + active directory

Our wireless uses a Cisco ACS server for Radius with PEAP authentication and various levels of encryption, we don't broadcast the SSID, etc.

I can get logged into the MAC with an Ethernet cable and an Active Directory account, I can log into our corporate wireless with PEAP and a domain logon, but I can't do both at once.

I can export the 802.x configuration to the logon window, and I see it there, but there's a problem.

I need to provide the "domain" information to logon to the Mac: domain\user. The Wireless authentication doesn't want to see a domain, so the user has to be "user" not "domain\user".

What can I do? Is there a way to setup the wireless to always auth against a system keyring for that 802.x configuration?

Will there be an OS X update that puts the domain logon in a separate field and select whether or not to forward the domain credential to the Radius server (best flexible solution for all).

Anyone solved this problem yet?

MacBook Pro 15", Mac OS X (10.4.6), Airport WLAN

Posted on May 19, 2006 8:56 AM

Reply
5 replies

May 22, 2006 8:07 AM in response to NeedHelpwithMacsSometimes

Hi NeedHelpwithMacsSometimes,

With your network, are you sure the DNS server is not looking at your Mac and saying: "I've already issued an IP address to you?"
It has to authenticate the mac address to hand out the IP address. Are there any rules in place preventing the DNS server from handing out 2 IP addresses to the same node (or named client)?

May 23, 2006 6:45 AM in response to Vipir

We don't have a DNS server that hands out IP addresses although that would be a neat trick 😉

On my test wireless network our DHCP server does not use client MAC authentication.

This has to do with auth'ing to the RADIUS Server or the Apple implementation of PEAP, on the wired lan (same DHCP server) I can log in with an AD account.

On the wireless, I export the working 802.x config to the login screen and I can't get a domain logon.

Do Macintoshes have local logs of this stuff?

May 23, 2006 7:27 AM in response to NeedHelpwithMacsSometimes

Sorry, poorly worded on my part. . .
What I meant was are there any rules preventing DHCP from handing the same named node 2 ip addresses.
I do realize DNS handles the name/ip resolutions.
If an account gets hosed in DNS, and contact to DNS cannot be reached, the IP address will never make it because the DHCP server cannot be resolved for the client. The DHCP server will not be able to hand out any IP address to a client that cannot be verified.
I may be off-base here, but just following my own coouriosity. Can you set the wireless IP address manually with router and gateway info to see if it will work then?

Acitve directory adds a whole new set of security items in the mix.

802.x wireless login + active directory

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.