Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Wireless authetication question 1

Status
Not open for further replies.
Nov 26, 2007
25
0
0
US
Hello all. I have successfully setup a wireless access point using WPA with AES encryption. As a test I created a self signed server certificate on the server with Internet Authentication Service installed on it. I then installed the certificate on a client (then went into the wireless properties and selected that self signed server certificate) and tested. There are items in between like configuring the access point to speak to the radius server and to create a remote access policy.

The questions I have are the following:

1) For each remote site that I have an access point do I need to have a server with Internet Authentication Service installed...and if I don't how will the access point know what IP to give out.

2) Is it possible to create one certificate for my entire domain rather then a server certificate....maybe push out foo.local certs to each client.

Thanks for any insight.
 
oops, I didn't actually answer the questions :)

1. You can have the access points point to a central IAS server if you wish. How are you doing DHCP?? from a windows server or the AP?

2. Yes, the link I posted above covers this in a lot of detail

Paul
MCSE


"Two things are infinite: the universe and human stupidity; and I'm not sure about the the universe."
Albert Einstein
 
Thanks for the links pagy.

I have read some of it. And it seems there are two ways of securing wireless.
a) certificate services
or
b) PEAP

I am using peap which seems to be working ok.

Yes I am using DHCP at multiple locations and however I can not get an ip when connecting to the IAS server at our datacenter. How can I tell access point to give out an ip address for the subnet its one.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top