- Community Home
- >
- Networking
- >
- Legacy
- >
- Switches, Hubs, Modems
- >
- Re: 802.1x + dyn vlan (via radius) + homedir mappi...
Switches, Hubs, and Modems
1752594
Members
3058
Online
108788
Solutions
Forums
Categories
Company
Local Language
юдл
back
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
юдл
back
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Blogs
Information
Community
Resources
Community Language
Language
Forums
Blogs
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО07-01-2007 11:13 PM
тАО07-01-2007 11:13 PM
802.1x + dyn vlan (via radius) + homedir mapping
following environment:
- hp 2650
- win 2003 ads/ias/ca
- win xp client
- peap(ms-chapv2) security
all working fine with peap(ms-chapv2) and dyn vlans via radius-attribute.
but i've one problem...with dyn vlan enabled (via radius attribute) SOMETIMES the user does not become his home-directory mapped. when the user logoff from win xp and login again then he gets his homedir.
it looks like a timing-problem.
a 802.1x-login without dyn vlan (via radius-attribute) works without any problems.
any ideas!?
config hp 2650:
vlan 1
name "DEFAULT_VLAN"
untagged 13-50
ip address 192.168.0.249 255.255.255.0
no untagged 1-12
exit
vlan 2
name "testvlan"
untagged 1-12
tagged 49-50
exit
aaa authentication port-access eap-radius
radius-server host 192.168.0.2 key 123456789
aaa port-access authenticator 11-12
aaa port-access authenticator 11 unauth-vid 2
aaa port-access authenticator 12 unauth-vid 2
aaa port-access authenticator active
aaa port-access 11-12
config ias:
peap(ms-chapv2)
tunnel-medium-type: 802
tunnel-pvt-group: 1
tunnel-type: virtual lans
thanks in advance...
- hp 2650
- win 2003 ads/ias/ca
- win xp client
- peap(ms-chapv2) security
all working fine with peap(ms-chapv2) and dyn vlans via radius-attribute.
but i've one problem...with dyn vlan enabled (via radius attribute) SOMETIMES the user does not become his home-directory mapped. when the user logoff from win xp and login again then he gets his homedir.
it looks like a timing-problem.
a 802.1x-login without dyn vlan (via radius-attribute) works without any problems.
any ideas!?
config hp 2650:
vlan 1
name "DEFAULT_VLAN"
untagged 13-50
ip address 192.168.0.249 255.255.255.0
no untagged 1-12
exit
vlan 2
name "testvlan"
untagged 1-12
tagged 49-50
exit
aaa authentication port-access eap-radius
radius-server host 192.168.0.2 key 123456789
aaa port-access authenticator 11-12
aaa port-access authenticator 11 unauth-vid 2
aaa port-access authenticator 12 unauth-vid 2
aaa port-access authenticator active
aaa port-access 11-12
config ias:
peap(ms-chapv2)
tunnel-medium-type: 802
tunnel-pvt-group: 1
tunnel-type: virtual lans
thanks in advance...
2 REPLIES 2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО07-09-2007 01:56 AM
тАО07-09-2007 01:56 AM
Re: 802.1x + dyn vlan (via radius) + homedir mapping
On XP at least with SP2 you normally have two 802.1X authentications occuring:
1. Computer authentication
2. User authentication after a user logs in
I assume that the computer authenticates in a different VLAN than user is doing.
There is a synchronization issues during User Authentication. User Domain logon and Logon GPO are executed in parallel with 802.1x user authentication and DHCP request.
When there is a VLAN switching between Computer and User authentication, User GPO is started using the computer connectivity and then 802.1X user authentication starts as well as DHCP request this causes the processes to be started in parallel when they should be serialized, and, user authentication and logon to fail.
Due to this problem MS does not support changing VLANs on 802.1X.
You may have a workaround. Create a local script, instead of a remote logon script. Let this script loops until it gets network connectivity. This script should than start a Logon script from a share.
1. Computer authentication
2. User authentication after a user logs in
I assume that the computer authenticates in a different VLAN than user is doing.
There is a synchronization issues during User Authentication. User Domain logon and Logon GPO are executed in parallel with 802.1x user authentication and DHCP request.
When there is a VLAN switching between Computer and User authentication, User GPO is started using the computer connectivity and then 802.1X user authentication starts as well as DHCP request this causes the processes to be started in parallel when they should be serialized, and, user authentication and logon to fail.
Due to this problem MS does not support changing VLANs on 802.1X.
You may have a workaround. Create a local script, instead of a remote logon script. Let this script loops until it gets network connectivity. This script should than start a Logon script from a share.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО07-09-2007 07:01 AM
тАО07-09-2007 07:01 AM
Re: 802.1x + dyn vlan (via radius) + homedir mapping
hi,
i'm not changing vlans between computer- and userauthentication.
i've configured only one policy in ias (tunnel-pvt-group: 1). ias also checks only one domain-group...members of this group are computer- AND useraccount.
now i've changed the untagged vlan on ports 11&12 to vlan 1 and i think it's looks better...but at the moment i'm not sure...
i'm not changing vlans between computer- and userauthentication.
i've configured only one policy in ias (tunnel-pvt-group: 1). ias also checks only one domain-group...members of this group are computer- AND useraccount.
now i've changed the untagged vlan on ports 11&12 to vlan 1 and i think it's looks better...but at the moment i'm not sure...
The opinions expressed above are the personal opinions of the authors, not of Hewlett Packard Enterprise. By using this site, you accept the Terms of Use and Rules of Participation.
News and Events
Support
© Copyright 2024 Hewlett Packard Enterprise Development LP