802.1X Configuration .

802.1X Configuration Ter ena 802.1X workshop t he Net herlands, Amsterdam, March 30 th Paul Dekkers

What makes EAP adaptable

Man-in-the-Middle assault That\'s the reason we require a decent EAP component!

RADIUS intermediary ing

RADIUS Client-Server demonstrate Authenticator is a RADIUS customer Authentication-server is the RADIUS server RADIUS server can be a customer also

RADIUS – what\'s in the bundle UDP, ports 1645/1646 or 1812/1813 Mind the firewall! Characteristics, similar to User-Name, User-Password, EAP-Message Shared Secret

RADIUS and REALMS Use well-picked domains: ideally like an email address, user@institution.ccTLD Important with PROXY-ing

Guest Access

Traffic partition without 1x

Traffic detachment with 1x Supplicant Authenticator (AP or switch) RADIUS server University X RADIUS server SURFnet office User DB User DB Guest Paul.Dekkers@surfnet.nl Internet Guest VLAN Employee VLAN Central RADIUS intermediary server Students VLAN

Traffic division with 1x

Hands-on setup

Configuration : Radiator Linear Global design AuthPort 1812 AcctPort 1813 LogDir/var/log/sweep DbDir/and so on/radiator Clients Handlers

Configuration : Radiator RADIUS Clients <Client> Secret 6.6obaFkm&RNs666 Identifier AP1 IdenticalClients, </Client>

Configuration : Radiator <Handler Realm=surfnet.nl> <AuthBy FILE> Filename clients </AuthBy> </Handler>

Configuration : Radiator <Handler Realm=surfnet.nl> <AuthBy FILE> Filename clients EAPType TTLS, PEAP, MSCHAP-V2 EAPTLS_CAFile root-ca.pem EAPTLS_CertificateFile server.pem EAPTLS_CertificateType PEM EAPTLS_PrivateKeyFile private.pem EAPTLS_PrivateKeyPassword mystery EAPTLS_MaxFragmentSize 1024 AutoMPPEKeys </AuthBy> </Handler>

Configuration : Radiator <Handler Realm=surfnet.nl, Request-Type=Accounting-Request> # Accept, and log </Handler> <Handler Realm=surfnet.nl, TunnelledByTTLS=1> # PAP </Handler> <Handler Realm=surfnet.nl, TunnelledByPEAP=1> # EAP-MSCHAPv2 </Handler> <Handler Realm=surfnet.nl> # EAP-TTLS and EAP-PEAP </Handler>

Configuration : Radiator, Identifiers and Catch-all <AuthBy RADIUS> Identifier SURFNET-PROXY Host range proxy.surfnet.nl Secret Sdfg8WeR98r09d8fg AuthPort 1812 AcctPort 1813 </AuthBy> <Handler> AuthBy SURFNET-PROXY </Handler>

RADIUS intermediary circle Good arrangement is more intricate, regularly needs in anticipation for intermediary circles

Configuration: Access-Point

Cisco AP - RADIUS AP1(config)#aaa new-show aaa aggregate server range rad_eap server auth-port 1812 acct-port 1813 aaa validation login eap_methods assemble rad_eap aaa bookkeeping system acct_methods begin stop bunch rad_acct span server have auth-port 1812 acct-port 1813 key X

Cisco AP - Wireless Interface AP1(config)# interface dot11Radio 0 AP1(config-if)# encryption mode figures wep40 AP1(config-if)# communicate key change 1800 AP1(config-if)# no ssid torrent AP1(config-if)# ssid SURFnet AP1(config-if-ssid)# confirmation open eap eap_methods AP1(config-if-ssid)# visitor mode AP1(config-if-ssid)# ^Z

Cisco switch – empower RADIUS Switch# arrange terminal Switch(config)# aaa new-demonstrate Switch(config)# span server have auth-port 1812 key <secret>

Cisco switch – empower 802.1x Switch(config)# aaa verification dot1x default amass sweep Switch(config)# dot1x framework auth-control Switch(config)# interface fastethernet0/1 Switch(config-if)# traversing tree portfast Switch(config-if)# switchport mode get to Switch(config-if)# switchport get to vlan 10 Switch(config-if)# dot1x port-control auto Switch(config-if)# end Switch(config-if)# dot1x visitor vlan 60

Windows and wired 802.1x

Extra in hands-on Configuration of VLAN\'s: Can you empower "meandering" with another gathering? Could you make a SSID for clients without 802.1x?

