Re: [WIRELESS-LAN] Eduroam adoption (and migration process)

2017-04-28 Thread Matthew Newton
y you can't use EAP-TLS for your local users on eduroam. Visitors can still use PEAP, or EAP-TTLS, or whatever else they need to, but that's not something for you to have to worry about. Matthew -- Matthew Newton, Ph.D. <m...@leicester.ac.uk> Systems Specialist, Infrastructure Se

Re: [WIRELESS-LAN] Windows 10 eduroam EAP/TLS adding "host/" before username in RADIUS request?

2017-02-09 Thread Matthew Newton
On Thu, Feb 09, 2017 at 09:23:10AM +, Paul Seward wrote: > On 8 February 2017 at 23:58, Matthew Newton <m...@leicester.ac.uk> wrote: > > > > Presuming you just auth with a username and password (albeit not > > supplied by the user) then I can't think why

Re: [WIRELESS-LAN] Windows 10 eduroam EAP/TLS adding "host/" before username in RADIUS request?

2017-02-08 Thread Matthew Newton
not set the anonymous (outer) identifier with machine/computer auth? That should work if you can - just set it to '@your.realm'. Matthew -- Matthew Newton, Ph.D. <m...@leicester.ac.uk> Systems Specialist, Infrastructure Services, I.T. Services, University of Leicester, Leicester LE1 7RH, Uni

Re: [WIRELESS-LAN] Wireless Mobility

2016-08-10 Thread Matthew Newton
nce on controller AP licences is also dodgy IMO (or "good business practise", from Cisco's point of view), and definitely something to watch out for if you have lots of spare controller AP licences around. Matthew -- Matthew Newton, Ph.D. <m...@leicester.ac.uk> Systems

Re: [WIRELESS-LAN] Cisco AP Groups and other cool stuff...

2016-07-22 Thread Matthew Newton
On Fri, Jul 22, 2016 at 03:41:17PM +0100, Paul Seward wrote: > On 22 July 2016 at 15:24, Matthew Newton <m...@leicester.ac.uk> wrote: > > > > We've been using an in-house perl module[0] to manage the APs with > > SNMP and do this for all new APs without any issue. &g

Re: [WIRELESS-LAN] Cisco AP Groups and other cool stuff...

2016-07-22 Thread Matthew Newton
APs with SNMP and do this for all new APs without any issue. Cheers, Matthew [0] https://github.com/mcnewton/cisco-wlc-perl - documentation severely lacking, sorry. -- Matthew Newton, Ph.D. <m...@leicester.ac.uk> Systems Specialist, Infrastructure Services, I.T. Services, University of

Re: [WIRELESS-LAN] eduroam ssid

2016-06-20 Thread Matthew Newton
That's a whole can of worms to be opened... and rather defeats the point of offering a visitor service; I'd hazard a guess that more people use PEAP than anything else. Cheers, Matthew -- Matthew Newton, Ph.D. <m...@leicester.ac.uk> Systems Specialist, Infrastructure Services, I.T. Services

Re: [WIRELESS-LAN] 802.11b data rates disabled?

2016-06-20 Thread Matthew Newton
z the slowest rate we allow allow is 12Mbps, and for 5Gzh the slowest is 24Mbps. The thing to watch out is that your coverage area will drop (which is probably a good thing, but you may need to install more APs...) Matthew -- Matthew Newton, Ph.D. <m...@leicester.ac.uk> Systems Speciali

Re: [WIRELESS-LAN] Turning off 2.4 on a select SSID?

2016-04-07 Thread Matthew Newton
u've got none left for yourselves? And presumably Engineering have lots of CCI because all of their APs are on the same frequency? Not critcising, just trying to understand! :) Matthew -- Matthew Newton, Ph.D. <m...@le.ac.uk> Systems Specialist, Infrastructure Services, I.T. Services, University of

Re: [WIRELESS-LAN] Eduroam Radius Server

2016-03-11 Thread Matthew Newton
re anyone using this configuration for Eduroam that > could possibly help me if I get stuck? I am much more familiar > with the wireless controller end of the house. Thank We run FreeRADIUS (2.x, 3.0 and 3.1) on Debian (wheezy and jessie), so you're not alone! Matthew -- Matthew Newton, Ph.D. <

Re: [WIRELESS-LAN] Recent Radius Meltdowns

2016-03-10 Thread Matthew Newton
dius-users/2015-March/075969.html -- Matthew Newton, Ph.D. <m...@le.ac.uk> Systems Specialist, Infrastructure Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, <ith...@le.ac.uk> ** Participation a

Re: [WIRELESS-LAN] Recent Radius Meltdowns

2016-03-10 Thread Matthew Newton
P RADIUS server not responding traps, however. Cheers, Matthew -- Matthew Newton, Ph.D. <m...@le.ac.uk> Systems Specialist, Infrastructure Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, <ith...@le.ac.uk>

Re: [WIRELESS-LAN] WLC 5508 logging authentications

2016-03-03 Thread Matthew Newton
02.1X of course your RADIUS logs are also good for this. But for open networks SNMP traps is the only way to go that I'm aware of. We don't run PI either. Cheers, Matthew -- Matthew Newton, Ph.D. <m...@le.ac.uk> Systems Specialist, Infrastructure Services, I.T. Services, University of

Re: [WIRELESS-LAN] Cisco WLC CPU ACL

2015-12-15 Thread Matthew Newton
t are tedious to configure from the CLI. So other comments stand - disable ACLs, apply new one, re-enable ACL. You pretty much have to do that anyway, so just make sure rule 1 permits SSH from your management network and you'll be fine if something does happen to go wrong. Matthew -- Matthew New

Re: [WIRELESS-LAN] strange WLC behavior

2015-12-03 Thread Matthew Newton
8 reboot in one of the > > instances, and it didn’t appear to help. So likely behaviour caused by some external factor, such as the above. But could be anything like eap timers not tuned well, wireless issues at the edge, etc. Or backend auth being slow. Cheers, Matthew -- Matthew Newton,

Re: [WIRELESS-LAN] Active directory account lockout N-2 policy

2015-12-02 Thread Matthew Newton
f TTLS/PAP then probably NTLM or LDAP. RADIUS server shouldn't matter. Only exception I can think of is EAP-TLS then it won't hit AD at all as it's certificate based so will never lock an account out. Matthew -- Matthew Newton, Ph.D. <m...@le.ac.uk> Systems Specialist, Infrastructure S

Re: [WIRELESS-LAN] Measuring RADIUS Auths

2015-10-19 Thread Matthew Newton
server file. They can then be plotted with $GRAPHER_OF_CHOICE. Cheers, Matthew -- Matthew Newton, Ph.D. <m...@le.ac.uk> Systems Specialist, Infrastructure Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, <ith...@le.ac.uk> ***

Re: [WIRELESS-LAN] Measuring RADIUS Auths

2015-10-19 Thread Matthew Newton
h this issue. Fast SSD backed servers can also help. Memory doesn't matter much in my experience, but ntlm_auth has a large startup cost and winbind writes cache to disk for every auth. Matthew -- Matthew Newton, Ph.D. <m...@le.ac.uk> Systems Specialist, Infrastructure Services, I.T. Se

Re: [WIRELESS-LAN] Sanity check- spontaneously changing WLC configs- is it just us?

2015-09-15 Thread Matthew Newton
n't use prime/wcs/ncs/whatever Cisco are promoting these days, and use an in-house system instead for basic AP management and monitoring. Matthew -- Matthew Newton, Ph.D. <m...@le.ac.uk> Systems Specialist, Infrastructure Services, I.T. Services, University of Leicester, Leices

Re: [WIRELESS-LAN] Special characters mschapv2

2015-08-13 Thread Matthew Newton
-CHAPv2 - it's usually when people are authenticating against LDAP. There's nothing special about @ or !, and I've never heard of any issues with them in a password. But then, we're a FreeRADIUS site, not ISE. Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Specialist, Infrastructure

Re: [WIRELESS-LAN] Peer-to-peer traffic blocking with multiple controllers

2015-07-08 Thread Matthew Newton
eduroamblock 14 out config acl rule action eduroamblock 14 permit config acl apply eduroamblock ! apply eduroamblock acl to eduroam interface config interface acl eduroam-if eduroamblock -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Specialist, Infrastructure Services, I.T

Re: [WIRELESS-LAN] TLS cert, and profile installation problems

2015-04-23 Thread Matthew Newton
error prone than getting users to install certificates? Or maybe I misunderstood and that is what you are already doing and it's still not working correctly? Cheers, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Specialist, Infrastructure Services, I.T. Services, University of Leicester

Re: [WIRELESS-LAN] WLC 5508 Reboots- 8.0.110.0 Code

2015-03-18 Thread Matthew Newton
by a bug in AVC (CSCuq97965) which is supposed to have been fixed in 8.0.110.0. Thanks Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Specialist, Infrastructure Services, I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom For IT help contact helpdesk extn. 2253, ith

Re: [WIRELESS-LAN] Cisco WLC Microsoft NPS for .1x

2014-11-26 Thread Matthew Newton
Protocol Pack Protocol Pack Version: 9.0 Engine Version: 16 The workaround was to disable WLAN-QoS-Application Visibility for all WLANs. How long have you been running 8.0? Just a month? Since the w/c 1 September, so just shy of three months. Cheers, Matthew -- Matthew Newton, Ph.D. m

Re: [WIRELESS-LAN] Cisco WLC Microsoft NPS for .1x

2014-11-25 Thread Matthew Newton
by a bug in AVC - CSCuq97965. Having turned AVC off, we've not had a crash since in about 3-4 weeks. Apart from that, so far 8.0 seems generally fine. Cheers, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Specialist, Infrastructure Services, I.T. Services, University of Leicester

Re: [WIRELESS-LAN] RADIUS Monitoring

2014-10-08 Thread Matthew Newton
, and turn your syslogs into graphs that way without having to have scripts that grep logs and count up matching strings, etc. I've not tried that yet, but it's on my list to look at! Cheers, Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Specialist, Infrastructure Services, I.T

Re: [WIRELESS-LAN] Cisco 8.0.100.0 code rollback

2014-10-03 Thread Matthew Newton
often. We did have a problem on the external APs (in the UNII-2 band, or Band-B here in the UK) as we hadn't enabled those frequencies on the controller. DFS caused the radio to disable for 30 minutes (again, per spec). Now they just jump to another channel. Cheers, Matthew -- Matthew Newton

Re: [WIRELESS-LAN] Give a little, get a little

2014-09-26 Thread Matthew Newton
really good stuff -Not the best quality stuff, but I feel good about it -It is bug-riddled crap, or gimmicky -I'm so very ashamed... Can we tick all four? :) Matthew -- Matthew Newton, Ph.D. m...@le.ac.uk Systems Specialist, Infrastructure Services, I.T. Services, University of Leicester