Wednesday, July 29

Cisco AP, Microsoft IAS, PEAP Issues

I had a recent PEAP deployment for a client go south this week. It was supposed to be a simple reconfiguration from LEAP to PEAP, no big deal....

3 Cisco 1231 AP's running 12.4, Microsoft IAS server, Windows 2003 Server, self signed certificate, Cisco Aironet Cards and Windows XP/Vista Clients.

After everything was configured I could not get the wireless to work. I looked into many potential causes and had a Cisco and Microsoft Call going with no luck. I also had the configuration mirror Microsoft and Cisco documents to the letter and had ruled out all solutions I could find online. I was recieving several errors in my event logs related to IAS:

- Event 2, Reason-Code=8, Reason=the specified user account does not exist.
- Reason-Code = 16, Reason = Authentication was not successful because an unknown user name or incorrect password was used.
- Reason-Code = 260, Reason = The message or signature supplied for verification has been altered

I accidently discovered what I believe the problem to be after trying to install a hotfix. The hotfix failed with this error:

The Service Pack 2 \i386\update\update.inf file is not correct.


Which then led me to this KB from Microsoft stating the fact that this change is unsupportable and will cause system instability: http://support.microsoft.com/kb/933700

"Microsoft does not support changing the location of the Program Files folder by modifying theProgramFilesDir registry value. If you change the location of the Program Files folder, you may experience problems with some Microsoft programs or with some software updates."

As far as I can tell the issue was caused due to the registry change or potential corruption of installed windows components/hotfixes after such change.

I reinstalled IAS on another server, mirrored the configuration and updated the cert on clients and AP configs. My wireless clients began working immediatly with no further issues.

This issue was rather difficult to pin point so I hope it saves someone else some headaches.

Thursday, July 23

New Cisco 1252 AP's

The Cisco 1252 Wireless N AP's don't come with an external power supply out of the box like the others int eh 1200 series do. So if you don't plan on using POE or a power injector you'll need this part: AIR-PWR-SPLY1=

Also with the AP's there are three 2.4 GHz Dipole part numbers listed in the ordering guide:

AIR-ANT2422DG-R
AIR-ANT2422DW-R
AIR-ANT4941

The "DG" part number is a gray antenna that does not pivot and is shorter than the other two. The only place I was able to find the clarification on Cisco's site was here:

http://cisco.com/en/US/prod/collateral/wireless/ps7183/ps469/at_a_glance_c45-513837.pdf