# PEAP and EAP-TLS on Server 2008 and Cisco WLC

**URL:** https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036
**Category:** Lessons Discussion
**Created:** [December 26, 2016, 6:42pm UTC](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036 "2016-12-26T18:42:27Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [December 26, 2016, 6:42pm UTC](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036/1 "2016-12-26T18:42:27Z")

</div>

This topic is to discuss the following lesson:

> **[PEAP and EAP-TLS on Server 2008 and Cisco WLC](https://networklessons.com/miscellaneous/peap-and-eap-tls-on-server-2008-and-cisco-wlc)**
>
> This lesson teaches you how to configure PEAP + EAP-TLS on a Windows 2008 RADIUS server with a Cisco Wireless LAN Controller.

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [June 20, 2013, 4:55pm UTC](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036/2 "2013-06-20T16:55:26Z")

</div>

Great Peace there, for the purpose of practice, i have a Linksys wireless Router I share my internet with friends on the same apt. My Isp assigns me IP Dynamically through a modem and connected to them(ISP) on PPoE style. I want to implement this so my friends don’t log other friends behind my back. Onces they are logged on no second login with same credentials can be logged

Thank You

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [June 21, 2013, 7:27pm UTC](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036/3 "2013-06-21T19:27:31Z")

</div>

Using PEAP will work well because you can track what usernames are accessing your wireless network, and you can permit just a single login for each user.

It does take time to setup the radius server, freeradius is a nice and simple alternative for the Microsoft solution btw.

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [June 24, 2013, 2:54pm UTC](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036/4 "2013-06-24T14:54:11Z")

</div>

Many thanks dear… perfect post

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [July 18, 2013, 1:23pm UTC](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036/5 "2013-07-18T13:23:55Z")

</div>

Useful explanation! I want to use EAP-TLS for authentiation with wlc 5508, but :  
1- do I have to install certificate on all clients asset?  
2- I want that client will have no thing to do only select the SSID without any settings to do (if it’s not possible this means that I have to configure 200 assets!)

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [July 18, 2013, 1:24pm UTC](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036/6 "2013-07-18T13:24:21Z")

</div>

Useful explanation! I want to use EAP-TLS for authentiation with wlc 5508, but :  
1- do I have to install certificate on all clients asset?  
2- I want that client will have no thing to do only select the SSID without any settings to do (if it’s not possible this means that I have to configure 200 assets!)

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [July 18, 2013, 4:14pm UTC](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036/7 "2013-07-18T16:14:43Z")

</div>

Many thanks for the explanation. my company has over then 200 lap top, how to proceed?  
what about the DNS because we already a DNS and ip address are delivered automatically.

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [July 18, 2013, 5:10pm UTC](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036/8 "2013-07-18T17:10:22Z")

</div>

If you want to use EAP-TLS then you will need client certificates and yes somehow you will have to provision these to your clients. For Windows computers in the domain you can use group policy to auto-enroll certificates and auto-configure the wireless profile.

For Apple devices you can look for “MDM” which is meant to configure iPhones and iPads on a large scale. There’s probably also something for Android devices…

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [July 18, 2013, 5:11pm UTC](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036/9 "2013-07-18T17:11:31Z")

</div>

So what exactly is your question? In my example I installed DNS because Active Directory requires it. If you have an Active Directory then you can use your current DNS?

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [July 19, 2013, 9:01am UTC](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036/10 "2013-07-19T09:01:35Z")

</div>

Exactly, what I want is to push out the policy on end user devices: the client have only to accept the certificate and the process will transparent for him, no configuration to do.  
could you help me on how to realise it?

Regards

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [July 19, 2013, 9:02am UTC](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036/11 "2013-07-19T09:02:58Z")

</div>

This is possible but it depends on the client. Are you talking about Windows 7 laptops or other devices like Apple or Android?

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [July 19, 2013, 9:19am UTC](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036/12 "2013-07-19T09:19:37Z")

</div>

To be more clear, I’ve already an architecture with AD and DNS… but as I’m quite new to this stuff, I’ve installed a new windows server 2008 and I follow your steps, and for this should I install a new active directory? or is it possible to make a link to the existing AD or simply copy the groups to the new AD?

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [July 19, 2013, 9:47am UTC](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036/13 "2013-07-19T09:47:41Z")

</div>

If you have an AD and DNS then you only need to install the CA and NPS roles. I wouldn’t recommend to implement this right away in your production environment, best to try everything first in a test lab using vmware or virtualbox to understand how all components work together.

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [July 19, 2013, 9:55am UTC](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036/14 "2013-07-19T09:55:08Z")

</div>

Sorry but I don’t find to replay to your post bellow, this is why I answer here.

then yes, I talk about windows 7 and XP laptop and when I solve this categorie I will probably need to do the same in android, if it’s not possible then could you make a post please with what’s possible to realise?

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [July 19, 2013, 10:14am UTC](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036/15 "2013-07-19T10:14:26Z")

</div>

Are your Windows XP / 7 laptops in the domain or in a workgroup? Domain is easy since you can use group policy to enroll the client certificates and configure the wireless profile for them. If they are in a workgroup then you’ll have to do some scripting if you want everything to be auto-configured. It’s also not a bad idea to create a simple user manual so that users can get a certificate.

Android devices are difficult to “auto enroll”. I’m not sure if there is management software that can do this…I know there is for Apple (google for Apple MDM).

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [July 19, 2013, 10:34am UTC](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036/16 "2013-07-19T10:34:03Z")

</div>

Yes, all laptops are already on a specific domain

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [July 19, 2013, 10:40am UTC](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036/17 "2013-07-19T10:40:05Z")

</div>

I’ve a problem, I noted that 80% of laptops are on a domain and the rest of on other domain. Is there a solution for this?

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [July 19, 2013, 2:50pm UTC](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036/18 "2013-07-19T14:50:17Z")

</div>

There probably is. You could create some trust relations between domains, or create a script or something to do automate the following: [https://networklessons.com/wireless/peap-and-eap-tls-on-server-2008-and-cisco-wlc/#Configure-Wireless-Client](https://networklessons.com/wireless/peap-and-eap-tls-on-server-2008-and-cisco-wlc/#Configure-Wireless-Client)

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [July 23, 2013, 7:14am UTC](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036/19 "2013-07-23T07:14:17Z")

</div>

Thank you Rene for the explanation, it’s very helpful.  
I’m trying to implement your examlpe, I’ve created a test lab, I’ve installed a windows server 2008 R2 on a VMare and I want to use a new AD from the server 2008 (not the existing from the production architecture), then I have 2 questions:

1- As the server is on a VMare what precautions should I take, to isolate my test LAB to don’t disturb the production installation?  
2- for the test I’ll install the AD and DNS (all your steps) but when I want to migrate to the existing AD and DNS how can I proceed? sould I remove AD and DNS from the server 2008, is it sufficient ?

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [July 24, 2013, 9:12pm UTC](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036/20 "2013-07-24T21:12:24Z")

</div>

Make sure your is not connected somehow to your production network as you might run into issues. I use a separate VLAN on my switch for testing purposes. If you only want to practice with the servers in VMWare then you can set the NICs of your VM guests to use another physical NIC or host-only.

Removing the AD and DNS roles is possible but I always prefer to start with a clean setup. See if you can get everything up and running in VMware and if it works, re-build it for the production network. When you install some roles and remove them later, you never know what kind of “leftovers” you might find later…

[Next page](https://forum.networklessons.com/t/peap-and-eap-tls-on-server-2008-and-cisco-wlc/1036.md?page=2)
