I have recently deployed 3 Cisco 1242 AP’s using IAS and PEAP as stated in the Ultimate Wireless Security Guide posted on this site. I followed the guide exactly and so far it is working perfectly.
The issue we are having is with our client sites. All machines are on our domain and connect to our network via a VPN tunnel. We are using Checkpoint Safe@ 500 edge devices connecting to Nokia IP1220. We have approximately 60 VPN tunnels connected. When we configure an AP to authenticate accross this tunnel it hammers our Nokia and brings EVERY tunnel we have down.
I have looked at the logs on our IAS server and it looks like the devices cannot authenticate the user. The client machines continuously try to authenticate, but never do. I see “authentication failed” numerous times in the AP as well.
I have been told by our firewall administrator that we are not blocking any ports through the the VPN tunnel.
My only guess is that the tunnel cannot encrypt/decrypt the authentication process with IAS.
Please, if anyone has any thoughts, questions, or insite please let me know. Thank you so much for your help!!