Security

 View Only
  • 1.  Tunnel EAP (TEAP) Windows 11

    Posted Oct 24, 2023 12:26 PM

    Hi All,

    I am trying to configure EAP-TEAP for Windows 11 machines and see that it does not allow me to select "Automatically use my Windows logon name and password.." option which is greyed out.  (see below).  Appreciate if someone can advise how to fix this. 

    I found this (https://learn.microsoft.com/en-us/answers/questions/1036203/cant-configure-teap-settings-for-wired-connection) article but seems it just not a straight forward and also not sure this will have any security breach. 



  • 2.  RE: Tunnel EAP (TEAP) Windows 11

    Posted Oct 25, 2023 09:18 AM

    See if you can setup the profile and export it to an XML.  Once you have the XML, see if you can import it to the computer while Device Guard is enabled.

    1. Disable Device Guard:
      - gpedit.msc -> Computer Configuration | Administrative Templates | System | Device Guard
    2. Setup and test TEAP settings for your connection.  Make sure it works correctly and connects.
    3. Export the LAN profile for your TEAP settings:
      - netsh lan export profile folder=c:\lan\profiles
    4. Set the Device guard settings back to how they were before your changes
    5. Delete the TEAP settings for your LAN adapter
    6. Import the LAN XML profile and test to see if it works:
      - add profile filename="c:\lan\profiles\Profile1.xml" interface="Local Area Connection"

    On an other note - I do not have Device Guard enabled on my machine.  I have never touched this setting before and I do not think that is something we have set to enable/disable anywhere.  My machine is running Windows 11 Pro 21H2.  
    "Automatically use my Windows logon name and password.." is not grayed out for me.




  • 3.  RE: Tunnel EAP (TEAP) Windows 11

    Posted Oct 27, 2023 10:14 AM

    Hi MF,

    Thank you so much for your reply.. Let me go through your steps and check this out.. again hope this will not break and Windows OS security breach..?




  • 4.  RE: Tunnel EAP (TEAP) Windows 11

    Posted Oct 27, 2023 09:58 AM

    Please note that MSCHAPv2 is strongly deprecated, and EAP-TLS (client certificate authentication, also as inner methods for TEAP) is probably the only way to go.

    The link discusses credential guard, as also mentioned in the other response, which I think it the reason the 'Use my Windows login' is greyed out. Be prepared that future versions of Windows may make it even harder to use legacy/insecure authentication like MSCHAPv2.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 5.  RE: Tunnel EAP (TEAP) Windows 11

    Posted Oct 27, 2023 10:16 AM

    Hi Herman,

    Thanks for your advise/comments on this, I too with you and always trying to use EAP-TLS whenever possible.. but sometime if a machine is shared between group of users, not sure TEAP method two (Secondary Auth) will work with EAP-TLS as well..?




  • 6.  RE: Tunnel EAP (TEAP) Windows 11

    Posted Oct 31, 2023 11:25 AM

    Yes, TEAP can use EAP-TLS as the (both) inner methods.

    Yes, you can have TEAP and EAP-TLS in the same service.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------