|
|

14-07-2008, 12:28 PM
|
|
Regular
Join Date: Jun 2008
Group: Regulars
Location: Melbourne
Posts: 519
|
Connecting to Monash Uni: WPA Enterprise Security?
Well I am trying to get my iPhone 3G onto the Monash wireless network (especially as Optus 3G reception is patchy here: mostly indoors). ITS won't help as they said the iPhone has no WPA Enterprise security support (or maybe it was WPA2 Enterprise security support). The wireless network that I need to get on "Monash-Connect" shows up in the list of wireless networks showing security. However in the settings it doesn't allow me to choose what type of security it is, so I said join another network choosing WPA Enterprise and then WPA2 Enterprise.
For those who know the Monash network, I have also registered the iPhone's MAC address, so it all should work. Has anyone been able to access the network here at Monash, or know have any luck on getting on WPA (2) Enterprise networks?
|
|
|
|
|
|
|
|

14-07-2008, 01:23 PM
|
|
Regular
Join Date: Jul 2005
Group: Regulars
Location: NSW
Posts: 4,493
|
I am pretty sure the iPhone supports WPA and WPA2.
At my uni, we use Cisco VPN to connect via Mac/PC/Linux. We have a strictly "no PDA" support policy which really sucks. So all I can do on my iPhone is access the intranet which basically means checking my uni webmail...
I was thinking 2.0 firmware can do something for me since it has all those enterprise features (used by uni, USYD) but I haven't looked into it yet. I am not holding my breath...
|
|
|
|
|
|
|
|

14-07-2008, 01:30 PM
|
|
Regular
Join Date: Jan 2005
Group: Regulars
Location: Adelaide
Posts: 2,208
|
iphone 2.0 firmware supports cisco vpn, wpa enterprise etc that was some of the major upgrades
__________________
MacBook White 2GHz Intel Core Duo, 2GB Ram, 250GB HD
PowerMac G4 Dual 1.25GHz, 1.75GB Ram, 250GB SATAII RAID 1, 2x80GB HD, Mac OS X Server 10.4 (dead psu)
--------------------
AusDataHost | My Flickr | Portfolio/Photoblog
|
|
|
|
|
|
|
|

14-07-2008, 01:30 PM
|
|
Regular
Join Date: Jun 2008
Group: Regulars
Location: Melbourne
Posts: 519
|
Looks like I'm going to have to use the Enterprise Device Configuration Tool, and request what I presume is going to be very specific information about sever settings and what not. If I get it working I'll post the configuration file and/or settings.
One of my inquiries with ITS about getting iPhone support and allowing more than one MAC address got resolved with:
Quote:
|
At the moment the Monash Wireless network cannot be configured for iPhones and other mobile phones. Moreover students can only setup one device for access to the wireless network.
|
__________________
White MacBook 2.2GHz 4GB RAM Leopard, White 3G iPhone 16GB
|
|
|
|
|
|
|
|

14-07-2008, 01:42 PM
|
|
Regular
Join Date: Jul 2005
Group: Regulars
Location: NSW
Posts: 4,493
|
Only one? That's poor.
USYD has no MAC address registration required.
Same for UNSW with the exception of a private CSE network (up to 5 MAC addresses, I think or is that 3... it's still a lot of wireless devices for a student: laptop, mobile...second laptop?).
|
|
|
|
|
|
|
|

14-07-2008, 01:47 PM
|
|
Member
Join Date: Mar 2006
Group: Regulars
Posts: 43
|
It would be great to get some sort of confirmation that someone was connecting to USYD WiFi through using Cisco VPN - this is the major issue that's holding me from getting a Touch or iPhone.
|
|
|
|
|
|
|
|

14-07-2008, 01:49 PM
|
|
Regular
Join Date: Jul 2005
Group: Regulars
Location: NSW
Posts: 4,493
|
Quote:
Originally Posted by Maxim Litvinov
It would be great to get some sort of confirmation that someone was connecting to USYD WiFi through using Cisco VPN - this is the major issue that's holding me from getting a Touch or iPhone.
|
You can access intranet only. I doubt IT Helpdesk etc will even bother to help because they have a strict no PDA/mobile policy.
Quote:
|
PDA's Not Supported/No Available Client
|
|
|
|
|
|
|
|
|

14-07-2008, 01:50 PM
|
|
Regular
Join Date: Jun 2008
Group: Regulars
Location: Melbourne
Posts: 519
|
Quote:
Originally Posted by Huy
Only one? That's poor.
|
Post-grad students get 2 MAC address I think, and staff I have no idea how many they get. But it sucks we get only 1 MAC address for the network. iPhone or laptop.
|
|
|
|
|
|
|
|

14-07-2008, 02:10 PM
|
|
Regular
Join Date: Apr 2005
Group: Regulars
Posts: 163
|
Like Nokias, it supports WPA Enterprise/802.1x but doesn't support TTLS-PAP.
Update:
The only way to connect to a TTLS-PAP network is by installing a profile from the iPhone Configuration Utility.
Last edited by retroneo; 15-07-2008 at 12:18 PM.
|
|
|
|
|
|
|
|

14-07-2008, 03:46 PM
|
|
Member
Join Date: Mar 2006
Group: Regulars
Posts: 43
|
Quote:
|
You can access intranet only. I doubt IT Helpdesk etc will even bother to help because they have a strict no PDA/mobile policy.
|
How is it that they can restrict a PDA to the intranet, but allow a laptop to connect to the internet through their servers though?
Surely the only thing that's required is that you have Cisco VPN software on your system with the correct login data? And doesn't the new firmware specifically include this software.
I know IT will specifically not SUPPORT PDAs, but this just refers to whether they'll give you assistance, not to whether or not it's possible to connect using PDAs.
|
|
|
|
|
|
|
|

14-07-2008, 03:50 PM
|
|
Regular
Join Date: Jul 2005
Group: Regulars
Location: NSW
Posts: 4,493
|
Quote:
Originally Posted by Maxim Litvinov
How is it that they can restrict a PDA to the intranet, but allow a laptop to connect to the internet through their servers though?
Surely the only thing that's required is that you have Cisco VPN software on your system with the correct login data? And doesn't the new firmware specifically include this software.
I know IT will specifically not SUPPORT PDAs, but this just refers to whether they'll give you assistance, not to whether or not it's possible to connect using PDAs.
|
They are not able to restrict PDA access. The fact is, you can connect to the wireless network since it is an open network (with authentication). The issue is, you can't access external sites because you need the credentials etc. This is where Cisco VPN comes in.
Of course, that doesn't stop you from SSH tunneling either but I have tried on the iPhone (1st gen) and was unsuccessful because the session ended as soon as I launched Safari (one app at a time, no background processes, etc).
The new 2.0 firmware does have this support but I have not yet tried it. I haven't been on campus for a few weeks but will be coming in some time this week. I'll give it a shot. The only thing they provide you with is the PCF (VPN profile) which may be useful, since it contains the config details but I think there's more to it than just that.
It is possible for intranet, but not internet. I will have a play around some time this week with it. I don't think it's going to work though.
EDIT
Alright. It seems to be working. Screenshots and details to follow, for USYD users. I can't seem to get Safari to go through the proxy, so I don't think it will work.
Important details/ config data erased from public viewing. PM if you need details.
 
I am connected with an IP address, etc everything is fine however I do not get the authentication prompt in Safari, so I'm unable to test the Internet there. That's where the road ends.
Last edited by Huy; 14-07-2008 at 04:18 PM.
|
|
|
|
|
|
|
|

14-07-2008, 06:41 PM
|
|
Regular
Join Date: Jun 2008
Group: Regulars
Location: Melbourne
Posts: 519
|
I think I may have a solution, I'll test it tomorrow, and post info here if it works. For those curious it requires the iPhone Configuration Tool to set up enterprise level settings.
__________________
White MacBook 2.2GHz 4GB RAM Leopard, White 3G iPhone 16GB
|
|
|
|
|
|
|
|

14-07-2008, 07:10 PM
|
|
Regular
Join Date: Jun 2005
Group: Regulars
Location: Hobart
Posts: 256
|
Quote:
Originally Posted by retroneo
Like Nokias, it supports WPA Enterprise/802.1x but doesn't support TTLS-PAP.
|
Damn. I was looking forward to using my iPhone on UTAS's wireless network 
|
|
|
|
|
|
|
|

14-07-2008, 07:23 PM
|
|
Regular
Join Date: Jan 2005
Group: Regulars
Location: Brisbane
Posts: 344
|
Quote:
Originally Posted by aspro
Damn. I was looking forward to using my iPhone on UTAS's wireless network 
|
Not to worry. iPhone/iPod 2.0 does support TTLS-PAP. To configure it, you need to create a profile using the iPhone Configuration Utility. Available at Apple - Downloads - Application Updates - iPhone Configuration Utility 1.0 for Mac OS X
I'm also waiting for Nokia to get their finger out and support TTLS-PAP! 
|
|
|
|
|
|
|
|

14-07-2008, 08:48 PM
|
|
Member
Join Date: May 2008
Group: Member
Location: Melbourne
Posts: 16
|
Hope you find a solution Matthew! I'd love to be able to use my touch on the Uni's Wifi!
|
|
|
|
|
|