cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
797
Views
9
Helpful
5
Replies

Certificate Authentication using computer with HyperV vSwitch

creserva1
Level 1
Level 1

Does the native supplicant for Windows 10 support it? My test laptop keep failing when HyperV vSwitch manager is turned on.

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

Windows 8.1 with Hyper-V external switch – 802.1x will not work | Ward Vissers says,

If I will change switch mode to Internal/Private it will start working.

From https://social.technet.microsoft.com/forums/windows/en-US/341cbe70-3fa7-4991-a7e4-4f1af63df4d0/windows-8-hyperv-8021x-eapol-request-missing i read that “official” statement from Microsoft is that 802.1x with Hyper-V on Windows 8.1 is not working by design. #Fail Microsoft.

View solution in original post

5 Replies 5

howon
Cisco Employee
Cisco Employee

Hi, Chuck. vSwitch interface may have its own supplicant settings that needs to be setup. Go to list of network connections on the Windows PC and make sure the supplicant is enabled and configured like the real interface. Also, make sure the physical switch interface is configured as multi-auth mode to allow multiple MAC addresses.

Tested in mine deployment ,not working . Dot1x fail every time. All is configured right, multi-auth ,machine got valid certificate the adaptor is configure to use dot1x,but it fail.

Damien Miller
VIP Alumni
VIP Alumni

I think the question here would be does the vSwitch forward/proxy EAPoL from the native suplicant if it is logically placed inbetween.  A quick debug or packet capture might indicate that the network port is not receiving it from the client. 

It's been a bit since I got down in the weeds but I believe the switch if configured to perform dot1x will send an eap request/identity packet, the client will send a response.  With a client native supplicant configured to perform dot1x I would expect to see a eapol start at the switchport.  I think debug radius authentication will show you this exchange. 

hslai
Cisco Employee
Cisco Employee

Windows 8.1 with Hyper-V external switch – 802.1x will not work | Ward Vissers says,

If I will change switch mode to Internal/Private it will start working.

From https://social.technet.microsoft.com/forums/windows/en-US/341cbe70-3fa7-4991-a7e4-4f1af63df4d0/windows-8-hyperv-8021x-eapol-request-missing i read that “official” statement from Microsoft is that 802.1x with Hyper-V on Windows 8.1 is not working by design. #Fail Microsoft.

creserva1
Level 1
Level 1

I have tested this and no EAP message when Hyper vSwitch is turned on and 802.1x authentication. I agreed with hslai #Fail Microsoft.

No HyperV vSwitch successful auth 802.1x computer auth.

Capture1.PNG

With HyperV vSwitch failed auth there aren’t any EAP message coming from my laptop.

Capture2.PNG.jpg