Go Back   Velocity Reviews > Newsgroups > Wireless Networking
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Wireless Networking - EAP RADIUS error...

 
Thread Tools Search this Thread
Old 05-22-2006, 01:09 AM   #1
Default EAP RADIUS error...


I'm setting up a wireless network, using a Cisco Aironet 1200 AP, Windows
2000 native domain, running IAS. I've set up a stand-alone root CA, issued
certificates to the two DCs that are running IAS, and have configured a GPO
to autoenroll certificates to computers belonging to a specific OU. The
certificate deployment works fine, the laptops can see the AP, but upon
attempting authentication the clients display an error message stating that
Windows cannot locate a certificate to log on to the network. The following
warning is logged by IAS on the DC:

User host/laptop.domain.com was denied access.
Fully-Qualified-User-Name = DOMAIN\laptop$
NAS-IP-Address = 10.xx.xx.xx
NAS-Identifier = AP
Called-Station-Identifier = 1234.5678.90AB
Calling-Station-Identifier = 0123.4567.89AB
Client-Friendly-Name = AP
Client-IP-Address = 10.xx.xx.xx
NAS-Port-Type = 19
NAS-Port = 328
Policy-Name = Allow WLAN Access
Authentication-Type = EAP
EAP-Type = <undetermined>
Reason-Code = 16
Reason = There was an authentication failure because of an unknown user
name or a bad password.

I've played with a few different settings with regards to the registry in
the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\EAPOL\Parame ters\General\Global\
tweaking the values for AuthMode and SupplicantMode.

What am I missing? Any help would be greatly appreciated, and if anyone
needs further information, just ask. Thanks!

Kirk Hauer, CCNA, MCSE


=?Utf-8?B?S0hhdWVy?=
  Reply With Quote
Old 05-22-2006, 10:07 AM   #2
S. Pidgorny
 
Posts: n/a
Default Re: EAP RADIUS error...
Kirk,

I would try to use PEAP - just temporarily - to make sure that the server
infrastructure is okay.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-


"KHauer" <> wrote in message
news:A846EA0B-FE76-4BC9-8F90-...
> I'm setting up a wireless network, using a Cisco Aironet 1200 AP, Windows
> 2000 native domain, running IAS. I've set up a stand-alone root CA, issued
> certificates to the two DCs that are running IAS, and have configured a
> GPO
> to autoenroll certificates to computers belonging to a specific OU. The
> certificate deployment works fine, the laptops can see the AP, but upon
> attempting authentication the clients display an error message stating
> that
> Windows cannot locate a certificate to log on to the network. The
> following
> warning is logged by IAS on the DC:
>
> User host/laptop.domain.com was denied access.
> Fully-Qualified-User-Name = DOMAIN\laptop$
> NAS-IP-Address = 10.xx.xx.xx
> NAS-Identifier = AP
> Called-Station-Identifier = 1234.5678.90AB
> Calling-Station-Identifier = 0123.4567.89AB
> Client-Friendly-Name = AP
> Client-IP-Address = 10.xx.xx.xx
> NAS-Port-Type = 19
> NAS-Port = 328
> Policy-Name = Allow WLAN Access
> Authentication-Type = EAP
> EAP-Type = <undetermined>
> Reason-Code = 16
> Reason = There was an authentication failure because of an unknown user
> name or a bad password.
>
> I've played with a few different settings with regards to the registry in
> the key:
> HKEY_LOCAL_MACHINE\Software\Microsoft\EAPOL\Parame ters\General\Global\
> tweaking the values for AuthMode and SupplicantMode.
>
> What am I missing? Any help would be greatly appreciated, and if anyone
> needs further information, just ask. Thanks!
>
> Kirk Hauer, CCNA, MCSE





S. Pidgorny
  Reply With Quote
Old 05-26-2006, 03:13 AM   #3
Dave Mitton
 
Posts: n/a
Default Re: EAP RADIUS error...
Was the FQUN actually the name of the system (not the user)?
If so, then it's machine authentication that's failing.

You can uncheck the client side option that says send machine credentials, and
that will go away.
I don't know exactly what you need to configure in the Remote Access Policy on
your IAS to accept them. But someone from MS should know.

Dave.

KHauer <> wrote:

>I'm setting up a wireless network, using a Cisco Aironet 1200 AP, Windows
>2000 native domain, running IAS. I've set up a stand-alone root CA, issued
>certificates to the two DCs that are running IAS, and have configured a GPO
>to autoenroll certificates to computers belonging to a specific OU. The
>certificate deployment works fine, the laptops can see the AP, but upon
>attempting authentication the clients display an error message stating that
>Windows cannot locate a certificate to log on to the network. The following
>warning is logged by IAS on the DC:
>
>User host/laptop.domain.com was denied access.
> Fully-Qualified-User-Name = DOMAIN\laptop$
> NAS-IP-Address = 10.xx.xx.xx
> NAS-Identifier = AP
> Called-Station-Identifier = 1234.5678.90AB
> Calling-Station-Identifier = 0123.4567.89AB
> Client-Friendly-Name = AP
> Client-IP-Address = 10.xx.xx.xx
> NAS-Port-Type = 19
> NAS-Port = 328
> Policy-Name = Allow WLAN Access
> Authentication-Type = EAP
> EAP-Type = <undetermined>
> Reason-Code = 16
> Reason = There was an authentication failure because of an unknown user
>name or a bad password.
>
>I've played with a few different settings with regards to the registry in
>the key:
>HKEY_LOCAL_MACHINE\Software\Microsoft\EAPOL\Param eters\General\Global\
>tweaking the values for AuthMode and SupplicantMode.
>
>What am I missing? Any help would be greatly appreciated, and if anyone
>needs further information, just ask. Thanks!
>
>Kirk Hauer, CCNA, MCSE



Dave Mitton
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Need help on Modelsim VHDL syntax? ASAP:) kaji General Help Related Topics 0 03-14-2007 10:43 PM
Need help on a Modelsim VHDL Syntax? ASAP:) kaji Software 0 03-14-2007 10:43 PM
Need Help on a Modelsim VHDL Syntax....ASAP:) kaji Hardware 0 03-14-2007 10:41 PM
Parser Error Message: Could not load type 'Microsoft.SharePoint.ApplicationPages.Glob rasmita General Help Related Topics 0 09-05-2006 05:49 AM
Parser Error Message: Could not load type 'Microsoft.SharePoint.ApplicationPages.Glob rasmita General Help Related Topics 0 09-05-2006 05:46 AM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46