Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > 802.1x authentication fails after Windows XP reboot

Reply
Thread Tools

802.1x authentication fails after Windows XP reboot

 
 
ttripp
Guest
Posts: n/a
 
      03-18-2009
I have XP SP3 installed on a workstation, configured to use 802.1x
authentication with a Cisco 3750 switch and a Microsoft NAP server
providing RADIUS services.

When I boot up the workstation, 802.1x authentication fails. If I
unplug the network cable from the workstation, then plug it back in,
the workstation immedately authenticates and grabs and IP address from
DHCP.

If I reboot, authentication fails again until I unplug and replug the
cable. I can get the same result if I do a "shut/no shut" on the
Cisco switch's port.

Obviously, there's nothing actually wrong with 802.1x authentication,
or RADIUS or the switch. It's only when the workstation first boots
up; I'm guessing that while it's booting up, some service(s) are still
coming up and preventing authentication from working, but once the
workstation has finished booting, it is stuck in the switch's "failed
authentication" vlan, and the only way to restart the authentication
process is to break the network connection.

Since I'm going to deploy 802.1x to a couple of thousand workstations,
unplugging cables or reseting switch ports isn't a practical solution.

Does anyone know how to resolve this problem? Thanks.
 
Reply With Quote
 
 
 
 
Andrey Tarasov
Guest
Posts: n/a
 
      03-18-2009
ttripp wrote:
> I have XP SP3 installed on a workstation, configured to use 802.1x
> authentication with a Cisco 3750 switch and a Microsoft NAP server
> providing RADIUS services.
>
> When I boot up the workstation, 802.1x authentication fails. If I
> unplug the network cable from the workstation, then plug it back in,
> the workstation immedately authenticates and grabs and IP address from
> DHCP.
>
> If I reboot, authentication fails again until I unplug and replug the
> cable. I can get the same result if I do a "shut/no shut" on the
> Cisco switch's port.
>
> Obviously, there's nothing actually wrong with 802.1x authentication,
> or RADIUS or the switch. It's only when the workstation first boots
> up; I'm guessing that while it's booting up, some service(s) are still
> coming up and preventing authentication from working, but once the
> workstation has finished booting, it is stuck in the switch's "failed
> authentication" vlan, and the only way to restart the authentication
> process is to break the network connection.
>
> Since I'm going to deploy 802.1x to a couple of thousand workstations,
> unplugging cables or reseting switch ports isn't a practical solution.
>
> Does anyone know how to resolve this problem? Thanks.


I wonder if this discussion is relevant to your problem -

http://social.technet.microsoft.com/...-152b956567bc/

Also in XP SP3 wired part of 802.1x supplicant is a separate service and
no longer part of wireless zero config. It's in manual start mode by
default. Have you changed it to auto?

Regards,
Andrey.
 
Reply With Quote
 
 
 
 
ttripp
Guest
Posts: n/a
 
      03-18-2009
On Mar 18, 3:31*pm, Andrey Tarasov <and...@email.com> wrote:
> ttripp wrote:
> > I have XP SP3 installed on a workstation, configured to use 802.1x
> > authentication with a Cisco 3750 switch and a Microsoft NAP server
> > providing RADIUS services.

>
> > When I boot up the workstation, 802.1x authentication fails. *If I
> > unplug the network cable from the workstation, then plug it back in,
> > the workstation immedately authenticates and grabs and IP address from
> > DHCP.

>
> > If I reboot, authentication fails again until I unplug and replug the
> > cable. *I can get the same result if I do a "shut/no shut" on the
> > Cisco switch's port.

>
> > Obviously, there's nothing actually wrong with 802.1x authentication,
> > or RADIUS or the switch. *It's only when the workstation first boots
> > up; I'm guessing that while it's booting up, some service(s) are still
> > coming up and preventing authentication from working, but once the
> > workstation has finished booting, it is stuck in the switch's "failed
> > authentication" vlan, and the only way to restart the authentication
> > process is to break the network connection.

>
> > Since I'm going to deploy 802.1x to a couple of thousand workstations,
> > unplugging cables or reseting switch ports isn't a practical solution.

>
> > Does anyone know how to resolve this problem? *Thanks.

>
> I wonder if this discussion is relevant to your problem -
>
> http://social.technet.microsoft.com/...verNAP/thread/...
>
> Also in XP SP3 wired part of 802.1x supplicant is a separate service and
> no longer part of wireless zero config. It's in manual start mode by
> default. Have you changed it to auto?
>
> Regards,
> Andrey.- Hide quoted text -
>
> - Show quoted text -


That's interesting. I tried a little more testing and if I just let
the workstation sit, it will authenticate itself after about 25
minutes, which is about the same time as mentioned in the link you
provided.
 
Reply With Quote
 
ttripp
Guest
Posts: n/a
 
      03-19-2009
On Mar 18, 4:07*pm, ttripp <ttr...@manh.com> wrote:
> On Mar 18, 3:31*pm, Andrey Tarasov <and...@email.com> wrote:
>
>
>
>
>
> > ttripp wrote:
> > > I have XP SP3 installed on a workstation, configured to use 802.1x
> > > authentication with a Cisco 3750 switch and a Microsoft NAP server
> > > providing RADIUS services.

>
> > > When I boot up the workstation, 802.1x authentication fails. *If I
> > > unplug the network cable from the workstation, then plug it back in,
> > > the workstation immedately authenticates and grabs and IP address from
> > > DHCP.

>
> > > If I reboot, authentication fails again until I unplug and replug the
> > > cable. *I can get the same result if I do a "shut/no shut" on the
> > > Cisco switch's port.

>
> > > Obviously, there's nothing actually wrong with 802.1x authentication,
> > > or RADIUS or the switch. *It's only when the workstation first boots
> > > up; I'm guessing that while it's booting up, some service(s) are still
> > > coming up and preventing authentication from working, but once the
> > > workstation has finished booting, it is stuck in the switch's "failed
> > > authentication" vlan, and the only way to restart the authentication
> > > process is to break the network connection.

>
> > > Since I'm going to deploy 802.1x to a couple of thousand workstations,
> > > unplugging cables or reseting switch ports isn't a practical solution..

>
> > > Does anyone know how to resolve this problem? *Thanks.

>
> > I wonder if this discussion is relevant to your problem -

>
> >http://social.technet.microsoft.com/...verNAP/thread/...

>
> > Also in XP SP3 wired part of 802.1x supplicant is a separate service and
> > no longer part of wireless zero config. It's in manual start mode by
> > default. Have you changed it to auto?

>
> > Regards,
> > Andrey.- Hide quoted text -

>
> > - Show quoted text -

>
> That's interesting. *I tried a little more testing and if I just let
> the workstation sit, it will authenticate itself after about 25
> minutes, which is about the same time as mentioned in the link you
> provided.- Hide quoted text -
>
> - Show quoted text -


I tested using the hotfix mentioned in the link you provided, and it
corrected the problem. Another wonderful Microsoft "feature". Now
I've got to figure out how to get this hotfix out to all the
workstations in my company.
 
Reply With Quote
 
Igor Mamuzic aka Pseto
Guest
Posts: n/a
 
      03-19-2009
"ttripp" <> wrote in message
news:eb675d54-52c3-4aee-8d89-...
On Mar 18, 4:07 pm, ttripp <ttr...@manh.com> wrote:

> I tested using the hotfix mentioned in the link you provided, and it
> corrected the problem. Another wonderful Microsoft "feature". Now
> I've got to figure out how to get this hotfix out to all the
> workstations in my company.


Do you have Active Directory?



 
Reply With Quote
 
ttripp
Guest
Posts: n/a
 
      03-23-2009
On Mar 19, 8:55*am, "Igor Mamuzic aka Pseto"
<igor.mamuzicMAKNI_...@zg.t-com.hr> wrote:
> "ttripp" <ttr...@manh.com> wrote in message
>
> news:eb675d54-52c3-4aee-8d89-...
> On Mar 18, 4:07 pm, ttripp <ttr...@manh.com> wrote:
>
> > I tested using the hotfix mentioned in the link you provided, and it
> > corrected the problem. *Another wonderful Microsoft "feature". *Now
> > I've got to figure out how to get this hotfix out to all the
> > workstations in my company.

>
> Do you have Active Directory?


Does anyone know if this affects Windows Server 2000 or 2003? The
link only mentions XP, Vista and Server 2008, but I have other OSes to
worry about.
 
Reply With Quote
 
HawkEye22 HawkEye22 is offline
Junior Member
Join Date: May 2009
Posts: 1
 
      05-26-2009
ttrip,

Can i ask you a couple of questions?
I am doing a little research to implement 802.1X authentication.
Which option for EAP do you use in windows? is that PEAP?
And do you use certificates? If yes? how did you do that?

Thanks in advance,

HawkEye22
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Reboot, reboot, reboot Lawrence D'Oliveiro NZ Computing 12 03-07-2009 11:35 PM
Singleton class fails on reboot keepyourstupidspam@yahoo.co.uk C++ 12 07-09-2006 09:36 PM
INFO: Reboot problm after rebooting dual Linux/Windows system Gary G. Taylor Computer Support 2 06-12-2006 01:16 AM
To reboot the PIX or not reboot - that is the question Darren Green Cisco 1 03-14-2006 10:59 PM
Forms Authentication Fails Between ASP.NET 1.0 and 1.1 Applications (Cookie Decryption Fails) John Saunders ASP .Net 1 11-18-2003 03:25 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57