Jump to content

Recommended Posts

Posted

I do love my Ruckus wireless and has always worked beautifully so i just let it be.

 

The other day it was brought to my attention that our Netbooks aren't connecting. Now i quite often get the "no logon servers available blah blah" error but this time it's all of them, not just one or two.

 

They all authenticate via certificate deployed via GPO, sat on their own WLAN.

 

Looking in the logs, the netbook i was testing has the entries:

 

2013/10/02 14:13:40 High User fails authentication too many times in a row when joining WLAN[HPS Wireless] at AP[AP13]. User is temporarily blocked from the system for [30 seconds].

2013/10/02 14:13:06 Low host/NETBOOK-061.harborne.pri User[host/NETBOOK-061.harborne.pri] disconnects from WLAN[HPS Wireless] at AP[AP13]

2013/10/02 14:12:48 Low host/NETBOOK-061.harborne.pri User[host/NETBOOK-061.harborne.pri] disconnects from WLAN[HPS Wireless] at AP[AP13]

 

One thing i have noticed is that its Uptime is *cough*480d 20h 27m*cough* (where the hell does the time go!?!) so a reboot might not be a bad idea.

 

Any other suggests of what to have a look at?

Posted (edited)

You won't get a DHCP address until the full 802.1x authentication is complete, so it can't be that. It states in the log that authentication is failing.

 

What radius solution are you using ? Can you see anything in the radius server logs to indicate timeouts being reached ? I would suspect delayed authentication frames, probably due to WiFi issues. Does this device manage to get on the network successfully when connecting to an alternative AP ?

 

The best thing to do is a frame capture on both the wifi and wired side of the network and to view a full 802.1X EAP exchange, then you can identify which frames are lost and therefore where the problem is.

 

I realise that's not easy for you to organse but try and do your best to test this.

 

Post back any other relevant info.

 

NM

Edited by neilmac
Posted

Ok, so far: A reboot of my Controller didnt work. Netbooks can happily connect to the other Open Auth connections.

 

DHCP is fine.

 

Now...at this point I hold my hands up and say I'm still new to the certificate side of things. I guess they've always been part of the process when things were set up by others.

 

Funnily enough, there are certificates that expired on Sunday, the day before this all kicked off. They're for my 2008 server. Under the Intermidate Certification Autorities folder there are two identical looking certs sat in the Cert Revocation list.....this im guessing is an issue?

 

I feel so ill, i'm only here and not in bed because i want these netbooks working...

Posted

See, i thought i was daft to consider this. I have had one wired in but it made no difference. Is there a way to force it down?

 

Though if i go to certmrg.msc i can see it in there....

Posted

Doing a gpupdate /force should pull it down, if you're deploying it through GPOs normally. As it'll be on the normal GPO tick refresh etc. Then it'll probably need full restart (but may not)

 

Steve

Posted

That should do it :( But the other option would be "certutil -pulse" which would initiate the autoenrollment, but not sure if that'll do anything more if the other isn't working anyway.

 

Steve

Posted

You have to add the certificate back on the NPS server (it doesn't update automatically)

 

NPS - Network policy - constraints - authentication methods - smart card or certificate, then pick the new cert from the drop down list (should be in there now).

Posted
Done, no difference. Still repeatedly failing authentication when joining WLAN....

 

days like these make me hate my job...

 

Wipe it and start again?

Posted (edited)

now that you have added the updated cert to NPS, restarted NPS, I would hard wire the client , remove the existing certs off the client and gpupdate /force and not sure how much it helps but I ignore any prompts to log off / reboot etc and then do the gpupdate /sync and then reboot with the network cable still in , only disconnect the network cable either at the logon screen or after trying to connect to wifi ( either or )

 

May also be worth while checking to see if the client has had the new cert added to it ( I normally do start --> run --> mmc --> ok --> file --> add / remove snap in --> certificates --> I presume it is my user account that you select as far as the type of certificate(s) that you need to manage on the client laptop / netbook --> expand the relevant folders / directories ( which I believe is certificates --current user --> personal --> certificates --> middle pane should show the certificate(s) that are on the client

 

Try and connect again ?

 

Presume you dont have to wait 20 to 30 mins for GPO settings etc to sync between servers etc ?

 

Also remove any previously configured WLAN Network profiles in windows or any network utils ie intel / access connections or whatever ( if any are installed ) ??

Edited by mac_shinobi
Posted

The certificates etc where I work is done by the server / network team so couldn't tell you as no experience of Ruckus or certificates tbh. However the certificates we use are in personal as it has been setup as a user certificate ( originally it was setup and linked as a computer certificate but we found that users could copy this to get wireless on there own personal devices which we didn't want ) so it was then changed from a computer certificate to a user certificate.

 

Will just stay subscribed now as can't really help much more

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...