Jump to content

Wireless authentication stopped working following reboot of NPS server


Recommended Posts

Posted (edited)

Hi,

 

We've encountered an unusual issue with our wireless network, following the reboot of our Network Policy Server (on Mon 18 Sept).

 

Basically, the domain-joined laptops can no longer connect to the wireless network (not authenticated). They are configured to connect to a hidden SSID that uses 802.1x for authentication. Each laptop is authenticated using machine certificates which are automatically issued from Microsoft certificate services.

 

The other 802.1x authenticated wireless network broadcast by the controller also stopped working at the same time (which is used for staff's own devices and authenticates using their AD username/password rather than having a certificate installed on the device.)

 

The NPS logs (NPS is installed onto a DC), show expected successful/unsuccessful authentication/connections, but shows no events what-so-ever after the reboot. It's almost as if NPS has stopped functioning or has stopped receiving (or listening for) an 802.1x requests from the wireless controller. However, the windows system event log shows recurring error events relating to NPS:

 

"A RADIUS message with the Code field set to 1, which is not valid, was received on port 1812 from RADIUS client Juniper_Curric. Valid values of the RADIUS Code field are documented in RFC 2865." EventID 16.

 

The odd thing about this error is according to RFC 2865, Code 1 is a normal 802.1x access request.

 

Following the reboot of the NPS server, two KBs were activated (were previously installed and were pending a reboot to take affect):

 

KB4038792 Security roll-up

KB4041085 .Net framework update

 

According to MS, the former is supposed to include a fix for a bug relating to 802.1x. But according to a non-MS article, the KB can also cause connectivity issues with 802.1x authenticated wireless devices. Implementing the suggested registry fix or completely uninstalling the KB doesn't resolve the issue. And we can't find any info on the latter KB being the cause any wireless or 802.1x issues.

 

Something that might be relevant, a few weeks ago we accidentally created a new root CA cert in Microsoft Certificate Services, so we now have two root CA certs. As mentioned above, Cert Services is being used to provide domain joined wireless devices with machoine certificates. However, after a little investigation and testing, we decided that this probably wasn't the root cause of the issue, but we aren't 100% sure.

 

As a temporary resolution, we are manually connecting the domain-joined laptops to the WPA-PSK SSID (which is still working) and have updated the GPO policy to require the laptops to connect this SSID instead of the non-working 802.1x network.

 

Anyone I'm putting it out there to any experts on wireless or 8021x auth (or anyone else) who might have some idea of what the problem could be?

 

Kind Regards,

 

Bruce.

Edited by Bruce123
Posted

Hi,

 

I had a read of the MS article for KB4038792 and followed a link to the "August 15, 2017—KB4034663 (Preview of Monthly Rollup)"

 

https://support.microsoft.com/en-gb/help/4034663

 

Which has the following about half way down;

 

Known issues in this update

 

Symptom Workaround

NPS authentication may break, and wireless clients may fail to connect.

 

On the server, set the following DWORD registry key's value to = 0: SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\13\DisableEndEntityClientCertCheck

 

Maybe that will help.

 

Thanks,

Martin

Posted
Hi,

 

I had a read of the MS article for KB4038792 and followed a link to the "August 15, 2017—KB4034663 (Preview of Monthly Rollup)"

 

https://support.microsoft.com/en-gb/help/4034663

 

Which has the following about half way down;

 

Known issues in this update

 

Symptom Workaround

NPS authentication may break, and wireless clients may fail to connect.

 

On the server, set the following DWORD registry key's value to = 0: SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\13\DisableEndEntityClientCertCheck

 

Maybe that will help.

 

Thanks,

Martin

 

Hi Martin,

 

Thank you for looking into this.

 

Unfortunately we already tried this fix (this was the registry change I referred to) and it didn't work. We also tried uninstalling KB entirely...

 

Thanks anyway.

 

Kind Regards,

 

Bruce.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...