Jump to content

Recommended Posts

Posted

I'm wondering if anyone can help me out here

 

ive previously set up EAP-TLS machine based authentication at one of our sites using their new Aruba instant set up which works nicely, machines get added into a group, after a quick policy update they connect with no issue

 

ive not gone to do this at another site which has a Ruckus solution and am having issues, as far as I can tell ive done it all the same

 

- set up the policy's in NPS

- added the new NPS in ruckus under AAA servers

-created a new SSID for this and selected the NPS server (I did initially try dynamic VLAN's but have since set it to static just for testing to see if the issue lies there)

-GPO's for cert enrolment and adding the network

 

when I connect, NPS does state that

 

Network Policy Server granted access to a user.

 

but in Ruckus under the client connectivity it fails on RADIUS access Reject, Reason: (code 21)AAA authentication failed Info: Invalid user role

 

any insight into this ?

Posted

From your list, you may need to add the Ruckus Controller/APs as a RADIUS Client.

 

Also your NPS Server will likely provide more helpful error messages. This can be viewed in Event Viewer: Custom Views > Server Roles > Network Policy and Access Services.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...