Jump to content

Recommended Posts

Posted (edited)

i Started to experience intermittent wireless problems last week, this week no one can get a wireless connect apart from a few random ones. I set up 35 Access points(wag102), IAS(server 2003) and 3 netgear Wireless smart switches last summer . This set up has worked fine up until last week. I haven't changed any settings honest! I m getting the following error message on the IAS server event viewer:

 

All users get the same message. If you can help i would be most grateful

 

User host/RMLAPBRODIEN.campion.internal was denied access.

Fully-Qualified-User-Name = campion.internal/Establishments/SEC/Locations - SEC/Staff Notebooks/RMLAPBRODIEN

NAS-IP-Address = 10.122.140.41

NAS-Identifier = 10.122.140.43

Called-Station-Identifier = 001B2F24EB80

Calling-Station-Identifier = 001B2FAF8F40

Client-Friendly-Name = SmartSwitch Slave 2

Client-IP-Address = 10.122.140.43

NAS-Port-Type = Wireless - IEEE 802.11

NAS-Port = 1

Proxy-Policy-Name = Use Windows authentication for all users

Authentication-Provider = Windows

Authentication-Server =

Policy-Name = Wireless Access

Authentication-Type = PEAP

EAP-Type =

Reason-Code = 16

Reason = Authentication was not successful because an unknown user name or incorrect password was used.

 

 

all user receive the same error.

Edited by mtdmitchell
Posted (edited)
f so this might be worth a look: A user is not successfully authenticated when NTLMv2 authentication is used on a Windows Server 2003-based IAS server

 

i think that only applies to 2003 Sp1, thanks anyway, i have server 2003 sp2 installed

Edited by mtdmitchell
Posted
i Started to experience intermittent wireless problems last week, this week no one can get a wireless connect apart from a few random ones. I set up 35 Access points(wag102), IAS(server 2003) and 3 netgear Wireless smart switches last summer . This set up has worked fine up until last week. I haven't changed any settings honest! I m getting the following error message on the IAS server event viewer:

 

All users get the same message. If you can help i would be most grateful

 

User host/RMLAPBRODIEN.campion.internal was denied access.

Fully-Qualified-User-Name = campion.internal/Establishments/SEC/Locations - SEC/Staff Notebooks/RMLAPBRODIEN

NAS-IP-Address = 10.122.140.41

NAS-Identifier = 10.122.140.43

Called-Station-Identifier = 001B2F24EB80

Calling-Station-Identifier = 001B2FAF8F40

Client-Friendly-Name = SmartSwitch Slave 2

Client-IP-Address = 10.122.140.43

NAS-Port-Type = Wireless - IEEE 802.11

NAS-Port = 1

Proxy-Policy-Name = Use Windows authentication for all users

Authentication-Provider = Windows

Authentication-Server =

Policy-Name = Wireless Access

Authentication-Type = PEAP

EAP-Type =

Reason-Code = 16

Reason = Authentication was not successful because an unknown user name or incorrect password was used.

 

 

all user receive the same error.

 

It seems to me that the host is denied rather than the user i.e. the machine account is not allowed access for some reason.

 

Have you got a policy created that allows computers to connect to wireless before the user logs in? - to sort of simulate the wired experience

 

Ash.

Posted (edited)
It seems to me that the host is denied rather than the user i.e. the machine account is not allowed access for some reason.

 

Have you got a policy created that allows computers to connect to wireless before the user logs in? - to sort of simulate the wired experience

 

Ash.

 

Policy is set for All Domain computers and Domain Users

 

Infact i followed your instructions to the letter, it has worked fine for over 5 months.

Edited by mtdmitchell
Posted (edited)
Policy is set for All Domain computers and Domain Users

 

Infact i followed your instructions to the letter, it has worked fine for over 5 months.

 

Hmm, Just wondering if you certificate has expired or comming up to expiration. You can try renewing the certificate to see if it cures this problem.

 

Also which cert method are you using?

 

1 Enterprise CA

2 Stand-alone CA

3 Self-signed Cert

 

One other thing you can try is to create a policy for domain computer seperately and another seperate policy for domain users. Also check that the user has "control through remote policy" setting enabled on the dial-in tab of the user properties.

 

Your domain functional level must be windows 2000 or 2003 for the above option to be available.

 

Also make sure that the shared secret is correct at both ends on the AP or controller as well as its corrosponding entry in Radius Clients section of IAS as this will cause authentication issues if they don't match.

 

Ash.

Edited by spc-rocket
Posted
Hmm, Just wondering if you certificate has expired or comming up to expiration. You can try renewing the certificate to see if it cures this problem.

 

Also which cert method are you using?

 

1 Enterprise CA

2 Stand-alone CA

3 Self-signed Cert

 

One other thing you can try is to create a policy for domain computer seperately and another seperate policy for domain users. Also check that the user has "control through remote policy" setting enabled on the dial-in tab of the user properties.

 

Your domain functional level must be windows 2000 or 2003 for the above option to be available.

 

Also make sure that the shared secret is correct at both ends on the AP or controller as well as its corrosponding entry in Radius Clients section of IAS as this will cause authentication issues if they don't match.

 

Ash.

 

thanks for the replies Ash, i really appreiciate it.

 

I have an RM CC3 network so we are using the Enterprise C.A . The certificate doesn't expire for another 2-3 months.control through remote policy is on and Shared Secret is ok.

 

I will try a seperate policy.

Posted

Ash can you tell me if the CA is actually installed on the stations of a cc3 network or are they on the stations because they are joined to the domain?

 

I see they can be pushed out though group policy but RM dont do this from what i can see

Posted
Ash can you tell me if the CA is actually installed on the stations of a cc3 network or are they on the stations because they are joined to the domain?

 

I see they can be pushed out though group policy but RM dont do this from what i can see

 

Hiya,

 

On the RM CC3 they have the enterprise CA installed on the forest root server so it does make it easier to request the certificates from the FR server. Because its enterprise CA, the root certificate of the CA is automatically copied to all stations that are joined to the domain so you don't need to use the GPO method to roll out the root cert. to stations.

 

From memory i think RM calles the Certificate authority CA followed by the name of the school i think i.e. CA Wakefiled School.

 

In your configuration on the laptop you should have a tick next to this certificate for it to identify the Radius server. The reason for this is that you want to know that the radius server you are connected is trusted and is not bogus otherwise there are potential for man in the middle attacks.

 

So if you used your enterprise CA to obtain a Cert for your IAS server then you should be okay.

 

If you are trying to authenticate stations that are not domain joined then you need to copy the root certificate of the enterprise CA and import it to the station (in the trusted root certification authority store).

 

Can you try renewing the certificate to see if it cures the problem. I think its the cert that's the issue.

 

I'm on annual leave from next week for about a month so won't be able to get back to you but do tell me how you get on.

 

Ash.

  • Thanks 1
Posted

I re-issued the CA earlier in the week and it has cured the problem on 99% of the laptops. I just have few random laptops which will not Authenticate ( A rebuild cures the problem). Strange because if i manually add the CA or delete the CA on the laptop it still does not work. Another strange thing is these stations have two or three CA's installed. But not to worry as im back up and running now thanks to your advise.

 

I asked about the certificate because i spoke to a RM tech who is telling the no CA is copied onto the RM stations.:eek:

 

Thanks again

Martin

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...