mtdmitchell Posted February 3, 2009 Posted February 3, 2009 (edited) i Started to experience intermittent wireless problems last week, this week no one can get a wireless connect apart from a few random ones. I set up 35 Access points(wag102), IAS(server 2003) and 3 netgear Wireless smart switches last summer . This set up has worked fine up until last week. I haven't changed any settings honest! I m getting the following error message on the IAS server event viewer: All users get the same message. If you can help i would be most grateful User host/RMLAPBRODIEN.campion.internal was denied access. Fully-Qualified-User-Name = campion.internal/Establishments/SEC/Locations - SEC/Staff Notebooks/RMLAPBRODIEN NAS-IP-Address = 10.122.140.41 NAS-Identifier = 10.122.140.43 Called-Station-Identifier = 001B2F24EB80 Calling-Station-Identifier = 001B2FAF8F40 Client-Friendly-Name = SmartSwitch Slave 2 Client-IP-Address = 10.122.140.43 NAS-Port-Type = Wireless - IEEE 802.11 NAS-Port = 1 Proxy-Policy-Name = Use Windows authentication for all users Authentication-Provider = Windows Authentication-Server = Policy-Name = Wireless Access Authentication-Type = PEAP EAP-Type = Reason-Code = 16 Reason = Authentication was not successful because an unknown user name or incorrect password was used. all user receive the same error. Edited February 3, 2009 by mtdmitchell
jamesb Posted February 3, 2009 Posted February 3, 2009 Are the working ones consistently working? Do any of them have a different service pack installed? If so this might be worth a look: A user is not successfully authenticated when NTLMv2 authentication is used on a Windows Server 2003-based IAS server
mtdmitchell Posted February 3, 2009 Author Posted February 3, 2009 Are the working ones consistently working? Do any of them have a different service pack installed? If so this might be worth a look: A user is not successfully authenticated when NTLMv2 authentication is used on a Windows Server 2003-based IAS server no consistency what so ever. All Laptops are Xp Sp2
mtdmitchell Posted February 3, 2009 Author Posted February 3, 2009 (edited) f so this might be worth a look: A user is not successfully authenticated when NTLMv2 authentication is used on a Windows Server 2003-based IAS server i think that only applies to 2003 Sp1, thanks anyway, i have server 2003 sp2 installed Edited February 3, 2009 by mtdmitchell
spc-rocket Posted February 3, 2009 Posted February 3, 2009 i Started to experience intermittent wireless problems last week, this week no one can get a wireless connect apart from a few random ones. I set up 35 Access points(wag102), IAS(server 2003) and 3 netgear Wireless smart switches last summer . This set up has worked fine up until last week. I haven't changed any settings honest! I m getting the following error message on the IAS server event viewer: All users get the same message. If you can help i would be most grateful User host/RMLAPBRODIEN.campion.internal was denied access. Fully-Qualified-User-Name = campion.internal/Establishments/SEC/Locations - SEC/Staff Notebooks/RMLAPBRODIEN NAS-IP-Address = 10.122.140.41 NAS-Identifier = 10.122.140.43 Called-Station-Identifier = 001B2F24EB80 Calling-Station-Identifier = 001B2FAF8F40 Client-Friendly-Name = SmartSwitch Slave 2 Client-IP-Address = 10.122.140.43 NAS-Port-Type = Wireless - IEEE 802.11 NAS-Port = 1 Proxy-Policy-Name = Use Windows authentication for all users Authentication-Provider = Windows Authentication-Server = Policy-Name = Wireless Access Authentication-Type = PEAP EAP-Type = Reason-Code = 16 Reason = Authentication was not successful because an unknown user name or incorrect password was used. all user receive the same error. It seems to me that the host is denied rather than the user i.e. the machine account is not allowed access for some reason. Have you got a policy created that allows computers to connect to wireless before the user logs in? - to sort of simulate the wired experience Ash.
mtdmitchell Posted February 3, 2009 Author Posted February 3, 2009 (edited) It seems to me that the host is denied rather than the user i.e. the machine account is not allowed access for some reason. Have you got a policy created that allows computers to connect to wireless before the user logs in? - to sort of simulate the wired experience Ash. Policy is set for All Domain computers and Domain Users Infact i followed your instructions to the letter, it has worked fine for over 5 months. Edited February 3, 2009 by mtdmitchell
spc-rocket Posted February 3, 2009 Posted February 3, 2009 (edited) Policy is set for All Domain computers and Domain Users Infact i followed your instructions to the letter, it has worked fine for over 5 months. Hmm, Just wondering if you certificate has expired or comming up to expiration. You can try renewing the certificate to see if it cures this problem. Also which cert method are you using? 1 Enterprise CA 2 Stand-alone CA 3 Self-signed Cert One other thing you can try is to create a policy for domain computer seperately and another seperate policy for domain users. Also check that the user has "control through remote policy" setting enabled on the dial-in tab of the user properties. Your domain functional level must be windows 2000 or 2003 for the above option to be available. Also make sure that the shared secret is correct at both ends on the AP or controller as well as its corrosponding entry in Radius Clients section of IAS as this will cause authentication issues if they don't match. Ash. Edited February 3, 2009 by spc-rocket
mtdmitchell Posted February 3, 2009 Author Posted February 3, 2009 Hmm, Just wondering if you certificate has expired or comming up to expiration. You can try renewing the certificate to see if it cures this problem. Also which cert method are you using? 1 Enterprise CA 2 Stand-alone CA 3 Self-signed Cert One other thing you can try is to create a policy for domain computer seperately and another seperate policy for domain users. Also check that the user has "control through remote policy" setting enabled on the dial-in tab of the user properties. Your domain functional level must be windows 2000 or 2003 for the above option to be available. Also make sure that the shared secret is correct at both ends on the AP or controller as well as its corrosponding entry in Radius Clients section of IAS as this will cause authentication issues if they don't match. Ash. thanks for the replies Ash, i really appreiciate it. I have an RM CC3 network so we are using the Enterprise C.A . The certificate doesn't expire for another 2-3 months.control through remote policy is on and Shared Secret is ok. I will try a seperate policy.
mtdmitchell Posted February 6, 2009 Author Posted February 6, 2009 Ash can you tell me if the CA is actually installed on the stations of a cc3 network or are they on the stations because they are joined to the domain? I see they can be pushed out though group policy but RM dont do this from what i can see
spc-rocket Posted February 7, 2009 Posted February 7, 2009 Ash can you tell me if the CA is actually installed on the stations of a cc3 network or are they on the stations because they are joined to the domain? I see they can be pushed out though group policy but RM dont do this from what i can see Hiya, On the RM CC3 they have the enterprise CA installed on the forest root server so it does make it easier to request the certificates from the FR server. Because its enterprise CA, the root certificate of the CA is automatically copied to all stations that are joined to the domain so you don't need to use the GPO method to roll out the root cert. to stations. From memory i think RM calles the Certificate authority CA followed by the name of the school i think i.e. CA Wakefiled School. In your configuration on the laptop you should have a tick next to this certificate for it to identify the Radius server. The reason for this is that you want to know that the radius server you are connected is trusted and is not bogus otherwise there are potential for man in the middle attacks. So if you used your enterprise CA to obtain a Cert for your IAS server then you should be okay. If you are trying to authenticate stations that are not domain joined then you need to copy the root certificate of the enterprise CA and import it to the station (in the trusted root certification authority store). Can you try renewing the certificate to see if it cures the problem. I think its the cert that's the issue. I'm on annual leave from next week for about a month so won't be able to get back to you but do tell me how you get on. Ash. 1
mtdmitchell Posted February 7, 2009 Author Posted February 7, 2009 I re-issued the CA earlier in the week and it has cured the problem on 99% of the laptops. I just have few random laptops which will not Authenticate ( A rebuild cures the problem). Strange because if i manually add the CA or delete the CA on the laptop it still does not work. Another strange thing is these stations have two or three CA's installed. But not to worry as im back up and running now thanks to your advise. I asked about the certificate because i spoke to a RM tech who is telling the no CA is copied onto the RM stations. Thanks again Martin
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now