dezt Posted October 31, 2008 Posted October 31, 2008 I've just looked at our radius server and could not find the same error you have got, but by comparing your IAS record and mine, i have the poicy name listed under Authentication server when someone is granted access. At a guess i would say double check your IAS remote access policy. If need be delete it and build a new one.
spc-rocket Posted October 31, 2008 Posted October 31, 2008 I have been asked by the LEA to tighten our wireless security as we are using WEP. Followed Asok's excellent howto and everything seems to be in place. However I am receiving an authentication failed when trying to connect manually from a wireless client laptop. Below is the entry in the logs: User JSCHS\ajones_laptop was denied access. Fully-Qualified-User-Name = JSCHS\ajones_laptop NAS-IP-Address = 172.16.64.11 NAS-Identifier = Called-Station-Identifier = 00-1A-70-A6-19-72:linksys-n Calling-Station-Identifier = 00-14-A5-0E-8A-38 Client-Friendly-Name = LinkSys WAP4400N T6 Client-IP-Address = 172.16.64.11 NAS-Port-Type = Wireless - IEEE 802.11 NAS-Port = 0 Proxy-Policy-Name = Use Windows authentication for all users Authentication-Provider = Windows Authentication-Server = Policy-Name = Authentication-Type = EAP EAP-Type = Reason-Code = 48 Reason = The connection attempt did not match any remote access policy. Can anyone help please. Hi there, It seems that the policies that you have does not match the request that is sent by the clients so it uses the default deny rule which is to deny access. Make sure that your policies are correct and it catches the user you are tryign to login. You need to make sure that it ctaches the computer (machine) as well as the user. Ash.
jsnetman Posted October 31, 2008 Posted October 31, 2008 Thanks Ashok, after a bit of tinkering and a reboot of the servers all is well. But because I was stuck I do not have time to reconfig all the access points. I will have to come in one Saturday and complete the project.
northernrob Posted November 5, 2008 Posted November 5, 2008 Thanks for the excellent documentation. I have configured my IAS Server, deployed certificate and group policy. I am currently tested one client and the wireless hangs with a status of Validating identity. The wireless point I am testing is a ProCurve Wireless Access Point 10ag, I have entered the IP Address, IP Port and Radius Secret. On the server I get the following error; Event Type: Error Event Source: IAS Event Category: None Event ID: 16 Date: 05/11/2008 Time: 10:19:24 User: N/A Computer: servK301 Description: A RADIUS message with the Code field set to 1, which is not valid, was received on port 1646 from RADIUS client Server Cup HP Procurve. Valid values of the RADIUS Code field are documented in RFC 2865. For more information, see Help and Support Center at Events and Errors Message Center: Basic Search. Thanks in advance
tomscaper Posted November 6, 2008 Posted November 6, 2008 I have been playing around with this for a while now, and am about to give up, went through all the documentation and set up up IAS and created a group policy and certificates using selfssl. I configured the wireless access point to look at the radius server, and set it using WPA and TKIP, on the machine i want wireless to connect from, it just get the error that it could not authenticate. Not sure where i could of went wrong, or if it is the access point or some setting i have missed.
plexer Posted November 6, 2008 Posted November 6, 2008 Have a look at Elektron from Periodik Labs: Elektron RADIUS Server for Wireless Security you can download a trial of it. We use it for our radius server. Ben
jsnetman Posted November 6, 2008 Posted November 6, 2008 Don't know what help this will give. I had the same sort of problem but could not determine what the problem was eventually I ran a windows update rebooted server and magically it sprang to life. Keep fiddling it is well worth it to secure your wireless. We had to under LEA guidelines. One thing I did do after reading an MS whitepaper on preparing AD for radius server was enable reverse encryption of passwords at domain level and reset the user password I was testing. Someone please tell me if you do not have to enable reverse encryption as I read somewhere else its a slight wekening of security.
spc-rocket Posted November 6, 2008 Posted November 6, 2008 (edited) I have been playing around with this for a while now, and am about to give up, went through all the documentation and set up up IAS and created a group policy and certificates using selfssl. I configured the wireless access point to look at the radius server, and set it using WPA and TKIP, on the machine i want wireless to connect from, it just get the error that it could not authenticate. Not sure where i could of went wrong, or if it is the access point or some setting i have missed. Have you created the Remote Access Polices and do they contain the right groups i.e. groups which has computer and or users. Also make sure that the shared secret is correctly entered on both the AP as well as the enty in IAS. The following hotfixes that i know of : IAS Server (2003) - 323538 - 931533 - 883659 Windows XP wireless fixes - 893357 - 917021 - 923154 Windows Vista - 932063 Ash. Edited November 6, 2008 by spc-rocket
tomscaper Posted November 6, 2008 Posted November 6, 2008 Have you created the Remote Access Polices and do they contain the right groups i.e. groups which has computer and or users. Also make sure that the shared secret is correctly entered on both the AP as well as the enty in IAS. Ash. Yeah i have the groups set up right, i have created a group called wireless and put the laptops in that group, is that all i need to do. I have checked that the shared secret is the same. I am just trying now to create the certificate again as i think i made a mistake last time. Other than that i cant think of anything else.
spc-rocket Posted November 6, 2008 Posted November 6, 2008 Yeah i have the groups set up right, i have created a group called wireless and put the laptops in that group, is that all i need to do. I have checked that the shared secret is the same. I am just trying now to create the certificate again as i think i made a mistake last time. Other than that i cant think of anything else. Hiya, Can you provide the following: - is the laptop/desktop joined to the domain? - what is wireless card vendor? Intel, Broadcom etc - If its a self-signed cert have to imported to the trusted root certification authority? some screenshots of the remote access policies would also help. Ash.
broc Posted November 6, 2008 Posted November 6, 2008 @Ash, Hi, Can you check the last Server 2003 hotfix number for me please? When I searched for it on MS Help & Support site it said 932063 was a Vista Client Wireless hotfix? Thanks
tomscaper Posted November 6, 2008 Posted November 6, 2008 (edited) Hiya, Can you provide the following: - is the laptop/desktop joined to the domain? - what is wireless card vendor? Intel, Broadcom etc - If its a self-signed cert have to imported to the trusted root certification authority? some screenshots of the remote access policies would also help. Ash. Yeah joined laptop to domain. Wireless is builtin to laptop and is realtek 8187B Self signed certificate is imported in trusted root certfication authority on the laptop in question and on the IAS server. plus on the dc where the group policy is applied. When i log on the laptop is just says "could not connect to Wireless SSID Have attached screenshot, the laptop is in the group on the screenshot. Edited November 6, 2008 by tomscaper
spc-rocket Posted November 6, 2008 Posted November 6, 2008 @Ash, Hi, Can you check the last Server 2003 hotfix number for me please? When I searched for it on MS Help & Support site it said 932063 was a Vista Client Wireless hotfix? Thanks Hiya, Yes you're right it is a vista hotfix. I'll update my other post. Thanks. Ash.
spc-rocket Posted November 6, 2008 Posted November 6, 2008 Yeah joined laptop to domain. Wireless is builtin to laptop and is realtek 8187B Self signed certificate is imported in trusted root certfication authority on the laptop in question and on the IAS server. plus on the dc where the group policy is applied. When i log on the laptop is just says "could not connect to Wireless SSID Have attached screenshot, the laptop is in the group on the screenshot. Hmm, Seems interesting, that realtek card seems to causes issues for a lot of people by the looks of it. Can you post some config the "edit profile" (screenshot you sent earlier). If the card is 802.11n capable can you disable this for testing to see if there are any issues with this. Also make sure that the device is not set to power off when not i use - this setting is found in the device properties in Device Manager. Ash.
tomscaper Posted November 6, 2008 Posted November 6, 2008 here are the screenshots of the edit part, blured out certificate as it is schools name. Was under the assumption the card was just 802.11b/g.
spc-rocket Posted November 7, 2008 Posted November 7, 2008 here are the screenshots of the edit part, blured out certificate as it is schools name. Was under the assumption the card was just 802.11b/g. That looks okay to me. You could try using another laptop with another wireless card (from another vendor such as Intel) to see if the drivers for the realtek are no good. Driver updates play a big part in stable wireless connections, so far the intel wireless card are pretty good and reliable. Ash.
plexer Posted November 7, 2008 Posted November 7, 2008 Try the 30 day trial of the odessey access client. Ben
tomscaper Posted November 7, 2008 Posted November 7, 2008 That looks okay to me. You could try using another laptop with another wireless card (from another vendor such as Intel) to see if the drivers for the realtek are no good. Driver updates play a big part in stable wireless connections, so far the intel wireless card are pretty good and reliable. Ash. It never connects at all even if i set it manually, it just says cannot connect to 3com or something on the lines of that. Drivers are the new from the realtek site.
spc-rocket Posted November 7, 2008 Posted November 7, 2008 It never connects at all even if i set it manually, it just says cannot connect to 3com or something on the lines of that. Drivers are the new from the realtek site. Hiya, Does it have the bubbles (kind of orbiting the icon) going around the wireless icon in the task bar (next to the clock)? Also is the connection in windows profile set to automatic rather than manual. Having it manual will not initiate the connection during start up or other times. My guess is that the drivers are not written very well by the looks of it. If it is possible can you use another laptop with built-in wireless card i.e. intel and then try it with that. This will hoepfull eliminate the radius and AP side of things. Also do you get any errors in the system log on the radius server? Ash. 1
tomscaper Posted November 7, 2008 Posted November 7, 2008 Hiya, Does it have the bubbles (kind of orbiting the icon) going around the wireless icon in the task bar (next to the clock)? Also is the connection in windows profile set to automatic rather than manual. Having it manual will not initiate the connection during start up or other times. My guess is that the drivers are not written very well by the looks of it. If it is possible can you use another laptop with built-in wireless card i.e. intel and then try it with that. This will hoepfull eliminate the radius and AP side of things. Also do you get any errors in the system log on the radius server? Ash. To be honest because of the amount of time it is taking i have reset the access point to wep and i am just manually setting the key on each laptop. There are 60 to do and they need them yesterday. I think i will come back to this one a bit later once everything has settled down. The connection is set to automatic. as i need this to connect when the laptop starts up incase there are any gpo updates. the wireless in the corner does nothing and then just pops up with a message saying cannot connect to 3com, plus if it is the drivers or the built in card, then i am going to have to find another way as all 60 have the same spec. Thanks again for all your help tho.
tomscaper Posted November 7, 2008 Posted November 7, 2008 The message that pops up when logged on is "Windows cannot log you on to 3Com" Then another windows cannot connect you to your prefered wireless network.
northernrob Posted November 12, 2008 Posted November 12, 2008 The error I had was the client wouldn't authenticate. The status of the wireless would remain on validating identity. I created a new certificate with a different name, assigned it to the server and client and changed the IAS policy and it worked fine. Thanks for the help, very happy 1
broc Posted November 12, 2008 Posted November 12, 2008 We are having a spate of problems with our wireless clients at the moment and this thread seems a good place to start... Environment is 3Com WX2200 managed wireless controller, 35x 3Com AP2750 Access points. The hardware has been up & running for over a year without problems. Software environment is Server 2003, running IAS on DC, clients are all xp SP2, hardware is a mix of DELL systems, mostly Latitude with a variety of Intel and Dell wireless cards. Setup pretty much as Ash's absolutely splendid document describes although I could have done it a lot quicker with less pain if I had been able to read it before starting from scratch setting our wireless network up! Over the last few months (since July) we have seen a gradual increase in the number of clients failing to get a working wireless connection. Symptoms reported as 'Domain not available'. The client can see the wireless network but just sits there claiming they cannot validate. In many cases, simply connecting the machine using a CAT5 cable, leaving it a while for policies to be applied results in a happy system that can connect to wireless again. This is not always the case, and in extreme cases (mainly systems with Intel 2200BG cards) we have ended up reimaging the systems as it's quicker than spending a lot of time delving into why it won't work. The event records on the server for IAS rarely show any indication of problems; we have had some timeouts recorded (reason code 96) but in almost all cases we see a timeout followed almost immediately by a successful connection. Client event logs are not helpful either. Looking at 3WXM (Managed controller software) we sometimes see a failing system that has successfully contacted the WLAN controller and is sat with an IP address of 0.0.0.0, my guess is it is waiting for an IP address through DHCP and this doesn't happen for some reason. At one point last month I had 45 laptops stacked in my office awaiting 'repair'. Curiously it only happens to student laptops, never staff. Most staff connect via CAT5 unless they are 'roaming' around the school so I guess they are less likely to have a problem. We have yet to see the initial problem happen in front of us, where a machine suddenly decides it isn't going to play nice. I need some insight into how to get some diagnostics without having to turn on traces for 250+ student laptops and wait for the problem to happen. I am guessing the problem seems to revolve around the DHCP and certificate authentication processes but I am at a loss right now as to why & when things break. 1
DMcCoy Posted November 12, 2008 Posted November 12, 2008 Are you validating the server certificate provided by IAS? Is it still valid? You could try unticking the validate server under the peap settings and see if it starts working. 2
spc-rocket Posted November 12, 2008 Posted November 12, 2008 I did reply to you a bit earlier but looks like that post has gone missing for some reason. Strange. Ash. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now