Jump to content

Recommended Posts

Posted

I'm trying to setup Radius on a Windows 2008 R2 (clients with problem are Win 7 pro) and having a bit of a nightmare. The Wireless system is Meraki and the Meraki test with Radius works fine and I am able to connect to the SSID using an IPAD and manually entering data.

 

When trying to connect from a domain joined Win 7 laptop I get the following errors. But can't seem to work it out??

 

Network Policy Server denied access to a user.

Contact the Network Policy Server administrator for more information.

User:
Security ID:			NULL SID
Account Name:			host/machine.domain.Local
Account Domain:			domain
Fully Qualified Account Name:	domain\machine$

Client Machine:
Security ID:			NULL SID
Account Name:			-
Fully Qualified Account Name:	-
OS-Version:			-
Called Station Identifier:		0Mac-Address:SSIDNAME - Secure WLAN
Calling Station Identifier:		0Mac-Address

NAS:
NAS IPv4 Address:		AP-IP
NAS IPv6 Address:		-
NAS Identifier:			-
NAS Port-Type:			Wireless - IEEE 802.11
NAS Port:			0

RADIUS Client:
Client Friendly Name:		RADIUS CLIENT NAME
Client IP Address:			RADIUS CLIENT IP

Authentication Details:
Connection Request Policy Name:	NAP 802.1X (Wireless)
Network Policy Name:		-
Authentication Provider:		Windows
Authentication Server:		Server.domain.Local
Authentication Type:		PEAP
EAP Type:			-
Account Session Identifier:		-
Logging Results:			Accounting information was written to the local log file.
Reason Code:			16
Reason:				Authentication failed due to a user credentials mismatch. Either the user name provided does not map to an existing user account or the password was incorrect.

 

Network Policy Server denied access to a user.

Contact the Network Policy Server administrator for more information.

User:
Security ID:			NULL SID
Account Name:			domain\username
Account Domain:			domain
Fully Qualified Account Name:	domain\username

Client Machine:
Security ID:			NULL SID
Account Name:			-
Fully Qualified Account Name:	-
OS-Version:			-
Called Station Identifier:		Mac-Address:SSID - Secure WLAN
Calling Station Identifier:		MAC-Address

NAS:
NAS IPv4 Address:		AP-IP
NAS IPv6 Address:		-
NAS Identifier:			-
NAS Port-Type:			Wireless - IEEE 802.11
NAS Port:			0

RADIUS Client:
Client Friendly Name:		RADIUS CLIENT NAME
Client IP Address:			RADIUS CLIENT IP

Authentication Details:
Connection Request Policy Name:	NAP 802.1X (Wireless)
Network Policy Name:		-
Authentication Provider:		Windows
Authentication Server:		Server.domain.Local
Authentication Type:		PEAP
EAP Type:			-
Account Session Identifier:		-
Logging Results:			Accounting information was written to the local log file.
Reason Code:			16
Reason:				Authentication failed due to a user credentials mismatch. Either the user name provided does not map to an existing user account or the password was incorrect.

Posted
I'm trying to setup Radius on a Windows 2008 R2 (clients with problem are Win 7 pro) and having a bit of a nightmare. The Wireless system is Meraki and the Meraki test with Radius works fine and I am able to connect to the SSID using an IPAD and manually entering data.

 

When trying to connect from a domain joined Win 7 laptop I get the following errors. But can't seem to work it out??

 

Network Policy Server denied access to a user.

Contact the Network Policy Server administrator for more information.

User:
   Security ID:            NULL SID
   Account Name:            host/machine.domain.Local
   Account Domain:            domain
   Fully Qualified Account Name:    domain\machine$

Client Machine:
   Security ID:            NULL SID
   Account Name:            -
   Fully Qualified Account Name:    -
   OS-Version:            -
   Called Station Identifier:        0Mac-Address:SSIDNAME - Secure WLAN
   Calling Station Identifier:        0Mac-Address

NAS:
   NAS IPv4 Address:        AP-IP
   NAS IPv6 Address:        -
   NAS Identifier:            -
   NAS Port-Type:            Wireless - IEEE 802.11
   NAS Port:            0

RADIUS Client:
   Client Friendly Name:        RADIUS CLIENT NAME
   Client IP Address:            RADIUS CLIENT IP

Authentication Details:
   Connection Request Policy Name:    NAP 802.1X (Wireless)
   Network Policy Name:        -
   Authentication Provider:        Windows
   Authentication Server:        Server.domain.Local
   Authentication Type:        PEAP
   EAP Type:            -
   Account Session Identifier:        -
   Logging Results:            Accounting information was written to the local log file.
   Reason Code:            16
   Reason:                Authentication failed due to a user credentials mismatch. Either the user name provided does not map to an existing user account or the password was incorrect.

 

Network Policy Server denied access to a user.

Contact the Network Policy Server administrator for more information.

User:
   Security ID:            NULL SID
   Account Name:            domain\username
   Account Domain:            domain
   Fully Qualified Account Name:    domain\username

Client Machine:
   Security ID:            NULL SID
   Account Name:            -
   Fully Qualified Account Name:    -
   OS-Version:            -
   Called Station Identifier:        Mac-Address:SSID - Secure WLAN
   Calling Station Identifier:        MAC-Address

NAS:
   NAS IPv4 Address:        AP-IP
   NAS IPv6 Address:        -
   NAS Identifier:            -
   NAS Port-Type:            Wireless - IEEE 802.11
   NAS Port:            0

RADIUS Client:
   Client Friendly Name:        RADIUS CLIENT NAME
   Client IP Address:            RADIUS CLIENT IP

Authentication Details:
   Connection Request Policy Name:    NAP 802.1X (Wireless)
   Network Policy Name:        -
   Authentication Provider:        Windows
   Authentication Server:        Server.domain.Local
   Authentication Type:        PEAP
   EAP Type:            -
   Account Session Identifier:        -
   Logging Results:            Accounting information was written to the local log file.
   Reason Code:            16
   Reason:                Authentication failed due to a user credentials mismatch. Either the user name provided does not map to an existing user account or the password was incorrect.

 

 

Are you using MS-CHAP?

 

Tis worth double checking the certificates for clients and servers. You can tick a box somewhere in the settings to not validate the server certificate for testing, if that works then that points to a non trusted certificate in your infrastructure.

Posted
Are you using MS-CHAP?

 

Tis worth double checking the certificates for clients and servers. You can tick a box somewhere in the settings to not validate the server certificate for testing, if that works then that points to a non trusted certificate in your infrastructure.

 

It is configured allow it - shall i just try with normal CHAP?

 

I'm guessing its just a case of pulling the radius servers cert out and installing on the client?

Posted
It is configured allow it - shall i just try with normal CHAP?

 

I'm guessing its just a case of pulling the radius servers cert out and installing on the client?

 

MS-CHAP is fine, just requires the server certificate to be trusted on the machine if you have validation on. Did you mean you have it turned on atm? Turn it off for a sec to test, if it works then its at least narrowed it down to this!

Posted
MS-CHAP is fine, just requires the server certificate to be trusted on the machine if you have validation on. Did you mean you have it turned on atm? Turn it off for a sec to test, if it works then its at least narrowed it down to this!

 

I have kind of inherited this so not 100% sure if its by the book. I have 4 rules currently

rule 1: Health Policy - NAP802.1x (Wireless Compliant) - users have to be in ad group auth set to Microsoft Encrypted Auth Version 2 (MS-CHAP-v2) user can change password along with Microsoft Encrypted Auth (MS-Chap) user can change password.

rule 2: Health Policy NAP 802.1X (Wireless) Noncompliant. Auth same as above

Rules 3: Nap-Cable Value Computer is non NAP-capable, nas port type Wireless - other OR Wireless - IEE 802.11, user is required to be in group.

rule 4: user is Member of said group auth methods Microsoft Encrypted Auth Version 2 (MS-CHAP-v2) user can change password along with Microsoft Encrypted Auth (MS-Chap) user can change password, Encrypted Chap Unencrypted auth PAP, SPAP.

@plexer I have created a group which both the user and the machine are part of.

Posted

I think this boils back to the SSL cert on the clients being issued by a different internal CA to the Domain controller's present one. I've now imported that SSL cert from the root ca on the client side and imported into the domain controllers trusted root ca.

 

This now gets me to another error:

 

Network Policy Server denied access to a user.

Contact the Network Policy Server administrator for more information.

User:
Security ID:			NULL SID
Account Name:			host/clienthostname
Account Domain:			domain
Fully Qualified Account Name:	domain\clienthostname$

Client Machine:
Security ID:			NULL SID
Account Name:			-
Fully Qualified Account Name:	-
OS-Version:			-
Called Station Identifier:		Mac-Address:SSID - Secure WLAN
Calling Station Identifier:		Mac-Address
NAS:
NAS IPv4 Address:		AP-IP
NAS IPv6 Address:		-
NAS Identifier:			-
NAS Port-Type:			Wireless - IEEE 802.11
NAS Port:			0

RADIUS Client:
Client Friendly Name:		RADIUSCLIENTNAME
Client IP Address:			RadiusClientIP same as NAS IP?

Authentication Details:
Connection Request Policy Name:	NAP 802.1X (Wireless)
Network Policy Name:		-
Authentication Provider:		Windows
Authentication Server:		DomainController
Authentication Type:		EAP
EAP Type:			-
Account Session Identifier:		-
Logging Results:			Accounting information was written to the local log file.
Reason Code:			22
Reason:				The client could not be authenticated  because the Extensible Authentication Protocol (EAP) Type cannot be processed by the server.

Posted

We've just had the Error 16 issue when trying to setup Eduroam and found that it was in fact SSL Certificate related as others have suggested (we were using PEAP as well as MS-Chapv2)

 

Make sure your certs are correctly trusted at both ends, and all intermediates and roots are installed on servers and clients.

Posted
We've just had the Error 16 issue when trying to setup Eduroam and found that it was in fact SSL Certificate related as others have suggested (we were using PEAP as well as MS-Chapv2)

 

Make sure your certs are correctly trusted at both ends, and all intermediates and roots are installed on servers and clients.

 

Have successfully done that part but Now I get an error code 22!

Posted
Have you enabled the cert in NPS (Policies -> Network Policies -> {your policy} -> Constraints -> Auth Method -> PEAP -> Edit)
Posted
Hehe I love error codes!!

 

Did you turn off certificate validation? It will only check for a valid domain password then.

 

Nope where can I set that?

Posted
Nope where can I set that?

 

In the wireless settings in group policy.

 

Edit the network SSID you are connecting to, then in 802.1x tab choose settings and there should be a validate server certificate listed in the optinos, just untick for testing.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...