Re: Wireless Re-Authentication

From: Sam Salhi [MSFT] (samers_at_online.microsoft.com)
Date: 02/16/05


Date: Tue, 15 Feb 2005 20:47:02 -0800

Change the policy to something like windows groups and see what happens. If
the problem goes away. I would contact the AP manufacturer to see why
they're not sending the right nas-port-type in their Radius requests to the
server

-- 
      =============================================
  This posting is provided "AS IS" with no warranties, and confers no rights
      =============================================
"Tmccabe" <Tmccabe@discussions.microsoft.com> wrote in message 
news:C080BC69-902C-474F-ADEE-CF04711D9490@microsoft.com...
>I have an issue where my users get their wieless connection dropped and the
> icon inthe tray will say "re-authenticating" or similar. I have a slew of
> system event log errors on my IAS server - 2 different types listed below.
> ----
> User FARM\lshauf was denied access.
> Fully-Qualified-User-Name = FARM\lshauf
> NAS-IP-Address = 10.25.1.2
> NAS-Identifier = NBF_AP1
> Called-Station-Identifier = 0012.00d6.e5b0
> Calling-Station-Identifier = 000e.354c.fe9c
> Client-Friendly-Name = NBF_AP1
> Client-IP-Address = 10.25.1.2
> NAS-Port-Type = Wireless - IEEE 802.11
> NAS-Port = 186579
> Proxy-Policy-Name = Wireless
> Authentication-Provider = Windows
> Authentication-Server = <undetermined>
> Policy-Name = <undetermined>
> Authentication-Type = EAP
> EAP-Type = <undetermined>
> Reason-Code = 48
> Reason = The connection attempt did not match any remote access policy.
>
> ------------------
> Error Type 2
>
> Access request for user host/LON440L.fbc.internal was discarded.
> Fully-Qualified-User-Name = fbc.internal/LON/LONlaptop/LON440L
> NAS-IP-Address = 10.40.2.3
> NAS-Identifier = LON_AP1
> Called-Station-Identifier = 0012.80e1.ded0
> Calling-Station-Identifier = 000e.354c.ebd8
> Client-Friendly-Name = LON_AP1
> Client-IP-Address = 10.40.2.3
> NAS-Port-Type = Wireless - IEEE 802.11
> NAS-Port = 19231
> Proxy-Policy-Name = wireless
> Authentication-Provider = Windows
> Authentication-Server = <undetermined>
> Reason-Code = 97
> Reason = The authentication request was not processed because it contained
> a Remote Authentication Dial-In User Service (RADIUS) message that was not
> appropriate for the secure authentication transaction.
>
> -----
>
> my wireless policy on the IAS server is simple. You have to be part of the
> domain wireless user group which contains the users and the computers.
>
> The connection request policy in the IAS settings contains the NAS types
> 802.11 and "other" as the only attribues. Do I need more entries inthe
> connection request policy ?
>
> I cant think of what else I need to do to fix theis re-athentication 
> issue.
> Any help would be greatly appreciated. 


Relevant Pages

  • Re: RADIUS (IAS) and Cisco Concentrator? (PDF Attachment)
    ... go to the "Remote Access Policies" and double-click the policy you ... click Edit Profile and select the Authentication tab. ... Authentication-Provider = Windows ...
    (microsoft.public.windows.server.active_directory)
  • IAS ID 2
    ... I have an Aironet 350 and W2K3 IAS with one policy active. ... Authentication EAP Methods Smartcard, MS-CHAP v2 and PAP ... Authentication-Provider = Windows ... Reason = The connection attempt did not match any remote access policy. ...
    (microsoft.public.internet.radius)
  • Re: IAS ID 2
    ... Looks like that authentication attempt was for a MAC address which is not ... the login was granted by the> matching policy. ... > Authentication-Provider = Windows ...
    (microsoft.public.internet.radius)
  • Windows Shortcut Keys and "ALT+TAB" not working because of GPO
    ... We've got an issue with a machine policy which prohibits us of using Windows ... Deny access to this computer from the network Support_388945a0, ... Policy Setting ...
    (microsoft.public.de.german.windowsxp.gruppen.richtlinien)
  • Re: GP errors
    ... Then later shutdown second one and start the first one. ... machine (MTCCSAPROUTER) to the domain and those errors are not coming. ... The policy for which it is giving access denied error is the Default ... Windows cannot query for the list of Group Policy objects. ...
    (microsoft.public.windows.server.active_directory)