IAS Radius & WAP yields Error Code 23



Hi,

Im trying to setup a 3COM Wireless access point to authenticate my
users against RADIUS. I've created a remote acces policy and put it at
the top of the order.

I'm using PEAP and my cert shows up as OK.
I've authoirzed my "Domain Users" group to have access to the unit.

I am on a Windows 2003 SP1 Server. My laptop is Windows XP SP1, using
the Atheros Client.

I receive the following error:

User bnicolae was denied access.
Fully-Qualified-User-Name = DOMAIN.COM/OU/username
NAS-IP-Address = 10.10.30.99
NAS-Identifier = WAP02
Called-Station-Identifier = removed
Calling-Station-Identifier = removed
Client-Friendly-Name = WAP02
Client-IP-Address = 10.10.30.99
NAS-Port-Type = Wireless - IEEE 802.11
NAS-Port = 1
Proxy-Policy-Name = Use Windows authentication for all users
Authentication-Provider = Windows
Authentication-Server = <undetermined>
Policy-Name = Allow Wireless LAN Access
Authentication-Type = PEAP
EAP-Type = <undetermined>
Reason-Code = 23
Reason = Unexpected error. Possible error in server or client
configuration.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Any ideas on what the unexpected error might be?

.



Relevant Pages

  • Re: PDC Emulator
    ... > PDC Emulator is used to authenticate down level clients on the network ... > downlevel level client cross the WAN link to access PDC Emulator or it ...
    (microsoft.public.windows.server.active_directory)
  • Re: Grr...
    ... entered my password and "We could not authenticate your login..." ... Looked up the number for Customer Support (after going through SEVERAL ... the client hadn't been updated. ... checking uo.stratics there HAD been a client patch last week. ...
    (rec.games.computer.ultima.online)
  • Re: Java GSS/Kerberos issue - Autheticating server
    ... I can authenticate as that particular principal in the client portion of the ... I have a server and a client portion of code that pass GSS-wrapped kerberos ... Client authenticates to kerberos server and logs in, ...
    (comp.protocols.kerberos)
  • RE: Connect Computer and VPN
    ... traffic from the internal network. ... leverage either the Firewall client and the SecureNAT client to send the ... Un-tick "Require all users to authenticate" option. ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: Issues with IAS and Verisign Cert
    ... Exporting and importing seems to work. ... The client can authenticate but its ... Reason = The client could not be authenticated because the Extensible ... If so yes the certificate is stored in the IAS ...
    (microsoft.public.internet.radius)

Loading