IAS PEAP MSCHAP v2 authentication issue

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: glenn (glenn_at_discussions.microsoft.com)
Date: 10/12/04


Date: Mon, 11 Oct 2004 22:31:02 -0700

I have IAS setup, Server 2003 standard with a Thawte certificate to
authenticate Wireless XP SP1 clients via Cisco 1200 AP's. When I logon to the
client I usually can pull a valid IP address and the system log on the IAS
server shows the client and user granted access. The issue is that after
about 20 seconds the user id is denied access and the IP address is dropped
from a valid one to a 169 ip address. I have a group policy setup at the
laptop OU with the wireless policy.

In the system logs I see that the user and client were granted access then I
see a bunch of errors per the below:

Reason code 96- the authentication request was not processed because the
session timed out.

If I leave the client on it will authenticate again several times but it
will drop off after each authentication.



Relevant Pages

  • Re: Java GSS/Kerberos issue - Autheticating server
    ... I can authenticate as that particular principal in the client portion of the ... I have a server and a client portion of code that pass GSS-wrapped kerberos ... Client authenticates to kerberos server and logs in, ...
    (comp.protocols.kerberos)
  • SSL - Different procedures to authenticate Server and Client
    ... Why in SSL the procedure to authenticate the Client (see ... below) is not the same to authenticate the Server (see ... the public key in the certificate. ...
    (Security-Basics)
  • Re: 2003 server in a NT4 Domain.
    ... > network drive was created on the client. ... > domain and was able to see the shared resources on the 2003 server. ... Separate "See" as in browse from Authenticate. ... >>Report exact error messages. ...
    (microsoft.public.win2000.active_directory)
  • Re: Postfix + Auth + SSL + pop3s/imaps
    ... users to authenticate can run unprivileged and request saslauthd to ... Otherwise the server must run as root in order to access ... would a mail server that uses port ... and client will exchange keys and an encrypted session is initiated. ...
    (freebsd-questions)
  • Re: Java GSS/Kerberos issue - Autheticating server
    ... Client authenticates to kerberos server and logs in, ... Generates a login context and tries to authenticate against the ...
    (comp.protocols.kerberos)