Re: Vista wireless using IAS and WPA-Enterprise

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hello Paul,

If you have any updates, please feel free to let us know.

Thanks & Regards,

Ken Zhao

Microsoft Online Support
Microsoft Global Technical Support Center

Get Secure! - www.microsoft.com/security <http://www.microsoft.com/security>
====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.





--------------------
| Thread-Topic: Vista wireless using IAS and WPA-Enterprise
| thread-index: AcfKz0gdXKJORXLhTFCZDosYYzs3GQ==
| X-WBNR-Posting-Host: 207.46.193.207
| From: =?Utf-8?B?UGF1bCBNY2tlbm5h?= <JazzyJ187@xxxxxxxxxxxxxxxx>
| References: <CB717348-F026-42B2-BED0-6AD0DAF42784@xxxxxxxxxxxxx>
<OvXp5E9xHHA.404@xxxxxxxxxxxxxxxxxxxx>
<EB1DC5EB-D1C7-43D2-943E-755251B9E8B5@xxxxxxxxxxxxx>
<uE4PtN$xHHA.5068@xxxxxxxxxxxxxxxxxxxx>
<44117B87-F9C9-40F4-9597-753F965AB39E@xxxxxxxxxxxxx>
<i#i1t7ByHHA.5836@xxxxxxxxxxxxxxxxxxxxxx>
<5ED8C7EE-1A2C-42BE-BB12-A9858AD4B819@xxxxxxxxxxxxx>
<ylouZoQyHHA.4200@xxxxxxxxxxxxxxxxxxxxxx>
<48856C53-3BE8-49D7-8D48-687C01484770@xxxxxxxxxxxxx>
<vERUwpeyHHA.6140@xxxxxxxxxxxxxxxxxxxxxx>
| Subject: Re: Vista wireless using IAS and WPA-Enterprise
| Date: Fri, 20 Jul 2007 06:10:02 -0700
| Lines: 309
| Message-ID: <F9366AE2-B047-409A-B59A-CBDE0DADABB7@xxxxxxxxxxxxx>
| MIME-Version: 1.0
| Content-Type: text/plain;
| charset="Utf-8"
| Content-Transfer-Encoding: 8bit
| X-Newsreader: Microsoft CDO for Windows 2000
| Content-Class: urn:content-classes:message
| Importance: normal
| Priority: normal
| X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.2826
| Newsgroups: microsoft.public.windows.server.networking
| Path: TK2MSFTNGHUB02.phx.gbl
| Xref: TK2MSFTNGHUB02.phx.gbl
microsoft.public.windows.server.networking:5920
| NNTP-Posting-Host: tk2msftsbfm01.phx.gbl 10.40.244.148
| X-Tomcat-NG: microsoft.public.windows.server.networking
|
| Hi,
|
| I will try that, Thanks for all your help Ken.
|
| Regards
| Paul Mckenna
|
| ""Ken Zhao [MSFT]"" wrote:
|
| > Hi Paul,
| >
| > Thanks for your reply.
| >
| > Based on my deep research, it seems to be certificate issue.
| >
| > At this moment, please check RADIUS server to see if there are lots of
| > certificates, which may be more than the limit that the IAS server can
send
| > in the list to the wireless clients while authentication. If lots of
| > certificates exist in RADIUS server, please try to delete the
certificates
| > which are not required. And then reboot the server to remove the cached
| > certificates which the server has to see if it can help. For more
related
| > information, please refer to:
| >
| > 933430: Clients cannot make connections if you require client
certificates
| > on a Web site or if you use IAS in Windows Server 2003
| > http://support.microsoft.com/kb/933430/en-us
| >
| > Hope that helps!
| >
| > Thanks & Regards,
| >
| > Ken Zhao
| >
| > Microsoft Online Support
| > Microsoft Global Technical Support Center
| >
| > Get Secure! - www.microsoft.com/security
<http://www.microsoft.com/security>
| > ====================================================
| > When responding to posts, please "Reply to Group" via your newsreader
so
| > that others may learn and benefit from your issue.
| > ====================================================
| > This posting is provided "AS IS" with no warranties, and confers no
rights.
| >
| >
| >
| >
| >
| > --------------------
| > | Thread-Topic: Vista wireless using IAS and WPA-Enterprise
| > | thread-index: AcfJOVEUcuDIWd+FTk2zil1LiYAfTA==
| > | X-WBNR-Posting-Host: 207.46.193.207
| > | From: =?Utf-8?B?UGF1bCBNY2tlbm5h?= <JazzyJ187@xxxxxxxxxxxxxxxx>
| > | References: <CB717348-F026-42B2-BED0-6AD0DAF42784@xxxxxxxxxxxxx>
| > <OvXp5E9xHHA.404@xxxxxxxxxxxxxxxxxxxx>
| > <EB1DC5EB-D1C7-43D2-943E-755251B9E8B5@xxxxxxxxxxxxx>
| > <uE4PtN$xHHA.5068@xxxxxxxxxxxxxxxxxxxx>
| > <44117B87-F9C9-40F4-9597-753F965AB39E@xxxxxxxxxxxxx>
| > <i#i1t7ByHHA.5836@xxxxxxxxxxxxxxxxxxxxxx>
| > <5ED8C7EE-1A2C-42BE-BB12-A9858AD4B819@xxxxxxxxxxxxx>
| > <ylouZoQyHHA.4200@xxxxxxxxxxxxxxxxxxxxxx>
| > | Subject: Re: Vista wireless using IAS and WPA-Enterprise
| > | Date: Wed, 18 Jul 2007 05:44:01 -0700
| > | Lines: 320
| > | Message-ID: <48856C53-3BE8-49D7-8D48-687C01484770@xxxxxxxxxxxxx>
| > | MIME-Version: 1.0
| > | Content-Type: text/plain;
| > | charset="Utf-8"
| > | Content-Transfer-Encoding: 8bit
| > | X-Newsreader: Microsoft CDO for Windows 2000
| > | Content-Class: urn:content-classes:message
| > | Importance: normal
| > | Priority: normal
| > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.2826
| > | Newsgroups: microsoft.public.windows.server.networking
| > | Path: TK2MSFTNGHUB02.phx.gbl
| > | Xref: TK2MSFTNGHUB02.phx.gbl
| > microsoft.public.windows.server.networking:5872
| > | NNTP-Posting-Host: tk2msftsbfm01.phx.gbl 10.40.244.148
| > | X-Tomcat-NG: microsoft.public.windows.server.networking
| > |
| > |
| > | Thanks for your suggestion.
| > |
| > | I've tried turning off autotuninglevel on the Vista machines but with
no
| > | joy, I've also looked at the KB articles none of which seem to relate
to
| > the
| > | problem i'm having but i've tried the suggestions, Still nothing.
| > |
| > | Just to recap when using any 3Com Access Point with a windows Vista
| > client
| > | the 3com access point sends data to the IAS server to say it wants to
use
| > EAP
| > | (even thought vista is configured to use PEAP) authentication, with
an XP
| > | client the 3com box sends it want to use PEAP authentication. If i
enable
| > | EAP-TLS authentication on IAS and install a user certificate on the
Vista
| > | machine and set Vista to use a certificate to log in, the connection
| > works
| > | but it's a lot of hassle maintaining and installing certificates for
each
| > | user, i would much rather use PEAP.
| > |
| > | Regards
| > | Paul Mckenna
| > | ""Ken Zhao [MSFT]"" wrote:
| > |
| > | > Hi Paul,
| > | >
| > | > Based on my research, if the problem only occurs on Windows Vista
| > machines,
| > | > I suggest you perform the following steps on the Vista machines:
| > | >
| > | > 1�£�®Click Start , click All Programs, click Accessories, and
then
| > click
| > | > Command Prompt.
| > | > 2�£�®At the command prompt, type the following command, and
then press
| > ENTER:
| > | > netsh interface tcp set global autotuninglevel=disabled
| > | > This command disables the Receive Window Auto-Tuning feature.
| > | > 3�£�®Try to make a non-HTTP network connection.
| > | > Note: If the connectivity problem is resolved, contact the
manufacturer
| > of
| > | > the firewall device for steps to correct the issue.
| > | > 4�£�®At a command prompt, type the following command, and then
press
| > ENTER:
| > | > netsh interface tcp set global autotuninglevel=normal
| > | > This command enables Receive Window Auto-Tuning again so that you
can
| > take
| > | > advantage of the network throughput performance increase it
provides.
| > | >
| > | > Also I found there are new KB articles already described for this
issue
| > and
| > | > give the workaround.
| > | > 934430: Network connectivity may fail when you try to use Windows
Vista
| > | > behind a firewall device
| > | > http://support.microsoft.com/kb/934430
| > | >
| > | > 929868: A Web site sends data very slowly or drops the data
completely
| > when
| > | > you use Windows Vista Enterprise
| > | > http://support.microsoft.com/kb/929868
| > | >
| > | > 935400: It takes a very long time to download an e-mail message
from a
| > POP3
| > | > server in Outlook 2007
| > | > http://support.microsoft.com/kb/935400
| > | >
| > | > Hope that helps!
| > | >
| > | > Thanks & Regards,
| > | >
| > | > Ken Zhao
| > | >
| > | > Microsoft Online Support
| > | > Microsoft Global Technical Support Center
| > | >
| > | > Get Secure! - www.microsoft.com/security
| > <http://www.microsoft.com/security>
| > | > ====================================================
| > | > When responding to posts, please "Reply to Group" via your
newsreader
| > so
| > | > that others may learn and benefit from your issue.
| > | > ====================================================
| > | > This posting is provided "AS IS" with no warranties, and confers no
| > rights.
| > | >
| > | >
| > | >
| > | >
| > | >
| > | > --------------------
| > | > | Thread-Topic: Vista wireless using IAS and WPA-Enterprise
| > | > | thread-index: AcfIWYuctoKjZd5iSS+80+2oiJEvyg==
| > | > | X-WBNR-Posting-Host: 207.46.19.197
| > | > | From: =?Utf-8?B?UGF1bCBNY2tlbm5h?= <JazzyJ187@xxxxxxxxxxxxxxxx>
| > | > | References: <CB717348-F026-42B2-BED0-6AD0DAF42784@xxxxxxxxxxxxx>
| > | > <OvXp5E9xHHA.404@xxxxxxxxxxxxxxxxxxxx>
| > | > <EB1DC5EB-D1C7-43D2-943E-755251B9E8B5@xxxxxxxxxxxxx>
| > | > <uE4PtN$xHHA.5068@xxxxxxxxxxxxxxxxxxxx>
| > | > <44117B87-F9C9-40F4-9597-753F965AB39E@xxxxxxxxxxxxx>
| > | > <i#i1t7ByHHA.5836@xxxxxxxxxxxxxxxxxxxxxx>
| > | > | Subject: Re: Vista wireless using IAS and WPA-Enterprise
| > | > | Date: Tue, 17 Jul 2007 03:02:12 -0700
| > | > | Lines: 217
| > | > | Message-ID: <5ED8C7EE-1A2C-42BE-BB12-A9858AD4B819@xxxxxxxxxxxxx>
| > | > | MIME-Version: 1.0
| > | > | Content-Type: text/plain;
| > | > | charset="Utf-8"
| > | > | Content-Transfer-Encoding: 7bit
| > | > | X-Newsreader: Microsoft CDO for Windows 2000
| > | > | Content-Class: urn:content-classes:message
| > | > | Importance: normal
| > | > | Priority: normal
| > | > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.2826
| > | > | Newsgroups: microsoft.public.windows.server.networking
| > | > | Path: TK2MSFTNGHUB02.phx.gbl
| > | > | Xref: TK2MSFTNGHUB02.phx.gbl
| > | > microsoft.public.windows.server.networking:5830
| > | > | NNTP-Posting-Host: tk2msftsbfm01.phx.gbl 10.40.244.148
| > | > | X-Tomcat-NG: microsoft.public.windows.server.networking
| > | > |
| > | > | Hi,
| > | > |
| > | > | Thanks for your suggestion I've tried this and it makes no
| > difference, I
| > | > | tried setting it to various numbers 1344,1000,64,128 none made
any
| > | > | difference. I have since found out that using another make Access
| > Point
| > | > | rather than 3Com and Vista will connect but all 3Com acccess
points
| > i've
| > | > | tried work fine with XP but not with Vista.
| > | > |
| > | > | I'm not sure what else to try.
| > | > |
| > | > | Regards
| > | > | Paul Mckenna
| > | > |
| > | > | ""Ken Zhao [MSFT]"" wrote:
| > | > |
| > | > | > Hello Paul,
| > | > | >
| > | > | > Thank you for using newsgroup!
| > | > | >
| > | > | > From your post, I'd like to suggest you try to reduce the EAP
| > packet
| > | > size
| > | > | > of a Remote Authentication Dial-In User Service (RADIUS)
server.
| > You
| > | > can do
| > | > | > this by using the Framed-MTU attribute in Internet
Authentication
| > | > Services
| > | > | > (IAS) of a Microsoft Windows Server 2003-based computer. For
more
| > | > detailed
| > | > | > steps, please refer to:
| > | > | > 883389: How to reduce the EAP packet size by using the Framed
MTU
| > | > attribute
| > | > | > in Windows Server 2003
| > | > | > http://support.microsoft.com/default.aspx?scid=kb;EN-US;883389
| > | > | >
| > | > | > Thanks & Regards,
| > | > | >
| > | > | > Ken Zhao
| > | > | >
| > | > | > Microsoft Online Support
| > | > | > Microsoft Global Technical Support Center
| > | > | >
| > | > | > Get Secure! - www.microsoft.com/security
| > | > <http://www.microsoft.com/security>
| > | > | > ====================================================
| > | > | > When responding to posts, please "Reply to Group" via your
| > newsreader
| > | > so
| > | > | > that others may learn and benefit from your issue.
| > | > | > ====================================================
| > | > | > This posting is provided "AS IS" with no warranties, and
confers no
| > | > rights.
| > | > | >
| > | > | >
| > | > | >
| > | > | >
| > | > | >
| > | > | > --------------------
| > | > | > | Thread-Topic: Vista wireless using IAS and WPA-Enterprise
| > | > | > | thread-index: AcfH9YDU6jOQn/+xSL2/iOe7lK2ZoQ==
| > | > | > | X-WBNR-Posting-Host: 207.46.193.207
| > | > | > | From: =?Utf-8?B?UGF1bCBNY2tlbm5h?=
<JazzyJ187@xxxxxxxxxxxxxxxx>
| > | > | > | References:
<CB717348-F026-42B2-BED0-6AD0DAF42784@xxxxxxxxxxxxx>
| > | > | > <OvXp5E9xHHA.404@xxxxxxxxxxxxxxxxxxxx>
| > | > | > <EB1DC5EB-D1C7-43D2-943E-755251B9E8B5@xxxxxxxxxxxxx>
| > | > | > <uE4PtN$xHHA.5068@xxxxxxxxxxxxxxxxxxxx>
| > | > | > | Subject: Re: Vista wireless using IAS and WPA-Enterprise
| > | > | > | Date: Mon, 16 Jul 2007 15:06:04 -0700
| > | > | > | Lines: 115
| > | > | > | Message-ID:
<44117B87-F9C9-40F4-9597-753F965AB39E@xxxxxxxxxxxxx>
| > | > | > | MIME-Version: 1.0
| > | > | > | Content-Type: text/plain;
| > | > | > | charset="Utf-8"
| > | > | > | Content-Transfer-Encoding: 7bit
| > | > | > | X-Newsreader: Microsoft CDO for Windows 2000
| > | > | > | Content-Class: urn:content-classes:message
| > | > | > | Importance: normal
| > | > | > | Priority: normal
| > | > | > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.2826
| > | > | > | Newsgroups: microsoft.public.windows.server.networking
| > | > | > | Path: TK2MSFTNGHUB02.phx.gbl
| > | > | > | Xref: TK2MSFTNGHUB02.phx.gbl
| > | > | > microsoft.public.windows.server.networking:5812
| > | > | > | NNTP-Posting-Host: tk2msftsbfm01.phx.gbl 10.40.244.148
| > | > | > | X-Tomcat-NG: microsoft.public.windows.server.networking
| > | > | > |
| > | > | > | again I Appreciate your response but this works with XP, XP
sends
| > the
| > | > | > message
| > | > | > | to IAS that it wants to use PEAP authentication where as
Vista
| > sends
| > | > the
| > | > | > | message to use EAP (which is not configured and is not
something
| > i
| > | > want
| > | > | > to
| > | > | > | use) even though Vista is configured to use PEAP.
| > | > | > | So although these error message will probably help with
someone
| > who
| > | > wants
| > | > | > to
| > | > | > | use EAP-TLS without having properly configured it. They don't
| > really
| > | > shed
| > | > | > any
| > | > | > | light on my problem.
| > | > | > |
|

.



Relevant Pages

  • RE: VPN error 619 Windows 2003 SBS NO ISA
    ... Microsoft Online Support ... Microsoft Global Technical Support Center ... | connect to a Routing and Remote Access server ... | | I have tried numerous user accounts on the remote server INCLUDING the ...
    (microsoft.public.windows.server.networking)
  • Re: User Profiles and Setting from 2003 32bit to 2003 64bit?
    ... we can use ADMT to migrate user profiles and settings in domain. ... Microsoft Online Support ... Microsoft Global Technical Support Center ... | in the Default User folder that need to be included for the new server. ...
    (microsoft.public.windows.server.migration)
  • Re: Win2000 Server Move to new Hardware (server)
    ... Microsoft Online Support ... Microsoft Global Technical Support Center ... | Subject: RE: Win2000 Server Move to new Hardware ... | Windows installation to another different hardware. ...
    (microsoft.public.windows.server.migration)
  • Re: Event SRV error 2012
    ... this event error may be caused by more reasons. ... know what symptoms you are encountering on the server? ... Microsoft Online Support ... Microsoft Global Technical Support Center ...
    (microsoft.public.windows.server.general)
  • Re: Event SRV error 2012
    ... getting some people complaining that the network seems slow. ... know what symptoms you are encountering on the server? ... Microsoft Online Support ... Microsoft Global Technical Support Center ...
    (microsoft.public.windows.server.general)