Please help! I am just about to go berserk and pull a terror attack on my Radius Server. WIFI users cannot authenticate



The same setup has been working for 3 days. All of sudden, the user
cannot authenticate. The user doesnt get prompted to enter
username/domain when connecting to the wifi lan. What follows is the
complete log of the error. There has been no changes to my setup. I
am using a cisco 4400 controller and 1 LWAP access point by cicso.
It connects to my radius server based on windows 2003


Please, any input in the matter is hjghly appreciated. I have been
fighting with this for a few days and cannot get it resolved. Microsft
knowledge base articles have not helped me any.



Server: Windows Server 2003 x64 SP1 or R2
Client: Windows XP Pro SP2
From time to time some of my XP SP2 clients fail to authenticate with
IAS
and thus end up working without WLAN. This is what I get in System
log:

Event Type: Warning
Event Source: IAS
Event Category: None
Event ID: 2
Date: 2007.02.09
Time: 13:49:46
User: N/A
Computer: server
Description:
User host/pc1.firm.com was denied access.
Fully-Qualified-User-Name = firm.com/computers/pc1
NAS-IP-Address = 10.19.247.234
NAS-Identifier = FIRM
Called-Station-Identifier = 00-18-FE-D0-B0-39
Calling-Station-Identifier = 00-90-4B-B9-D3-A8
Client-Friendly-Name = FIRM
Client-IP-Address = 10.19.247.234
NAS-Port-Type = Wireless - IEEE 802.11
NAS-Port = 0
Proxy-Policy-Name = Use Windows authentication for all users
Authentication-Provider = Windows
Authentication-Server = <undetermined>
Policy-Name = WLAN
Authentication-Type = PEAP
EAP-Type = <undetermined>
Reason-Code = 262
Reason = The supplied message is incomplete. The signature was not
verified.


.



Relevant Pages

  • Re: Smartcard authentication in a multi-tier application
    ... side where the user enters the username and password and on the server ... since SC authentication on the Windows client results in a Kerberos ... ticket which can then be used to authenticate to the server. ...
    (microsoft.public.platformsdk.security)
  • Re: [ok] [Full-Disclosure] RE: [Full-Disclosure]MS should re-write code with security in mind
    ... almost all Windows users demand backward compatibility. ... > security upgrades available on MS's site. ... > and authenticate all mail transfer. ...
    (Full-Disclosure)
  • RE: 802.1x, Computers, Wired Security
    ... I am trying to setup 802.1x using HP's IDM and W2K3 IAS. ... the user to authenticate to IAS once they have logged on to Windows. ... Does the client computer need to have a cert? ...
    (microsoft.public.windows.server.active_directory)
  • Re: 802.1X, Windows supplicant and IAS
    ... I have seen issues with Windows XP SP2 clients trying to authenticate ... via a Cisco 2950 switch and Cisco ACS server. ... "Due to a defect in the Microsoft PEAP supplicant provided in Windows ...
    (microsoft.public.security)
  • How to create processes on another computer using a Smartcard user
    ... I have an application that will be running as a "client". ... card reader which will authenticate using a smartcard (DoD PKI CAC card to be ... The "server" application will be running as a Windows service. ... Can I use Active Directory to authenticate this user on my "server"? ...
    (microsoft.public.platformsdk.security)