IAS: "use-windows-logon" fails authentication; Fully-Qualified-User-Name issue?
i've got weird issue. i've set 802.1x wireless network points windows ias radius server authentication.
the radius client/authenticator aruba wlan controller.
supplicant standard win 7 machines
when set wireless profile proper settings , "use windows logon" enabled authentication fails.
when uncheck "use windows logon"-checkbox, presented systray-popup enter user, passwd , domain. when enter windows logon details there.. authentication works.
obvious difference between granted , denied access in radius logs fully-qualified-user-name. not sure why though. user enters same info in windows logon box in 802.1x authentication box.
got idea why happening? i've been stuck on weeks , ready give on damn checkbox.
################################################################################
access denied (use windows logon checked)
-------
event type: warning
event source: ias
event category: none
event id: 2
date: 29/06/2011
time: 14:43:19
user: n/a
computer: ias-radius
description:
user domain\userx denied access.
fully-qualified-user-name = domain\userx
nas-ip-address = 1.2.3.4
nas-identifier = 1.2.3.4
called-station-identifier = 000b86612940
calling-station-identifier = 001de027ed77
client-friendly-name = wlan controller ip 2
client-ip-address = 1.2.3.4
nas-port-type = wireless - ieee 802.11
nas-port = 0
proxy-policy-name = use windows authentication users
authentication-provider = windows
authentication-server = <undetermined>
policy-name = <undetermined>
authentication-type = ms-chapv2
eap-type = <undetermined>
reason-code = 16
reason = authentication not successful because unknown user name or incorrect password used.
more information, see , support center @ http://go.microsoft.com/fwlink/events.asp.
data:
0000: 2e 05 07 80 ...?
################################################## ##############################
access granted (entered logon manualy)
--------
event type: information
event source: ias
event category: none
event id: 1
date: 29/06/2011
time: 14:44:21
user: n/a
computer: ias-radius
description:
user domain\userx granted access.
fully-qualified-user-name = domain.be/domain users/ict/it-helpdesk/first lastname
nas-ip-address = 1.2.3.4
nas-identifier = 1.2.3.4
client-friendly-name = wlan controller ip 2
client-ip-address = 1.2.3.4
calling-station-identifier = 001de027ed77
nas-port-type = wireless - ieee 802.11
nas-port = 0
proxy-policy-name = use windows authentication users
authentication-provider = windows
authentication-server = <undetermined>
policy-name = wireless domain-data
authentication-type = ms-chapv2
eap-type = <undetermined>
more information, see , support center @ http://go.microsoft.com/fwlink/events.asp.
data:
0000: 00 00 00 00 ....
################################################################################
hi koenv,
thanks posting here.
will domain account affected issue ? have changed password domain account ? credential entry did input when prompted user name , password ?
try clean stored credential on client , logon client updated credential see how going:
have verified setting in aruba wlan controller?
for more information please refer link below:
realm names
http://technet.microsoft.com/en-us/library/cc779938(ws.10).aspx
authentication problem on 802.1x wireless network
regards,
tiger li
technet subscriber support in forum
if have feedback on our support, please contact tnmff@microsoft.com.
please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread.
Windows Server > Network Access Protection
Comments
Post a Comment