IAS: "use-windows-logon" fails authentication; Fully-Qualified-User-Name issue?


i've got weird issue. i've set 802.1x wireless network points windows ias radius server authentication.

the radius client/authenticator aruba wlan controller.
supplicant standard win 7 machines

when set wireless profile proper settings , "use windows logon" enabled authentication fails.
when uncheck "use windows logon"-checkbox, presented systray-popup enter user, passwd , domain. when enter windows logon details there.. authentication works.

obvious difference between granted , denied access in radius logs fully-qualified-user-name. not sure why though. user enters same info in windows logon box in 802.1x authentication box.
got idea why happening? i've been stuck on weeks , ready give on damn checkbox.

################################################################################
access denied (use windows logon checked)
-------
event type: warning
event source: ias
event category: none
event id: 2
date: 29/06/2011
time: 14:43:19
user: n/a
computer: ias-radius
description:
user domain\userx denied access.
fully-qualified-user-name = domain\userx
nas-ip-address = 1.2.3.4
nas-identifier = 1.2.3.4
called-station-identifier = 000b86612940
calling-station-identifier = 001de027ed77
client-friendly-name = wlan controller ip 2
client-ip-address = 1.2.3.4
nas-port-type = wireless - ieee 802.11
nas-port = 0
proxy-policy-name = use windows authentication users
authentication-provider = windows
authentication-server = <undetermined>
policy-name = <undetermined>
authentication-type = ms-chapv2
eap-type = <undetermined>
reason-code = 16
reason = authentication not successful because unknown user name or incorrect password used.

more information, see , support center @ http://go.microsoft.com/fwlink/events.asp.
data:
0000: 2e 05 07 80 ...?
################################################## ##############################
access granted (entered logon manualy)
--------
event type: information
event source: ias
event category: none
event id: 1
date: 29/06/2011
time: 14:44:21
user: n/a
computer: ias-radius
description:
user domain\userx granted access.
fully-qualified-user-name = domain.be/domain users/ict/it-helpdesk/first lastname
nas-ip-address = 1.2.3.4
nas-identifier = 1.2.3.4
client-friendly-name = wlan controller ip 2
client-ip-address = 1.2.3.4
calling-station-identifier = 001de027ed77
nas-port-type = wireless - ieee 802.11
nas-port = 0
proxy-policy-name = use windows authentication users
authentication-provider = windows
authentication-server = <undetermined>
policy-name = wireless domain-data
authentication-type = ms-chapv2
eap-type = <undetermined>

more information, see , support center @ http://go.microsoft.com/fwlink/events.asp.
data:
0000: 00 00 00 00 ....


################################################################################

hi koenv,

 

thanks posting here.

 

will domain account affected issue ? have changed password domain account ? credential entry did input when prompted user name , password ?

try clean stored credential on client , logon client updated credential see how going:

 

http://windows.microsoft.com/en-us/windows7/store-passwords-certificates-and-other-credentials-for-automatic-logon

 

have verified setting in aruba wlan controller?

 

for more information please refer link below:

 

realm names

http://technet.microsoft.com/en-us/library/cc779938(ws.10).aspx

 

authentication problem on 802.1x wireless network

http://blogs.technet.com/b/yuridiogenes/archive/2008/04/18/authentication-problem-on-a-802-1x-wireless-network.aspx

 

regards,

 

tiger li

 

technet subscriber support in forum

if have feedback on our support, please contact  tnmff@microsoft.com.


please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread.


Windows Server  >  Network Access Protection



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file