NPS-RADIUS problems with authentication methods.


hi! have next scenario:

pki infrastructure: 1 offline standalone root ca (server a) , 1 enterprise subordinate ca (serverb). both windows server 2008 r2 enterprise. serverb 1 use give certificates.

servidor nps-radius (serverc): windows server 2008 r2, certificate of server issued serverb using template workstation.

access point (ap-radius): configured radius client on serverc.

the authentication method i'm using, is: eap-tls; clients i'm issuing certificates, either workstation or user certificate. both templates version 1 (windows 2000).

when connect access radius, prompts me user/pwd (maybe because have 2 rules, 1 has condition of 'domain users' , other asks 'domain computers'). here added rule in nps named 'only certificates':

under network policies:

         condition: nas port - wireless ieee 802.11

         policy enabled, grant network access.

         restrictions: authentication methods: eap types: smart card or certificate - (eap-tls)

         processing order: 2 (the 1st policy auths domain computers eap-tls, , 3rd, domain users)

note: on network request policy section, don't have enabled 'invalidate configuration of network authentication policy' (sorry i'm translating spanish) on policy.

but, when connect again on non-domain computer, still prompts me user/pwd. if type data, denies me access. when check log on nps-radius server, on event viewer find: motive code: 22 motive: client can't authenticated because server can't process eap type.

the question is: shouldn't asking me credentials, right? in event, shows me using network policy defined recently.

 

hi luis,

 

thanks posting here.

 

which windows version running on client computers ?

since these non-domain joined computer , should import ca client accessing ca website first. , suspect might not set network authentication method client either. suggest take links below , following introduction configure client:

 

configure wireless computers running windows vista use eap-tls

http://technet.microsoft.com/en-us/library/dd283057(ws.10).aspx

 

configure computers running windows xp use eap-tls

http://technet.microsoft.com/en-us/library/dd283002(ws.10).aspx

 

thanks.

 

tiger li

 

technet subscriber support in forum

if have feedback on our support, please contact tngfb@microsoft.com


please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread.


Windows Server  >  Security



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS