Authentication failed for log time Off PCsAll logtime off (1weeks-1month) PCs after start ending &quot;Authentication failed&quot; and 802.1x managed port must be set to normal mode &quot;without 802.1x&quot;.<br/><br/>NAPSTAT windows is empty,manually unplug/plug network cable -&gt; authentication failed.<br/>IN NPS log is not any items about this computers.<br/><br/>Others - day by day used PCs working fine.<br/><br/>OS Windows Vista w/SP1 (PC Dell Optiplex 755, 960, Fujutsu Siemens Esprimo P5916)<br/><br/>Catalyst C2960 with last IOS and corect setup dot1x<br/><br/><br/>Affected PCs (1week or more off) -&gt; Catalyst not understand anwer from NPS and authentication timeouted and port status notconnect.<br/><br/>Is this known problem ?<br/>© 2009 Microsoft Corporation. All rights reserved.Tue, 25 Aug 2009 17:23:53 Z0b97998c-7dfd-4ba1-9c8f-af901d0625cbhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#0b97998c-7dfd-4ba1-9c8f-af901d0625cbhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#0b97998c-7dfd-4ba1-9c8f-af901d0625cbrudi01http://social.technet.microsoft.com/Profile/en-US/?user=rudi01Authentication failed for log time Off PCsAll logtime off (1weeks-1month) PCs after start ending &quot;Authentication failed&quot; and 802.1x managed port must be set to normal mode &quot;without 802.1x&quot;.<br/><br/>NAPSTAT windows is empty,manually unplug/plug network cable -&gt; authentication failed.<br/>IN NPS log is not any items about this computers.<br/><br/>Others - day by day used PCs working fine.<br/><br/>OS Windows Vista w/SP1 (PC Dell Optiplex 755, 960, Fujutsu Siemens Esprimo P5916)<br/><br/>Catalyst C2960 with last IOS and corect setup dot1x<br/><br/><br/>Affected PCs (1week or more off) -&gt; Catalyst not understand anwer from NPS and authentication timeouted and port status notconnect.<br/><br/>Is this known problem ?<br/>Tue, 30 Jun 2009 12:44:46 Z2009-07-01T08:55:51Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#d718c2ea-3ceb-4e4b-a507-c6101d322adahttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#d718c2ea-3ceb-4e4b-a507-c6101d322adaGreg Lindsayhttp://social.technet.microsoft.com/Profile/en-US/?user=Greg%20LindsayAuthentication failed for log time Off PCsHi,<br/><br/>If I understand the problem correctly, some computers are failing 802.1X authentication. Other computers are fine.<br/><br/>This appears to be a client side problem. What is the authentication method (PEAP-MSCHAPv2 or PEAP-EAP-TLS)? How many computers are affected? Have you checked the computer certificate on these clients?<br/><br/>-GregFri, 03 Jul 2009 05:26:33 Z2009-07-03T05:26:33Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#38c780d8-5d70-4455-b1b1-97fba578fa5ehttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#38c780d8-5d70-4455-b1b1-97fba578fa5erudi01http://social.technet.microsoft.com/Profile/en-US/?user=rudi01Authentication failed for log time Off PCsHi Greg,<br/><br/>all computers the same configuration (many hardware identicaly), some (long time not used) failing 802.1X (NPS server send not understand response to C2960, authentication timeouted).<br/><br/>Auth. method -&gt; PEAP-MSCHAPv2<br/>Affected 10 computes - 2 weeks Off (in this week I disable Windows Defender via GPO and Microsoft Update send <a href="http://support.microsoft.com/default.aspx/kb/971026">http://support.microsoft.com/default.aspx/kb/971026</a>)<br/><br/>How I check computer certificate ?<br/><br/>Thanks<br/>L.Fri, 03 Jul 2009 06:05:50 Z2009-07-03T06:06:33Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#6a2df60f-45dd-484e-8f2c-1f2482b71396http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#6a2df60f-45dd-484e-8f2c-1f2482b71396Greg Lindsayhttp://social.technet.microsoft.com/Profile/en-US/?user=Greg%20LindsayAuthentication failed for log time Off PCs<p>Hi,<br/><br/>I am guessing that you don't see failed authentication attempts on NPS because the network interface is shut down after failed computer authentication. You can see this on the switch as line protocol down for that port.<br/><br/>To verify the client has a domain certificate:</p> <p>1. Click Start and click Run.<br/>2. Type mmc, and then press ENTER.<br/>3. On the File menu, click Add/Remove Snap-in.<br/>4. Click Certificates, click Add, select Computer account, and then click Next.<br/>5. Verify that Local computer: (the computer this console is running on) is selected, click Finish, and then click OK.<br/>6. In the console tree, double-click Certificates (Local Computer), double-click Personal, and then click Certificates.</p> <p>On a domain joined client, you should see a certificate here with <em><strong>Intended Purposes</strong></em> of <strong><em>Client Authentication</em></strong>. Make sure this certificate is not expired. If it is expired, you will need to regain connection to your CA to request a new one.<br/><br/>If that is not the problem, you might get some helpful information from event viewer on the client under Applications and Services Logs\Microsoft\Windows\Wired-Autoconfig\Operational, but sometimes the events here don't say much about why authentication failed.</p> <p>You mentioned that you disabled Windows Defender via GPO and these computers were turned off for 2 weeks. Are you saying that you think these computers are noncompliant? What normally happens to noncompliant computers? Do you put them into a different VLAN?</p> <p>-Greg</p>Fri, 03 Jul 2009 06:46:14 Z2009-07-03T06:46:14Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#fdee77f8-9057-47f6-9230-8998db139284http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#fdee77f8-9057-47f6-9230-8998db139284rudi01http://social.technet.microsoft.com/Profile/en-US/?user=rudi01Authentication failed for log time Off PCs<br/>Hi,<br/>certificates is OK<br/><br/>In logs sometimes error:<br/><span style="font-size:xx-small"> <p>Wired 802.1X Authentication failed.</p> <p>Network Adapter: Realtek RTL8169/8110 Family PCI Gigabit Ethernet NIC (NDIS 6.0)</p> <p>Interface GUID: {eb612c21-a126-4ca1-b749-8b9764fe275b}</p> <p>Peer Address: 001C0F9A5622</p> <p>Local Address: 003005A260DB</p> <p>Connection ID: 0x1</p> <p>Identity: -</p> <p>User: -</p> <p>Domain: -</p> <p>Reason: 0x50006</p> <p>Reason Text: The authenticator is no longer present</p> <p>Error Code: 0x0<br/>xxxxxxxxxxxxxxxxxxxxxxx<br/><br/><br/>but the same error in working state.<br/><br/><br/>In NAP agent log:<br/> <p>Log Name:      Microsoft-Windows-NetworkAccessProtection/Operational<br/>Source:        Microsoft-Windows-SystemHealthAgent<br/>Date:          1.7.2009 14:17:57<br/>Event ID:      1020<br/>Task Category: None<br/>Level:         Error<br/>Keywords:      <br/>User:          NETWORK SERVICE<br/>Computer:      PCUVT5.faf.cuni.cz<br/>Description:<br/>Automatic remediation for antispyware failed. Windows could not turn on Windows Defender. <br/>Failure Code: 0x800704ec<br/>Event Xml:<br/>&lt;Event xmlns=&quot;<a href="http://schemas.microsoft.com/win/2004/08/events/event">http://schemas.microsoft.com/win/2004/08/events/event</a>&quot;&gt;<br/>  &lt;System&gt;<br/>    &lt;Provider Name=&quot;Microsoft-Windows-SystemHealthAgent&quot; Guid=&quot;{B1BEBB9A-24AA-4B83-9E4A-38C2A9A44377}&quot; /&gt;<br/>    &lt;EventID&gt;1020&lt;/EventID&gt;<br/>    &lt;Version&gt;0&lt;/Version&gt;<br/>    &lt;Level&gt;2&lt;/Level&gt;<br/>    &lt;Task&gt;0&lt;/Task&gt;<br/>    &lt;Opcode&gt;0&lt;/Opcode&gt;<br/>    &lt;Keywords&gt;0x4000000000000000&lt;/Keywords&gt;<br/>    &lt;TimeCreated SystemTime=&quot;2009-07-01T12:17:57.088816700Z&quot; /&gt;<br/>    &lt;EventRecordID&gt;596&lt;/EventRecordID&gt;<br/>    &lt;Correlation /&gt;<br/>    &lt;Execution ProcessID=&quot;1288&quot; ThreadID=&quot;3416&quot; /&gt;<br/>    &lt;Channel&gt;Microsoft-Windows-NetworkAccessProtection/Operational&lt;/Channel&gt;<br/>    &lt;Computer&gt;PCUVT5.faf.cuni.cz&lt;/Computer&gt;<br/>    &lt;Security UserID=&quot;S-1-5-20&quot; /&gt;<br/>  &lt;/System&gt;<br/>  &lt;EventData&gt;<br/>    &lt;Data Name=&quot;FailureCode&quot;&gt;0x800704ec&lt;/Data&gt;<br/>    &lt;Data Name=&quot;FailureString&quot;&gt;<br/>    &lt;/Data&gt;<br/>  &lt;/EventData&gt;<br/>&lt;/Event&gt;</p> <p> Log Name:      Microsoft-Windows-NetworkAccessProtection/Operational<br/>Source:        Microsoft-Windows-NetworkAccessProtection<br/>Date:          1.7.2009 14:24:37<br/>Event ID:      30<br/>Task Category: None<br/>Level:         Error<br/>Keywords:      <br/>User:          NETWORK SERVICE<br/>Computer:      PCUVT5.faf.cuni.cz<br/>Description:<br/>The System Health Agent 79745 has returned an error code 3.<br/>Event Xml:<br/>&lt;Event xmlns=&quot;<a href="http://schemas.microsoft.com/win/2004/08/events/event">http://schemas.microsoft.com/win/2004/08/events/event</a>&quot;&gt;<br/>  &lt;System&gt;<br/>    &lt;Provider Name=&quot;Microsoft-Windows-NetworkAccessProtection&quot; Guid=&quot;{4EF850D8-BF30-4E64-A917-EE21B9BE1F0A}&quot; /&gt;<br/>    &lt;EventID&gt;30&lt;/EventID&gt;<br/>    &lt;Version&gt;0&lt;/Version&gt;<br/>    &lt;Level&gt;2&lt;/Level&gt;<br/>    &lt;Task&gt;0&lt;/Task&gt;<br/>    &lt;Opcode&gt;0&lt;/Opcode&gt;<br/>    &lt;Keywords&gt;0x8000000000000000&lt;/Keywords&gt;<br/>    &lt;TimeCreated SystemTime=&quot;2009-07-01T12:24:37.058346300Z&quot; /&gt;<br/>    &lt;EventRecordID&gt;610&lt;/EventRecordID&gt;<br/>    &lt;Correlation /&gt;<br/>    &lt;Execution ProcessID=&quot;1288&quot; ThreadID=&quot;3716&quot; /&gt;<br/>    &lt;Channel&gt;Microsoft-Windows-NetworkAccessProtection/Operational&lt;/Channel&gt;<br/>    &lt;Computer&gt;PCUVT5.faf.cuni.cz&lt;/Computer&gt;<br/>    &lt;Security UserID=&quot;S-1-5-20&quot; /&gt;<br/>  &lt;/System&gt;<br/>  &lt;UserData&gt;<br/>    &lt;NapEvent xmlns:auto-ns2=&quot;<a href="http://schemas.microsoft.com/win/2004/08/events">http://schemas.microsoft.com/win/2004/08/events</a>&quot; xmlns=&quot;myNs&quot;&gt;<br/>      &lt;SHAId&gt;3&lt;/SHAId&gt;<br/>      &lt;Error&gt;3&lt;/Error&gt;<br/>    &lt;/NapEvent&gt;<br/>  &lt;/UserData&gt;<br/>&lt;/Event&gt;</p> <span lang=CS></span></p> <p> After two weeks off - yes NONCOMPLIANT, but authentication failed. After five restart NIC, restart PC ....<br/>Yes I use separate VLAN for Noncomplant network.<br/><br/>L.</p> </span>Fri, 03 Jul 2009 07:49:25 Z2009-07-03T07:55:06Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#c999ac1c-99de-4ec7-b499-e7f0077ebac6http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#c999ac1c-99de-4ec7-b499-e7f0077ebac6rudi01http://social.technet.microsoft.com/Profile/en-US/?user=rudi01Authentication failed for log time Off PCsThats new message in Wired_autocinfig log, after start this problem:<br/><br/> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-family:'Tahoma','sans-serif';color:black;font-size:10pt">Log Name:      Microsoft-Windows-Wired-AutoConfig/Operational<br/>Source:        Microsoft-Windows-Wired-AutoConfig<br/>Date:          29.6.2009 8:50:03<br/>Event ID:      15514<br/>Task Category: None<br/>Level:         Error<br/>Keywords:      <br/>User:          SYSTEM<br/>Computer:      PCKFCHKL6.faf.cuni.cz<br/>Description:<br/>Wired 802.1X Authentication failed.</span><span style=""></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-family:'Tahoma','sans-serif';color:black;font-size:10pt"> Network Adapter: Intel(R) 82566DM-2 Gigabit Network Connection<br/> Interface GUID: {e7423c21-b37b-49a4-b928-0f1b6a80f544}<br/> Peer Address: 001CF640ED99<br/> Local Address: 00219B53353A<br/> Connection ID: 0x1<br/> Identity: -<br/> User: -<br/> Domain: -<br/> Reason: 0x70004<br/> Reason Text: Netwik not respond for authentication requests.<br/> Error Code: 0x0<br/>Event Xml:<br/>&lt;Event xmlns=&quot;<a href="http://schemas.microsoft.com/win/2004/08/events/event"><span style="color:#0000ff">http://schemas.microsoft.com/win/2004/08/events/event</span></a>&quot;&gt;<br/>  &lt;System&gt;<br/>    &lt;Provider Name=&quot;Microsoft-Windows-Wired-AutoConfig&quot; Guid=&quot;{b92cf7fd-dc10-4c6b-a72d-1613bf25e597}&quot; /&gt;<br/>    &lt;EventID&gt;15514&lt;/EventID&gt;<br/>    &lt;Version&gt;0&lt;/Version&gt;<br/>    &lt;Level&gt;2&lt;/Level&gt;<br/>    &lt;Task&gt;0&lt;/Task&gt;<br/>    &lt;Opcode&gt;0&lt;/Opcode&gt;<br/>    &lt;Keywords&gt;0x8000000000000000&lt;/Keywords&gt;<br/>    &lt;TimeCreated SystemTime=&quot;2009-06-29T06:50:03.513Z&quot; /&gt;<br/>    &lt;EventRecordID&gt;3454&lt;/EventRecordID&gt;<br/>    &lt;Correlation /&gt;<br/>    &lt;Execution ProcessID=&quot;1112&quot; ThreadID=&quot;1744&quot; /&gt;<br/>    &lt;Channel&gt;Microsoft-Windows-Wired-AutoConfig/Operational&lt;/Channel&gt;<br/>    &lt;Computer&gt;PCKFCHKL6.faf.cuni.cz&lt;/Computer&gt;<br/>    &lt;Security UserID=&quot;S-1-5-18&quot; /&gt;<br/>  &lt;/System&gt;<br/>  &lt;EventData&gt;<br/>    &lt;Data Name=&quot;InterfaceGuid&quot;&gt;{E7423C21-B37B-49A4-B928-0F1B6A80F544}&lt;/Data&gt;<br/>    &lt;Data Name=&quot;InterfaceDescription&quot;&gt;Intel(R) 82566DM-2 Gigabit Network Connection&lt;/Data&gt;<br/>    &lt;Data Name=&quot;SwitchMAC&quot;&gt;001CF640ED99&lt;/Data&gt;<br/>    &lt;Data Name=&quot;LocalMAC&quot;&gt;00219B53353A&lt;/Data&gt;<br/>    &lt;Data Name=&quot;ConnectionID&quot;&gt;0x1&lt;/Data&gt;<br/>    &lt;Data Name=&quot;Identity&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;User&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;Domain&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;ReasonCode&quot;&gt;0x70004&lt;/Data&gt;<br/>    &lt;Data Name=&quot;ReasonText&quot;&gt;Netwik not respond for authentication requests.&lt;/Data&gt;<br/>    &lt;Data Name=&quot;ErrorCode&quot;&gt;0x0&lt;/Data&gt;<br/>  &lt;/EventData&gt;<br/>&lt;/Event&gt;</span><span style=""></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style=""><span style="font-size:small"><span style="font-family:Times New Roman"> <br/>and from NetworkAccessProtection log:<br/><br/> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-family:'Tahoma','sans-serif';color:black;font-size:10pt">Log Name:      Microsoft-Windows-NetworkAccessProtection/Operational<br/>Source:        Microsoft-Windows-NetworkAccessProtection<br/>Date:          29.6.2009 8:49:23<br/>Event ID:      30<br/>Task Category: None<br/>Level:         Error<br/>Keywords:      <br/>User:          NETWORK SERVICE<br/>Computer:      PCKFCHKL6.faf.cuni.cz<br/>Description:<br/>The System Health Agent 79745 has returned an error code 2.<br/>Event Xml:<br/>&lt;Event xmlns=&quot;<a href="http://schemas.microsoft.com/win/2004/08/events/event"><span style="color:#0000ff">http://schemas.microsoft.com/win/2004/08/events/event</span></a>&quot;&gt;<br/>  &lt;System&gt;<br/>    &lt;Provider Name=&quot;Microsoft-Windows-NetworkAccessProtection&quot; Guid=&quot;{4ef850d8-bf30-4e64-a917-ee21b9be1f0a}&quot; /&gt;<br/>    &lt;EventID&gt;30&lt;/EventID&gt;<br/>    &lt;Version&gt;0&lt;/Version&gt;<br/>    &lt;Level&gt;2&lt;/Level&gt;<br/>    &lt;Task&gt;0&lt;/Task&gt;<br/>    &lt;Opcode&gt;0&lt;/Opcode&gt;<br/>    &lt;Keywords&gt;0x8000000000000000&lt;/Keywords&gt;<br/>    &lt;TimeCreated SystemTime=&quot;2009-06-29T06:49:23.700Z&quot; /&gt;<br/>    &lt;EventRecordID&gt;15462&lt;/EventRecordID&gt;<br/>    &lt;Correlation /&gt;<br/>    &lt;Execution ProcessID=&quot;1464&quot; ThreadID=&quot;4064&quot; /&gt;<br/>    &lt;Channel&gt;Microsoft-Windows-NetworkAccessProtection/Operational&lt;/Channel&gt;<br/>    &lt;Computer&gt;PCKFCHKL6.faf.cuni.cz&lt;/Computer&gt;<br/>    &lt;Security UserID=&quot;S-1-5-20&quot; /&gt;<br/>  &lt;/System&gt;<br/>  &lt;UserData&gt;<br/>    &lt;NapEvent xmlns:auto-ns2=&quot;<a href="http://schemas.microsoft.com/win/2004/08/events"><span style="color:#0000ff">http://schemas.microsoft.com/win/2004/08/events</span></a>&quot; xmlns=&quot;myNs&quot;&gt;<br/>      &lt;SHAId&gt;2&lt;/SHAId&gt;<br/>      &lt;Error&gt;2&lt;/Error&gt;<br/>    &lt;/NapEvent&gt;<br/>  &lt;/UserData&gt;<br/>&lt;/Event&gt;</span><span style=""></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style=""> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-family:'Tahoma','sans-serif';color:black;font-size:10pt">Log Name:      Microsoft-Windows-NetworkAccessProtection/Operational<br/>Source:        Microsoft-Windows-SystemHealthAgent<br/>Date:          29.6.2009 8:50:03<br/>Event ID:      1020<br/>Task Category: None<br/>Level:         Error<br/>Keywords:      <br/>User:          NETWORK SERVICE<br/>Computer:      PCKFCHKL6.faf.cuni.cz<br/>Description:<br/>Automatic remediation for antispyware failed. Windows could not turn on Windows Defender. <br/>Failure Code: 0x800705b4<br/>Event Xml:<br/>&lt;Event xmlns=&quot;<a href="http://schemas.microsoft.com/win/2004/08/events/event"><span style="color:#0000ff">http://schemas.microsoft.com/win/2004/08/events/event</span></a>&quot;&gt;<br/>  &lt;System&gt;<br/>    &lt;Provider Name=&quot;Microsoft-Windows-SystemHealthAgent&quot; Guid=&quot;{b1bebb9a-24aa-4b83-9e4a-38c2a9a44377}&quot; /&gt;<br/>    &lt;EventID&gt;1020&lt;/EventID&gt;<br/>    &lt;Version&gt;0&lt;/Version&gt;<br/>    &lt;Level&gt;2&lt;/Level&gt;<br/>    &lt;Task&gt;0&lt;/Task&gt;<br/>    &lt;Opcode&gt;0&lt;/Opcode&gt;<br/>    &lt;Keywords&gt;0x4000000000000000&lt;/Keywords&gt;<br/>    &lt;TimeCreated SystemTime=&quot;2009-06-29T06:50:03.481Z&quot; /&gt;<br/>    &lt;EventRecordID&gt;15485&lt;/EventRecordID&gt;<br/>    &lt;Correlation /&gt;<br/>    &lt;Execution ProcessID=&quot;1464&quot; ThreadID=&quot;804&quot; /&gt;<br/>    &lt;Channel&gt;Microsoft-Windows-NetworkAccessProtection/Operational&lt;/Channel&gt;<br/>    &lt;Computer&gt;PCKFCHKL6.faf.cuni.cz&lt;/Computer&gt;<br/>    &lt;Security UserID=&quot;S-1-5-20&quot; /&gt;<br/>  &lt;/System&gt;<br/>  &lt;EventData&gt;<br/>    &lt;Data Name=&quot;FailureCode&quot;&gt;0x800705b4&lt;/Data&gt;<br/>    &lt;Data Name=&quot;FailureString&quot;&gt;<br/>    &lt;/Data&gt;<br/>  &lt;/EventData&gt;<br/>&lt;/Event&gt;</span><span style=""></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-family:'Tahoma','sans-serif';color:black;font-size:10pt"> </span></p> <span style=""><font size=3><font face="Times New Roman"> <p class=MsoNormal style="margin:0cm 0cm 0pt"> </p> </font></font></span></span><span style=""><font size=3> <p class=MsoNormal style="margin:0cm 0cm 0pt"> </p> </font></span></span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"> </p>Fri, 03 Jul 2009 08:34:27 Z2009-07-03T08:34:27Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#f1c9621f-20e5-4cba-aa95-6932b8d71259http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#f1c9621f-20e5-4cba-aa95-6932b8d71259Greg Lindsayhttp://social.technet.microsoft.com/Profile/en-US/?user=Greg%20LindsayAuthentication failed for log time Off PCs<p>Hi,</p> <p>If you have disabled Windows Defender in GPO, you must remove this requirement from the WSHV. I'm a little confused about why all computers are not reporting a problem if you have used a GPO to disable a health requirement.<br/><br/>What happens if you turn off a health requirement for one of the computers on your network that is working fine? Does it move to the noncompliant VLAN, remediate, and then move back to the compliant VLAN?<br/><br/>I am wondering if there is a problem with your remediation network in general, or if the problem is only with the 10 computers.<br/><br/>-Greg</p>Fri, 03 Jul 2009 17:30:03 Z2009-07-03T17:31:31Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#748a971b-d9ad-4e75-8523-af0ff40b2781http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#748a971b-d9ad-4e75-8523-af0ff40b2781rudi01http://social.technet.microsoft.com/Profile/en-US/?user=rudi01Authentication failed for log time Off PCsHi,<br/>I use FCS (another antispyware solutions). WSHV not use only Defender antispyware.<br/><br/>Another computer working OK, on this computers is actually forefront antispyware antipyware/definitions.<br/><br/>Only 10 computers is one week off (in this week ....).<br/><br/>L.Fri, 03 Jul 2009 19:17:11 Z2009-07-03T19:17:11Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#c4f151d7-40e9-4602-a453-a38b356b62aahttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#c4f151d7-40e9-4602-a453-a38b356b62aaGreg Lindsayhttp://social.technet.microsoft.com/Profile/en-US/?user=Greg%20LindsayAuthentication failed for log time Off PCsHi Rudi,<br/><br/>Has the password expired on the computers that fail to authenticate?<br/><br/>-GregSat, 22 Aug 2009 18:40:28 Z2009-08-22T18:40:28Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#777d1621-4763-4e17-a5a3-851702bd3778http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#777d1621-4763-4e17-a5a3-851702bd3778rudi01http://social.technet.microsoft.com/Profile/en-US/?user=rudi01Authentication failed for log time Off PCsHi Greg,<br/>No password is not expired.<br/>This is randmomly problem and in this case cisco not understand answer from NPS/Radius server. I prepare debug of this from cicco catalyst.<br/><br/>Thanks,<br/>Ladislav<br/>Mon, 24 Aug 2009 14:13:57 Z2009-08-24T14:13:57Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#7260d10a-02f7-405a-96e8-9eaabdfd6209http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#7260d10a-02f7-405a-96e8-9eaabdfd6209Greg Lindsayhttp://social.technet.microsoft.com/Profile/en-US/?user=Greg%20LindsayAuthentication failed for log time Off PCsHi Ladislav,<br/><br/>Have you tried updating Cisco IOS to the most recent version? I have found some cases where older IOS does not work 100% with NPS.<br/><br/>-GregMon, 24 Aug 2009 23:44:28 Z2009-08-24T23:44:28Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#db3a5d4c-9c72-4f9d-8a62-26faa39e633dhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#db3a5d4c-9c72-4f9d-8a62-26faa39e633drudi01http://social.technet.microsoft.com/Profile/en-US/?user=rudi01Authentication failed for log time Off PCsHi Greg,<br/>I use two series cisco switch:<br/><br/>series C2950 with IOS 12.1(22)EA13<br/>series C2960 with IOS 12.2(50)SE<br/><br/>LadislavTue, 25 Aug 2009 09:36:32 Z2009-08-25T09:36:32Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#511813d2-b8ae-4b19-b9bc-197115968abdhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0b97998c-7dfd-4ba1-9c8f-af901d0625cb#511813d2-b8ae-4b19-b9bc-197115968abdGreg Lindsayhttp://social.technet.microsoft.com/Profile/en-US/?user=Greg%20LindsayAuthentication failed for log time Off PCsHi Ladislav,<br/><br/>Those should be recent enough versions of IOS. I have found you need 12.1(22)EA9 on the 2950.<br/><br/>In the case of the switch not understanding the response from NPS, I think you are taking the right approach to use debug.<br/><br/>-GregTue, 25 Aug 2009 17:23:53 Z2009-08-25T17:23:53Z