Authentication fails/no response to the EAP Response identity packet <p class=MsoNoSpacing>Hello NAP gurus,</p> <p class=MsoNoSpacing>I’ve been unsuccessfully trying to set up NAP on Server 2008 (Standard version, SP1), and spending more time troubleshooting than I’d like to admit. I’m hoping someone on this forum can point me in the right direction. </p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>My eventual goal is to setup up NAP with dynamic VLAN distribution, depending on security membership status in Active Directory. (And later on I’d like to add more NAP bells and whistles of course.) Currently I’m just trying to get the authentication process working.</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>Problem: Each time I connect a host to my switch on an 802.1X enabled port, the authentication fails.</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>The error message on the 802.1x enabled supplicant (laptop, running XP SP3) is: </p> <p class=MsoNoSpacing>Wired 802.1X authentication failed </p> <p class=MsoNoSpacing>Reason: 327687</p> <p class=MsoNoSpacing>Reason Text: There was no response to the EAP Response identity packet</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>Corresponding log entry on NAP server (slightly obfuscated):</p> <p class=MsoNoSpacing>10.1.0.216,DOMAIN\user,07/16/2008,13:47:23,IAS,BRIDGE,12,1480,4,10.1.0.216,32,LAB SWITCH,6,2,7,1,5,3,61,15,87,3,30,00-1f-28-03-XX-XX,31,00-19-b9-69-XX-XX,77,CONNECT Ethernet 1000Mbps Full duplex,64,13,65,6,81,1,4108,10.3.0.253,4116,0,4128,Lab Switch in 10.3 subnet,4154,NAP 802.1X (Wired),4155,0,25,311 1 fe80::8c00:968d:9eca:XXXX 07/11/2008 19:51:26 7,4136,1,4142,0</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>10.1.0.216,DOMAIN\user,07/16/2008,13:47:23,IAS,BRIDGE,25,311 1 fe80::8c00:968d:9eca:XXXX 07/11/2008 19:51:26 7,4155,0,4154,NAP 802.1X (Wired),4128,Lab Switch in 10.3 subnet,4116,0,4108,10.3.0.253,4136,2,4142,0</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>10.1.0.216,DOMAIN\user,07/16/2008,13:47:42,IAS,BRIDGE,12,1480,4,10.1.0.216,32,LAB SWITCH,6,2,7,1,5,3,61,15,87,3,30,00-1f-28-03-XX-XX,31,00-19-b9-69-XX-XX,77,CONNECT Ethernet 1000Mbps Full duplex,64,13,65,6,81,1,4108,10.3.0.253,4116,0,4128,Lab Switch in 10.3 subnet,4154,NAP 802.1X (Wired),4155,0,25,311 1 fe80::8c00:968d:9eca:XXXX 07/11/2008 19:51:26 8,4136,1,4142,0</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>10.1.0.216,DOMAIN\user,07/16/2008,13:47:42,IAS,BRIDGE,25,311 1 fe80::8c00:968d:9eca:XXXX 07/11/2008 19:51:26 8,4155,0,4154,NAP 802.1X (Wired),4128,Lab Switch in 10.3 subnet,4116,0,4108,10.3.0.253,4136,2,4142,0</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>BRIDGE = NAP server, 10.3.1.1/16</p> <p class=MsoNoSpacing>LAB SWITCH = authenticator (HP ProCurve 2848), 10.1.0.216/16</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>Switch configuration (HP ProCurve 2848), mostly 802.1X relevant part(s):</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>hostname &quot;LAB SWITCH&quot; </p> <p class=MsoNoSpacing>vlan 1 </p> <p class=MsoNoSpacing><span style="">   </span>name &quot;DEFAULT_VLAN&quot; </p> <p class=MsoNoSpacing><span style="">   </span>untagged 1-48 </p> <p class=MsoNoSpacing><span style="">   </span>ip address 10.1.0.216 255.255.0.0 </p> <p class=MsoNoSpacing><span style="">   </span>ip helper-address 10.3.1.1 </p> <p class=MsoNoSpacing><span style="">   </span>exit </p> <p class=MsoNoSpacing>vlan 118 </p> <p class=MsoNoSpacing><span style="">   </span>name &quot;restricted&quot; </p> <p class=MsoNoSpacing><span style="">   </span>ip helper-address 10.3.1.1 </p> <p class=MsoNoSpacing><span style="">   </span>tagged 48 </p> <p class=MsoNoSpacing><span style="">   </span>exit </p> <p class=MsoNoSpacing>vlan 103 </p> <p class=MsoNoSpacing><span style="">   </span>name &quot;core&quot; </p> <p class=MsoNoSpacing><span style="">   </span>ip address 10.3.0.253 255.255.0.0 </p> <p class=MsoNoSpacing><span style="">   </span>ip helper-address 10.3.1.1 </p> <p class=MsoNoSpacing><span style="">   </span>tagged 48 </p> <p class=MsoNoSpacing><span style="">   </span>exit </p> <p class=MsoNoSpacing>vlan 110 </p> <p class=MsoNoSpacing><span style="">   </span>name &quot;staff&quot; </p> <p class=MsoNoSpacing><span style="">   </span>ip helper-address 10.3.1.1 </p> <p class=MsoNoSpacing><span style="">   </span>tagged 48 </p> <p class=MsoNoSpacing><span style="">   </span>exit </p> <p class=MsoNoSpacing>[…]</p> <p class=MsoNoSpacing>aaa authentication port-access eap-radius </p> <p class=MsoNoSpacing>radius-server host 10.3.1.1 </p> <p class=MsoNoSpacing>radius-server key password</p> <p class=MsoNoSpacing>aaa port-access authenticator 1-4</p> <p class=MsoNoSpacing>aaa port-access authenticator active</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>The switch has an uplink to a core Cisco switch on port 48 via trunk. The NAP server and the DHCP server are directly connected to the core switch. Both servers can be pinged from the switch.</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>NAP configuration:</p> <p class=MsoNoSpacing style="margin-left:0.5in;text-indent:-0.25in"><span style=""><span style="">1.<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal">       </span></span></span>I have a NAP 802.1X (Wired) Connection Request Policy, NAS port type: Ethernet</p> <p class=MsoNoSpacing style="margin-left:0.5in;text-indent:-0.25in"><span style=""><span style="">2.<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal">       </span></span></span>There are multiple Network policies in place (each for different VLANS, although at the moment I’m more concerned just getting the client/user authenticated.)<br> Each Network Policy is configured for Protected EAP, the RADIUS attributes include Framed-Protocol (PPP), Service Type (Framed), Tunnel-Type (Virtual LAN), Tunnel-Medium-Type (802), and Tunnel-Pvt-Group-ID (VLAN ID, for example 110). IP settings are set to “Client may request an IP address” (although I am currently using a static IP on the host, just for troubleshooting purposes. Once the authentication works I’ll switch it back to DHCP).</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>Settings on the host (XP, SP3):</p> <p class=MsoNoSpacing style="margin-left:0.5in;text-indent:-0.25in"><span style=""><span style="">1.<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal">       </span></span></span>IEEE 802.1X authentication is enabled</p> <p class=MsoNoSpacing style="margin-left:0.5in;text-indent:-0.25in"><span style=""><span style="">2.<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal">       </span></span></span>Network authentication method: PEAP<br> PEAP settings: Secured password (EAP-MSCHAP v2); </p> <p class=MsoNoSpacing style="margin-left:0.5in">and “Automatically use my Windows logon name and password).</p>  <p class=MsoNoSpacing>Sorry for the long post, but I wasn’t quite sure how to condense the problem without omitting potentially important information/configurations.</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>Any hint/tip is greatly appreciated. At the moment it seems I’m out of moves.</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>Thanks, </p> <p class=MsoNoSpacing>Dan.</p> © 2009 Microsoft Corporation. All rights reserved.Wed, 19 Aug 2009 20:16:14 Zdd44200b-b805-4d24-ad49-a0897eebefc6http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/dd44200b-b805-4d24-ad49-a0897eebefc6#dd44200b-b805-4d24-ad49-a0897eebefc6http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/dd44200b-b805-4d24-ad49-a0897eebefc6#dd44200b-b805-4d24-ad49-a0897eebefc6dbauhttp://social.technet.microsoft.com/Profile/en-US/?user=dbauAuthentication fails/no response to the EAP Response identity packet <p class=MsoNoSpacing>Hello NAP gurus,</p> <p class=MsoNoSpacing>I’ve been unsuccessfully trying to set up NAP on Server 2008 (Standard version, SP1), and spending more time troubleshooting than I’d like to admit. I’m hoping someone on this forum can point me in the right direction. </p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>My eventual goal is to setup up NAP with dynamic VLAN distribution, depending on security membership status in Active Directory. (And later on I’d like to add more NAP bells and whistles of course.) Currently I’m just trying to get the authentication process working.</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>Problem: Each time I connect a host to my switch on an 802.1X enabled port, the authentication fails.</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>The error message on the 802.1x enabled supplicant (laptop, running XP SP3) is: </p> <p class=MsoNoSpacing>Wired 802.1X authentication failed </p> <p class=MsoNoSpacing>Reason: 327687</p> <p class=MsoNoSpacing>Reason Text: There was no response to the EAP Response identity packet</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>Corresponding log entry on NAP server (slightly obfuscated):</p> <p class=MsoNoSpacing>10.1.0.216,DOMAIN\user,07/16/2008,13:47:23,IAS,BRIDGE,12,1480,4,10.1.0.216,32,LAB SWITCH,6,2,7,1,5,3,61,15,87,3,30,00-1f-28-03-XX-XX,31,00-19-b9-69-XX-XX,77,CONNECT Ethernet 1000Mbps Full duplex,64,13,65,6,81,1,4108,10.3.0.253,4116,0,4128,Lab Switch in 10.3 subnet,4154,NAP 802.1X (Wired),4155,0,25,311 1 fe80::8c00:968d:9eca:XXXX 07/11/2008 19:51:26 7,4136,1,4142,0</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>10.1.0.216,DOMAIN\user,07/16/2008,13:47:23,IAS,BRIDGE,25,311 1 fe80::8c00:968d:9eca:XXXX 07/11/2008 19:51:26 7,4155,0,4154,NAP 802.1X (Wired),4128,Lab Switch in 10.3 subnet,4116,0,4108,10.3.0.253,4136,2,4142,0</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>10.1.0.216,DOMAIN\user,07/16/2008,13:47:42,IAS,BRIDGE,12,1480,4,10.1.0.216,32,LAB SWITCH,6,2,7,1,5,3,61,15,87,3,30,00-1f-28-03-XX-XX,31,00-19-b9-69-XX-XX,77,CONNECT Ethernet 1000Mbps Full duplex,64,13,65,6,81,1,4108,10.3.0.253,4116,0,4128,Lab Switch in 10.3 subnet,4154,NAP 802.1X (Wired),4155,0,25,311 1 fe80::8c00:968d:9eca:XXXX 07/11/2008 19:51:26 8,4136,1,4142,0</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>10.1.0.216,DOMAIN\user,07/16/2008,13:47:42,IAS,BRIDGE,25,311 1 fe80::8c00:968d:9eca:XXXX 07/11/2008 19:51:26 8,4155,0,4154,NAP 802.1X (Wired),4128,Lab Switch in 10.3 subnet,4116,0,4108,10.3.0.253,4136,2,4142,0</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>BRIDGE = NAP server, 10.3.1.1/16</p> <p class=MsoNoSpacing>LAB SWITCH = authenticator (HP ProCurve 2848), 10.1.0.216/16</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>Switch configuration (HP ProCurve 2848), mostly 802.1X relevant part(s):</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>hostname &quot;LAB SWITCH&quot; </p> <p class=MsoNoSpacing>vlan 1 </p> <p class=MsoNoSpacing><span style="">   </span>name &quot;DEFAULT_VLAN&quot; </p> <p class=MsoNoSpacing><span style="">   </span>untagged 1-48 </p> <p class=MsoNoSpacing><span style="">   </span>ip address 10.1.0.216 255.255.0.0 </p> <p class=MsoNoSpacing><span style="">   </span>ip helper-address 10.3.1.1 </p> <p class=MsoNoSpacing><span style="">   </span>exit </p> <p class=MsoNoSpacing>vlan 118 </p> <p class=MsoNoSpacing><span style="">   </span>name &quot;restricted&quot; </p> <p class=MsoNoSpacing><span style="">   </span>ip helper-address 10.3.1.1 </p> <p class=MsoNoSpacing><span style="">   </span>tagged 48 </p> <p class=MsoNoSpacing><span style="">   </span>exit </p> <p class=MsoNoSpacing>vlan 103 </p> <p class=MsoNoSpacing><span style="">   </span>name &quot;core&quot; </p> <p class=MsoNoSpacing><span style="">   </span>ip address 10.3.0.253 255.255.0.0 </p> <p class=MsoNoSpacing><span style="">   </span>ip helper-address 10.3.1.1 </p> <p class=MsoNoSpacing><span style="">   </span>tagged 48 </p> <p class=MsoNoSpacing><span style="">   </span>exit </p> <p class=MsoNoSpacing>vlan 110 </p> <p class=MsoNoSpacing><span style="">   </span>name &quot;staff&quot; </p> <p class=MsoNoSpacing><span style="">   </span>ip helper-address 10.3.1.1 </p> <p class=MsoNoSpacing><span style="">   </span>tagged 48 </p> <p class=MsoNoSpacing><span style="">   </span>exit </p> <p class=MsoNoSpacing>[…]</p> <p class=MsoNoSpacing>aaa authentication port-access eap-radius </p> <p class=MsoNoSpacing>radius-server host 10.3.1.1 </p> <p class=MsoNoSpacing>radius-server key password</p> <p class=MsoNoSpacing>aaa port-access authenticator 1-4</p> <p class=MsoNoSpacing>aaa port-access authenticator active</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>The switch has an uplink to a core Cisco switch on port 48 via trunk. The NAP server and the DHCP server are directly connected to the core switch. Both servers can be pinged from the switch.</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>NAP configuration:</p> <p class=MsoNoSpacing style="margin-left:0.5in;text-indent:-0.25in"><span style=""><span style="">1.<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal">       </span></span></span>I have a NAP 802.1X (Wired) Connection Request Policy, NAS port type: Ethernet</p> <p class=MsoNoSpacing style="margin-left:0.5in;text-indent:-0.25in"><span style=""><span style="">2.<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal">       </span></span></span>There are multiple Network policies in place (each for different VLANS, although at the moment I’m more concerned just getting the client/user authenticated.)<br> Each Network Policy is configured for Protected EAP, the RADIUS attributes include Framed-Protocol (PPP), Service Type (Framed), Tunnel-Type (Virtual LAN), Tunnel-Medium-Type (802), and Tunnel-Pvt-Group-ID (VLAN ID, for example 110). IP settings are set to “Client may request an IP address” (although I am currently using a static IP on the host, just for troubleshooting purposes. Once the authentication works I’ll switch it back to DHCP).</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>Settings on the host (XP, SP3):</p> <p class=MsoNoSpacing style="margin-left:0.5in;text-indent:-0.25in"><span style=""><span style="">1.<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal">       </span></span></span>IEEE 802.1X authentication is enabled</p> <p class=MsoNoSpacing style="margin-left:0.5in;text-indent:-0.25in"><span style=""><span style="">2.<span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal">       </span></span></span>Network authentication method: PEAP<br> PEAP settings: Secured password (EAP-MSCHAP v2); </p> <p class=MsoNoSpacing style="margin-left:0.5in">and “Automatically use my Windows logon name and password).</p>  <p class=MsoNoSpacing>Sorry for the long post, but I wasn’t quite sure how to condense the problem without omitting potentially important information/configurations.</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>Any hint/tip is greatly appreciated. At the moment it seems I’m out of moves.</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>Thanks, </p> <p class=MsoNoSpacing>Dan.</p> Wed, 16 Jul 2008 21:57:48 Z2008-07-16T21:57:48Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/dd44200b-b805-4d24-ad49-a0897eebefc6#ffcc0df6-f7fb-4681-806d-d36589563bb8http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/dd44200b-b805-4d24-ad49-a0897eebefc6#ffcc0df6-f7fb-4681-806d-d36589563bb8Greg Lindsayhttp://social.technet.microsoft.com/Profile/en-US/?user=Greg%20LindsayAuthentication fails/no response to the EAP Response identity packet<font style="font-size:9pt" face="'Verdana','sans-serif'">Hi Dan,</font> <p><font style="font-size:9pt" face="'Verdana','sans-serif'">Can you please provide the following:<br><br></font></p><font style="font-size:9pt" face="'Verdana','sans-serif'"> <ul> <li>The output of &quot;netsh nap client show state&quot; from a command line on your XP SP3 machine.</li></font> <li><font style="font-size:9pt" face="'Verdana','sans-serif'">In </font></span><font style="font-size:9pt" face="'Verdana','sans-serif'">event viewer, custom views, server roles, network policy and access services, do you see event 6273? What is the reason that access was denied? If possible, provide the text of any events with a task category of &quot;Network Policy Server&quot; or if present any error events with a source of &quot;NPS.&quot;</font></li></ul> <p> </p><font style="font-size:9pt" face="'Verdana','sans-serif'"> <p>Thanks,<br>-Greg<br></p></font>Thu, 17 Jul 2008 23:50:55 Z2008-07-17T23:52:20Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/dd44200b-b805-4d24-ad49-a0897eebefc6#265752d3-e0a3-4a5b-b861-d171595f97bfhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/dd44200b-b805-4d24-ad49-a0897eebefc6#265752d3-e0a3-4a5b-b861-d171595f97bfdbauhttp://social.technet.microsoft.com/Profile/en-US/?user=dbauAuthentication fails/no response to the EAP Response identity packetHi, Greg, <br>here's what I could find:<br><br>1. <font style="font-size:9pt" face="'Verdana','sans-serif'">netsh nap client show state<br><br>Client state: <br>---------------------------------------------------- <br>Name                       = Network Access Protection Client <br>Description              = Microsoft Network Access Protection Client <br>Protocol version     = 1.0 <br>Status                   = Enabled <br>Restriction state      = Not restricted <br>Troubleshooting URL    =  <br>Restriction start time =  <br>Extended state         =  <br><br>Enforcement client state: <br>---------------------------------------------------- <br>Id                     = 79617 <br>Name                   = DHCP Quarantine Enforcement Client <br>Description            = Provides DHCP based enforcement for NAP <br>Version                = 1.0 <br>Vendor name            = Microsoft Corporation <br>Registration date      =  <br>Initialized            = No <br><br>Id                     = 79618 <br>Name                   = Remote Access Quarantine Enforcement Client <br>Description            = Provides the quarantine enforcement for RAS Client <br>Version                = 1.0 <br>Vendor name            = Microsoft Corporation <br>Registration date      =  <br>Initialized            = No <br><br>Id                     = 79619 <br>Name                   = IPSec Relying Party <br>Description            = Provides IPSec based enforcement for Network Access Protection <br>Version                = 1.0 <br>Vendor name            = Microsoft Corporation <br>Registration date      =  <br>Initialized            = No <br><br>Id                     = 79620 <br>Name                   = Wireless Eapol Quarantine Enforcement Client <br>Description            = Provides wireless Eapol based enforcement for NAP <br>Version                = 1.0 <br>Vendor name            = Microsoft Corporation <br>Registration date      =  <br>Initialized            = No <br><br>Id                     = 79621 <br>Name                   = TS Gateway Quarantine Enforcement Client <br>Description            = Provides TS Gateway enforcement for NAP <br>Version                = 1.0 <br>Vendor name            = Microsoft Corporation <br>Registration date      =  <br>Initialized            = No <br><br>Id                     = 79623 <br>Name                   = EAP Quarantine Enforcement Client <br>Description            = Provides EAP based enforcement for NAP <br>Version                = 1.0 <br>Vendor name            = Microsoft Corporation <br>Registration date      =  <br>Initialized            = Yes <br><br>System health agent (SHA) state: <br>---------------------------------------------------- <br>Id                     = 79744 <br>Name                   = Windows Security Health Agent<br> <br>Description            = The Windows Security Health Agent checks the compliance of a computer with an administrator-defined policy.<br> <br>Version                = 1.0<br> <br>Vendor name            = Microsoft Corporation<br> <br>Registration date      =  <br>Initialized            = Yes <br>Failure category       = None <br>Remediation state      = Success <br>Remediation percentage = 0 <br>Fixup Message          = (3237937214) - The Windows Security Health Agent has finished updating its security state.<br> <br>Compliance results     = <br>Remediation results    = <br><br>Ok.<br><br><br>#################################################################<br><br>2. There are no NPS entries in the event viewer; but there are plenty of entries like these two in the IAS log:<br><br>10.1.0.216,DOMAIN\user,07/18/2008,09:11:00,IAS,RAD,12,1480,4,10.1.0.216,32,LAB SWITCH,6,2,7,1,5,1,61,15,87,1,30,00-1f-28-03-aa-3f,31,00-19-b9-69-45-bc,77,CONNECT Ethernet 1000Mbps Full duplex,64,13,65,6,81,109,4108,10.3.0.253,4116,0,4128,lab_switch 10.3,4154,NAP 802.1X (Wired),4155,1,4129,DOMAIN\user,4130,DOMAIN\user,25,311 1 ::1 07/17/2008 23:04:39 175,4136,1,4142,0<br><br>10.1.0.216,</font><font style="font-size:9pt" face="'Verdana','sans-serif'">DOMAIN</font><font style="font-size:9pt" face="'Verdana','sans-serif'">\</font><font style="font-size:9pt" face="'Verdana','sans-serif'">user</font><font style="font-size:9pt" face="'Verdana','sans-serif'">,07/18/2008,09:11:00,IAS,RAD,25,311 1 ::1 07/17/2008 23:04:39 175,27,30,4130,</font><font style="font-size:9pt" face="'Verdana','sans-serif'">DOMAIN</font><font style="font-size:9pt" face="'Verdana','sans-serif'">\</font><font style="font-size:9pt" face="'Verdana','sans-serif'">user</font><font style="font-size:9pt" face="'Verdana','sans-serif'">,4129,</font><font style="font-size:9pt" face="'Verdana','sans-serif'">DOMAIN</font><font style="font-size:9pt" face="'Verdana','sans-serif'">\</font><font style="font-size:9pt" face="'Verdana','sans-serif'">user</font><font style="font-size:9pt" face="'Verdana','sans-serif'">,4108,10.3.0.253,4116,0,4128,lab_switch 10.3,4154,NAP 802.1X (Wired),4155,1,4136,11,4142,0<br><br>I don't see any inner </font>authentication protocol info (&quot;Secured password (EAP-MSCHAP v2)&quot;) or encoded password string. Could this be a certificate issue? How could I test this?<br><font style="font-size:9pt" face="'Verdana','sans-serif'"><br><br>To see if any RADIUS packets actually make it to NPS I removed my 802.1X switch from my list of RADIUS clients, and immediately I started seeing </font><font style="font-size:9pt" face="'Verdana','sans-serif'">entries like this one: <br></font><font style="font-size:9pt" face="'Verdana','sans-serif'">&quot;A RADIUS message was received from the invalid RADIUS client [...]&quot; .<br><br>Thanks for your help,<br><br>Dan<br><br>#########<br>#                 #<br># UPDATE:  #<br>#                #<br>########<br>Hours later I now have a lot of entries in </font><font style="font-size:9pt" face="'Verdana','sans-serif'">event viewer (under custom views, server roles, network policy and access services</font>). I'm not sure why those log entries didn't show up at the time...??? Anyways, here's one log entry (all the other ones are the same, event ID 6274):<br><br> <p class=MsoNoSpacing>Log Name:<span style="">      </span>Security</p> <p class=MsoNoSpacing>Source:<span style="">        </span>Microsoft-Windows-Security-Auditing</p> <p class=MsoNoSpacing>Date:<span style="">          </span>7/18/2008 12:58:49 PM</p> <p class=MsoNoSpacing>Event ID:<span style="">      </span>6274</p> <p class=MsoNoSpacing>Task Category: Network Policy Server</p> <p class=MsoNoSpacing>Level:<span style="">         </span>Information</p> <p class=MsoNoSpacing>Keywords:<span style="">      </span>Audit Failure</p> <p class=MsoNoSpacing>User:<span style="">          </span>N/A</p> <p class=MsoNoSpacing>Computer:<span style="">      </span>rad.DOMAIN.edu</p> <p class=MsoNoSpacing>Description:</p> <p class=MsoNoSpacing>Network Policy Server discarded the request for a user.</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>User:</p> <p class=MsoNoSpacing><span style="">                </span>Security ID:<span style="">                                         </span>NULL SID</p> <p class=MsoNoSpacing><span style="">                </span>Account Name:<span style="">                                 </span>DOMAIN\user</p> <p class=MsoNoSpacing><span style="">                </span>Account Domain:<span style="">                              </span>DOMAIN</p> <p class=MsoNoSpacing><span style="">                </span>Fully Qualified Account Name:<span style="">   </span>DOMAIN\user</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>Client Machine:</p> <p class=MsoNoSpacing><span style="">                </span>Security ID:<span style="">                                         </span>NULL SID</p> <p class=MsoNoSpacing><span style="">                </span>Account Name:<span style="">                                 </span>-</p> <p class=MsoNoSpacing><span style="">                </span>Fully Qualified Account Name:<span style="">   </span>-</p> <p class=MsoNoSpacing><span style="">                </span>OS-Version:<span style="">                                        </span>-</p> <p class=MsoNoSpacing><span style="">                </span>Called Station Identifier:<span style="">               </span>00-1f-28-03-aa-3f</p> <p class=MsoNoSpacing><span style="">                </span>Calling Station Identifier:<span style="">              </span>00-19-b9-69-45-bc</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>NAS:</p> <p class=MsoNoSpacing><span style="">                </span>NAS IPv4 Address:<span style="">                           </span>10.1.0.216</p> <p class=MsoNoSpacing><span style="">                </span>NAS IPv6 Address:<span style="">                           </span>-</p> <p class=MsoNoSpacing><span style="">                </span>NAS Identifier:<span style="">                                  </span>LAB SWITCH</p> <p class=MsoNoSpacing><span style="">                </span>NAS Port-Type:<span style="">                                 </span>Ethernet </p> <p class=MsoNoSpacing><span style="">                </span>NAS Port:<span style="">                                            </span>1</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>RADIUS Client:</p> <p class=MsoNoSpacing><span style="">                </span>Client Friendly Name:<span style="">                    </span>lab_switch 10.3</p> <p class=MsoNoSpacing><span style="">                </span>Client IP Address:<span style="">                            </span>10.3.0.253</p> <p class=MsoNoSpacing> </p> <p class=MsoNoSpacing>Authentication Details:</p> <p class=MsoNoSpacing><span style="">                </span>Proxy Policy Name:<span style="">                         </span>NAP 802.1X (Wired)</p> <p class=MsoNoSpacing><span style="">                </span>Network Policy Name:<span style="">                   </span>-</p> <p class=MsoNoSpacing><span style="">                </span>Authentication Provider:<span style="">              </span>Windows </p> <p class=MsoNoSpacing><span style="">                </span>Authentication Server:<span style="">                  </span>rad.DOMAIN.edu</p> <p class=MsoNoSpacing><span style="">                </span>Authentication Type:<span style="">                     </span>-</p> <p class=MsoNoSpacing><span style="">                </span>EAP Type:<span style="">                                            </span>-</p> <p class=MsoNoSpacing><span style="">                </span>Account Session Identifier:<span style="">         </span>-</p> <p class=MsoNoSpacing><span style="">                </span>Reason Code:<span style="">                                    </span>1</p> <p class=MsoNoSpacing><span style="">                </span>Reason:<span style="">                                                </span>An internal error occurred. Check the system event log for additional information. </p> <br><br><br>I didn't see any additional info in the system event log.<br><br><font style="font-size:9pt" face="'Verdana','sans-serif'"><br><br></font>Fri, 18 Jul 2008 16:29:03 Z2008-07-18T21:06:45Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/dd44200b-b805-4d24-ad49-a0897eebefc6#b495d504-57d9-4c92-bff7-5d9b707b76b9http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/dd44200b-b805-4d24-ad49-a0897eebefc6#b495d504-57d9-4c92-bff7-5d9b707b76b9Jean Tomazhttp://social.technet.microsoft.com/Profile/en-US/?user=Jean%20TomazAuthentication fails/no response to the EAP Response identity packet Hello , Dan<br><br>Question. Your switch have RFC 3580 Support ( Vlan dynamic ) ?Tue, 22 Jul 2008 12:17:20 Z2008-07-22T12:17:20Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/dd44200b-b805-4d24-ad49-a0897eebefc6#7e0cc1b1-3270-4e22-b3f6-8da9a391d40bhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/dd44200b-b805-4d24-ad49-a0897eebefc6#7e0cc1b1-3270-4e22-b3f6-8da9a391d40bdbauhttp://social.technet.microsoft.com/Profile/en-US/?user=dbauAuthentication fails/no response to the EAP Response identity packetHi, Jean,<br>the switch I'm using is an HP 2848, and it does support dynamic vlans. However, you were on the right track pointing at the switch as the culprit.  The firmware I was using had a bug in it where PEAP fails to authenticate with Microsoft IAS Radius server (it works without any problems with FreeRADIUS). The switch event log will report &quot;can't reach RADIUS server&quot;. I upgraded to I.10.43, and now it seems to work, this thread can be closed.<br><br>Thanks for your time guys, I really appreciate it!<br><br>Cheers, <br>Dan<br> Tue, 22 Jul 2008 16:31:34 Z2008-07-22T16:31:34Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/dd44200b-b805-4d24-ad49-a0897eebefc6#0f1222ae-0e63-41de-a9ab-fc1fbc921f64http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/dd44200b-b805-4d24-ad49-a0897eebefc6#0f1222ae-0e63-41de-a9ab-fc1fbc921f64Mike Van Slambrouckhttp://social.technet.microsoft.com/Profile/en-US/?user=Mike%20Van%20SlambrouckAuthentication fails/no response to the EAP Response identity packet<p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:small"><span style="font-family:Times New Roman">Hello,</span> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:small;font-family:Times New Roman"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:small;font-family:Times New Roman">I'm running into the same problem.<span>  </span> Only have a HP MSM750 Access Controller running: <table class=cntnt border=0 cellspacing=0 cellpadding=2 summary="layout table"> <tbody> <tr valign=top> <td align=right><span class=label>Software version:</span></td> <td><span class=label>5.2.6.0-01-7057</span></td> </tr> </tbody> </table> <br/> Has anyone else had this problem with the HP MSM750 Access Controller and Windows Server Ent 2008?<br/> </span></p>Fri, 26 Jun 2009 18:49:10 Z2009-06-30T00:02:00Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/dd44200b-b805-4d24-ad49-a0897eebefc6#4716fa7d-3ed4-4da3-91a1-36f64894e10ehttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/dd44200b-b805-4d24-ad49-a0897eebefc6#4716fa7d-3ed4-4da3-91a1-36f64894e10eEdersmhttp://social.technet.microsoft.com/Profile/en-US/?user=EdersmAuthentication fails/no response to the EAP Response identity packetHave same problem with HP 5400.. anyone has a solution? Thanks<br/>Tue, 28 Jul 2009 22:28:41 Z2009-07-28T22:28:41Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/dd44200b-b805-4d24-ad49-a0897eebefc6#8af9daf5-2ff5-47d0-9bcb-62ea9eaff26dhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/dd44200b-b805-4d24-ad49-a0897eebefc6#8af9daf5-2ff5-47d0-9bcb-62ea9eaff26dMullahvikhttp://social.technet.microsoft.com/Profile/en-US/?user=MullahvikAuthentication fails/no response to the EAP Response identity packetIf you are using XP SP3 see: KB969111 - A Windows XP Service Pack 3-based client computer cannot use the IEEE 802.1x authentication when you use PEAP with PEAP-MSCHAPv2 in a domain.<br/><br/>KMWed, 19 Aug 2009 11:47:26 Z2009-08-19T11:47:26Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/dd44200b-b805-4d24-ad49-a0897eebefc6#8789cb81-88b0-4d67-baa8-92eca05f2ed5http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/dd44200b-b805-4d24-ad49-a0897eebefc6#8789cb81-88b0-4d67-baa8-92eca05f2ed5Greg Lindsayhttp://social.technet.microsoft.com/Profile/en-US/?user=Greg%20LindsayAuthentication fails/no response to the EAP Response identity packetHi,<br/><br/>XP SP3 can use PEAP MSCHAPv2 with 802.1X. The problem noted in the hotfix is when you use it with a mandatory profile. This problem has been noted a few times on the forum.<br/><br/>-GregWed, 19 Aug 2009 20:16:14 Z2009-08-19T20:16:14Z