Network Access Protection ForumDiscussion of Network Access Protection© 2009 Microsoft Corporation. All rights reserved.Thu, 26 Nov 2009 02:42:56 Z7df95120-f35b-4dfc-bd62-ee246d6cb04ehttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/3157e7d6-eb40-4329-9414-b136a3622617http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/3157e7d6-eb40-4329-9414-b136a3622617yaplejhttp://social.technet.microsoft.com/Profile/en-US/?user=yaplejGPO 802.3 Policies "Settings" lockdownHello, and Happy Thanksgiving,<br/><br/>I am working on implementing NAP with 802.1x, and EAP enforcement on my network, and so far its going good.  I just extended my AD Schema so I could setup a Wired Network 802.3 Policy.  That worked great to configure the clients, but users can still go into &quot;Settings&quot; on the Authentication tab, and mess with settings.  Why isnt that locked down when the settings are applied via GPO?<br/><br/><br/>Thu, 26 Nov 2009 02:42:56 Z2009-11-26T02:42:56Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/ea2765e5-3fe3-4d7c-a45a-5dc24c584d25http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/ea2765e5-3fe3-4d7c-a45a-5dc24c584d25BIGFAINThttp://social.technet.microsoft.com/Profile/en-US/?user=BIGFAINTNAP Agent does not work<p>I start using NAP in our network, but there are something strange in our wireless clients.<br/><br/>We've already use WPA to enhance our wireless network security.<br/><br/>The issue is: some wirless users find their network was limited. I  check NPS log and find they meet &quot;NAP DHCP Non NAP-Capable&quot;. i need to restart napagent service to fix this issue. But if these clients use wired network, there is not the same issue.<br/><br/>What shall I do to fix this issue?  Thanks!</p>Thu, 26 Nov 2009 01:29:51 Z2009-11-26T01:29:51Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a9698005-aac3-42e6-9b5c-c00e9604b045http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a9698005-aac3-42e6-9b5c-c00e9604b045hmolinahttp://social.technet.microsoft.com/Profile/en-US/?user=hmolinaIAS crashs with msvcrt.dll under WIndows Server 2008 32bits<span lang=ES-MODERN>Hi,<br/> <br/> I have two servers with Windows Server 2008 32 bits which fails and becomes unresponsive.<br/> <br/> The event log says:<br/> <br/> &quot;Faulting application svchost.exe_IAS, version 6.0.6001.18000, time stamp 0x47918b89, faulting module msvcrt.dll, version 7.0.6002.18005, time stamp 0x49e0379e, exception code 0xc0000005, fault offset 0x0000a1c3, process id 0x414, application start time 0x01c9e9d991aa7614.&quot;<br/> <br/> The servers are fresh installed with the lastest patches installed and only with Firefox, Snort and WireShark applications installed.<br/> <br/> The roles installed are only NAP role for one of them and the second have NAP, IIS and Certification Authority. The are both Global Catalog and Domain Servers. The system is unable to recover and I have to push the reset button to recover :-s<br/> <br/> I have an third 2008 server 64 bits, with NAP and Routing Service roles installed, and  it do not fails (it is PDC, RID Master, Schema Master etc...., and not GC)<br/> <br/> Thanks in advance for any ideas.<br/> <br/> H.<br/> </span>Fri, 12 Jun 2009 22:23:11 Z2009-11-25T19:15:14Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/27fa744e-19ff-446d-b72b-74715adc7ac6http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/27fa744e-19ff-446d-b72b-74715adc7ac6bman226http://social.technet.microsoft.com/Profile/en-US/?user=bman226Securing Wireless network from unathorized devices.Hi,<br/><br/>I am trying to prevent non-domain / unathorized devices from connecting to our Wireless LAN. We are currently using 802.1x authentication using PEAP with IAS acting as the RADIUS Server. We are a complete Server 2003 shop running windows XP (for now). We had an issue arise that a domain user was able to connect his iPhone and ipod touch to our wireless network by entering his domain credentials. We have remote access policies setup that are supposed to check that 1) the device is part of our wireless security group and 2) that the user belongs to our wireless user group. We are also using a self signed certificate that is pushed out along with the wireless settings via group policy.<br/><br/>How can I prevent devices specifically non-domain wireless devices and Apple mobile devices from connecting to our wireless network? Any help would be greatly appreciated.Tue, 24 Nov 2009 23:12:16 Z2009-11-25T13:57:06Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/b82c4841-f5e5-4d33-bf03-7b5ccf24f436http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/b82c4841-f5e5-4d33-bf03-7b5ccf24f436hinjohttp://social.technet.microsoft.com/Profile/en-US/?user=hinjoNAP Shv failsHi all!<br/> <br/> I have been experiencing a very concerning problem and found very little on this topic as how to resolve it. I have built a custom Shv and Sha for NAP. When I register the Shv in the NPS everything goes well. It shows up in the NPS configuration snap-in and the solution works well. The Sha and Shv can communicate with eachother (through NAP interfaces) and restrict access depending on client conditions.<br/> <br/> But all of a sudden the communication stops (it can take up to severel hours) and in the NPS server logs I see just an error message saying<br/> <br/> &quot;SHV Id : 96119 can not create validator.&quot;<br/> <br/> <div class=c style="text-indent:-2em;margin-left:1em"><span class=m>  &lt;</span> <span class=t>Event</span> <span class=ns> xmlns</span> <span class=m>=&quot;</span> <strong class=ns>http://schemas.microsoft.com/win/2004/08/events/event</strong> <span class=m>&quot;</span> <span class=m>&gt;</span></div> <div> <div class=e> <div class=c style="text-indent:-2em;margin-left:1em"><a class=b href="#" class=b>-</a> <span class=m>&lt;</span> <span class=t>System</span> <span class=m>&gt;</span></div> <div> <div class=e> <div style="text-indent:-2em;margin-left:1em"><span class=b> </span> <span class=m>&lt;</span> <span class=t>Provider</span> <span class=t>Name</span> <span class=m>=&quot;</span> <strong>NPS</strong> <span class=m>&quot;</span> <span class=m> /&gt;</span></div> </div> <div class=e> <div style="text-indent:-2em;margin-left:1em"><span class=b> </span> <span class=m>&lt;</span> <span class=t>EventID</span> <span class=t> Qualifiers</span> <span class=m>=&quot;</span> <strong>49152</strong> <span class=m>&quot;</span> <span class=m>&gt;</span> <span class=tx>10001</span> <span class=m>&lt;/</span> <span class=t>EventID</span> <span class=m>&gt;</span></div> </div> <div class=e> <div style="text-indent:-2em;margin-left:1em"><span class=b> </span> <span class=m>&lt;</span> <span class=t>Level</span> <span class=m>&gt;</span> <span class=tx>2</span> <span class=m>&lt;/</span> <span class=t>Level</span> <span class=m>&gt;</span></div> </div> <div class=e> <div style="text-indent:-2em;margin-left:1em"><span class=b> </span> <span class=m>&lt;</span> <span class=t>Task</span> <span class=m>&gt;</span> <span class=tx>0</span> <span class=m>&lt;/</span> <span class=t>Task</span> <span class=m>&gt;</span></div> </div> <div class=e> <div style="text-indent:-2em;margin-left:1em"><span class=b> </span> <span class=m>&lt;</span> <span class=t>Keywords</span> <span class=m>&gt;</span> <span class=tx>0x80000000000000</span> <span class=m>&lt;/</span> <span class=t>Keywords</span> <span class=m>&gt;</span></div> </div> <div class=e> <div style="text-indent:-2em;margin-left:1em"><span class=b> </span> <span class=m>&lt;</span> <span class=t>TimeCreated</span> <span class=t>SystemTime</span> <span class=m>=&quot;</span> <strong>2009-09-08T10:00:24.000000000Z</strong> <span class=m>&quot;</span> <span class=m> /&gt;</span></div> </div> <div class=e> <div style="text-indent:-2em;margin-left:1em"><span class=b> </span> <span class=m>&lt;</span> <span class=t>EventRecordID</span> <span class=m>&gt;</span> <span class=tx>10414</span> <span class=m>&lt;/</span> <span class=t>EventRecordID</span> <span class=m>&gt;</span></div> </div> <div class=e> <div style="text-indent:-2em;margin-left:1em"><span class=b> </span> <span class=m>&lt;</span> <span class=t>Channel</span> <span class=m>&gt;</span> <span class=tx>System</span> <span class=m>&lt;/</span> <span class=t>Channel</span> <span class=m>&gt;</span></div> </div> <div class=e> <div style="text-indent:-2em;margin-left:1em"><span class=b> </span> <span class=m>&lt;</span> <span class=t>Computer</span> <span class=m>&gt;</span> <span class=tx>CORPAPP02.corp.com</span> <span class=m>&lt;/</span> <span class=t>Computer</span> <span class=m>&gt;</span></div> </div> <div class=e> <div style="text-indent:-2em;margin-left:1em"><span class=b> </span> <span class=m>&lt;</span> <span class=t>Security</span> <span class=m>/&gt;</span></div> </div> <div><span class=b> </span> <span class=m>&lt;/</span> <span class=t>System</span> <span class=m>&gt;</span></div> </div> </div> <div class=e> <div class=c style="text-indent:-2em;margin-left:1em"><a class=b href="#" class=b>-</a> <span class=m>&lt;</span> <span class=t>EventData</span> <span class=m>&gt;</span></div> <div> <div class=e> <div style="text-indent:-2em;margin-left:1em"><span class=b> </span> <span class=m>&lt;</span> <span class=t>Data</span> <span class=m>&gt;</span> <span class=tx>96119</span> <span class=m>&lt;/</span> <span class=t>Data</span> <span class=m>&gt;</span></div> </div> <div class=e> <div style="text-indent:-2em;margin-left:1em"><span class=b> </span> <span class=m>&lt;</span> <span class=t>Binary</span> <span class=m>&gt;</span> <span class=tx>1A400080</span> <span class=m>&lt;/</span> <span class=t>Binary</span> <span class=m>&gt;</span></div> </div> <div><span class=m>&lt;/</span> <span class=t>EventData</span> <span class=m>&gt;</span></div> </div> </div> <div><span class=m>&lt;/</span> <span class=t>Event</span> <span class=m>&gt;</span></div> </div> <br/> and the shv is out the game. It doesn't do anything, it still shows in the NPS configuration snap-in but doesn't communicate with the Sha anymore. What helps it to unregister the dll and register it again or to restart the NPS-service. Obviously something that it out of the question as a permanent solution<br/> <br/> <br/> The NPS server is running on a x64 Windows Server 2008 R2 Enterprise (no Service Pack installed) and the custom Shv is practically the NAP SDK sample with small modifications.<br/> <br/> <br/> At first I thought that this problem was only related to my Shv component but then I saw in another post that someone running the FCS Shv had the same problem, which lead me to believe that it just might had something to do with the NPS server itself!<br/> <br/> Here's a link to that posting <br/> <br/> http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/23ec6d43-4de8-4e25-88a2-93750724480e<br/> <br/> Since I haven't found much at all on this topic, whether people have gotten it to work or not, it would be great if you could enlighten me as to you did to make it work and on what platform so that I can replicate it or if you have had the problem and solved it!<br/> <br/> Anyone with any ideas what I could try or point me in any direction will do though?!<br/> <br/> Thanks a lot for your help!<br/> <br/>Wed, 09 Sep 2009 09:22:54 Z2009-11-25T13:56:02Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/ca05e8a3-6971-4e64-8135-0a39a38b6bb4http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/ca05e8a3-6971-4e64-8135-0a39a38b6bb4Wolfgang Neudorferhttp://social.technet.microsoft.com/Profile/en-US/?user=Wolfgang%20NeudorferDeploying NAP 802.1x Enforcement w/ 3com 4500 or 5500Hi!<br><br>I try to get the 802.1x Step-by-Step Guide to work in my Test Lab. I followed the instructions and everythings seems to be OK as my switch (3Com 4500) gets RADIUS Accept-Access from NAP Server (the logs look good too). Unfortunaltey the switch sends an EAP-Failure message to the client and the port keeps down.<br><br>I know that this isn't a support forum for 3Com but I would really appreciate any help.<br><br>Here is my configuration (the client uses port 1/0/5):<br><br>====================================<br><font size=2><span style="font-family:Courier">4500&gt;display current-configuration</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier"> private-group-id mode standard</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier"> local-server nas-ip 127.0.0.1 key 3com</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier"> domain default enable ams</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier"> igmp-snooping enable</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier"> dot1x</span><br style="font-family:Courier"><span style="font-family:Courier"> dot1x authentication-method eap</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier"> undo password-control aging enable</span><br style="font-family:Courier"><span style="font-family:Courier"> undo password-control length enable</span><br style="font-family:Courier"><span style="font-family:Courier"> password-control login-attempt 3 exceed lock-time 360</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier">radius scheme system</span><br style="font-family:Courier"><span style="font-family:Courier">radius scheme radius1</span><br style="font-family:Courier"><span style="font-family:Courier"> primary authentication 192.168.0.2<br> accounting optional<br style="font-family:Courier"></span><span style="font-family:Courier"> key authentication secret</span><br style="font-family:Courier"><span style="font-family:Courier"> timer response-timeout 5</span><br style="font-family:Courier"><span style="font-family:Courier"> retry 5</span><br style="font-family:Courier"><span style="font-family:Courier"> user-name-format without-domain</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier">domain ams</span><br style="font-family:Courier"><span style="font-family:Courier"> scheme radius-scheme radius1</span><br style="font-family:Courier"><span style="font-family:Courier">domain system</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier">local-user admin</span><br style="font-family:Courier"><span style="font-family:Courier"> service-type ssh telnet terminal</span><br style="font-family:Courier"><span style="font-family:Courier"> level 3</span><br style="font-family:Courier"><span style="font-family:Courier">local-user manager</span><br style="font-family:Courier"><span style="font-family:Courier"> service-type ssh telnet terminal</span><br style="font-family:Courier"><span style="font-family:Courier"> level 2</span><br style="font-family:Courier"><span style="font-family:Courier">local-user monitor</span><br style="font-family:Courier"><span style="font-family:Courier"> service-type ssh telnet terminal</span><br style="font-family:Courier"><span style="font-family:Courier"> level 1</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier">acl number 4999</span><br style="font-family:Courier"><span style="font-family:Courier"> rule 0 deny dest 0000-0000-0000 ffff-ffff-ffff</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier">vlan 1</span><br style="font-family:Courier"><span style="font-family:Courier"> description DEFAULT_VLAN</span><br style="font-family:Courier"><span style="font-family:Courier"> igmp-snooping enable</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier">vlan 2</span><br style="font-family:Courier"><span style="font-family:Courier"> description NONCOMPLIANT_VLAN</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier">vlan 3</span><br style="font-family:Courier"><span style="font-family:Courier"> description COMPLIANT_VLAN</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier">interface Vlan-interface1</span><br style="font-family:Courier"><span style="font-family:Courier"> ip address 192.168.0.3 255.255.255.0</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier">interface Aux1/0/0</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier">interface Ethernet1/0/1</span><br style="font-family:Courier"><span style="font-family:Courier"> stp edged-port enable</span><br style="font-family:Courier"><span style="font-family:Courier"> broadcast-suppression PPS 3000</span><br style="font-family:Courier"><span style="font-family:Courier"> priority trust</span><br style="font-family:Courier"><span style="font-family:Courier"> packet-filter inbound link-group 4999 rule 0</span><br style="font-family:Courier"><span style="font-family:Courier"> dot1x port-method portbased</span><br style="font-family:Courier"><br style="font-family:Courier"><span style="font-family:Courier">[...]</span><br style="font-family:Courier"><br style="font-family:Courier"><span style="font-family:Courier">interface Ethernet1/0/5</span><br style="font-family:Courier"><span style="font-family:Courier"> stp edged-port enable</span><br style="font-family:Courier"><span style="font-family:Courier"> broadcast-suppression PPS 3000</span><br style="font-family:Courier"><span style="font-family:Courier"> priority trust</span><br style="font-family:Courier"><span style="font-family:Courier"> packet-filter inbound link-group 4999 rule 0</span><br style="font-family:Courier"><span style="font-family:Courier"> dot1x port-method portbased</span><br style="font-family:Courier"><span style="font-family:Courier"> dot1x</span><br style="font-family:Courier"><br style="font-family:Courier"><span style="font-family:Courier">[...]</span><br style="font-family:Courier"><br style="font-family:Courier"><span style="font-family:Courier">interface GigabitEthernet1/0/25</span><br style="font-family:Courier"><span style="font-family:Courier"> dot1x port-method portbased</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier">interface GigabitEthernet1/0/26</span><br style="font-family:Courier"><span style="font-family:Courier"> dot1x port-method portbased</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier">interface GigabitEthernet1/0/27</span><br style="font-family:Courier"><span style="font-family:Courier"> shutdown</span><br style="font-family:Courier"><span style="font-family:Courier"> dot1x port-method portbased</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier">interface GigabitEthernet1/0/28</span><br style="font-family:Courier"><span style="font-family:Courier"> shutdown</span><br style="font-family:Courier"><span style="font-family:Courier"> dot1x port-method portbased</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier"> sysname 4500</span><br style="font-family:Courier"><span style="font-family:Courier"> undo xrn-fabric authentication-mode</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier">interface NULL0</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier"> snmp-agent</span><br style="font-family:Courier"><span style="font-family:Courier"> snmp-agent local-engineid 8000002B001AC12D89C06877</span><br style="font-family:Courier"><span style="font-family:Courier"> snmp-agent community read public</span><br style="font-family:Courier"><span style="font-family:Courier"> snmp-agent community write private</span><br style="font-family:Courier"><span style="font-family:Courier"> snmp-agent sys-info version all</span><br style="font-family:Courier"><span style="font-family:Courier">#</span><br style="font-family:Courier"><span style="font-family:Courier">user-interface aux 0 7</span><br style="font-family:Courier"><span style="font-family:Courier"> authentication-mode scheme</span><br style="font-family:Courier"><span style="font-family:Courier">user-interface vty 0 4</span><br style="font-family:Courier"><span style="font-family:Courier"> authentication-mode scheme</span></font><br>====================================<br><br><br>Thanks in advance.<br><br>Wolfgang<br>Mon, 26 Nov 2007 21:03:49 Z2009-11-25T08:55:43Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/cd4f58e7-1ebf-496f-94b6-d43606a314e3http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/cd4f58e7-1ebf-496f-94b6-d43606a314e3helena238http://social.technet.microsoft.com/Profile/en-US/?user=helena238Auto-remediation problem with NAP 802.1x Wired and Windows Firewall<span class=value>I have a NAP lab consisting of the following elements:<br/> 1 Windows Server 2003 DC (VM)<br/> 1 Windows Server 2008 SP1 NPS Server (VM)<br/> 1 Cisco 802.1x-capable switch<br/> 1 Windows XP SP3 client<br/> GPOs containing the appropriate settings to get NAP 802.1x PEAP working with XP SP3<br/> 1 user account that is an administrator on the client machine<br/> <br/> The lab works fine.  When the client is compliant, it is placed in a Compliant VLAN, and when it is not compliant, it is placed in a Non-Complaint VLAN.<br/> <br/> The issue: If you turn off Windows Firewall on the client, but it is required by NPS, and auto-remediation is enabled in NPS, the Firewall turns on and off about every 5 seconds.  As a result, the client is put first in one VLAN and then the other until you start to see DHCP deny messages in the event log.  It appears that auto-remediation is fighting with the local setting.  The only way to make it stop bouncing is to open Windows Firewall from the Control Panel at one of the moments when the Windows Firewall is disabled, and enable it.<br/> <br/> The question: Why is this happening, and is it a bug, or is there a workaround?</span>Wed, 18 Nov 2009 23:42:16 Z2009-11-25T00:53:28Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/41e86cce-5882-48ef-a817-3c0c972ed1e9http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/41e86cce-5882-48ef-a817-3c0c972ed1e9ibjean325http://social.technet.microsoft.com/Profile/en-US/?user=ibjean325Unauthorized Apple iPODs and MAC notebooks connect to my wireless networkI need to prevent Apple iPODs and Mc Notebooks from connetiong to my wireless network.  Currently I have Server 2003 IAS Sever and Enterprise Certificate Services installed and configured on my network.  Clients authenticate using domain account username and psasswords.  Machine Certificates are installed on every domain client notebook using a GPO. These policies worked great for XP Pro and Vista Business clients.  I have noticed however that Apple iTouch devices and Apple notebooks can connect to my wireless network if the owner has a valid domain username and password.   How are these client machine negotianting a certificate?<br/>I need to lock this down. I am sure this must be a common issue....<br/>My Cisco Access Points are 1100 and 1200 APs.  They are clients of the IAS server.<br/>Thanks<br/>ibjean325Wed, 21 Oct 2009 19:36:23 Z2009-11-24T23:33:41Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/c54b15d6-fed0-45f4-be11-f09fde1fff3chttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/c54b15d6-fed0-45f4-be11-f09fde1fff3cMigration To Vistahttp://social.technet.microsoft.com/Profile/en-US/?user=Migration%20To%20VistaHow can we change or reset the submitted IPsec Gpo in an Active directory <br/>1. Decided to have an IPsec on the Active directory to govern the traffic in a 2008 domain members and environment.<br/>2. Edited a policy script, lists of Filter action,FilterNames, address filters.. etc..and rules.<br/>3. Loaded The IPsec Policy script by the command netshel -F ScriptFileName.txt<br/>4. Created a new GroupPolicyObject in the Domain and linked it and in the asigned it and then run the gPupdate /force and Saw it Fuynction well in all the domain member nodes.<br/>5. After 24 hours of observation decided to add a couple of more lists,, to allow for the trafic to the File and priner servers and also the IE ProxiServer.<br/>6. Deasign the Submitted policy and run gpupdate /force and then repeated the steps 1 and then reasigned the policy. Here I noticed that there are double entries in the Property View of the Policy.<br/>7. This time deasigned and then deleted the policy and run the force gpupdate... Working in the DC node.<br/>8. Verfied that there are No inhibition and that NO IPsec was active on some of the domain member nodes.<br/>9. Did the steps 1 and already here the response to the NetShel command states that there are already entries for the filter Lists and rules..<br/>So My question is what is the correct procedure to wipe out an IP sec policy and resubmit it in an elegant and problem free way.<br/><br/>Looking forward to your help<br/>Regards<br/><hr class="sig">BlueOceanSun, 22 Nov 2009 21:22:35 Z2009-11-25T05:55:31Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/012008b8-0b95-40a1-a267-31edbf790aebhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/012008b8-0b95-40a1-a267-31edbf790aeballfelfoulhttp://social.technet.microsoft.com/Profile/en-US/?user=allfelfoulGPO for configuring 802.1x wired clients with XP SP3Hi,<br/>We use actually cisco switchs with ACS like radius server mapped on windows 2003 R2 Active directory server. We use user authentication PEAP-CHAP-V2.<br/>I extend the schema as described in microsoft documentation <a href="http://technet.microsoft.com/fr-fr/library/bb967647.aspx"><span style="color:#0033cc">http://technet.microsoft.com/fr-fr/library/bb967647.aspx</span></a> to use the computer authentication first.<br/>Now, when i try to modify an GPO, Computer Configuration | Windows Settings | Security Settings | Wired Network (IEEE 802.3) Policies node in the Group Policy Management Editor, this node isn't exist.<br/><br/>Thank you for your helpWed, 11 Nov 2009 09:37:11 Z2009-11-23T10:43:29Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/188cd4fd-67ff-469f-b968-b6f1c186cf1fhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/188cd4fd-67ff-469f-b968-b6f1c186cf1fT.Z.http://social.technet.microsoft.com/Profile/en-US/?user=T.Z.NAP XP SP3 problems when SQL LoggingHi,<br/><br/>I have used the following DHCP NAP step-by-step guide to configure my POC environment:<br/><a title="http://www.microsoft.com/downloads/details.aspx?FamilyID=ac38e5bb-18ce-40cb-8e59-188f7a198897&amp;displaylang=en" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=ac38e5bb-18ce-40cb-8e59-188f7a198897&amp;displaylang=en"><span style="color:#0033cc;font-size:x-small">http://www.microsoft.com/downloads/details.aspx?FamilyID=ac38e5bb-18ce-40cb-8e59-188f7a198897&amp;displaylang=en</span></a><br/><br/>First thing I noticed is that the XP client reports incorrect compliant and non-compliant states.<br/><br/>So I found some other threads here: <a href="http://social.technet.microsoft.com/Forums/en-US/itproxpsp/thread/f7abe0f2-0186-428c-9252-9d22b03dd496">http://social.technet.microsoft.com/Forums/en-US/itproxpsp/thread/f7abe0f2-0186-428c-9252-9d22b03dd496</a><br/>And I tried this setting on the client:<br/><span style="font-size:small"><span style="color:#000000;font-size:12px">[HKLM\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\DhcpGlobalForceBroadcastFlag\0] &quot;0&quot;=dword:00000001<br/></span></span><br/>But the problem still persists....I can disable the Firewall, Windows Updates, have no AV product installed...and sometimes the NAP client reports non-compliance, then a few minutes later it says everything is compliant.<br/><br/>THEN I found this little anomaly:<br/>If I do not log to SQL; NAP client seem to report work correctly.<br/>BUT the moment I configure NPS logging to SQL, the NAP client does not work - I can have everything disable on the client (firewall, av, etc) and NAPSTAT displays a very healthy system.<br/><br/>For my test environment, I am running a single VM with Windows 2008 AD, NPS, DHCP, SQL 2005 SP2; and another single VM with XP SP3.<br/><br/>Regards,<br/>Tom Thu, 20 Aug 2009 11:17:56 Z2009-11-21T06:29:49Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/c6a3d6de-9b82-4b3a-a578-f9b79cbf7d36http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/c6a3d6de-9b82-4b3a-a578-f9b79cbf7d36Kumar Rakeshhttp://social.technet.microsoft.com/Profile/en-US/?user=Kumar%20RakeshNAp Reporting issueDear All,<br/><br/>Thanks for your kind support.<br/><br/>i have some question -<br/>1. how i come to know which systems got the certificate<br/>2. how i will know that NAP agent services are not started on which PC<br/>3. how i will know that which PC is not reporting to NAP server<br/>4. how many PC are noncomplaint or complaint<br/>5. how i will know that which not getting the certificate or NAP policy not applied<br/>6. why CA is issuing more that one certificate for the same client <br/>7. how many and which PC have the Full Network Acess or limite or restricted<br/> <hr class=sig> Rakesh KumarTue, 17 Nov 2009 07:37:16 Z2009-11-20T02:34:50Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/984e805b-92ae-48f7-ab97-60ad619785f9http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/984e805b-92ae-48f7-ab97-60ad619785f9Jacky.Wuhttp://social.technet.microsoft.com/Profile/en-US/?user=Jacky.WuAdd group issue<p>During adding the group to NPS, there is error message popping up, showing that &quot;Windows cannot process the object witht the name &quot;ACS VLAN 117&quot;because the following error: The specified domain either does not exist or could not be contacted&quot;<br/><br/>Could some one tell me why? How to solve the issue?</p>Thu, 12 Nov 2009 05:30:33 Z2009-11-19T06:30:45Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/f670df31-83e4-4269-80f2-2b60322a97d4http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/f670df31-83e4-4269-80f2-2b60322a97d4gunnarwbhttp://social.technet.microsoft.com/Profile/en-US/?user=gunnarwbNAP - 2 Minute Logon DelayI need to know how to get my NAP deployment to authenticate faster.  Often when people log in in the morning if they hit CNTL-ALT-DELETE and attempt to log in the moment the computer comes up they get &quot;no domain controller available&quot; message.  Right now they are considering removing NAP because of this as it just caused us a heck of a Monday morning problem.  Eventually it will authenticate but it takes to long for the way people work.  I'm doing dual authentication so I'm considering removing the MAC-based as it isn't needed as much.  Also I use HP Switches and one of the settings is &quot;aaa port-access authenticator &lt;PORT&gt; quiet-period 30&quot; I know this setting has the EAP authentication delay 30 seconds between retries (which is most likely causing the delay).  I just want to know what I should do to speed up the authentication process.<br/><br/>-GunnarMon, 26 Oct 2009 12:59:30 Z2009-11-18T15:15:47Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/79053f1b-d3c4-494b-9fb8-ed87d3984a2ehttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/79053f1b-d3c4-494b-9fb8-ed87d3984a2eBillWCHhttp://social.technet.microsoft.com/Profile/en-US/?user=BillWCHNPS Server Install Fails Win08 x64 Only DCI cannot get NPS to install on our ONLY server - a Windows 2008 64 bit DC.   There is no precise reason given for failure to install, it just tries to do it, fails, and says the server must be restarted.   In the Event Log is refers to Event 1617, which is no help at all.   There's absolutely nothing in the install logs that gives any additional detail - in fact - that log is full of entries with a January 2008 date - and the server itself was installed this past August (2009)!<br/> <br/> I've seen some posts from MSFT about removing the DC role, etc. but obviously that's just not possible here as it is the ONLY DC and is in live production.<br/> <br/>Fri, 23 Oct 2009 22:12:13 Z2009-11-17T21:41:37Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/997c5441-b301-4cde-9e9b-a04cf419e686http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/997c5441-b301-4cde-9e9b-a04cf419e686altbjhttp://social.technet.microsoft.com/Profile/en-US/?user=altbjCannot access certain websitesI can use internet just fine, except for a select few websites. My browser tries to load them up like forever and eventually gives up.<br/> <br/> among the websites unavailable to me are bioware.com, ign.com, acclaim.com, plaync.com, avg.com and others I can't think of right now. Note that in the past, I could and did access them.<br/> <br/> I've googled up (thank god I can at least access google!) various solutions and tried them all but to no avail- Dr. TCP, the Hosts file under system32/drivers/etc, playing around with security and firewall settings, changing browsers, none of these have worked.<br/> <br/> pinging any of the websites I can't acccess yields a &quot;Destination host unreachable&quot; message.<br/> <br/> Oh yeah, I also use winXP, DSL connection, provided by WLAN, which is in Germany.<br/> <br/> Any help would be really appreciated- especially since I don't seem to be the only one who's getting this problem.Sat, 14 Nov 2009 17:36:32 Z2009-11-17T17:57:57Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/5ad621a2-41c6-494f-8057-96180c329d37http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/5ad621a2-41c6-494f-8057-96180c329d37Mr Jstinhttp://social.technet.microsoft.com/Profile/en-US/?user=Mr%20JstinNAP & VPN Errors<p>All - I've been racking my brain for a day or two on this. I'm having an issue with W7 &amp; VPN clients when NAP is enabled on Wink 2008 R2 Enterprise box.<br/><br/>With EAP enabled my W7 client keeps getting an Error 741: The Local Computer does not support this encryption type. Here's how my W7 machine looks...<br/><br/>C:\&gt;netsh nap client show grouppolicy</p> <p>NAP client configuration (group policy):<br/>----------------------------------------------------</p> <p>NAP client configuration:<br/>----------------------------------------------------</p> <p>Cryptographic service provider (CSP) = Microsoft RSA SChannel Cryptographic Provider, keylength = 2048</p> <p>Hash algorithm = sha1RSA (1.3.14.3.2.29)</p> <p>Enforcement clients:<br/>----------------------------------------------------<br/>Name            = DHCP Quarantine Enforcement Client<br/>ID              = 79617<br/>Admin           = Disabled</p> <p>Name            = IPsec Relying Party<br/>ID              = 79619<br/>Admin           = Disabled</p> <p>Name            = RD Gateway Quarantine Enforcement Client<br/>ID              = 79621<br/>Admin           = Disabled</p> <p>Name            = EAP Quarantine Enforcement Client<br/>ID              = 79623<br/>Admin           = Enabled</p> <p>Client tracing:<br/>----------------------------------------------------<br/>State = Disabled<br/>Level = Disabled</p> <p>Ok.<br/><br/>Client state:<br/>----------------------------------------------------<br/>Name                   = Network Access Protection Client<br/>Description            = Microsoft Network Access Protection Client<br/>Protocol version       = 1.0<br/>Status                 = Enabled<br/>Restriction state      = Not restricted<br/>Troubleshooting URL    =<br/>Restriction start time =<br/>Extended state         =<br/>GroupPolicy            = Configured</p> <p>Enforcement client state:<br/>----------------------------------------------------<br/>Id                     = 79617<br/>Name                   = DHCP Quarantine Enforcement Client<br/>Description            = Provides DHCP based enforcement for NAP<br/>Version                = 1.0<br/>Vendor name            = Microsoft Corporation<br/>Registration date      =<br/>Initialized            = No</p> <p>Id                     = 79619<br/>Name                   = IPsec Relying Party<br/>Description            = Provides IPsec based enforcement for Network Access Protection<br/>Version                = 1.0<br/>Vendor name            = Microsoft Corporation<br/>Registration date      =<br/>Initialized            = No</p> <p>Id                     = 79621<br/>Name                   = RD Gateway Quarantine Enforcement Client<br/>Description            = Provides RD Gateway enforcement for NAP<br/>Version                = 1.0<br/>Vendor name            = Microsoft Corporation<br/>Registration date      =<br/>Initialized            = No</p> <p>Id                     = 79623<br/>Name                   = EAP Quarantine Enforcement Client<br/>Description            = Provides Network Access Protection enforcement for EAP authenticated network connections, such as those used with 802.1X and<br/>PN technologies.<br/>Version                = 1.0<br/>Vendor name            = Microsoft Corporation<br/>Registration date      =<br/>Initialized            = Yes</p> <p>System health agent (SHA) state:<br/>----------------------------------------------------<br/>Id                     = 79744<br/>Name                   = Windows Security Health Agent</p> <p>Description            = The Windows Security Health Agent monitors security settings on your computer.</p> <p>Version                = 1.0</p> <p>Vendor name            = Microsoft Corporation</p> <p>Registration date      =<br/>Initialized            = Yes<br/>Failure category       = None<br/>Remediation state      = Success<br/>Remediation percentage = 0<br/>Fixup Message          = (3237937214) - The Windows Security Health Agent has finished updating the security state of this computer.</p> <p>Compliance results     =<br/>Remediation results    =</p> <p>Ok.<br/><br/><br/>If I switch my clients back to MS CHAP v2, I can login fine but nothing happens as far as remediation goes. I really want to see this work...thanks!</p>Tue, 10 Nov 2009 19:09:04 Z2009-11-17T09:24:26Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/38228538-2a0b-4506-9f8d-9885bb685cbdhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/38228538-2a0b-4506-9f8d-9885bb685cbdjc23http://social.technet.microsoft.com/Profile/en-US/?user=jc23WINDOWS 7 Ultimate NAP Client missing the Remote Access Enforcement Client??I'm testing the windows 7 NAP client and I noticed that way our users connect, the remote access enforcement client , is missing. It was also known as enforcement id 79618.  Has Microsoft removed this, or have they rolled the remote access enforcement client functionality into one of the four other enforcement clients?<br/><br/>The only clients listed as available are <br/>DHCP Quarantine        ID:79617<br/>IPSec Relaying           ID:79619<br/>RD Relay Quarantine  ID:79621<br/>EAP Quarantine         ID: 79623<br/><br/>Thanks in advance<br/>Tue, 10 Nov 2009 16:26:44 Z2009-11-16T08:43:37Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/5d75be97-9208-4358-bf60-de060e1fcab8http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/5d75be97-9208-4358-bf60-de060e1fcab8J.D Singhhttp://social.technet.microsoft.com/Profile/en-US/?user=J.D%20SinghNAP DHCP ProblemHi Guys,<br/> <br/> I am configuring DHCP NAP Using Virtual Machines but could not configure. I used that step by step guide but at the end when I turned off the firewall it is not turning on automatically. Please someone help me.Fri, 13 Nov 2009 15:29:10 Z2009-11-16T02:55:16Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/450be98c-fdb9-4ffb-80a7-f45cdc180a59http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/450be98c-fdb9-4ffb-80a7-f45cdc180a59nd_sandhuhttp://social.technet.microsoft.com/Profile/en-US/?user=nd_sandhuwindows security health chec<span style="font-family:Arial;font-size:13px;white-space:pre">by default, what does <strong>windows security health chec</strong>k on a windows vista client?</span>Fri, 13 Nov 2009 05:07:53 Z2009-11-16T04:08:01Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a7c9d0ec-950a-4b96-ab7e-8f9480e4b087http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a7c9d0ec-950a-4b96-ab7e-8f9480e4b087nd_sandhuhttp://social.technet.microsoft.com/Profile/en-US/?user=nd_sandhuNAP related<span style="font-family:Arial;font-size:13px;white-space:pre">What other enforcement mechanisms are available with <strong>Network Access Protection</strong>?</span>Fri, 13 Nov 2009 05:01:52 Z2009-11-15T19:40:35Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/88e4b7a5-ec3c-48f6-9737-c6d3e424f9behttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/88e4b7a5-ec3c-48f6-9737-c6d3e424f9beSunnyYeunghttp://social.technet.microsoft.com/Profile/en-US/?user=SunnyYeungRemote Access Policy(only allow Lan connection)How I setup a Remote Access Policy to allow only LAN connection?<br/>I have a small business server 2003.<br/>I am able to &quot;Remote Desktop Connection&quot; to the server from WAN.<br/><br/>Right now, I don't want any connection from WAN being able to connection to the server.<br/>Only LAN can remote desktop to server. How can I setup the policy without using ISA?<br/><br/>Thank youWed, 11 Nov 2009 16:37:12 Z2009-11-13T17:12:23Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/337d0ce8-1f0a-4b25-92fc-5c7384e5c378http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/337d0ce8-1f0a-4b25-92fc-5c7384e5c378Dietmar H.http://social.technet.microsoft.com/Profile/en-US/?user=Dietmar%20H.completely reinstall NPS with original settings?<p>Hi! I am very new on this NPS/NAP topic. I deleted the standard settings by mistake on my Windows Server 2008 R2. If I deinstall the NPS role and install the rule again there are the latest settings. Is it possible to reinstall NPS with 'factory settings'? There are no SHVs after reinstalling. <br/><br/>Is the NPS role demaged until I have to reinstall the whole server or is there a way to 'reset' NPS to first install state?<br/><br/>Every tip is very appreciated! Dietmar</p><hr class="sig">DietmarWed, 11 Nov 2009 09:59:00 Z2009-11-16T09:38:22Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/637eeb1d-abfe-45e0-8b0b-473c44a59e06http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/637eeb1d-abfe-45e0-8b0b-473c44a59e06gunnarwbhttp://social.technet.microsoft.com/Profile/en-US/?user=gunnarwbDefault Firewall Rules NPS ServerIs there a way to get back my default windows firewall rules that I got after installing NPS?  I had to import a policy from my DC because I just made one of my NPS servers a DC.  Unfortunately I lost my NPS settings, I can re-import the old settings but I need both the NPS and the DC firewall rules.  If there is a way just to send a command and have NPS recreate these rules that woudl be idea.<br/><br/>Gunnar<br/><br/>Mon, 09 Nov 2009 19:43:08 Z2009-11-10T04:31:34Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/98708036-661b-4a4a-adb9-dafbcd323917http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/98708036-661b-4a4a-adb9-dafbcd323917Rama Mohanhttp://social.technet.microsoft.com/Profile/en-US/?user=Rama%20MohanNAP DHCP Non NAP-CapableWe are deploying NAP with Windows 2008 R2. Both NPS and DHCP roles enabled on one machine. While the NAP enforcement is enabled on one machine, the NAP non-capable Windows XP machine gets full access to network. Once we do a IPconfig /releae and /renew it gets restricted IP address. Again if we do a IPconfig /releae and /renew it gets full access. It is happening alternatively. The Window 7 machines are working as desired. first time and  consecutive  /release and /renew also they are getting restricted IP address.  We have already installed hotfix KB953761. Any fix for Windows XP SP3 machines? Help needed from the experts...<br/><br/>Best Regards,<br/><br/>Rama Mohan<br/>H/P: 9987001939Sat, 07 Nov 2009 10:21:02 Z2009-11-10T01:35:46Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a987cf99-7f7c-4bbc-b8fd-e262a61db1f9http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a987cf99-7f7c-4bbc-b8fd-e262a61db1f9TuckerDavishttp://social.technet.microsoft.com/Profile/en-US/?user=TuckerDavisAdding NAP Role - Error I am currently running a 2003 R2 native domain consisting of (1) 2003 R2 DC, <br>(1) 2003 DC and (2) 2008 Server DC's.<br><br>My 2003 DC is an IAS server.<br><br>I am trying to add the NAP role to my 2008 DC's but on both I recieve the <br>following error:<br><br>Network Policy and Access Services:  Installation Failed<br><br>Attempt to install Server failed with error code 0x80070643.  Fatal error <br>during installation.<br><br>Can any one help me out with way I can not add this role?  IAS is the only <br>service that is keeping me from from removing the 2003 servers and going all <br>2008 Native.<br><br>(I can not upgrade my 2003 Servers to 2008).<br><br>Thanks - TDMon, 06 Oct 2008 21:11:29 Z2009-11-06T22:35:32Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/7fe61f69-3543-4d1f-b00f-8557e1f11801http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/7fe61f69-3543-4d1f-b00f-8557e1f11801Bhavtoshhttp://social.technet.microsoft.com/Profile/en-US/?user=BhavtoshXP client cant access Win2003 Server in same workgroup<span style="font-family:verdana, geneva, lucida, 'lucida grande', arial, helvetica, sans-serif;font-size:13px">i have 2 machines with XP and win2003 and both have manual IP in same subnet; i want to access window 2003 via IE and also shared folders and vice versa?</span> <div><span style="font-family:verdana, geneva, lucida, 'lucida grande', arial, helvetica, sans-serif;font-size:small"><span style="font-size:13px"><br/></span></span></div> <div><span style="font-family:verdana, geneva, lucida, 'lucida grande', arial, helvetica, sans-serif;font-size:13px">both cant ping each other; i tried editing the host file in XP to access win2003 but still no luck; my firewall is on in both and if i need to check something here then kindly tell the sections to check.<br/><br/>they are in same workgroup but still no luck;<br/><br/>pls help</span></div><hr class="sig">Good day ,BhavtoshWed, 16 Sep 2009 16:37:19 Z2009-11-06T08:54:16Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/93b6a685-ee7c-4ff6-94c5-709e94ec6a51http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/93b6a685-ee7c-4ff6-94c5-709e94ec6a51Sandowhttp://social.technet.microsoft.com/Profile/en-US/?user=SandowNPS allows Macintosh Authentication even if not in Windows Group.<p class=MsoNormal style="margin:0in 0in 10pt"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt">We are in the process of implementing PEAP with AD authentication in our environment.  We are running Server 2008 NPS and Cisco WLC's at our locations.  We recently discovered that the MacBook can authenticate with a username and password that are not in our wireless group.  The Windows PC's, on the domain or not can not authenticate if they are not in the groups.  If they are in the groups they are fine.  What would be causing the Mac's to bypass the groups for authentication through NPS?</span></p>Mon, 02 Nov 2009 13:58:13 Z2009-11-06T00:46:20Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/3f833538-e3b2-4e87-8324-013c1bdb5523http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/3f833538-e3b2-4e87-8324-013c1bdb5523aurimas_http://social.technet.microsoft.com/Profile/en-US/?user=aurimas_802.1x alternativesHi, <br/><br/>we are using 802.1x on our environment, but it works terrible with windows, is any alternative of this, like authentication in order to get IP, with certificates or something ? <br/><br/>thnaks<br/>aurimasThu, 05 Nov 2009 14:57:20 Z2009-11-10T06:45:11Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/1b0a108e-7769-402d-aa24-38b4f0f38908http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/1b0a108e-7769-402d-aa24-38b4f0f38908carmeisterhttp://social.technet.microsoft.com/Profile/en-US/?user=carmeisterNAP and Windows 7 Client &lt;!-- /* Font Definitions */ @font-face {font-family:&quot;Cambria Math&quot;; panose-1:2 4 5 3 5 4 6 3 2 4; mso-font-charset:1; mso-generic-font-family:roman; mso-font-format:other; mso-font-pitch:variable; mso-font-signature:0 0 0 0 0 0;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4; mso-font-charset:0; mso-generic-font-family:swiss; mso-font-pitch:variable; mso-font-signature:-1610611985 1073750139 0 0 159 0;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {mso-style-unhide:no; mso-style-qformat:yes; mso-style-parent:&quot;&quot;; margin:0in; margin-bottom:.0001pt; mso-pagination:widow-orphan; font-size:11.0pt; font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;; mso-fareast-font-family:Calibri; mso-fareast-theme-font:minor-latin; mso-bidi-font-family:&quot;Times New Roman&quot;;} .MsoChpDefault {mso-style-type:export-only; mso-default-props:yes; font-size:10.0pt; mso-ansi-font-size:10.0pt; mso-bidi-font-size:10.0pt;} @page Section1 {size:8.5in 11.0in; margin:1.0in 1.0in 1.0in 1.0in; mso-header-margin:.5in; mso-footer-margin:.5in; mso-paper-source:0;} div.Section1 {page:Section1;} --&gt; <p class=MsoNormal><span style="font-size:10pt">I have clients running MS XP and Vista and with NAP with results as I expect.</span></p> <p class=MsoNormal><span style="font-size:10pt">When I try a Windows 7 client I have issues.</span></p> <p class=MsoNormal><span style="font-size:10pt">I issue the <strong>napstat</strong> command and it says the SHA is not present.</span></p> <p class=MsoNormal><span style="font-size:10pt">When I issue the <strong><span style="color:black">netsh NAP client show state </span> </strong> <span style="color:black">command under ID = 79744 SHA</span> </span></p> <p class=MsoNormal><span style="font-size:10pt;color:black">Is says initialized = no </span></p> <p class=MsoNormal><span style="font-size:10pt;color:black">I am using EAP quarantine enforcement client and it is initialized.</span></p> <p class=MsoNormal><span style="font-size:10pt;color:black"> </span></p> <p class=MsoNormal><span style="font-size:10pt;color:black">I am totally new to NAP and Microsoft for that matter so I need much remediation.</span></p> <p class=MsoNormal><span style="font-size:10pt;color:black">Are there some specifics for Windows 7?</span></p> <p class=MsoNormal><span style="font-size:10pt;color:black"> </span></p>Tue, 03 Nov 2009 12:48:56 Z2009-11-04T23:43:28Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a7c1f643-6e18-492c-834e-59867c8b2e08http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a7c1f643-6e18-492c-834e-59867c8b2e08Dagmar Heideckerhttp://social.technet.microsoft.com/Profile/en-US/?user=Dagmar%20HeideckerServer 2003 as a NAP client?Hi,<br/><br/>before Windows Server 2008 was RTM I read in several articles that a NAP client for Server 2003 will be available via Windows update. However, I cannot find any. Is there a chance to configure a Windows Server 2003 as a NAP client? What about Server 2003 R2?<br/><br/>Thank you for your help!<br/><br/>DagmarWed, 04 Nov 2009 20:20:14 Z2009-11-04T22:04:19Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/5376ebfb-d8ea-498d-8862-c418dbb843dchttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/5376ebfb-d8ea-498d-8862-c418dbb843dchuihuiyaphttp://social.technet.microsoft.com/Profile/en-US/?user=huihuiyapNetwok Access ProblemHi, all<br/><br/>my domain has been sharing same folder but I can access at my network palce, before that I and my company user can be access. Now I use IP to access from the network?<br/><br/>How to fix this problem.<br/><br/>I am using win 2000 server the PC is second DC.Wed, 04 Nov 2009 03:41:53 Z2009-11-11T02:09:11Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/f7b06057-1348-4c92-ba74-034ae3f16a61http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/f7b06057-1348-4c92-ba74-034ae3f16a61Danpeihttp://social.technet.microsoft.com/Profile/en-US/?user=DanpeiPrinter excemption using 802.1X enforcmentHi All<br/><br/>I am doing test on 802.1x enforcement. what to know if there is way to wildcard printer and other IP enable devices without OS using the calling station ID feature. as it was disscussed in the following link. <a href="http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/cd410b9e-b6ff-4303-b6c0-44030a1adfd0?prof=required">http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/cd410b9e-b6ff-4303-b6c0-44030a1adfd0?prof=required</a>. I mananged to use MAC authentication with creating username and password using MAC Address in AD and created policy successfuly and put the printer into the vlan by NPS policy.  I want to know if there is other way. As we have over 1000 HP printers and it is lots of work to create that many user names<br/><br/>Thanks<br/><br/>DanielThu, 28 May 2009 19:22:21 Z2009-11-03T02:00:16Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0fe84e1b-22f8-4ec4-840f-b7c8b5e3a129http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0fe84e1b-22f8-4ec4-840f-b7c8b5e3a129David Kraxnerhttp://social.technet.microsoft.com/Profile/en-US/?user=David%20KraxnerNetwork Access Protection Agent failed to acquire a certificate for the request My network policy server suddenly quit functioning and is issuing thousands of errors (see below). Previously it had been functioning fine. Fortunately I was still in reporting mode. I am using NAP for IPsec. <br/><br/><strong>Event ID: 26 Source: HRA</strong><br/><span lang=EN>The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {3C0A1519-6C31-439E-B33E-8EE7BFE21DE8} - 2009-11-01 16:37:29.062Z from <a href="https://swopenps.swopeparkwayhc.int/domainhra/hcsrvext.dll">https://swopenps.swopeparkwayhc.int/domainhra/hcsrvext.dll</a>. The request failed with the error code (500). This server will not be tried again for 10 minutes.See the HRA administrator for more information.<br/><br/>On the client side<br/><br/><strong>Event ID: 21 Source: NAPAgent<br/></strong><span style="font-size:xx-small">The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {2CB52616-49C5-4CD7-B090-585AE90B4ECB} - 2009-11-02 04:09:06.276Z from https://swopenps.swopeparkwayhc.int/domainhra/hcsrvext.dll.<br/>The request failed with the error code (500). This server will not be tried again for 10 minutes.</span><br/><br/><strong>When I issue the command &quot;netsh nap client show configuration&quot; from a client I get the</strong> <strong>following:</strong><br/><br/>NAP client configuration:<br/>---------------------------------------------------- <p>Cryptographic service provider (CSP) = Microsoft RSA SChannel Cryptographic Prov<br/>ider, keylength = 2048</p> <p>Hash algorithm = sha1RSA (1.3.14.3.2.29)</p> <p>Enforcement clients:<br/>----------------------------------------------------<br/>Name            = DHCP Quarantine Enforcement Client<br/>ID              = 79617<br/>Admin           = Disabled</p> <p>Name            = Remote Access Quarantine Enforcement Client<br/>ID              = 79618<br/>Admin           = Disabled</p> <p>Name            = IPSec Relying Party<br/>ID              = 79619<br/>Admin           = Disabled</p> <p>Name            = Wireless Eapol Quarantine Enforcement Client<br/>ID              = 79620<br/>Admin           = Disabled</p> <p>Name            = TS Gateway Quarantine Enforcement Client<br/>ID              = 79621<br/>Admin           = Disabled</p> <p>Name            = EAP Quarantine Enforcement Client<br/>ID              = 79623<br/>Admin           = Disabled</p> <p>Client tracing:<br/>----------------------------------------------------<br/>State = Disabled<br/>Level = Disabled</p> <p>Ok.<br/><br/><strong>When I issue the command &quot;netsh nap client show grouppolicy&quot; from a client I get the</strong> <strong>following:</strong><br/><br/>NAP client configuration (group policy):<br/>----------------------------------------------------</p> <p>NAP client configuration:<br/>----------------------------------------------------</p> <p>Cryptographic service provider (CSP) = Microsoft RSA SChannel Cryptographic Prov<br/>ider, keylength = 2048</p> <p>Hash algorithm = sha1RSA (1.3.14.3.2.29)</p> <p>Enforcement clients:<br/>----------------------------------------------------<br/>Name            = DHCP Quarantine Enforcement Client<br/>ID              = 79617<br/>Admin           = Enabled</p> <p>Name            = Remote Access Quarantine Enforcement Client<br/>ID              = 79618<br/>Admin           = Disabled</p> <p>Name            = IPSec Relying Party<br/>ID              = 79619<br/>Admin           = Enabled</p> <p>Name            = Wireless Eapol Quarantine Enforcement Client<br/>ID              = 79620<br/>Admin           = Disabled</p> <p>Name            = TS Gateway Quarantine Enforcement Client<br/>ID              = 79621<br/>Admin           = Disabled</p> <p>Name            = EAP Quarantine Enforcement Client<br/>ID              = 79623<br/>Admin           = Disabled</p> <p>Client tracing:<br/>----------------------------------------------------<br/>State = Disabled<br/>Level = Disabled</p> <p>Trusted server group configuration:<br/>----------------------------------------------------<br/>Group            = HRA Servers<br/>Require Https    = Enabled<br/>URL              = <a href="https://swopenps.swopeparkwayhc.int/domainhra/hcsrvext.dll">https://swopenps.swopeparkwayhc.int/domainhra/hcsrvext.dll</a><br/>Processing order = 1</p> <p>User interface settings:<br/>----------------------------------------------------<br/>Title       = Swope Community Enterprises<br/>Description = Network Health Assessment<br/>Image       =</p> <p>Ok.<br/><br/>The command <strong>&quot;netsh nap client show configuration&quot; </strong>shows IPsec Relying Party as &quot;disabled&quot;, whereas the command <strong>&quot;netsh nap client show grouppolicy&quot; </strong>shows IPsec Relying Party as enabled.<br/><br/>When accessing the trusted server URL from the client's browser I get the message  &quot;500 - Internal server error&quot;, which from reading other posts normally indicates the ability to connect via SSL.<br/><br/>The clients used to receive the&quot;Health Cetificate&quot;, but are no longer receiving the certificates.</p> <p align=left>Here is my setup:<br/> 1 windows 2008 server .DC , Root CA and DNS<br/> 1 Windows 2008 server , NPS , HRA , Stand alone SUB<br/> 450 plus Windows XP Clients - Joined to the Domain <br/><br/>Any and all assistance is greatly appreciated.</p> </span>Mon, 02 Nov 2009 04:13:47 Z2009-11-04T06:50:44Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/cfa4cda6-fdb7-448e-b609-6ba0891bbc09http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/cfa4cda6-fdb7-448e-b609-6ba0891bbc09scomeauhttp://social.technet.microsoft.com/Profile/en-US/?user=scomeauNPS Installation Failure<p>I seem to be having the same issue as here: <a href="http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0571c5a4-5b51-43d9-a77e-26481b799119">http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/0571c5a4-5b51-43d9-a77e-26481b799119</a>, but it appears that no clear direction seems to be given.&nbsp; I've tried all the recommendations for security, etc., but still no-go on the install.&nbsp; Every time I try to install NPS on my one 2008 server, it fails and then asks to reboot for the uninstall.&nbsp; The Server Manager log gives the following:<br />4932: 2009-10-13 19:00:18.423 [CBS]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ...parents that will be auto-installed: '&lt;none&gt;'<br />4932: 2009-10-13 19:00:18.439 [CBS]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ...default children to turn-off: '&lt;none&gt;'<br />4932: 2009-10-13 19:00:18.501 [CBS]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ...current state of 'IAS NT Service': p: Staged, a: Staged, s: UninstallRequested<br />4932: 2009-10-13 19:00:18.501 [CBS]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ...setting state of 'IAS NT Service' to 'InstallRequested'<br />4932: 2009-10-13 19:00:18.548 [CBS]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ...'IAS NT Service' : applicability: Applicable<br />4932: 2009-10-13 19:01:26.315 [CbsUIHandler]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Initiate: <br />4932: 2009-10-13 19:01:26.330 [InstallationProgressPage]&nbsp; Installing...<br />4932: 2009-10-13 19:07:03.215 [CbsUIHandler]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Error: -2147021879 : <br />4932: 2009-10-13 19:07:03.215 [CbsUIHandler]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Terminate: <br />4932: 2009-10-13 19:07:03.230 [CBS] Error (Id=0) Function: 'NativeMethods.GetPackageStatus(out status)' failed: 80070bc9 (-2147021879)<br />4932: 2009-10-13 19:07:03.230 [CBS]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ...done installing 'IAS NT Service '. Status: -2147021879 (80070bc9)<br />4932: 2009-10-13 19:07:03.230 [InstallationProgressPage]&nbsp; Verifying installation...<br />4932: 2009-10-13 19:07:03.261 [Provider]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Skipped configuration of 'NetworkPolicyServer' because install operation failed.<br />4932: 2009-10-13 19:07:03.261 [Provider]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br />[STAT] ---- CBS Session Consolidation -----<br />[STAT] For <br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 'NetworkPolicyServer'[STAT] installation(s) took '405.9273872' second(s) total.<br />[STAT] Configuration(s) took '0.0100242' second(s) total.<br />[STAT] Total time: '405.9374114' second(s).<br /><br />The IAS NT Service fails installation.&nbsp; I've added the "Full Control" to the IAS folder, but still no go.<br /><br />By the way, at one time, I DID have NPS installed on this server, but after I installed 2008 SP2, the NPS service wouldn't start.&nbsp; I uninstalled NPS and tried to re-install but no go.&nbsp; I uninstalled SP2, but I still cannot install the NPS role.<br /><br />Any help here would be appreciated.&nbsp; This last NPS install is prohibiting me from a full 2008 migration.<br /><br />Thanks!</p>Wed, 14 Oct 2009 14:50:41 Z2009-10-31T22:55:25Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/8a1cbc9e-162e-4c0f-a133-86cd075a267ehttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/8a1cbc9e-162e-4c0f-a133-86cd075a267erixorhttp://social.technet.microsoft.com/Profile/en-US/?user=rixorNAP 802.1x Enforcement . client xp sp3 can't get automatic ip after manual remedation.Hello!<br/><br/>Server's:<br/>Windows 2008 DC, DHCP, NAP<br/>Windows 2003 CA<br/><br/>Client: <br/>Windows XP SP3<br/><br/><br/><span style="font-size:x-small">I have followed &quot;Step By Step Guide 802.1x&quot; But i'm having one problem i can't getting ip on resolve manual remedation, need force release/renew to get ip...it's correct?<br/><br/>Thanks,<br/><br/>rixor</span>Mon, 26 Oct 2009 08:19:34 Z2009-11-02T08:05:23Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/e801bdac-9347-4efb-9d7c-bcf4d64aa927http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/e801bdac-9347-4efb-9d7c-bcf4d64aa927WarrenRhttp://social.technet.microsoft.com/Profile/en-US/?user=WarrenRNPS & EAP-MD5Hi there,<br><br>We are currently working on the deployment of 802.1x enterprise-wide.  Since we have some old devices that don't support 802.1x natively, and have a Cisco infrastructure, we decided to go the MAC Authentication Bypass route.<br><br>When we tested it prior, we were running Windows 2003 + IAS.  The test was flawless, however, it required us to enable Reversable Encryption and relax our password complexity requirements, which was unacceptable.  We then decided to upgrade to Windows 2008 to leverage the seperate password/complexity policy requirements based on a user or a group of users.<br><br>I've just finished setting that up, and it works perfect.  We decided to go with NPS, as it had a bunch of features that were lacking from Windows 2003's IAS (namelly exporting the configuration and being able to import it to our other IAS/NPS servers).  We currently run the NPS service on our DC's (two of them for redundancy), however, we can't seem to make the MAC Authentication Bypass work.  After some digging, it seems that Microsoft has removed support for EAP-MD5 from Vista/2008.  They mention that there are third party EAPHost compliant vendors that 'may' have EAP-MD5 support, but I've been unable to find any.<br><br>My question is, has anyone else ran into this problem?  If so, how did you go about fixing it.  Unfortunately, Cisco only seems to support EAP-MD5 for the MAC Authentication Bypass, we're currently running this on 3560 Catalyst switches.  I'd much rather get it working again on our NPS servers, as I don't want to revert back to IAS, as it's a pain to replicate the configurations between more than 1 box.<br><br>Thanks!<br><br>Warren  Mon, 11 Aug 2008 18:11:17 Z2009-10-29T15:24:27Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/ecb61d7b-bfb3-4ab8-9a29-d3da5b8d0660http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/ecb61d7b-bfb3-4ab8-9a29-d3da5b8d0660curious userhttp://social.technet.microsoft.com/Profile/en-US/?user=curious%20userremote access quatantine enforcement client problems on windows 7<p>I am running windows 7 rtm and am having trouble with the remote access quarantine client, in fact the client doesn't appear to be on this computer.. when i go to napclcfg.msc the remote access quatantine enforcement client is not listed.  If I try to enable it from the command prompt, this is the message I get<br/><br/>C:\Users\whittla&gt;netsh nap client set enforcement ID = 79618 ADMIN = &quot;ENABLE&quot;<br/>Element not found.</p> <p><br/>set enforcement<br/>   [ID = ] id<br/>   [ADMIN = ] ENABLE|DISABLE</p> <p><br/>   Enables or disables enforcement clients. You can specify one or more<br/>   enforcement clients, but you must specify at least one. By default, all<br/>   enforcement clients are disabled.</p> <p><br/>   Id - the identifier for the Quarantine Enforcement Client (QEC).</p> <p><br/>   Examples:</p> <p>     set enforcement ID = 67213 ADMIN = &quot;DISABLE&quot;<br/><br/>And if I run the &quot;NETSH NAP CLIENT SHOW GROUPPOLICY&quot; command I get this result<br/><br/><br/>NAP client configuration:<br/>----------------------------------------------------</p> <p>Cryptographic service provider (CSP) = Microsoft RSA SChannel Cryptographic Prov<br/>ider, keylength = 2048</p> <p>Hash algorithm = sha1RSA (1.3.14.3.2.29)</p> <p>Enforcement clients:<br/>----------------------------------------------------<br/>Name            = DHCP Quarantine Enforcement Client<br/>ID              = 79617<br/>Admin           = Disabled</p> <p>Name            = IPsec Relying Party<br/>ID              = 79619<br/>Admin           = Disabled</p> <p>Name            = RD Gateway Quarantine Enforcement Client<br/>ID              = 79621<br/>Admin           = Disabled</p> <p>Name            = EAP Quarantine Enforcement Client<br/>ID              = 79623<br/>Admin           = Enabled</p> <p>Client tracing:<br/>----------------------------------------------------<br/>State = Enabled<br/>Level = Advanced</p> <p>Ok.<br/><br/>Which shows that the client isn't even installed.  How can I install that client.<br/><br/>Thanks</p>Sat, 05 Sep 2009 15:43:23 Z2009-10-29T01:03:05Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/d887f0fa-34de-4c41-a4ea-b92f8623b236http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/d887f0fa-34de-4c41-a4ea-b92f8623b236Nicoolaihttp://social.technet.microsoft.com/Profile/en-US/?user=Nicoolaianonymous access to sharesI am sure people have asked this a million times, but i have been unable to find a clear answer.<br/> I took advantage of the trial download of Windows server 2008 R2 and installed it for my small home network. Now i want to make some network drives, but i don't want to send a username. Basically, i want this share to be wide open, to anyone who will be on my network.<br/> For some reason though, i cannot get this to work.<br/> <br/> I have added the anonymous user as everyone policy and have tried to add the shares to the list of shares, that allows anonymous. I'm not sure it is correct though.<br/> How do i define the shares in the list?<br/> I have a share called Files which is located at d:\files\<br/> But what do i add to the list? Just Files or D:\files or \\servername\files or something else?<hr class="sig">Nicolai Søndergaard LM Glasfiber A/SWed, 28 Oct 2009 07:17:42 Z2009-10-30T01:19:35Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/8fe01654-e6e8-471a-bb57-203ef341c897http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/8fe01654-e6e8-471a-bb57-203ef341c897Kumar Rakeshhttp://social.technet.microsoft.com/Profile/en-US/?user=Kumar%20RakeshAuto configuration of NAP featuresDear All,<br /><br />Thank s for your help.<br /><br />i have some question for NAP as below -<br /><br />1. How to configure NAP client setting(certificate installation, HRA autodiscovery settings&nbsp;etc)&nbsp;for client machines from a centralized location (group policy or SCCM).<br />2.How to set HRA trusted servers on client machine automaticaly.<br /><br />your kind help will be highly appreciated.<hr class="sig">Rakesh KumarThu, 08 Oct 2009 06:17:33 Z2009-10-28T07:12:45Z