Asked by:
NPS Error Code 23

General discussion
-
I just newly setup NPS for 802.1x wireless authentication. When a user tries to connect to the wireless network it is not connecting. Checked the log and its showing an error with Error code 23. Any thoughts on why this would be happening? I have the RADIUS clients on the NPS server set for all the WAP's on the network. Computer has the certificate that is setup in NPS.
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 5/12/2012 12:54:38 PM
Event ID: 6273
Task Category: Network Policy Server
Level: Information
Keywords: Audit Failure
User: N/A
Computer: PLTN-DC1.NLC.local
Description:
Network Policy Server denied access to a user.Contact the Network Policy Server administrator for more information.
User:
Security ID: S-1-5-21-1510070830-2813024272-3144571515-1205
Account Name: NLC\RGATES
Account Domain: NLC
Fully Qualified Account Name: NLC\RGATESClient Machine:
Security ID: S-1-0-0
Account Name: -
Fully Qualified Account Name: -
OS-Version: -
Called Station Identifier: 0E-27-22-BD-69-88:test
Calling Station Identifier: 70-F3-95-AF-BE-7ANAS:
NAS IPv4 Address: -
NAS IPv6 Address: -
NAS Identifier: -
NAS Port-Type: Wireless - IEEE 802.11
NAS Port: 0RADIUS Client:
Client Friendly Name: PLNPWPBO1
Client IP Address: 10.1.1.205Authentication Details:
Connection Request Policy Name: NLC Wireless
Network Policy Name: NLC Wireless
Authentication Provider: Windows
Authentication Server: PLTN-DC1.NLC.local
Authentication Type: PEAP
EAP Type: -
Account Session Identifier: -
Logging Results: Accounting information was written to the local log file.
Reason Code: 23
Reason: An error occurred during the Network Policy Server use of the Extensible Authentication Protocol (EAP). Check EAP log files for EAP errors.Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
<EventID>6273</EventID>
<Version>1</Version>
<Level>0</Level>
<Task>12552</Task>
<Opcode>0</Opcode>
<Keywords>0x8010000000000000</Keywords>
<TimeCreated SystemTime="2012-05-12T16:54:38.562402900Z" />
<EventRecordID>8225622</EventRecordID>
<Correlation />
<Execution ProcessID="588" ThreadID="2148" />
<Channel>Security</Channel>
<Computer>PLTN-DC1.NLC.local</Computer>
<Security />
</System>
<EventData>
<Data Name="SubjectUserSid">S-1-5-21-1510070830-2813024272-3144571515-1205</Data>
<Data Name="SubjectUserName">NLC\RGATES</Data>
<Data Name="SubjectDomainName">NLC</Data>
<Data Name="FullyQualifiedSubjectUserName">NLC\RGATES</Data>
<Data Name="SubjectMachineSID">S-1-0-0</Data>
<Data Name="SubjectMachineName">-</Data>
<Data Name="FullyQualifiedSubjectMachineName">-</Data>
<Data Name="MachineInventory">-</Data>
<Data Name="CalledStationID">0E-27-22-BD-69-88:test</Data>
<Data Name="CallingStationID">70-F3-95-AF-BE-7A</Data>
<Data Name="NASIPv4Address">-</Data>
<Data Name="NASIPv6Address">-</Data>
<Data Name="NASIdentifier">-</Data>
<Data Name="NASPortType">Wireless - IEEE 802.11</Data>
<Data Name="NASPort">0</Data>
<Data Name="ClientName">PLNPWPBO1</Data>
<Data Name="ClientIPAddress">10.1.1.205</Data>
<Data Name="ProxyPolicyName">NLC Wireless</Data>
<Data Name="NetworkPolicyName">NLC Wireless</Data>
<Data Name="AuthenticationProvider">Windows</Data>
<Data Name="AuthenticationServer">PLTN-DC1.NLC.local</Data>
<Data Name="AuthenticationType">PEAP</Data>
<Data Name="EAPType">-</Data>
<Data Name="AccountSessionIdentifier">-</Data>
<Data Name="ReasonCode">23</Data>
<Data Name="Reason">An error occurred during the Network Policy Server use of the Extensible Authentication Protocol (EAP). Check EAP log files for EAP errors.</Data>
<Data Name="LoggingResult">Accounting information was written to the local log file.</Data>
</EventData>
</Event>- Changed type Tiger LiMicrosoft employee Wednesday, May 16, 2012 5:58 AM
Saturday, May 12, 2012 5:48 PM
All replies
-
Hi,
In this thread the user was able to resolve the problem by reissuing the NPS server certificate.
See http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/c66cf0a8-24dd-4ccd-b5bb-16bd28ad8d4c for some detailed instructions.
I hope this helps,
-Greg
Saturday, May 12, 2012 6:12 PM -
Hi gatesr494,
Thanks for posting here.
I think we need fist to check the entries in EAP log where located under path “k%windir%\System32\Logfiles ” in order to accurately narrow down the root cause .
At this moment , could you generally discuss the settings we made on both server and client sides in case any misconfiguration? Or perhaps we can build the whole system with following the guide below:
802.1X Authenticated Wireless Access
http://technet.microsoft.com/en-us/library/cc771455(WS.10).aspx
Authentication Problem on a 802.1x Wireless Network
Regards,
Tiger Li
TechNet Subscriber Support in forum
If you have any feedback on our support, please contact tnmff@microsoft.com.
Tiger Li
TechNet Community Support
Monday, May 14, 2012 2:49 AM -
Hi gatesr494,
If there is any update on this issue, please feel free to let us know.
Regards,
Tiger Li
TechNet Subscriber Support in forum
If you have any feedback on our support, please contact tnmff@microsoft.com.Tiger Li
TechNet Community Support
Tuesday, May 15, 2012 8:32 AM