<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AiroNet 1140 Authentication Issues Windows Server 2008 NPS in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/aironet-1140-authentication-issues-windows-server-2008-nps/m-p/1823671#M140440</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any logs at the NPS server itself?&amp;nbsp; Attempt to authenticate again and then immediately open your 2008 server manager and navigate to...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Diagnostics &amp;gt; Event Viewer &amp;gt; Custome Views &amp;gt; Server Roles &amp;gt; Network Policy and Access Services&lt;/P&gt;&lt;P&gt;and &lt;/P&gt;&lt;P&gt;Diagnostics &amp;gt; Event Viewer &amp;gt; Windows Logs &amp;gt; Security&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you see any relevant entries for NPS as to why this request was rejected or client not authenticated?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see the AP is also configured as a local radius server.&amp;nbsp; This "should" not be a problem since your eap_methods is calling your rad_eap group, which is pointing back to NPS, however you might remove it for the sake of cleanliness of the config.&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;radius-server local&lt;/P&gt;&lt;P&gt;&amp;nbsp; no authentication mac&lt;/P&gt;&lt;P&gt;&amp;nbsp; nas 10.20.2.96 key 7 003555402B5F012F3D007B16062C46430759550B3A232F7E0A1636472C01402573&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lastly, on your NPS config, you may consider removing any "EAP Types" from the "settings" of the&amp;nbsp; "Connection Request Policy" and only include them in the "constraints" of the actual "Network Policy"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remove local radius config, connect a client, and post relevant NPS logs from event viewer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 Feb 2012 19:31:10 GMT</pubDate>
    <dc:creator>daviwatk</dc:creator>
    <dc:date>2012-02-08T19:31:10Z</dc:date>
    <item>
      <title>AiroNet 1140 Authentication Issues Windows Server 2008 NPS</title>
      <link>https://community.cisco.com/t5/wireless/aironet-1140-authentication-issues-windows-server-2008-nps/m-p/1823668#M140437</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have an AiroNet 1140 AP that we are trying to configure RADIUS authentication. Our RADIUS server is a Microsoft Windows Server 2008 NPS server. Unfortunately, our Wi-Fi clients are unable to authenticate. We appear to have everything configured on the AP and RADIUS server correctly, but we receive the following errors from the debug on the AP. Doug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Mar 14 05:46:58.413: RADIUS/DECODE: No response from radius-server; parse response; FAIL&lt;/P&gt;&lt;P&gt;*Mar 14 05:46:58.413: RADIUS/DECODE: Case error(no response/ bad packet/ op decode);parse response;&lt;/P&gt;&lt;P&gt;FAIL&lt;/P&gt;&lt;P&gt;*Mar 14 05:46:58.413: RADIUS/DECODE: No response from radius-server; parse response; FAIL&lt;/P&gt;&lt;P&gt;*Mar 14 05:46:58.413: RADIUS/DECODE: Case error(no response/ bad packet/ op decode);parse response;&lt;/P&gt;&lt;P&gt;FAIL&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 04:31:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/aironet-1140-authentication-issues-windows-server-2008-nps/m-p/1823668#M140437</guid>
      <dc:creator>puntgorda</dc:creator>
      <dc:date>2021-07-04T04:31:52Z</dc:date>
    </item>
    <item>
      <title>AiroNet 1140 Authentication Issues Windows Server 2008 NPS</title>
      <link>https://community.cisco.com/t5/wireless/aironet-1140-authentication-issues-windows-server-2008-nps/m-p/1823669#M140438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;that tells me that the NPS is either ignoring the request, or not receiving it.&amp;nbsp; In the NPS, you defined the AP as a NAS/Client?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post the config from the AP.&amp;nbsp; I'd also like to see the NPS config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Feb 2012 20:00:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/aironet-1140-authentication-issues-windows-server-2008-nps/m-p/1823669#M140438</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2012-02-07T20:00:20Z</dc:date>
    </item>
    <item>
      <title>AiroNet 1140 Authentication Issues Windows Server 2008 NPS</title>
      <link>https://community.cisco.com/t5/wireless/aironet-1140-authentication-issues-windows-server-2008-nps/m-p/1823670#M140439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Steve, Here is the config for the AP.&amp;nbsp; Some screenshots of the NPS config are below, too.&amp;nbsp; Please let me know if you need more information from our NPS server.&amp;nbsp; Thanks, Doug &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ap#sh run&lt;BR /&gt;Building configuration...&lt;/P&gt;&lt;P&gt;Current configuration : 2971 bytes&lt;BR /&gt;!&lt;BR /&gt;version 12.4&lt;BR /&gt;no service pad&lt;BR /&gt;service timestamps debug datetime msec&lt;BR /&gt;service timestamps log datetime msec&lt;BR /&gt;service password-encryption&lt;BR /&gt;!&lt;BR /&gt;hostname ap&lt;BR /&gt;!&lt;BR /&gt;logging rate-limit console 9&lt;BR /&gt;enable secret 5 $1$1IPZ$WkdzqdeeGvEPvQLCHfGXU.&lt;BR /&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa group server radius rad_eap&lt;BR /&gt; server 10.20.2.96 auth-port 1645 acct-port 1646&lt;BR /&gt;!&lt;BR /&gt;aaa group server radius rad_mac&lt;BR /&gt;!&lt;BR /&gt;aaa group server radius rad_acct&lt;BR /&gt;!&lt;BR /&gt;aaa group server radius rad_admin&lt;BR /&gt; server 10.20.2.96 auth-port 1645 acct-port 1646&lt;BR /&gt;!&lt;BR /&gt;aaa group server tacacs+ tac_admin&lt;BR /&gt;!&lt;BR /&gt;aaa group server radius rad_pmip&lt;BR /&gt;!&lt;BR /&gt;aaa group server radius dummy&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login eap_methods group rad_eap&lt;BR /&gt;aaa authentication login mac_methods local&lt;BR /&gt;aaa authorization exec default local&lt;BR /&gt;aaa accounting network acct_methods start-stop group rad_acct&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;dot11 syslog&lt;BR /&gt;!&lt;BR /&gt;dot11 ssid wifi&lt;BR /&gt;&amp;nbsp;&amp;nbsp; authentication open eap eap_methods&lt;BR /&gt;&amp;nbsp;&amp;nbsp; authentication network-eap eap_methods&lt;BR /&gt;&amp;nbsp;&amp;nbsp; authentication key-management wpa&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;username pg_ap privilege 15 secret 5 $1$rg0/$hTYIn.lysNUfxhzxqXonl/&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;bridge irb&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface Dot11Radio0&lt;BR /&gt; no ip address&lt;BR /&gt; no ip route-cache&lt;BR /&gt; !&lt;BR /&gt; encryption mode ciphers aes-ccm&lt;BR /&gt; !&lt;BR /&gt; ssid wifi&lt;BR /&gt; !&lt;BR /&gt; antenna gain 0&lt;BR /&gt; speed&amp;nbsp; basic-1.0 2.0 5.5 11.0 6.0 9.0 12.0 18.0 24.0 36.0 48.0 54.0 m0. m1. m2. m3. m4. m5. m6. m7.&lt;BR /&gt; m8. m9. m10. m11. m12. m13. m14. m15.&lt;BR /&gt; station-role root&lt;BR /&gt; bridge-group 1&lt;BR /&gt; bridge-group 1 subscriber-loop-control&lt;BR /&gt; bridge-group 1 block-unknown-source&lt;BR /&gt; no bridge-group 1 source-learning&lt;BR /&gt; no bridge-group 1 unicast-flooding&lt;BR /&gt; bridge-group 1 spanning-disabled&lt;BR /&gt;!&lt;BR /&gt;interface Dot11Radio1&lt;BR /&gt; no ip address&lt;BR /&gt; no ip route-cache&lt;BR /&gt; !&lt;BR /&gt; encryption mode ciphers aes-ccm&lt;BR /&gt; !&lt;BR /&gt; ssid wifi&lt;BR /&gt; !&lt;BR /&gt; antenna gain 0&lt;BR /&gt; dfs band 3 block&lt;BR /&gt; speed&amp;nbsp; basic-6.0 9.0 12.0 18.0 24.0 36.0 48.0 54.0 m0. m1. m2. m3. m4. m5. m6. m7. m8. m9. m10. m11&lt;BR /&gt;. m12. m13. m14. m15.&lt;BR /&gt; channel dfs&lt;BR /&gt; station-role root access-point&lt;BR /&gt; bridge-group 1&lt;BR /&gt; bridge-group 1 subscriber-loop-control&lt;BR /&gt; bridge-group 1 block-unknown-source&lt;BR /&gt; no bridge-group 1 source-learning&lt;BR /&gt; no bridge-group 1 unicast-flooding&lt;BR /&gt; bridge-group 1 spanning-disabled&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0&lt;BR /&gt; no ip address&lt;BR /&gt; no ip route-cache&lt;BR /&gt; duplex auto&lt;BR /&gt; speed auto&lt;BR /&gt; no keepalive&lt;BR /&gt; bridge-group 1&lt;BR /&gt; no bridge-group 1 source-learning&lt;BR /&gt; bridge-group 1 spanning-disabled&lt;BR /&gt;!&lt;BR /&gt;interface BVI1&lt;BR /&gt; ip address 10.40.0.200 255.255.0.0&lt;BR /&gt; no ip route-cache&lt;BR /&gt;!&lt;BR /&gt;ip default-gateway 10.40.0.1&lt;BR /&gt;ip http server&lt;BR /&gt;no ip http secure-server&lt;BR /&gt;ip http help-path &lt;A href="http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag"&gt;http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag&lt;/A&gt;&lt;BR /&gt;ip radius source-interface BVI1&lt;BR /&gt;radius-server local&lt;BR /&gt;&amp;nbsp; no authentication mac&lt;BR /&gt;&amp;nbsp; nas 10.20.2.96 key 7 003555402B5F012F3D007B16062C46430759550B3A232F7E0A1636472C01402573&lt;BR /&gt;!&lt;BR /&gt;radius-server attribute 32 include-in-access-req format %h&lt;BR /&gt;radius-server host 10.20.2.96 auth-port 1645 acct-port 1646 key 7 08100A08261D0F3E202A3B5C251E677C26&lt;BR /&gt;677B1C171E08576F7A4C077F19403C337F0C7C7D035B172550305F756934172E327A1B13250C154D4C3F1319305C3514&lt;BR /&gt;radius-server vsa send accounting&lt;BR /&gt;bridge 1 route ip&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt;line vty 0 4&lt;BR /&gt;!&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;ap#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/2/4/76423-Capture.PNG" class="jive-image" /&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/4/2/4/76424-Capture2.PNG" class="jive-image" /&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/2/4/76425-Capture3.PNG" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Feb 2012 19:05:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/aironet-1140-authentication-issues-windows-server-2008-nps/m-p/1823670#M140439</guid>
      <dc:creator>puntgorda</dc:creator>
      <dc:date>2012-02-08T19:05:35Z</dc:date>
    </item>
    <item>
      <title>AiroNet 1140 Authentication Issues Windows Server 2008 NPS</title>
      <link>https://community.cisco.com/t5/wireless/aironet-1140-authentication-issues-windows-server-2008-nps/m-p/1823671#M140440</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any logs at the NPS server itself?&amp;nbsp; Attempt to authenticate again and then immediately open your 2008 server manager and navigate to...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Diagnostics &amp;gt; Event Viewer &amp;gt; Custome Views &amp;gt; Server Roles &amp;gt; Network Policy and Access Services&lt;/P&gt;&lt;P&gt;and &lt;/P&gt;&lt;P&gt;Diagnostics &amp;gt; Event Viewer &amp;gt; Windows Logs &amp;gt; Security&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you see any relevant entries for NPS as to why this request was rejected or client not authenticated?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see the AP is also configured as a local radius server.&amp;nbsp; This "should" not be a problem since your eap_methods is calling your rad_eap group, which is pointing back to NPS, however you might remove it for the sake of cleanliness of the config.&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;radius-server local&lt;/P&gt;&lt;P&gt;&amp;nbsp; no authentication mac&lt;/P&gt;&lt;P&gt;&amp;nbsp; nas 10.20.2.96 key 7 003555402B5F012F3D007B16062C46430759550B3A232F7E0A1636472C01402573&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lastly, on your NPS config, you may consider removing any "EAP Types" from the "settings" of the&amp;nbsp; "Connection Request Policy" and only include them in the "constraints" of the actual "Network Policy"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remove local radius config, connect a client, and post relevant NPS logs from event viewer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Feb 2012 19:31:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/aironet-1140-authentication-issues-windows-server-2008-nps/m-p/1823671#M140440</guid>
      <dc:creator>daviwatk</dc:creator>
      <dc:date>2012-02-08T19:31:10Z</dc:date>
    </item>
    <item>
      <title>AiroNet 1140 Authentication Issues Windows Server 2008 NPS</title>
      <link>https://community.cisco.com/t5/wireless/aironet-1140-authentication-issues-windows-server-2008-nps/m-p/1823672#M140441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi David, &lt;/P&gt;&lt;P&gt;Here is an event in the NPS log. Doug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reason Code: 22&lt;BR /&gt;Reason: The client could not be authenticated because the Extensible Authentication Protocol (EAP) Type cannot be processed by the server. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Feb 2012 20:29:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/aironet-1140-authentication-issues-windows-server-2008-nps/m-p/1823672#M140441</guid>
      <dc:creator>puntgorda</dc:creator>
      <dc:date>2012-02-08T20:29:00Z</dc:date>
    </item>
    <item>
      <title>AiroNet 1140 Authentication Issues Windows Server 2008 NPS</title>
      <link>https://community.cisco.com/t5/wireless/aironet-1140-authentication-issues-windows-server-2008-nps/m-p/1823673#M140442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, since you are using PEAP on the server; make sure your client is configured as such (not smart card/etc)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MS further descrbes EAP Reason Code: 22 as...&lt;/P&gt;&lt;P&gt;Network Policy Server was unable to negotiate the use of an Extensible Authentication Protocol (EAP) type with the client computer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you remove the EAP types from the "connection request policy" and only use them in the conditions of the "network" policy?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Feb 2012 21:07:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/aironet-1140-authentication-issues-windows-server-2008-nps/m-p/1823673#M140442</guid>
      <dc:creator>daviwatk</dc:creator>
      <dc:date>2012-02-08T21:07:10Z</dc:date>
    </item>
    <item>
      <title>AiroNet 1140 Authentication Issues Windows Server 2008 NPS</title>
      <link>https://community.cisco.com/t5/wireless/aironet-1140-authentication-issues-windows-server-2008-nps/m-p/1823674#M140443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;It turned out the issue was with the certificate on the NPS server.&amp;nbsp; I replaced it and all is well.&amp;nbsp; Thank you,&amp;nbsp; Doug&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Feb 2012 13:33:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/aironet-1140-authentication-issues-windows-server-2008-nps/m-p/1823674#M140443</guid>
      <dc:creator>puntgorda</dc:creator>
      <dc:date>2012-02-10T13:33:51Z</dc:date>
    </item>
  </channel>
</rss>

