04-20-2018 02:45 PM - edited 02-21-2020 10:54 AM
dears,
I am doing EAP chaining and attached are the logs for the connection and screenshot for the authorization profile, the machine is in the AD domain still it is failing to authenticate ?? any hints experts.
the selected conditions are as belows
radius service type equal framed
radius nas port type equal Ethernet
Network access eap tunnel EAP-FAST
Network access authenticationmethod MSCHAPv2
Network access eap chaining results user and machine both succeeded
04-20-2018 04:13 PM
Hi
I see the following error in your log:
24344 RPC Logon request failed - STATUS_WRONG_PASSWORD,ERROR_INVALID_PASSWORD,jack-XYZ-OLD-PC$@XYZ.local
24485 Machine authentication against Active Directory has failed because of wrong password - XYZ_AD
What os version are you running on your pc?
04-20-2018 04:31 PM
Dear Francesco,
the windows version is 10 and I found the problem is due to the bug:
https://communities.cisco.com/thread/67962
and the fix is the below link
http://globalconfig.net/fix-eap-chaining-userpassedmachinefailed-issue-windows-8/
Thanks francesco
04-20-2018 05:15 PM
04-20-2018 05:48 PM - edited 04-20-2018 05:51 PM
Dear Francesco
Please find the attached screenshot,
I have small queries related to the connection statistics, when I click to see the statistic I saw the below
In the security information section:
encryption : none
Server:
credential type: None
In credential type it should show me username/password please correct me if I m wrong ??
and about encryption the complete session from windows machine to the ISE is encrypted then why encryption is shown as none.
04-22-2018 09:45 AM
04-22-2018 07:13 PM
04-24-2018 12:40 PM
Thanks Francesco
Can you validate that the machine hasn't been removed from AD
it is available
Can you try authenticating the machine only alone without eap-chaining to see what's happening?
only machine also fails
04-24-2018 01:30 PM
04-25-2018 07:03 AM
Dear Francesco,
If you are a cisco employee here is the TAC case number 684359762
thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide