ā10-06-2018 03:13 AM - edited ā03-08-2019 04:19 PM
Dear Sir,
i would like to ask about 802.1x authenication . i try to configure 802.1x Configure Wired 802.1X with NPS without using ISE or third-party appliance. I watched youtube training video and i followed these tutorials.
But when i am testing,i got authenication failed error.I tried to use EAP (PEAP) authenication method.
Please help me to troubleshoot in this case.Please see below Switchesdebug file and NPS server Logs
in
Solved! Go to Solution.
ā10-07-2018 09:00 PM
ā10-08-2018 10:58 AM
Hello there,
Have you tried setting the "Certificate Issued To" to the certificate that is local, or has the FQDN in the name, to any avail (i.e. one of the .local certs, I'm assuming)?
In the "Edit Protected EAP Properties" dialog box, according to the "Network Lessons" URL link provided in Francesco's comment:
"Make sure you have selected the correct certificate. This is the computer certificate that will be presented to wireless users when they connect using PEAP. It allows our wireless clients to confirm the identity of the RADIUS server."
and the Microsoft guide for Deploy server certificates for 802.1X wired and wireless deployments:
"In the Edit Protected EAP Properties dialog box, in Certificate issued to, NPS displays the name of your server certificate in the format ComputerName.Domain. For example, if your NPS is named NPS-01 and your domain is example.com, NPS displays the certificate NPS-01.example.com. In addition, in Issuer, the name of your certification authority is displayed, and in Expiration date, the date of expiration of the server certificate is shown."
Also can you confirm the current certificate configuration of the client computer?
Thanks
ā10-06-2018 11:45 AM
ā10-06-2018 10:08 PM
ā10-06-2018 11:02 PM
Hi ,
I am useing user certificate.
I am using PEAP .Not using MSCHAPv2.
i use auto enrollment certificate with GPO.But My server didn't recognized my computer as trusted.
my Radius said invilad client request.I think it is my certificate error.
I just want to know ,what kind of subject name will use for certificate ? i use user certificate template and subject name is PNP. In Certificate issued to drop drown list of NPS, what kind of certificate do i need to us i need to use local computer certificate or root CA ?.I am still confuse about this. I think i input wrong information request to create certificate
Please see below attachment for configuration screenshot
ā10-07-2018 01:41 PM
ā10-07-2018 04:49 PM
ā10-07-2018 09:00 PM
ā10-07-2018 11:51 PM
ā10-08-2018 01:27 PM
ā10-08-2018 10:58 AM
Hello there,
Have you tried setting the "Certificate Issued To" to the certificate that is local, or has the FQDN in the name, to any avail (i.e. one of the .local certs, I'm assuming)?
In the "Edit Protected EAP Properties" dialog box, according to the "Network Lessons" URL link provided in Francesco's comment:
"Make sure you have selected the correct certificate. This is the computer certificate that will be presented to wireless users when they connect using PEAP. It allows our wireless clients to confirm the identity of the RADIUS server."
and the Microsoft guide for Deploy server certificates for 802.1X wired and wireless deployments:
"In the Edit Protected EAP Properties dialog box, in Certificate issued to, NPS displays the name of your server certificate in the format ComputerName.Domain. For example, if your NPS is named NPS-01 and your domain is example.com, NPS displays the certificate NPS-01.example.com. In addition, in Issuer, the name of your certification authority is displayed, and in Expiration date, the date of expiration of the server certificate is shown."
Also can you confirm the current certificate configuration of the client computer?
Thanks
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: