cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
530
Views
15
Helpful
24
Replies

NPS RADIUS – “Message-Authenticator attribute is not valid

athan1234
Level 8
Level 8

Hi everyone,

Some time ago, I configured an SSID using 802.1X authentication with NPS, and it has been working correctly.

Now, I need to add a new SSID to the same NPS server. In this case, the computer that will connect to the SSID is not joined to the domain.

I created a new Network Policy in NPS and placed it at the top of the policy list. The conditions are:

  • NAS Port Type: Wireless – IEEE 802.11
  • Calling Station ID: *.wifiname$

The complete IP range is already configured under RADIUS Clients.

However, when I try to connect to the Wi-Fi network, I receive the following error in the NPS Event Viewer:

An Access-Request message was received from RADIUS client x.x.x.x with a Message-Authenticator attribute that is not valid.

I have been reading about this error, and several posts suggest that it may be related to an incorrect shared secret.

I have checked the shared secret and it seems to be correct. Nevertheless, to rule this out, I created a new RADIUS client containing only this AP and configured a completely new shared secret on both sides, Meraki and NPS.

Unfortunately, I still receive exactly the same error.

Has anyone experienced this issue before or have any idea what else I could check?

Thanks in advance.

 

 

 

 

 

24 Replies 24

aleabrahao
Meraki Community All-Star
Meraki Community All-Star

@athan1234 

Another thing that caught my attention is that you mentioned these users aren't in the domain, right? How do you expect NPS to validate these users?

Are they local users on the server? If NPS doesn't recognize the user base, this configuration won't work.

I am not a Cisco employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

Just a quick thought to share on the shared secret thing. Sometimes you might be using a character that is not supported by one or both devices and there is no specific message to help you with knowing that. Try to use a very simple shared secret and see if that works. If so, try to use a complex one with some standard symbols such as the ! and @.

I am using the same shared secret for another SSID, and it is working correctly.

For this reason, I am 100% sure that the shared secret is correct. i made this ssdi long time ago hahahaha

I could try changing it to a new, simpler shared secret just for testing, but I don't think the password itself is the problem, since the other SSID is currently working with the same one.

Makes sense, but probably I would still do it :). Also, if you could please share your redacted screenshots for review.

dylanfletcher37
Community Member

I would focus on Event ID 18 first. This means NPS is rejecting the RADIUS request while validating the Message Authenticator, so I would not spend much time changing the Network Policy yet.

Since you already tested the AP as a /32 RADIUS client with a new shared secret, I would capture one RADIUS request from the working SSID and one from the new SSID in Wireshark and compare them.

Check the source IP, Message Authenticator and the other RADIUS attributes being sent by the Meraki AP.

I would also check the Meraki RADIUS settings for the new SSID and see what Called Station ID and NAS ID are actually being sent.

The VLAN and the PC not being domain joined should not cause a Message Authenticator validation error. I would resolve that error first and then look at the Network Policy matching.

athan1234
Level 8
Level 8

Hmm... I’m not sure why I’m receiving this error:

Event ID :16

“A RADIUS message with the Code field set to 12, which is not valid, was received on port 1812 from RADIUS client APs-Meraki-xxx. Valid values of the RADIUS Code field are documented in RFC 2865.”

I’m not sure what could be causing this

aleabrahao
Meraki Community All-Star
Meraki Community All-Star

The combination of "invalid Message-Authenticator" and "Code 12" suggests NPS may be rejecting the RADIUS packet itself rather than the authentication request.

If possible, take a packet capture between the AP and NPS. That will quickly show whether the AP is sending malformed RADIUS packets, Status-Server probes, or something unexpected.

I am not a Cisco employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

 

  - @aleabrahao      >....suggests NPS may be rejecting the RADIUS packet itself rather than the authentication request.
                              That seems indeed true when looking at :
   https://community.cisco.com/t5/wireless/a-radius-message-with-the-code-field-set-to-12-which-is-not/m-p/5500172/highlight/true#M301305

   M.
               



-- ' Listen to the wind, it talks  
          Listen to the silence, it speaks
             Listen to your heart, it knows
Ganado Mucho (1809 to 1893 ) Navajo Indian

 

  -  @athan1234           FYI : https://community.cisco.com/t5/wireless/a-radius-message-with-the-code-field-set-to-12-which-is-not/m-p/5500172/highlight/true#M301305

  M.

 



-- ' Listen to the wind, it talks  
          Listen to the silence, it speaks
             Listen to your heart, it knows
Ganado Mucho (1809 to 1893 ) Navajo Indian

Davies66640
Community Member

The Message-Authenticator error can also be caused by an authentication-method or RADIUS configuration mismatch, not only the shared secret. Since you already tested with a new RADIUS client and shared secret, I’d check the Meraki SSID’s 802.1X/EAP settings and NPS policy conditions, especially the EAP method and certificate configuration.

Review Cisco Networking for a $25 gift card