cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
74207
Views
6
Helpful
26
Replies

Radius Connection Issue

Andy_NAG
Level 1
Level 1

setting up Radius Authentication for our corp network.

followed the instruction in terms of NPS but when i test the radius server it fails to connect. it doesnt give out any other error.

i checked the radius server and i have added the AP and went through event logs but i cant find any failures under security logs.

NPS logs doesnt have any record.

i am able to ping the radius server from the subnet i am on.

any other pointers or location i need to check.

26 Replies 26

yup i have all that.

removed the checks under constraints and testing now.

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

Lets check some basics (I'm assuming you are using WPA2-Enterprise mode):

  • Are you running an Enterprise CA?
  • Have you requested a certificate from that CA for the NPS server?
  • In Policies/Network Profiles:
    • On the Overview tab tick "Ignore user account dial-in properties"
    • I normally set a "Condition" that Nas-Port-Type=Wireless
      • Under "Constraints/Authentication Methods" un-tick all methods. Add PEAP. Edit PEAP and make sure the certificate you requested above is selected. Under EAP-Types make sure only EAP-MSCHAPv2 is selected.

will try this and let you know

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

And this is how the access points are setup (using the "Everything else" name).

image.pngimage.png

currently i have only added AP ip which is on different subnet compared to our corporate subnet.

so not sure if there is a point of adding the entire subnet

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

What connects these two subnets? Layer 3 switch, router, firewall?

Does the NPS server run antivirus that also contains a firewall?

Is Windows Firewall enabled on the NPS server? If so, has it got an exclusion for the 1812 and 1813 ports?

i might have to check the certificate its getting.

to my understanding all my settings are correct.

going through the certifcate requirement for this. let me see how i go.

its all sorted.

stupidest thing fixed the issue. not really sure how or why its fixed but its fixed.

IT 101 reboot the bloody NPS server.

TomC2
Community Member

For what it's worth, I was having this exact same issue with a Windows Server 2019 VM running NPS. Meraki could not connect to it, the key was right, the settings were right, everything was right. I rebooted the server and it suddenly started working.

Can I ask you this?

My MR42s gave been crapping out only on one of the radius SSIDs.

Did you notice something similar.

They could connect to NPS, but not to internet. sporadic in random parts of the building.

Is there a way to scedule weekly AP reboots all at once and I could just run them on Saturday at like 3am?

Thank you! This helped as the AP was relocated from another location and assigned new IP. I had to remove the AP from NPS and re-add with new IP/manual generated password. WORKED!

KayodeT
Community Member

Hi,

Had an issue where a few clients were not connecting to the WIF

- Radius, NPS, Computer Based Cert Auth, ADCS

- Certs OK on client and NPS

Other clients were connecting OK but my laptop and desktop seemed to not want to connect, wasnt even getting NPS radius reject messages on NPS, only on the meraki Dash.

Resolution,

It seems to be a problem with Win 10 21H2 and TPM (i have TPM2.0), i disabled TPM and wifi connects OK

Just to throw something out there about this issue

https://docs.microsoft.com/en-us/answers/questions/743920/nps-the-supplied-message-is-incomplete-the-signatu.html

KT

Review Cisco Networking for a $25 gift card