11-02-2017 09:04 PM
setting up Radius Authentication for our corp network.
followed the instruction in terms of NPS but when i test the radius server it fails to connect. it doesnt give out any other error.
i checked the radius server and i have added the AP and went through event logs but i cant find any failures under security logs.
NPS logs doesnt have any record.
i am able to ping the radius server from the subnet i am on.
any other pointers or location i need to check.
Solved! Go to Solution.
11-07-2017 01:52 PM
its all sorted.
stupidest thing fixed the issue. not really sure how or why its fixed but its fixed.
IT 101 reboot the bloody NPS server.
11-02-2017 09:06 PM
That typically happens when the RADIUS key does not match.
In NPS (at least in Server 2012R2 or better) you can assign a subnet that all clients are in (such as 10.0.0.0/8) and a common key. This makes it easy to leave Meraki devices configured to use DHCP (like access points).
11-02-2017 09:18 PM
i am running this on Server 2012.
but if its a bad key shouldnt i see it somewhere??
i am using radius only for corp network and the ip's will be forwarded via dhcp from our lan.
11-02-2017 09:19 PM
Nope. It logs nothing - nudda - if the key is wrong.
11-02-2017 09:25 PM
great.
any other possibilities of why this is not working?
11-02-2017 09:38 PM
@Philip D'Ath is likely correct, the most common issue is a mismatched shared secret between the AP and RADIUS server, but it could sometimes be fat-fingered IP address settings and a UDP port mismatch (make sure it's using 1812 and not some other port like 1645). Any of those things would likely cause radio silence from the RADIUS server.
11-02-2017 09:41 PM
its definitely 1812 and i have confirmed the password with 2 different people its definetly right.
i am using my account with and without domain prefix and confirmed the password.
my admin account has access to NPS server so i am not sure what else can be wrong.
this is is annoying the living daylights out of me.
11-02-2017 09:52 PM
Are you using an actual wireless client/supplicant or the "Test" button on the Access Control page in Dashboard? You already ran packet captures and/or ran it by Support to assist with some pcaps? Let's see what is or isn't traversing the AP.
11-02-2017 10:01 PM
i am doing test via dashboard of meraki
11-02-2017 10:38 PM
11-02-2017 10:41 PM
I have had issues with NPS many times where it doesn't log anything to the event viewer, like it should. Enable the option to log to a TXT file. By default it writes it out to:
c:\windows\system32\LogFiles
And the files begin with IN*. As long as the RADIUS secret is correct it will log success and failed responses there. They are a pain to read.
11-02-2017 10:46 PM
Hi Philip,
i did check that location but i dont see any files with IN. all i see are multiple subfolders but nothing says as radius server related.
11-02-2017 10:48 PM
In NPS right click the NPS server and select "properties". Make sure you have ticked to logged accepted and rejected connections.
11-02-2017 10:49 PM
logs are ticked for authentication success n reject.
iam verifying your other reply
11-02-2017 10:53 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide