New Posts  All Forums:Forum Nav:

RADIUS - Page 2

post #11 of 17
Thread Starter 
BUMP

And it seems wroking perfectly while port mirroring is working... doing it on Edimax AP only, as it is worst among those.
Actually dropping EAP and retaining WPA connection happened few days ago on another floor.
Getting ready FreeRadius instead of M$ solution, in hopes that it's just m$ behavior.
MyCrap v1.2
(19 items)
 
  
CPUMotherboardGraphicsGraphics
i7 950 Rampage III Formula Evga 470 PNY 470 
RAMHard DriveCoolingOS
G.Skill 2x4GB DDR3 1600Mhz Ares Dual Channel C... Crucial m4 NH-D14 Win 7 Ultimate 
MonitorKeyboardPowerCase
LG Scarlet 42LH70YR LCD G15 TX950 HAF 932 
MouseAudioAudioAudio
G500 Marantz SR5006 B&W 804D Musical Fidelity M6i 
Other
KRK10S sub 
  hide details  
Reply
MyCrap v1.2
(19 items)
 
  
CPUMotherboardGraphicsGraphics
i7 950 Rampage III Formula Evga 470 PNY 470 
RAMHard DriveCoolingOS
G.Skill 2x4GB DDR3 1600Mhz Ares Dual Channel C... Crucial m4 NH-D14 Win 7 Ultimate 
MonitorKeyboardPowerCase
LG Scarlet 42LH70YR LCD G15 TX950 HAF 932 
MouseAudioAudioAudio
G500 Marantz SR5006 B&W 804D Musical Fidelity M6i 
Other
KRK10S sub 
  hide details  
Reply
post #12 of 17
Thread Starter 
Deployed FreeRadius on CentOS.
This morning: Edmiax is not responding. I get access-accept connecting via engenius AP, but stuck on obtaining IP.
Seems like it is not NPS fault after all.

Any ideas?

All of servers are on esxi5, 12 servers.
Edited by DiNet - 11/14/12 at 11:45pm
MyCrap v1.2
(19 items)
 
  
CPUMotherboardGraphicsGraphics
i7 950 Rampage III Formula Evga 470 PNY 470 
RAMHard DriveCoolingOS
G.Skill 2x4GB DDR3 1600Mhz Ares Dual Channel C... Crucial m4 NH-D14 Win 7 Ultimate 
MonitorKeyboardPowerCase
LG Scarlet 42LH70YR LCD G15 TX950 HAF 932 
MouseAudioAudioAudio
G500 Marantz SR5006 B&W 804D Musical Fidelity M6i 
Other
KRK10S sub 
  hide details  
Reply
MyCrap v1.2
(19 items)
 
  
CPUMotherboardGraphicsGraphics
i7 950 Rampage III Formula Evga 470 PNY 470 
RAMHard DriveCoolingOS
G.Skill 2x4GB DDR3 1600Mhz Ares Dual Channel C... Crucial m4 NH-D14 Win 7 Ultimate 
MonitorKeyboardPowerCase
LG Scarlet 42LH70YR LCD G15 TX950 HAF 932 
MouseAudioAudioAudio
G500 Marantz SR5006 B&W 804D Musical Fidelity M6i 
Other
KRK10S sub 
  hide details  
Reply
post #13 of 17
sounds a policy issue or a wrong secret. if you follow the help instructions for Microsoft server it will get you working. one thing that you dont really need to do is lock it to a hardware specific vendor because you can catch the policy through NPS by the fact its a radius and type of connection request (ip) or/and other criteria .
Alot of online suggestions and articles did not work because they are to specific in the connection request criteria. so really you just need a simple criteria for the connection request then create a secure but not over zealous network policy to go with it.

your problem isnt the fact that its microsoft or "M$" its a misconfigured policy

how are the users setup on the server? and are the users setup to authenticate on the the domain by username and password?

one thing that sucks with using eap-peap is that any change or sometimes just viewing settings on the wireless profile on the client will corrupt the wireless profile and you will have to re download and attach the certificate wireless profile.

one last thing is to check and make sure that the specific port you told the router to use for the radius request is opened on the firewalls (both hardware AND software) on both the client and the server. alot of times authentication can be erratic of there is something like a software firewall blocking certain parts of communication.
Edited by aCe_eXtreME - 11/16/12 at 6:11pm
    
CPUMotherboardGraphicsRAM
iI5 655k oc the crap outa RiP DFI iTX now GiGaByTE Asus 4870x2 TriFan 2x1GB Corsair 
Hard DriveOSMonitorKeyboard
150GB VelociRaptor W7 x64 Gateway DiamondTron NF CRT not proud of it 
PowerCaseMouseMouse Pad
600Watt SilverStone SilverStone Sugo SG07 iTX not proud of it Xtract RipperXL 
  hide details  
Reply
    
CPUMotherboardGraphicsRAM
iI5 655k oc the crap outa RiP DFI iTX now GiGaByTE Asus 4870x2 TriFan 2x1GB Corsair 
Hard DriveOSMonitorKeyboard
150GB VelociRaptor W7 x64 Gateway DiamondTron NF CRT not proud of it 
PowerCaseMouseMouse Pad
600Watt SilverStone SilverStone Sugo SG07 iTX not proud of it Xtract RipperXL 
  hide details  
Reply
post #14 of 17
Thread Starter 
Tanks for trying, but no.
MyCrap v1.2
(19 items)
 
  
CPUMotherboardGraphicsGraphics
i7 950 Rampage III Formula Evga 470 PNY 470 
RAMHard DriveCoolingOS
G.Skill 2x4GB DDR3 1600Mhz Ares Dual Channel C... Crucial m4 NH-D14 Win 7 Ultimate 
MonitorKeyboardPowerCase
LG Scarlet 42LH70YR LCD G15 TX950 HAF 932 
MouseAudioAudioAudio
G500 Marantz SR5006 B&W 804D Musical Fidelity M6i 
Other
KRK10S sub 
  hide details  
Reply
MyCrap v1.2
(19 items)
 
  
CPUMotherboardGraphicsGraphics
i7 950 Rampage III Formula Evga 470 PNY 470 
RAMHard DriveCoolingOS
G.Skill 2x4GB DDR3 1600Mhz Ares Dual Channel C... Crucial m4 NH-D14 Win 7 Ultimate 
MonitorKeyboardPowerCase
LG Scarlet 42LH70YR LCD G15 TX950 HAF 932 
MouseAudioAudioAudio
G500 Marantz SR5006 B&W 804D Musical Fidelity M6i 
Other
KRK10S sub 
  hide details  
Reply
post #15 of 17
Quote:
Originally Posted by DiNet View Post

Tanks for trying, but no.

so you figured it out?
    
CPUMotherboardGraphicsRAM
iI5 655k oc the crap outa RiP DFI iTX now GiGaByTE Asus 4870x2 TriFan 2x1GB Corsair 
Hard DriveOSMonitorKeyboard
150GB VelociRaptor W7 x64 Gateway DiamondTron NF CRT not proud of it 
PowerCaseMouseMouse Pad
600Watt SilverStone SilverStone Sugo SG07 iTX not proud of it Xtract RipperXL 
  hide details  
Reply
    
CPUMotherboardGraphicsRAM
iI5 655k oc the crap outa RiP DFI iTX now GiGaByTE Asus 4870x2 TriFan 2x1GB Corsair 
Hard DriveOSMonitorKeyboard
150GB VelociRaptor W7 x64 Gateway DiamondTron NF CRT not proud of it 
PowerCaseMouseMouse Pad
600Watt SilverStone SilverStone Sugo SG07 iTX not proud of it Xtract RipperXL 
  hide details  
Reply
post #16 of 17
what messages are you seeing on the radius side for the test client at the authentication stage?

give me a full break down of the security type, eap methods and eap version. are you using MSCHAP?
post #17 of 17
Thread Starter 
Quote:
Originally Posted by aCe_eXtreME View Post

so you figured it out?

Not sure yet what exactly happens. It's affecting 1 engenius AP now. Difference is, there's tons of errors in switch log.
Description it gives is broad, but seems like device is storming before it shuts down or gets disconnected by HP switch. And device becomes unreachable.
It started to happen 15 minutes before end of the day, so i got just some ideas for now smile.gif
Plus 4 other AP's are working fine, so policy is fine. And yes, they have same exact settings.

Weird thing it started to act like this when I changed radius server in it setting back to microsoft.
MyCrap v1.2
(19 items)
 
  
CPUMotherboardGraphicsGraphics
i7 950 Rampage III Formula Evga 470 PNY 470 
RAMHard DriveCoolingOS
G.Skill 2x4GB DDR3 1600Mhz Ares Dual Channel C... Crucial m4 NH-D14 Win 7 Ultimate 
MonitorKeyboardPowerCase
LG Scarlet 42LH70YR LCD G15 TX950 HAF 932 
MouseAudioAudioAudio
G500 Marantz SR5006 B&W 804D Musical Fidelity M6i 
Other
KRK10S sub 
  hide details  
Reply
MyCrap v1.2
(19 items)
 
  
CPUMotherboardGraphicsGraphics
i7 950 Rampage III Formula Evga 470 PNY 470 
RAMHard DriveCoolingOS
G.Skill 2x4GB DDR3 1600Mhz Ares Dual Channel C... Crucial m4 NH-D14 Win 7 Ultimate 
MonitorKeyboardPowerCase
LG Scarlet 42LH70YR LCD G15 TX950 HAF 932 
MouseAudioAudioAudio
G500 Marantz SR5006 B&W 804D Musical Fidelity M6i 
Other
KRK10S sub 
  hide details  
Reply
New Posts  All Forums:Forum Nav:
  Return Home
  Back to Forum: Networking & Security