Discussion:
Server 2008 NPS and 802.1x with Cisco 2106 WLC
(too old to reply)
Roostermiester
2008-06-06 18:40:04 UTC
Permalink
Copied this posting from another group:

The NPS troubleshooting topic "Event ID 6273 — NPS Authentication Status"
might be of some assistance to you.

http://technet2.microsoft.com/WindowsServer2008/en/library/cafcb401-5e6e-4398-a571-efd93deb1eec1033.mspx

Also, just for future reference, the IAS/NPS Usenet newsgroup is
microsoft.public.internet.radius
I've setup Server 2008 NPS (which is also functioning as a DC) to
authenticate wireless clients through a Cisco 2106 wireless lan controller.
The computer certs are auto installed through Group Policy. However, when it
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 6/2/2008 12:24:38 PM
Event ID: 6273
Task Category: Network Policy Server
Level: Information
Keywords: Audit Failure
User: N/A
Computer: DC1.coaccess.com
Network Policy Server denied access to a user.
Contact the Network Policy Server administrator for more information.
Security ID: NULL SID
Account Name: 99C4R41.coaccess.com
Account Domain: COACCESS
Fully Qualified Account Name: COACCESS\99C4R41.coaccess.com
Security ID: NULL SID
Account Name: -
Fully Qualified Account Name: -
OS-Version: -
Called Station Identifier: 00-1F-CA-82-A1-80:coa
Calling Station Identifier: 00-90-96-A3-E4-1F
NAS IPv4 Address: 10.10.230.6
NAS IPv6 Address: -
NAS Identifier: COAWLC-2106
NAS Port-Type: Wireless - IEEE 802.11
NAS Port: 1
Client Friendly Name: COAWLC
Client IP Address: 10.10.230.6
Proxy Policy Name: Secure Wireless Connections Request
Network Policy Name: -
Authentication Provider: Windows
Authentication Server: DC1.coaccess.com
Authentication Type: EAP
EAP Type: -
Account Session Identifier: -
Reason Code: 8
Reason: The specified user account does not exist.
I haven't been able to come up with any good reason for the error. I do
recall having similar issues in a previous deployment and the solution was to
modify the computer name, but that has not worked in this case. Any ideas
what is causing this error?
Thanks
Roostermiester
2008-06-06 19:30:01 UTC
Permalink
What I don't get with this problem is that it doesn't even look like it's
hitting the Network Policy before it fails (it's not listed in the error).
Why then would I get a user account error?
Post by Roostermiester
The NPS troubleshooting topic "Event ID 6273 — NPS Authentication Status"
might be of some assistance to you.
http://technet2.microsoft.com/WindowsServer2008/en/library/cafcb401-5e6e-4398-a571-efd93deb1eec1033.mspx
Also, just for future reference, the IAS/NPS Usenet newsgroup is
microsoft.public.internet.radius
I've setup Server 2008 NPS (which is also functioning as a DC) to
authenticate wireless clients through a Cisco 2106 wireless lan controller.
The computer certs are auto installed through Group Policy. However, when it
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 6/2/2008 12:24:38 PM
Event ID: 6273
Task Category: Network Policy Server
Level: Information
Keywords: Audit Failure
User: N/A
Computer: DC1.coaccess.com
Network Policy Server denied access to a user.
Contact the Network Policy Server administrator for more information.
Security ID: NULL SID
Account Name: 99C4R41.coaccess.com
Account Domain: COACCESS
Fully Qualified Account Name: COACCESS\99C4R41.coaccess.com
Security ID: NULL SID
Account Name: -
Fully Qualified Account Name: -
OS-Version: -
Called Station Identifier: 00-1F-CA-82-A1-80:coa
Calling Station Identifier: 00-90-96-A3-E4-1F
NAS IPv4 Address: 10.10.230.6
NAS IPv6 Address: -
NAS Identifier: COAWLC-2106
NAS Port-Type: Wireless - IEEE 802.11
NAS Port: 1
Client Friendly Name: COAWLC
Client IP Address: 10.10.230.6
Proxy Policy Name: Secure Wireless Connections Request
Network Policy Name: -
Authentication Provider: Windows
Authentication Server: DC1.coaccess.com
Authentication Type: EAP
EAP Type: -
Account Session Identifier: -
Reason Code: 8
Reason: The specified user account does not exist.
I haven't been able to come up with any good reason for the error. I do
recall having similar issues in a previous deployment and the solution was to
modify the computer name, but that has not worked in this case. Any ideas
what is causing this error?
Thanks
Roostermiester
2008-06-06 20:14:01 UTC
Permalink
After playing around with the settings a bunch more I discovered it was a
matter of modifying the computer name (I had just modified it incorrectly
previously). On the connection request policy>Settings tab>Specify a
Realm>Attribute, under User-Name I added the following rule: replace
.domainname.com with $. After that change it worked fine. I don't know why
this isn't documented (or documented better) somewhere by now since it must
be an issue with a lot of deployments.
Post by Roostermiester
What I don't get with this problem is that it doesn't even look like it's
hitting the Network Policy before it fails (it's not listed in the error).
Why then would I get a user account error?
Post by Roostermiester
The NPS troubleshooting topic "Event ID 6273 — NPS Authentication Status"
might be of some assistance to you.
http://technet2.microsoft.com/WindowsServer2008/en/library/cafcb401-5e6e-4398-a571-efd93deb1eec1033.mspx
Also, just for future reference, the IAS/NPS Usenet newsgroup is
microsoft.public.internet.radius
I've setup Server 2008 NPS (which is also functioning as a DC) to
authenticate wireless clients through a Cisco 2106 wireless lan controller.
The computer certs are auto installed through Group Policy. However, when it
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 6/2/2008 12:24:38 PM
Event ID: 6273
Task Category: Network Policy Server
Level: Information
Keywords: Audit Failure
User: N/A
Computer: DC1.coaccess.com
Network Policy Server denied access to a user.
Contact the Network Policy Server administrator for more information.
Security ID: NULL SID
Account Name: 99C4R41.coaccess.com
Account Domain: COACCESS
Fully Qualified Account Name: COACCESS\99C4R41.coaccess.com
Security ID: NULL SID
Account Name: -
Fully Qualified Account Name: -
OS-Version: -
Called Station Identifier: 00-1F-CA-82-A1-80:coa
Calling Station Identifier: 00-90-96-A3-E4-1F
NAS IPv4 Address: 10.10.230.6
NAS IPv6 Address: -
NAS Identifier: COAWLC-2106
NAS Port-Type: Wireless - IEEE 802.11
NAS Port: 1
Client Friendly Name: COAWLC
Client IP Address: 10.10.230.6
Proxy Policy Name: Secure Wireless Connections Request
Network Policy Name: -
Authentication Provider: Windows
Authentication Server: DC1.coaccess.com
Authentication Type: EAP
EAP Type: -
Account Session Identifier: -
Reason Code: 8
Reason: The specified user account does not exist.
I haven't been able to come up with any good reason for the error. I do
recall having similar issues in a previous deployment and the solution was to
modify the computer name, but that has not worked in this case. Any ideas
what is causing this error?
Thanks
Loading...