Re: wireless authentication before logon

From: S. Pidgorny (slavickp_at_yahoo.com)
Date: 12/01/04

  • Next message: shaunmd: "RE: Home page hijacking"
    Date: Wed, 1 Dec 2004 20:17:48 +1100
    
    

    Have you removed the default remote access policy in IAS? That's the one
    requiring the dial-in permission.

    -- 
    Svyatoslav Pidgorny, MVP, MCSE
    -= F1 is the key =-
    "MToddH" <MToddH@discussions.microsoft.com> wrote in message
    news:053D42DE-EEF8-45A1-87A8-4286705986F9@microsoft.com...
    > I checked the event viewer and found this every time my machine attemps to
    > authenticate.  I have my computer & user accounts in the group that has
    been
    > granted access to the remote access policy.  It's interesting that I don't
    > have a Dial-in tab on my computer accounts as has been mentioned in some
    KB
    > articles.  I do have a Dial-in tab for users.
    >
    > Reason-Code = 65
    > Reason = The connection attempt failed because remote access permission
    for
    > the user account was denied. To allow remote access, enable remote access
    > permission for the user account, or, if the user account specifies that
    > access is controlled through the matching remote access policy, enable
    remote
    > access permission for that remote access policy.
    >
    >
    >
    > "S. Pidgorny <MVP>" wrote:
    >
    > > First and foremost, review the logs on IAS and on the client. Enable
    > > debugging on the access point and capture debugging info too. there
    might be
    > > clues - or the solution giveaways. Load wireless sniffer and see if the
    > > client tries to authenticate at all.
    > >
    > > Make sure that you don't install the wireless card's vendor client
    > > software/control application/anything but the driver.
    > > Update the driver to the latest version, preferably through Windows
    Update.
    > > If that still doesn't work - try another wireless card.
    > >
    > > -- 
    > > Svyatoslav Pidgorny, MVP, MCSE
    > > -= F1 is the key =-
    > >
    > > "MToddH" <MToddH@discussions.microsoft.com> wrote in message
    > > news:44A90D45-D418-48A3-BC0B-EA66827DEAF3@microsoft.com...
    > > > I am testing a wireless configuration using 802.1x with the AP
    > > authentication
    > > > running through IAS RADIUS & AD.  I am using EAP-TLS.  I have issued
    > > computer
    > > > and user certificates to my test users.
    > > >
    > > > I am using Win2003 IAS & CA with a Win2000 AD.
    > > >
    > > > Authentication and access seems to be working fine for me after domain
    > > > logon, but I can't get my machine to authenticate before logon
    happens.  I
    > > > want to allow my clients to acquire an IP before logon.  I have turned
    on
    > > > "Authenticate as Computer" on my client and my computer account is
    added
    > > to
    > > > the group that has access to the remote access policy.  Any
    suggestions?
    > >
    > >
    > >
    

  • Next message: shaunmd: "RE: Home page hijacking"

    Relevant Pages

    • Re: wireless authentication before logon
      ... granted access to the remote access policy. ... the user account was denied. ... > client tries to authenticate at all. ...
      (microsoft.public.security)
    • Re: Re-Authentication Woes
      ... Are there any other policies in your remote access policy list? ... > The Wifi policy inside IAS included the user group "wireless" and the NAS ...
      (microsoft.public.internet.radius)
    • Re: Configure IAS for variable dialback
      ... > is the RAS for our dialing - in users. ... To configure IAS remote access policy to allow callback for the group you ...
      (microsoft.public.internet.radius)
    • Re: Issues with IAS/802.1x authentication
      ... the Nas-Port-Type attribute correctly to the IAS server, ... > As soon as I modified the IAS Remote Access Policy and removed this policy ... >> server is throwing up a heap of authentication errors, ...
      (microsoft.public.internet.radius)
    • Re: IAS
      ... > control access using only the remote access policy although you can still ... >> I am using chap, do I need the reverse password encryption changed? ...
      (microsoft.public.windows.server.active_directory)