Conflicting IAS remote access policies problem



This concerns a IAS RADIUS server. I have a pre-existing IAS remote
access policy that authenticates all wireless users and allows them to
connect to my companies wireless network. I am a member of this
group.

I have created a second policy to allow exec priviledge logins to my
Cisco routers. I set the policy to allow anyone who is a member of
the Domain Admins group this right. I am a member of this group as
well.

When the wireless policy is listed first, and I attempt to login to my
Cisco router, I get an "IAS_INVALID_AUTH_TYPE" error in my IAS log,
but I can connect to my wireless network just fine. If I reverse the
order of the policies, I can log in to the Cisco router just fine, but
then I get the "IAS_INVALID_AUTH_TYPE" error when I connect to my
wireless network.

The logs also show that when the login is failing on the first policy,
it does not fall through to the second policy.

Is there any way around this? I want to stay in both the wireless
users and the Domain Admins groups; can I configure IAS to go down my
list of policies until I either reach one that accepts my login, or
I'm rejected by all policies? Thanks.
.



Relevant Pages

  • Re: Wireless Login help please
    ... bypass domain user configuration Group Policy. ... wireless card, logon with cached credentials, then plug their network card ... certificates may help. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Intermittent Wireless Connectivity
    ... From the Group Policy Properties menu, ... that the wireless policy is broken. ... > channel the kit was attempting to use was sitting at almost full ...
    (microsoft.public.windows.server.sbs)
  • Re: policy to enable login after network connection !! how ?
    ... I have some computer with wireless connection in our active directory ... I have put a policy on these computer to only login after network ... I'm presuming you mean "Always wait for network at computer startup & ... login" - it's a very good thing to use, ...
    (microsoft.public.windows.group_policy)
  • Re: Re-Authentication Woes
    ... The Wifi policy inside IAS included the user group "wireless" and the NAS ...
    (microsoft.public.internet.radius)
  • Re: Conflicting IAS remote access policies problem
    ... You need to define more specific remote access policies. ... The way RADIUS works is that you will authenticate based on the *first* matching policy. ... For example, to only apply the wireless policy to wirless connection, add the NAS-Port_Type to be Wireless - IEEE 802.11 condition ... I am a member of this ...
    (microsoft.public.security)